Modern Work Weekly — Week of 2026-06-30
Six CVEs land across libxml2, GNU gzip, attr, and acl for Linux-adjacent workloads, Intune's June release doubles down on AI-era endpoint hygiene, and a malicious Chromium extension spoofing Perplexity AI is actively redirecting browser search. EWS retirement remains on track for its October 2026 deadline.
Top 5 This Week
Six CVEs published across libxml2, GNU gzip, attr, and acl. These open-source components surface in Linux-adjacent and hybrid workloads. Review your exposure, especially on Azure Arc-connected Linux machines and any custom Docker images running in your environment.
Intune June release focuses on AI-era endpoint hygiene. Application currency, compliance at enrollment, and reduced vulnerability exposure are the headline themes. Review the release notes for new app management capabilities that can close version drift at scale.
Malicious Chromium extension spoofing Perplexity AI confirmed. The extension hijacks browser search using MV3 APIs. If you allow unmanaged browser extensions in your environment, this is a concrete case for tightening extension allowlisting policy in Intune or Defender for Endpoint.
Sentinel table insights panel now GA. Silent data connector failures and cost spikes are two of the most common Sentinel operational failures. This new 30-day ingestion view with anomaly detection and per-table cost estimates addresses both from a single pane.
Identity
- Secure AI at Scale: Join the Microsoft Entra + Purview Webinar Series [GA] — If your organization is scaling Copilot or custom AI agents, the identity and data governance gaps are compounding faster than most teams have budgeted for. This webinar series covers unifying identity access governance and data protection as a joint Entra and Purview strategy, specifically addressing non-human identities and AI prompt data flows. Worth registering your security architect and IAM lead.
Devices
What’s New in Microsoft Intune – June [GA] — This release targets the three fundamentals that AI-era endpoints require: compliance at enrollment, application currency, and reduced vulnerability surface. New app management capabilities address manual packaging overhead and version drift across large device fleets. Review the full release notes and identify which capabilities map to gaps in your current baseline.
Best Practices for Deploying Secure Boot Certificate Updates [GA] — Secure Boot certificate updates are rolling out across client devices, servers, and VMs via Windows Update, with OEM firmware support expanding in parallel. If you manage hybrid-joined servers or VMs with custom Secure Boot configurations, validate your deployment tooling and test certificate installation in a non-production group before broad rollout. The guidance includes proven validation tooling and rollout sequencing.
Microsoft a Leader in the Forrester Wave for Endpoint Management Platforms [GA] — Microsoft received the highest scores in both current offering and strategy in the Forrester Wave Q2 2026. Useful reference material for internal roadmap discussions or procurement justifications where you need third-party validation of the Intune platform direction.
Apps
Introducing Smarter Bot Protection in Microsoft Teams Meetings [GA] — Third-party AI bots joining meetings without explicit per-meeting consent have been a recurring privacy and security complaint. Teams now provides smarter detection and controls to prevent unauthorized bot attendance, particularly bots that persist across meetings after a one-time service connection. Review your meeting policy configuration and confirm bot admission controls are set appropriately for your sensitivity tiers.
Learning Agent Now Generally Available [GA] — Learning Agent in Microsoft 365 Copilot delivers personalized AI and Copilot skill recommendations based on each user’s role and work patterns, surfaced directly in Teams, Word, Excel, and PowerPoint. For orgs mid-rollout on Copilot licensing, this provides an in-product adoption pathway that reduces the need for separate change management campaigns. No additional configuration required beyond the M365 Copilot license.
Microsoft Teams: IntelliFrame People Labels in Teams Rooms on Windows [GA] — Remote participants will see AI-generated name labels on in-room attendees using voice and face profiles, with hover-over contact cards. Requires Teams Rooms Pro licensing and compatible intelligent cameras. Target availability is August 2026. Plan face enrollment policy and camera compatibility review if you manage a large Rooms estate.
