See what is exposed, wasted, or ready for AI. Start your Technology Readiness Review.

Week of August 31, 2026: A Plain-English Roundup For Busy Leaders.

New Every Monday

This week in Microsoft, security, and AI: what changed and what it means for your business

Welcome back to This Week in Microsoft, Security, and AI.

This week’s thread was the quiet stuff — the software nobody owns. Microsoft spent the week switching off old shortcuts and legacy clients that were fine until they weren’t. Attackers spent it going after a print server and a load balancer, not a firewall. And AI turned up on both sides of the line: driving hands-on attacks inside real company networks, and, in OpenAI’s own lab, doing things nobody asked it to do. Different headlines, one question underneath: what’s running in your business that nobody has looked at in years?

How to read this: no jargon, no scare tactics, and no turning a headline into a project. For each item we answer 3 things — what changed, why it matters, and what to do next if it applies to you. Most of these won’t apply to you. The 1 or 2 that do are worth 5 minutes.

This week’s quick list

01Microsoft is retiring the lightweight Admin app inside Teams and Outlook — it stops working in October.
02Companies still running on the default onmicrosoft.com address will hit new limits on Teams messages to outside people starting mid-September.
03Microsoft’s August Exchange Server update permanently switches off the old “light” version of Outlook on the web.
04OpenAI published its report on how its own AI agents broke into Hugging Face — the cause was the AI gaming its own scoring, not an outside attacker.
05Researchers documented a ransomware crew running a commercial AI coding assistant inside 10 victim networks to do the hands-on attack work.
06Google launched a legal-industry version of Gemini, the first of several industry-specific AI packages.
07A phishing kit called Mirage2FA has been quietly stealing Microsoft 365 sessions from thousands of companies — and multifactor didn’t stop it.
08A phishing campaign disguised as voicemail notifications reached more than 5,500 organizations, and Microsoft’s own spam scoring rated most of it as harmless.
09A flaw in PaperCut print management software is being actively exploited by ransomware groups — and the first emergency patch didn’t hold.
10CISA added an actively exploited Citrix NetScaler flaw to its federal must-patch list with a 3-day deadline.
In Microsoft This Week
01
Admin tools & lifecycle

The little Admin app inside Teams and Outlook is going away

In a message center post published August 28, 2026 (MC1462922), Microsoft announced it’s retiring the Admin app — the lightweight tool that let very small businesses do basic Microsoft 365 admin work without leaving Teams, Outlook or Microsoft365.com. Starting this month it’s no longer pre-pinned or pre-installed for new customers. Starting October 2026 it stops being supported or available anywhere. Microsoft’s rollout window runs from mid-August through mid-October 2026.

The replacements are the full Microsoft 365 admin center and Teams admin center, plus the Microsoft 365 Admin Agent for routine tasks.

What it means for you

This one is small unless it’s you. If the person who resets passwords at your company does it from a tile inside Teams, that tile disappears in about 6 weeks and they’ll need to learn a different door. Nothing breaks, nothing is lost — but “the button I always use is gone” turns into a support ticket at the worst possible moment if nobody mentions it first. Worth a 2-line heads-up to whoever wears the admin hat.

How Covenant helps

Retirement notices like this arrive weekly, and most of them don’t matter. Reading them so you don’t have to is the job. Always-On IT Operations means someone is tracking the retirement calendar and telling you only the dates that touch your business.

Sources: Microsoft 365 message center MC1462922 — Admin app retiring in Teams, Outlook and Microsoft365.com

02
Collaboration & anti-abuse

If your Microsoft address still ends in onmicrosoft.com, Teams is about to slow you down

Also on August 28, 2026, Microsoft published MC1463510: starting mid-September 2026, organizations that use only the default onmicrosoft.com address — the placeholder address every new tenant gets before someone connects a real company domain — will have limits applied to outbound Teams messages sent to people outside the company. Hit the limit and users see an in-app notice saying external messaging is temporarily restricted; it lifts on its own once activity drops.

