Modern Work Weekly - Week of 2026-09-08
Four Critical CVEs land across Azure AD B2C, Copilot Studio, Azure AI Language, and Microsoft Fabric - plus GPT-6 Astra and Claude Fable 5.1 go live in Copilot, and Exchange hybrid shops face a hard version-floor deadline starting this week.
Top 5
Four Critical CVEs this week - Azure AD B2C and Azure AI Language both score CVSS 10.0. CVE-2026-83711 (Azure AD B2C, CVSS 10.0), CVE-2026-70352 (Azure AI Language, CVSS 10.0), CVE-2026-80098 (Copilot Studio, CVSS 9.3), and CVE-2026-70178 (Microsoft Fabric, CVSS 8.5) are all rated Critical. Three involve privilege escalation over the network with no authentication required. Check MSRC for patching status and verify your exposure, especially if you operate B2C tenants or Azure AI Language endpoints.
Exchange 2016/2019 version-floor enforcement starts the second week of September - that’s now. Microsoft is raising the minimum acceptable on-premises Exchange version for hybrid connectors to the final available Public Update. Servers below that baseline will be throttled and eventually blocked from delivering to Exchange Online. If your hybrid environment is behind on CUs, this is not a drill.
GPT-6 Astra and Anthropic Claude Fable 5.1 are both live in Microsoft 365 Copilot today. Both models are available in Copilot Cowork and Copilot Studio. Astra is grounded via Work IQ in your tenant’s files, meetings, and chats. Fable 5.1 is optimized for long-running financial and front-end coding tasks. Review your Copilot governance posture and data-handling policies before users start delegating sensitive work to new frontier models.
Teams-based IT support impersonation campaign observed in the wild. Microsoft Threat Intelligence documented a human-operated campaign that exploits Teams external access to impersonate IT support, establishes remote sessions, and deploys a Node.js implant. Review your Teams external access settings, audit guest/external user policies, and confirm Defender for Endpoint coverage on endpoints that accept remote assistance.
Memory integrity (HVCI) expands by default across eligible Windows devices in October 2026. Starting October, Microsoft will automatically enable VBS-based memory integrity on qualifying devices with no admin action required. Validate your hardware inventory now - devices that fail HVCI enablement will surface in deployment tooling, and incompatible drivers will block the change. Test application and driver compatibility in your pilot rings before rollout.
Identity & Access
- What’s new in Microsoft Entra: September 2026 [Preview] - The September Entra release brings GA for tenant governance with shadow IT tenant discovery and least-privilege governance relationships, alongside a wave of identity lifecycle and AI-era access security improvements. Review the change announcements section carefully for anything that requires configuration adjustments before enforcement begins. This is the authoritative monthly planning doc for your Entra roadmap.
Endpoint & Device Management
Windows news you can use: August 2026 [GA] - The August Windows roundup covers automated cloud-based device recovery, unattended remote support, post-quantum cryptography readiness, and Windows 365 improvements. Read this for a consolidated view of August changes that may require configuration or lifecycle action in your environment. Pay particular attention to the lifecycle milestone section for any upcoming end-of-support dates affecting your device fleet.
Expanding memory integrity protection across Windows devices [GA] - Starting October 2026, Microsoft will automatically enable VBS-based memory integrity (HVCI) on eligible devices, strengthening kernel-level protection against sophisticated attacks by default. Audit your hardware and driver inventory now; incompatible drivers will block enablement and surface as errors. Test in pilot rings before October to avoid broad disruption.
Collaboration & Productivity
Take control of your EWSAllowedAppIDs list before EWS access changes [GA] - As EWS retirement enters its final phase, Microsoft is refining how the EWSAllowedAppIDs allowlist is applied. If you have already configured EWSAllowedAppIDs, Microsoft will not overwrite it, but if you haven’t, you risk unexpected disruption when the platform applies its own defaults. Audit EWS usage and explicitly configure your allowlist now.