Microsoft Copilot in PowerPoint: Edit Your Document in Government Clouds [GA] — GCC and sovereign cloud tenants will get Copilot-driven slide generation, layout updates, and brand kit integration in PowerPoint. GA target is September 2026. If you’re running GCC-H or GCC, add this to your Copilot rollout timeline and validate brand kit configuration ahead of release.
How to Determine Which Resource Mailboxes Are Being Actively Used [GA] — No native utilization report exists for Room, Equipment, or Workspace mailboxes. The Exchange team documents PowerShell-based approaches using
Get-CalendarViewingand related cmdlets to surface actual booking activity. Useful for pre-migration cleanup or license hygiene if you’re rationalizing your room mailbox inventory.Business Applications Built for Microsoft 365: Cubic Logics SharePoint Partner Showcase [GA] — Cubic Logics’ Apps365 portfolio covers contract management, HR, help desk, and related workflows built on SharePoint and the M365 ecosystem. Low engineering interest unless you’re evaluating SharePoint-native app alternatives to standalone SaaS tools.
Network
- How Karambit.AI and Microsoft Bring Software Authenticity to 14 Billion Files Per Month [GA] — Karambit.AI’s ecosystem-context approach augments static file analysis by determining whether a binary’s behavior is normal for its software lineage, not just whether it matches known signatures. At 14 billion files per month, this represents a meaningful signal layer for Defender’s detection pipeline. No direct admin action, but understanding this capability informs how you interpret Defender verdicts on packed or obfuscated binaries.
Visibility & Automation
Sentinel Table Insights: Monitor Ingestion Volume and Cost at a Glance [GA] — The new Table Insights panel on the Sentinel Tables page shows 30-day ingestion volume by tier, day-over-week fluctuations, top 5 tables by volume, last-data-received timestamps, estimated daily cost, and volume anomaly indicators. Silent connector failures and unexpected cost spikes are now detectable without custom workbooks or KQL queries. Enable this for every Sentinel workspace and establish a weekly review cadence for the anomaly indicator.
Chromium Extension Uses AI-Related Branding to Redirect Browser Search [GA] — A malicious extension spoofing Perplexity AI uses MV3 APIs and intermediary infrastructure to redirect browser search queries. This is an active threat targeting environments where users can install unvetted Chromium extensions. Audit your extension allowlist policy in Intune and Defender for Endpoint, and consider blocking extensions from outside the Chrome Web Store or a curated allow list.
CVE-2026-11979: Stack-Based Buffer Overflow in libxml2 [GA] — Stack-based buffer overflow in libxml2, a library widely bundled in Linux distributions and containerized workloads. Assess exposure on Arc-connected Linux machines and container images. Apply vendor patches as they become available and prioritize internet-facing or data-parsing workloads.
CVE-2026-41992 and CVE-2026-41991: Global Buffer Overflow and Predictable Temp File in GNU gzip [GA] — Two vulnerabilities in GNU gzip: a global buffer overflow and a predictable temporary file issue. Both affect Linux-based systems and pipeline workloads that process compressed archives. Patch gzip on all managed Linux endpoints and validate container base images.
CVE-2026-54371 and CVE-2026-54369: Symlink Traversal Privilege Escalation in attr and acl [GA] — Privilege escalation via symlink traversal in
attr(below 2.6.0) andacl(below 2.4.0) usinggetfattr,setfattr, andlibaclfunctions. Any Linux system running affected versions is at risk of local privilege escalation. Update both packages to the patched versions and verify current versions across your Linux fleet.CVE-2026-53325: Broken Error Propagation in agp/amd64 Kernel Module [GA] — Kernel-level issue in the AMD64 AGP driver affecting Linux systems. Scope is likely narrow for most M365 enterprise environments, but review if you run Linux VMs on AMD64 hardware with AGP exposed. Apply available kernel patches.