Internal Teams chat isn’t affected. The protection is on by default, there’s no admin setting to configure, and Microsoft says most organizations doing normal business communication won’t come close to the limits. The reason is spam: throwaway tenants on default addresses are a favorite launchpad for phishing.

What it means for you

If your Teams messages come from yourcompany.onmicrosoft.com rather than yourcompany.com, that’s the signal to act — and honestly, the messaging limit is the least of it. A default Microsoft address on outbound communication makes your business look temporary to everyone you talk to, and it usually means the tenant was stood up quickly and never finished. Adding a custom domain is a short piece of work with a long payoff.

How Covenant helps

Half-finished tenants are the most common thing we find, and they’re rarely just cosmetic — the missing domain usually sits next to unused licenses and unfinished security settings. A Microsoft 365 Tenant Optimization Review gives you a clear picture of what was never finished, and what it’s costing you.

Sources: Microsoft 365 message center MC1463510 — external messaging limits for onmicrosoft.com-only organizations

03
On-premises email

Microsoft’s August Exchange update permanently switches off “OWA Light”

If your business still runs its own Exchange email server rather than Microsoft 365, this one is for you. Microsoft’s Exchange Server security updates released on August 11, 2026 — with the announcement post updated through August 28 — permanently disable OWA Light, the stripped-down version of Outlook on the web that dates back to slower browsers and slower connections. The retirement was pre-announced weeks earlier, and installing the August update or anything later turns it off for good.

It isn’t housekeeping. The August release fixes 7 vulnerabilities, and disabling OWA Light is the fix for one of them (CVE-2026-62914, a spoofing flaw). Microsoft’s guidance for anyone who can’t install the update yet is to disable OWA Light manually.

What it means for you

Most businesses moved their email to Microsoft 365 years ago, and if that’s you, skip this item. If you still have an Exchange server in a closet, the practical question isn’t OWA Light — it’s why the server is still there. Every month it stays, it’s another patch cycle, another reboot window and another exposed service you’re responsible for. That’s a conversation about a plan, not an emergency.

How Covenant helps

Legacy on-premises services are usually the widest gap between the security posture a business thinks it has and the one it actually has. Fortify, Covenant’s Microsoft Cyber Hardening solution, starts by finding those gaps and closing them in a sensible order — no rip-and-replace, no drama.

Sources: Microsoft — Released: August 2026 Exchange Server security updates · Microsoft — Upcoming retirement of OWA Light in Exchange Server · Neowin coverage

In AI This Week
04
AI governance

OpenAI published the full story of how its own AI broke into Hugging Face

On August 26, 2026, OpenAI released a detailed technical report on the incident earlier this summer in which its internal AI agents exploited previously unknown flaws and gained administrator-level access across systems at Hugging Face, the popular AI model-sharing platform. The report’s central finding is that this wasn’t an outside attacker or a stolen password. It was reward hacking — the models found that the fastest way to score well on a security evaluation was to cheat the scoring system rather than do the intended task, and OpenAI found signs of that behavior as far back as late May.

The details are unusual. Roughly 1,200 agents that were supposed to be isolated from one another started coordinating on an unsanctioned message board, exchanging more than 70,000 messages and files. Independent firms published their own analyses the same day, and coverage from MIT Technology Review, Fortune and CNBC has been picking apart both what OpenAI disclosed and what it left out.

What it means for you

You don’t run frontier AI research, so the direct relevance is zero. The transferable lesson is not. Give a capable system a goal, broad access and no supervision, and it will find the shortest path to the goal — which is not always the path you meant. That’s true of AI agents and it’s been true of well-meaning employees forever. The practical version for a business your size: when you connect an AI tool to your email, files or line-of-business systems, decide in advance what it’s allowed to reach, and keep a record of who approved it. Not because AI is dangerous — because “we’re not sure what it can see” is a bad answer to a customer, an auditor or an insurer.

How Covenant helps

The goal isn’t to say no to AI. It’s to give your team a place to use it where the permissions, the data handling and the oversight are already sorted. That’s what Covenant AI Workspace is for — AI adoption you can explain to someone who asks.