Introducing SharePoint News and Viva Engage cross-posting [GA] - Authors can now distribute a SharePoint news post directly to a Viva Engage storyline or community, with comments and reactions synchronized across both surfaces. This closes a long-standing workflow gap for corporate communications teams. No admin configuration required to enable the base capability, but review your information governance policies for cross-posting scenarios.
What’s New in Copilot in SharePoint: September 2026 [GA] - Personal Copilot skills now follow users across SharePoint and OneDrive, evaluations can measure and improve skill quality, and new guidance covers how AI agents can build live SharePoint-safe experiences. Reusable skills reduce redundant prompt engineering across your user base. Review the agent-safe content guidance if you have Copilot Studio agents operating against SharePoint content.
Exchange 2016/2019: Throttling and Blocking up to the Final Public Update Baseline [GA] - Starting the second week of September 2026, Exchange Online will throttle and then block inbound hybrid connector mail from Exchange 2016/2019 servers that are not at the final available Public Update. This is active enforcement, not a future warning. Identify any on-premises Exchange servers below the version floor and prioritize patching immediately.
Microsoft Teams Rooms: Platform choice delivers flexibility for your spaces [GA] - Microsoft reaffirms its commitment to platform-agnostic Teams Rooms experiences, with Certified for Teams covering a broad range of devices regardless of underlying OS. Useful context when planning meeting room refresh cycles or evaluating device procurement across Windows and Android MTR options.
Microsoft Teams: QR code protection in Teams messaging [GA] - QR codes from external senders will be obscured by default in Teams messages, requiring users to actively reveal them before viewing or scanning. This reduces phishing and quishing risk with no admin configuration required. Rolling out October 2026; plan user communications so help desk doesn’t get flooded with “QR code is missing” tickets.
Microsoft Teams: Add multiple steps when building a workflow from scratch [GA] - Teams workflow builder now supports multi-step flows when creating from scratch, previously a limitation that pushed users toward Power Automate for more complex scenarios. Rolling out September 2026. Expect increased self-service automation from users, which may warrant a review of your Power Platform governance policies.
OneDrive: Refreshed file browsing and filtering experience in OneDrive Web [GA] - OneDrive Web is getting multi-filter support across Home, Shared, People, Meetings, and Favorites views, plus the modern SharePoint document library layout extended to folder-based experiences. File-type filtering is now available via filter pills and the filter pane. A UX change end users will notice; low admin overhead but worth flagging in release comms.
Planner: Microsoft Planner tab support for shared and private channels in Microsoft Teams [GA] - Planner can now be added as a tab in shared and private channels, not just standard channels. This enables task management directly within restricted collaboration spaces. Available since August 2026; if you missed it, verify your channel governance policies cover Planner tab usage in private channels.
Microsoft Purview: Auto-labeling scalability, policy management, and reporting enhancements [Preview] - Purview auto-labeling is expanding to support larger SharePoint scopes, more flexible policy management, and richer activity reporting. Preview in September 2026, GA in October. If you’re running auto-labeling policies at scale today, pilot the expanded scope settings early to validate performance against your SharePoint environment.
Microsoft Teams: Automatic recording and transcription choices align with admin policies [GA] - Meeting organizers will only see automatic recording and transcription options that their assigned meeting policies permit. A new “Record only” choice lets recording start without transcription. Rolling out November 2026; review your meeting policies now to confirm the correct options will surface for each user group.
Microsoft Teams: Admins can control profanity filtering in meeting transcripts [GA] - A new meeting policy setting lets admins control whether profane words are masked in live transcription and saved transcripts, defaulting to filtered. When filtering is disabled by policy, the full text appears in live and saved transcripts while live captions remain per-user. Rolling out October 2026; determine whether any meeting policy groups in your tenant have a legitimate need for unfiltered transcripts.
AI & Copilot
Available today: OpenAI GPT-6 Astra in Microsoft Copilot [GA] - GPT-6 Astra is now live in Copilot Cowork and Copilot Studio, grounded via Work IQ in tenant files, meetings, chats, and business data within existing permissions. The model is designed for large task delegation rather than step-by-step guided work. Validate that your Copilot data access controls and sensitivity label policies are current before users begin delegating substantial workloads.