Action Required
EWS Disablement Deadline: October 2026 [GA] — Deadline: October 2026. Immediately audit all applications and service accounts authenticating to Exchange Online via EWS. Configure
EWSAllowedAppIDsto protect any app not yet migrated to Graph, then set hard internal migration milestones well before October. Do not wait for Microsoft to enforce disablement to discover dependencies.Malicious Chromium Extension: Active Threat Requiring Policy Review [GA] — Active threat. Review and tighten browser extension policies in Intune and Defender for Endpoint this week. Block installation of extensions outside an approved allow list, and hunt for the Perplexity AI-spoofing extension on any managed endpoints where extension installs are currently unrestricted.
CVE-2026-54371 and CVE-2026-54369: Privilege Escalation in attr and acl [GA] — Patch urgency: high for any environment with managed Linux endpoints. Update
attrto 2.6.0+ andaclto 2.4.0+ across all Linux systems. Validate patched versions in Arc-connected machines and container base images. Local privilege escalation via symlink traversal is a reliable lateral movement enabler in compromised environments.CVE-2026-11979 and CVE-2026-41992/41991: libxml2 and gzip Vulnerabilities on Linux Workloads [GA] — Patch as vendor updates land. Prioritize internet-facing Linux systems and any data pipeline workloads that parse XML or process compressed archives. Inventory affected package versions across Arc-connected machines, AKS nodes, and container base images before the next patch cycle closes.
Intune June Release: Application Currency and Enrollment Compliance [GA] — Within the next 30 days, review the June Intune release notes and identify new app management capabilities that address version drift in your environment. With AI agents increasingly acting on behalf of users, endpoint compliance and application currency are direct security controls, not just operational hygiene.
Sources
- https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-june/ba-p/4491983
- https://www.microsoft.com/en-us/security/blog/2026/06/25/microsoft-a-leader-in-the-forrester-wave-for-endpoint-management-platforms/
- https://techcommunity.microsoft.com/t5/windows-it-pro-blog/best-practices-for-deploying-secure-boot-certificate-updates/ba-p/4529884
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11979
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-53325
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41992
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41991
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54371
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54369
- https://techcommunity.microsoft.com/t5/microsoft-security-community/understand-your-sentinel-tables-at-a-glance-monitor-with-table/ba-p/4530738
- https://www.microsoft.com/en-us/security/blog/2026/06/29/chromium-extension-uses-airelated-branding-redirect-browser-search/
- https://techcommunity.microsoft.com/t5/microsoft-entra-blog/secure-ai-at-scale-join-the-microsoft-entra-purview-webinar/ba-p/4530257
- https://techcommunity.microsoft.com/t5/microsoft-security-community/how-karambit-ai-and-microsoft-bring-software-authenticity-to-14/ba-p/4528606
- https://www.microsoft.com/microsoft-365/roadmap?id=566702
- https://www.microsoft.com/microsoft-365/roadmap?id=566701
- https://www.microsoft.com/microsoft-365/roadmap?id=566700
- https://techcommunity.microsoft.com/t5/microsoft-teams-blog/introducing-smarter-bot-protection-in-microsoft-teams-meetings/ba-p/4531375
- https://techcommunity.microsoft.com/t5/exchange-team-blog/introducing-ewsallowedappids-preparing-for-the-final-phase-of/ba-p/4529471
- https://techcommunity.microsoft.com/t5/exchange-team-blog/how-to-determine-which-resource-mailboxes-are-being-actively/ba-p/4521577
- https://techcommunity.microsoft.com/t5/microsoft-365-copilot-blog/learning-agent-now-generally-available-personalized-ai/ba-p/4524571
- https://techcommunity.microsoft.com/t5/microsoft-sharepoint-blog/business-applications-built-for-microsoft-365-cubic-logics/ba-p/4530898
- https://techcommunity.microsoft.com/t5/microsoft-security-community/security-community-spotlight-sathish-veerapandian/ba-p/4530697
- https://techcommunity.microsoft.com/t5/microsoft-security-community/how-karambit-ai-and-microsoft-bring-software-authenticity-to-14/ba-p/4528606