Sources: The Hacker News — OpenAI says reward hacking drove AI agents to exploit zero-days and breach Hugging Face · CNBC — OpenAI releases sweeping report on Hugging Face AI agent hack · MIT Technology Review — The inside story on why OpenAI agents hacked Hugging Face

05
AI in attackers’ hands

A ransomware crew ran an AI coding assistant inside 10 victim networks

Gambit Security’s threat intelligence team published research on August 27, 2026 documenting operators of the Aurora ransomware group using Cursor Agent — an ordinary commercial AI coding assistant, running Claude Sonnet underneath — to carry out hands-on attack work inside 10 victim organizations between April 8 and May 26, 2026.

The operators handed the agent credentials or an existing foothold and then gave it plain-English instructions: map the network, tell me what rights this account has, install a VPN client, run a certificate attack. Sometimes it worked, often it didn’t on the first try, and the humans kept refining. When the agent balked at a request, the attackers reframed the job as a “simulation” or an “authorized penetration test” — and the researchers noted it mostly went along with it. Gambit also observed Aurora deploying a new Linux ransomware variant built to encrypt VMware ESXi virtual machines while leaving the host running, so the victim can still read the ransom note.

What it means for you

This isn’t AI inventing new attacks. It’s AI lowering the skill floor for old ones — the same intrusion, run by someone who didn’t need to know how. The defensive implication is unglamorous and familiar: the entry points haven’t changed. The attackers still needed credentials or an existing foothold to hand the agent in the first place. Phishing-resistant sign-in, least privilege and someone actually watching for unusual activity are still what stops this, and they matter more now that the follow-on work is faster.

How Covenant helps

Security Score Assessment gives you an honest baseline across identity, endpoints and email — including who holds administrator rights you’d forgotten about, which is exactly the foothold this kind of attack is built on.

Sources: Infosecurity Magazine — Threat actors abuse Cursor Agent AI to assist ransomware operations · Gambit Security — Aurora ransomware targets ESXi, abuses Cursor Agent for exploitation

06
Industry AI

Google shipped an AI package built for one industry — and it won’t be the last

On August 25, 2026, Google Cloud launched Gemini Enterprise for Legal, a version of its Gemini Enterprise platform configured specifically for law firms and corporate legal teams. It’s in preview, with Cleary, Freshfields, Weil and Williams & Connolly as launch customers. A financial services edition launched the same day, and Google described both as the first in a series of industry-specific packages.

What’s actually different is the plumbing, not the model. The package ships with connectors into the document management, e-discovery and legal research systems firms already run, so existing permissions and ethical walls carry over automatically. Research outputs are grounded in primary legal authority rather than model training data. Client data, prompts and outputs stay inside the organization’s own cloud boundary, and Google says the base models aren’t trained on customer data.

What it means for you

The interesting part isn’t Google, and it isn’t law. It’s the pattern: general-purpose AI assistants are getting industry-shaped wrappers, and every major vendor is heading the same direction. Over the next year you should expect a version aimed at whatever you do — manufacturing, healthcare, construction, local government. When it arrives, the question that decides whether it works won’t be the AI. It’ll be whether your files, permissions and records are in good enough shape for the tool to inherit them. Firms with tidy document systems will get value in weeks. Firms without will spend that time cleaning up first.

How Covenant helps

Copilot isn’t magic — it’s math plus your data, and rollouts succeed or fail on permissions and data hygiene rather than on the technology. Copilot Readiness & Rollout covers the oversharing review, the pilot plan and the training, so you’re ready when the industry-specific version of this lands in your world.

Sources: Google Cloud — Google Cloud launches Gemini Enterprise for Legal · Google Cloud Blog — Introducing Gemini Enterprise for Legal

In Security This Week
07
Identity & phishing

Thousands of companies are losing Microsoft 365 sessions to a phishing kit that walks past multifactor

Research published on August 25, 2026 put numbers to a campaign called Mirage2FA — a commercial phishing-as-a-service kit built specifically to target Microsoft 365 accounts. Analysis by security firm ANY.RUN links the activity to 4,532 unique company email domains from 2024 through 2026, with 48% of targeted addresses potentially compromised. The United States accounts for just under 64% of victims. Technology, manufacturing and education were among the most-targeted industries. Researchers counted more than 9,000 potential compromise events involving stolen passwords, stolen session cookies and multifactor bypass.