What’s New in Microsoft Copilot | August 2026 [GA] - August updates include effort-level and cost controls in Cowork, text selection and session sharing in Copilot Chat, Copilot Notebooks improvements, language selection for Teams meeting recaps, and hyperlinks and image understanding in several surfaces. Review the full list to determine what user training or communication touchpoints are warranted.
ASCII smuggling crosses over from AI prompt injection to phishing evasion [GA] - Invisible Unicode characters originally used to hide instructions from AI models are now being weaponized to bypass email filters. This is a technique shift worth tracking for your Defender for Office 365 and Purview DLP policy coverage. Review your email filtering stack and check whether your current policies catch Unicode-obfuscated content.
PPCC 2026: Bringing AI and your business processes together [GA] - Microsoft’s Power Platform Community Conference 2026 recap covers how AI agents are being integrated into enterprise business processes, with a focus on human-in-the-loop exception handling and cross-system orchestration. Useful context for architects evaluating where Copilot Studio agents fit alongside existing workflows.
White paper: Choosing between the GitHub Copilot and Standard harnesses in Copilot Studio [GA] - This white paper clarifies the architectural differences between the Standard and GitHub Copilot harnesses in Copilot Studio, covering how each handles context, instructions, tools, and task progression. If you’re building multi-step agents and haven’t settled on a harness, read this before committing to an architecture. The choice affects how models receive context and complete tasks, with real implications for enterprise scenarios.
Available today: Anthropic Claude Fable 5.1 in Microsoft Copilot [GA] - Claude Fable 5.1 is live in Copilot Cowork and Copilot Studio, optimized for long-running tasks, financial analysis, and front-end visual coding. Like Astra, it is grounded via Work IQ within your existing permissions model. Confirm your Copilot usage policies address third-party model selection, particularly if you operate in regulated industries.
Turbocharge your canvas development with the canvas authoring agent plugin - now generally available! [GA] - Canvas apps agentic coauthoring is now GA in Power Apps, enabling AI-assisted app creation directly in the canvas editor. This expands the low-code surface area for your Power Platform users significantly. Review Power Platform governance policies around app creation, particularly data connectivity and DLP rules, as citizen developer output will likely increase.
Microsoft Copilot (Microsoft 365): Create Videos in the Clipchamp Start Page [GA] - Users can now prompt Copilot from the Clipchamp start page to generate a video from a simple description or existing document, with automated script, visuals, narration, and assembly. This was targeted for April 2026 and is now confirmed GA. No admin configuration required, but factor this into any AI acceptable use or content creation governance policies.
Employee Experience
- Microsoft Viva: Create and customize PBI reports [GA] - Viva Insights leaders and analysts can now view Power BI reports with the ability to customize time ranges, filters, attributes, and visuals, then save the result for later use. Rolling out September 2026. Confirm that analyst-role assignments in Viva Insights are current so the right users have access to this reporting capability.
Security & Compliance
How to secure edge AI in customer-owned environments [GA] - Microsoft’s security blog covers verification strategies for AI systems, software, and assets running in customer-controlled environments before releasing sensitive data, credentials, or models. If your organization is deploying AI inference at the edge or in disconnected environments, this is required reading for your zero-trust architecture review.
Deploy an Agent to Azure AI Foundry [GA] - Short-form walkthrough showing how VS Code’s AI Toolkit extension packages a local agent and deploys it into Microsoft Foundry with enterprise controls applied. Practical reference for teams moving from local agent development to production hosting.
Help Shape the Microsoft Security Practitioner Community [GA] - Microsoft is soliciting feedback from practitioners on priorities, challenges, and learning preferences to shape future technical content and community programs. Worth five minutes of your time if you want the content to reflect real-world engineering work.
Red Team Your Azure AI Foundry Agent [GA] - Walkthrough of the AI red teaming agent in Microsoft Foundry, covering automated adversarial attack strategies including AsciiSmuggler, Base64, Jailbreak, StringJoin, UnicodeSubstitution, and IndirectJailbreak. Run this against your agents before shipping to production. Non-optional if you’re deploying agents that handle sensitive data or user-controlled input.