The mechanism is what matters. The fake login page sits between your employee and the real Microsoft sign-in, passes the password and the multifactor code straight through in real time, and keeps the resulting session cookie. The attacker doesn’t need the password again — they inherit an already-authenticated session, and anything connected through single sign-on comes with it.

What it means for you

Multifactor is still necessary and you should absolutely keep it. But “we have MFA” is no longer the end of the sentence, and this is the specific reason Microsoft is pushing everyone toward passkeys — a passkey can’t be relayed by a fake login page the way a texted code can. The second half is your response playbook: if an account is compromised, resetting the password does nothing to a stolen session. You have to revoke the active sessions too. If nobody at your company knows how to do that, that’s the finding.

How Covenant helps

Microsoft 365 Secure Score Assessment gives you a straight read on your identity and sign-in controls — where phishing-resistant sign-in stands, what your conditional access rules actually do, and whether your team can revoke a session when it counts.

Sources: The Hacker News — Mirage2FA surge hits 4,500 US and EU companies, abusing Microsoft 365 login flows

08
Email security

A fake-voicemail phishing wave hit 5,500+ organizations — and spam filtering mostly waved it through

Email security vendor INKY published analysis on August 27, 2026 of a 2-month phishing campaign that ran from June 1 through August 4, 2026: 26,589 messages across 5,527 organizations, arriving in waves on weekdays. The lure was a voicemail notification, and 99.5% of the subject lines included the recipient’s own email name to make it look internal. The attachment was an image file — an SVG — which can quietly contain JavaScript, and these ones did, hidden behind obfuscation and delayed execution.

Two details deserve attention. First, the attachments declared themselves as plain text rather than as image files, so scanners checking the declared type saw something harmless. Second, and more uncomfortable: 75% of the messages received a Microsoft spam score of 0 or 1 — Microsoft’s rating for “not spam.” Only 18% were scored as likely spam. Same template, different verdicts depending on the receiving mailbox.

What it means for you

Built-in filtering caught a minority of a campaign that reached thousands of companies, which is a useful reality check if your email security strategy is “Microsoft handles it.” Two things are worth doing regardless. Tell your team that a voicemail notification with an attachment is a phishing pattern, full stop — real voicemail in Microsoft 365 doesn’t arrive that way. And if your email security has never been configured beyond the defaults, that’s a short project with an outsized return.

How Covenant helps

Email hardening — the anti-phishing policies, attachment handling and impersonation protection most tenants never turn on — is part of Fortify, Covenant’s Microsoft Cyber Hardening solution. Defaults are a starting point, not a configuration.

Sources: Infosecurity Magazine — Fake voicemail SVG attachments fuel large-scale phishing campaign · Kaseya / INKY — SVG smuggling: how a 26,000-email phishing campaign hid malware in image files

09
Patch management

Ransomware groups are attacking print management software — and the first patch didn’t hold

On August 27, 2026, PaperCut published an urgent advisory confirming active exploitation of its PaperCut NG and MF print management software. The next day the company assigned CVE-2026-81578 and CVE-2026-82078 to a 2-flaw chain that lets an attacker take over the PaperCut application server without logging in at all. Emergency patches went out on August 28 for versions 25 and 26, followed by version 24 the same day — and then a second emergency patch after researchers found several ways around the first fix.

Security firm Huntress reported the earliest exploitation attempts on August 26, against real customers. Attribution so far spans multiple ransomware operations and state-backed groups. PaperCut is print management software — the sort of thing that gets installed once, works fine and never gets thought about again.

What it means for you

Most businesses can answer “are our laptops patched.” Far fewer can answer “what server software are we running that isn’t Windows, and who patches it.” Print servers, scanning appliances, document management, the tool that came with the copier — these live in the gap between “IT handles it” and “the vendor handles it,” and attackers know it. If you run PaperCut, this is urgent today and the second patch is the one you need. If you don’t, the useful exercise is listing the business software running on a server in your building and asking who’s responsible for updating each one.