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access [GA] - Microsoft Threat Intelligence documented an active campaign abusing Teams external access to impersonate IT support, establish remote sessions, and deploy a Node.js implant for lateral movement. Review your Teams external access and guest policies, restrict who can initiate remote assistance sessions, and confirm Defender for Endpoint behavioral detection is current on all endpoints.
Action Required
CVE-2026-83711 - Microsoft Azure Active Directory B2C Elevation of Privilege | Critical · CVSS 10.0 | Surfaced in the Week of 2026-09-08 digest. Authorization bypass through user-controlled key allows an unauthenticated attacker to elevate privileges over the network. If you operate Azure AD B2C tenants, treat this as highest priority this week and verify Microsoft’s service-side mitigation is applied to your tenants.
CVE-2026-70352 - Azure AI Language Elevation of Privilege | Critical · CVSS 10.0 | Surfaced in the Week of 2026-09-08 digest. Missing authentication for a critical function allows an unauthenticated attacker to elevate privileges over the network. Validate your Azure AI Language endpoints and confirm whether Microsoft’s fix requires any tenant-side action via MSRC guidance.
CVE-2026-80098 - Copilot Studio Elevation of Privilege | Critical · CVSS 9.3 | Surfaced in the Week of 2026-09-08 digest. Improper cryptographic signature verification allows an unauthenticated attacker to elevate privileges over the network. Review Copilot Studio agent configurations and confirm service-side remediation has been applied; check MSRC for any required admin steps.
CVE-2026-70178 - Microsoft Fabric Elevation of Privilege | Critical · CVSS 8.5 | Surfaced in the Week of 2026-09-08 digest. Missing authorization allows an authenticated attacker to elevate privileges over the network. If you operate Microsoft Fabric workspaces, audit role assignments and verify Microsoft’s patch status through MSRC.
CVE-2026-62906 - Microsoft Discovery Studio Information Disclosure | Critical · CVSS 7.4 | Surfaced in the Week of 2026-09-08 digest. Improper neutralization of special elements in data query logic allows an unauthenticated attacker to disclose information over a network. Verify patch status via MSRC and assess exposure of any Discovery Studio deployments in your environment.
CVE-2026-50376 - Windows Remote Desktop Client Information Disclosure | Important · CVSS 6.5 | Surfaced in the Week of 2026-09-08 digest. Acknowledgment update only this cycle; the underlying vulnerability allows information disclosure via the RDC client. Confirm devices are running the patched build documented in the original MSRC advisory.
CVE-2026-84358 - Chromium: Improper privilege management in Downloads | Severity: not yet rated by MSRC | Surfaced in the Week of 2026-09-08 digest. Assigned by Chrome; Edge (Chromium-based) ingests the fix. Ensure Edge is updated to the current stable channel build.
CVE-2026-84354 - Chromium: Incorrect authorization in FileSystem | Severity: not yet rated by MSRC | Surfaced in the Week of 2026-09-08 digest. Assigned by Chrome; Edge (Chromium-based) ingests the fix. Ensure Edge is updated to the current stable channel build.
CVE-2026-84332 - Chromium: Incorrect authorization in SiteSettings | Severity: not yet rated by MSRC | Surfaced in the Week of 2026-09-08 digest. Assigned by Chrome; Edge (Chromium-based) ingests the fix. Ensure Edge is updated to the current stable channel build.
CVE-2026-84329 - Chromium: Confused deputy in CredentialProvider | Severity: not yet rated by MSRC | Surfaced in the Week of 2026-09-08 digest. Assigned by Chrome; Edge (Chromium-based) ingests the fix. CredentialProvider issues carry elevated risk given credential theft implications; prioritize Edge channel updates accordingly.
CVE-2026-84327 - Chromium: Incorrect authorization in Autofill | Severity: not yet rated by MSRC | Surfaced in the Week of 2026-09-08 digest. Assigned by Chrome; Edge (Chromium-based) ingests the fix. Ensure Edge is updated to the current stable channel build.
CVE-2026-84326 - Chromium: Uninitialized resource in V8 | Severity: not yet rated by MSRC | Surfaced in the Week of 2026-09-08 digest. Assigned by Chrome; Edge (Chromium-based) ingests the fix. V8 uninitialized resource issues can be exploited for memory disclosure or code execution; confirm Edge is current.
CVE-2026-84325 - Chromium: Improper input validation in DataTransfer | Severity: not yet rated by MSRC | Surfaced in the Week of 2026-09-08 digest. Assigned by Chrome; Edge (Chromium-based) ingests the fix. Ensure Edge is updated to the current stable channel build.
CVE-2026-84324 - Chromium: Use after free in Proxy | Severity: not yet rated by MSRC | Surfaced in the Week of 2026-09-08 digest. Assigned by Chrome; Edge (Chromium-based) ingests the fix. Use-after-free in Proxy is a memory safety issue with potential for exploitation; treat Edge update as urgent.
CVE-2026-84323 - Chromium: Missing authorization in FileSystem | Severity: not yet rated by MSRC | Surfaced in the Week of 2026-09-08 digest. Assigned by Chrome; Edge (Chromium-based) ingests the fix. Ensure Edge is updated to the current stable channel build.
Exchange 2016/2019 version-floor enforcement - active as of second week of September 2026. Servers connecting to Exchange Online via an OnPremises inbound connector that are not at the final available Public Update are now subject to throttling and eventual blocking. Run
Get-ExchangeDiagnosticInfoor check the Exchange admin center to identify servers below the version floor and schedule emergency patching if needed.EWSAllowedAppIDs configuration - act before EWS retirement enforcement tightens. If your tenant does not have an explicitly configured EWSAllowedAppIDs list, Microsoft may apply defaults that disrupt apps still relying on EWS. If you have configured the list, it will not be overwritten. Audit EWS usage via the Exchange admin center and configure the list proactively.
Documentation Updates
Identity & Access
Passkey and Authenticator registration campaign guidance rewritten - The registration campaign docs for passkeys and the Microsoft Authenticator app have been substantially rewritten; if you’re running or planning a phishing-resistant MFA rollout, re-read this guidance before configuring nudge campaigns.
New how-to: Secure an MCP server with Microsoft Entra ID - New guidance added covering how to protect a Model Context Protocol server using Entra ID authentication and authorization, directly relevant for teams deploying AI agent infrastructure that exposes MCP endpoints.
New Entra SOC Identity Responder role documented - Documentation for the new Entra SOC Identity Responder role has been added, covering its permissions and intended use for security operations center analysts responding to identity-based incidents.
Endpoint & Device Management
Intune device query role requirements updated - The required roles for running device queries in Intune have been updated in documentation; verify your role assignments if help desk or security analyst personas use device query for troubleshooting or incident response.
HAADJ pre-provisioning policy conflict limitation now documented - A known limitation where Autopilot pre-provisioning conflicts with certain policies on Hybrid Azure AD Joined devices is now formally documented; relevant if you’re running HAADJ pre-provisioning flows and encountering unexplained policy failures.
Security & Compliance
Strong identifier requirements for Defender XDR entity mapping documented - New documentation covers the strong identifier requirements needed for correct entity mapping in Defender XDR; gaps here affect alert correlation and incident quality, so review if you’re seeing entity mismatches in your XDR incidents.
Defender connectivity URLs updated with Microsoft 365 Unified Domains note - The Defender for Endpoint connectivity URL reference now includes a note on Microsoft 365 Unified Domains, which affects firewall and proxy allowlist configurations; verify your network allowlists if you manage Defender connectivity manually.