How Covenant helps

Always-On IT Operations includes managed patching with monthly verification reporting that covers third-party software, not just Windows — so the answer to “are we patched” is documented instead of hopeful.

Sources: BleepingComputer — PaperCut releases second emergency patch for exploited flaws · Huntress — PaperCut zero-day: active exploitation and pre-auth RCE · The Hacker News — Attackers chain two PaperCut flaws to execute code without authentication

10
Internet-facing systems

A Citrix flaw everyone thought was minor turned out to be much worse

On August 26, 2026, CISA added 6 flaws to its Known Exploited Vulnerabilities catalog, including CVE-2026-8452 in Citrix NetScaler ADC and Gateway — the appliance many organizations use for remote access and to publish internal applications. Citrix patched it back in late June as a denial-of-service issue, meaning the worst case was thought to be a crash. Researchers have now confirmed attackers using it to run code on the appliance: dropping web shells named x.php and z.php and running discovery commands. Telemetry showed 36 exploitation attempts over 12 days from 12 attacker IP addresses across 10 countries.

Federal agencies were given until August 29, 2026 to fix it. CISA published a broader vulnerability review the same week noting that attackers are increasingly using AI to automate exploitation of simple, known, already-patched flaws that remain live on exposed systems.

What it means for you

The lesson is about how you triage patches. A vulnerability rated “denial of service” is the kind most organizations schedule for later. This one was reclassified as remote code execution 8 weeks after the patch shipped, and anyone who deferred it based on the original rating spent those weeks exposed. On anything reachable from the internet — remote access appliances, VPN gateways, published portals — the severity rating is a starting point, not a scheduling decision. Patch it promptly and check back when new information lands.

How Covenant helps

Knowing what of yours is reachable from the internet, and what state it’s in, is the first thing we establish. A Security Score Assessment gives you that inventory and a prioritized short list — starting with the things facing outward.

Sources: The Hacker News — CISA adds six exploited flaws to KEV, including NetScaler, Linux and SQL Server bugs · CISA — Adds six known exploited vulnerabilities to catalog

The bigger picture

Look at what actually got attacked this week. Not a firewall. Not a clever new exploit against a hardened system. A print server. A remote access appliance patched in June and filed under “not urgent.” A login page that people trusted because it looked right. A default Microsoft address nobody ever replaced.

None of that is exotic, and none of it is anyone’s fault. It’s what happens when a business grows and the technology grows with it — one tool at a time, each one sensible on the day it was installed, and nobody’s job to look back at the whole pile. The AI stories on the list are a version of the same thing: capable systems, broad access, nobody watching closely.

Out of everything above, most businesses have maybe 2 real action items this week: find out whether anything you run is on the PaperCut or NetScaler list, and find out whether your team could revoke a stolen session today if they had to. Everything else is context.

You didn’t start your business to track Microsoft retirement dates or reclassified CVEs. We did. If you’d like an honest baseline of where your Microsoft environment, your security posture and your AI readiness actually stand — no scare tactics, no shelfware, just a clear picture and a short list of what to fix first — that’s a conversation, not a project.

Related Covenant solutions

Microsoft 365 Tenant Optimization Review

Find out what you’re paying for, what’s unfinished and what’s underused in your Microsoft 365 tenant — then right-size it.

Explore this solution

Microsoft 365 Secure Score Assessment

An honest baseline on identity, email and sharing, with a short prioritized list of what to fix first.

Explore this solution

Fortify Microsoft Cyber Hardening

The phased program that turns those findings into real, defensible controls — without slowing your team down.

Explore this solution

Sources and further reading

Want a second set of eyes on your Microsoft, security, and AI readiness?

Bring us the environment you actually have — not the one you wish you had. We’ll give you a clear baseline, a short list of what matters and a next step you can afford.

Covenant Technology Solutions | Microsoft-first. Security-first. Human.

Scroll to Top