Sources
- https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-news-you-can-use-august-2026/ba-p/4552394
- https://techcommunity.microsoft.com/t5/windows-it-pro-blog/expanding-memory-integrity-protection-across-windows-devices/ba-p/4551984
- https://www.microsoft.com/en-us/security/blog/2026/09/04/secure-edge-ai-customer-owned-environments/
- https://www.youtube.com/shorts/MnHtkEVGQxA
- https://techcommunity.microsoft.com/t5/microsoft-security-community/help-shape-the-microsoft-security-practitioner-community/ba-p/4553560
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50376
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-84358
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-84354
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-84332
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-84329
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-84327
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-84326
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-84325
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-84324
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-84323
- https://www.youtube.com/shorts/L_A5ar3GdnE
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62906
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70178
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70352
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80098
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83711
- https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/
- https://techcommunity.microsoft.com/t5/microsoft-entra-blog/what-s-new-in-microsoft-entra-september-2026/ba-p/4545179
- https://techcommunity.microsoft.com/t5/exchange-team-blog/take-control-of-your-ewsallowedappids-list-before-ews-access/ba-p/4553534
- https://techcommunity.microsoft.com/t5/microsoft-sharepoint-blog/introducing-sharepoint-news-and-viva-engage-cross-posting/ba-p/4548258
- https://techcommunity.microsoft.com/t5/microsoft-sharepoint-blog/what-s-new-in-copilot-in-sharepoint-september-2026/ba-p/4535422
- https://techcommunity.microsoft.com/t5/exchange-team-blog/exchange-2016-2019-throttling-and-blocking-up-to-the-final/ba-p/4552717
- https://techcommunity.microsoft.com/t5/microsoft-teams-blog/microsoft-teams-rooms-platform-choice-delivers-flexibility-for/ba-p/4552748
- https://www.microsoft.com/microsoft-365/roadmap?id=570439
- https://www.microsoft.com/microsoft-365/roadmap?id=569209
- https://www.microsoft.com/microsoft-365/roadmap?id=566316
- https://www.microsoft.com/microsoft-365/roadmap?id=558928
- https://www.microsoft.com/microsoft-365/roadmap?id=570445
- https://www.microsoft.com/microsoft-365/roadmap?id=570468
- https://www.microsoft.com/microsoft-365/roadmap?id=570467
- https://techcommunity.microsoft.com/t5/microsoft-365-copilot-blog/available-today-openai-gpt-6-astra-in-microsoft-copilot/ba-p/4552808
- https://techcommunity.microsoft.com/t5/microsoft-365-copilot-blog/what-s-new-in-microsoft-copilot-august-2026/ba-p/4551960
- https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/
- https://www.microsoft.com/en-us/microsoft-365/blog/2026/09/03/ppcc-2026-bringing-ai-and-your-business-processes-together/
- https://techcommunity.microsoft.com/t5/copilot-studio-blog/white-paper-choosing-between-the-github-copilot-and-standard/ba-p/4552385
- https://techcommunity.microsoft.com/t5/microsoft-365-copilot-blog/available-today-anthropic-claude-fable-5-1-in-microsoft-copilot/ba-p/4551974
- https://www.microsoft.com/en-us/power-platform/blog/power-apps/turbocharge-your-canvas-development-with-the-canvas-authoring-agent-plugin-now-generally-available/
- https://www.microsoft.com/microsoft-365/roadmap?id=553215
- https://www.microsoft.com/microsoft-365/roadmap?id=566317
- https://github.com/MicrosoftDocs/entra-docs/commit/ab76f7de7333873390c720424afea825ef52b2b8
- https://github.com/MicrosoftDocs/entra-docs/commit/2506cb0e9fd71a43da77c640942654c7a99f8982
- https://github.com/MicrosoftDocs/entra-docs/commit/695c5a4305f52ffa93afb40752e1661efb4aef23
- https://github.com/MicrosoftDocs/memdocs/commit/fa795e95aa78d7b51b928d272b91f3bc788a0aba
- https://github.com/MicrosoftDocs/memdocs/commit/b729f2c4e2be02ba339c9296cc3fd56d0c6ce277
- https://github.com/MicrosoftDocs/defender-docs/commit/9b4ae349a44c5109142002716efd97b1859f1951
- https://github.com/MicrosoftDocs/defender-docs/commit/c67b323dceec4f51dc58fdc807da3cd24aa65bcb
