The thread running through this week
The four stories logged on this desk over the past two days look unrelated: a broken Office update, an exposed VPN test server, a new Android malware strain, and an urgent GitLab patch. They share a single thread. The mechanisms the software industry relies on to keep systems safe and current - the patch, the test environment, the published vulnerability disclosure - are themselves generating risk. Security work in 2026 is less about whether a fix exists than about whether the fix, and the infrastructure around it, can be trusted to arrive without collateral damage.
The patch as a source of harm
Microsoft Excel users report that this week's KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, according to BleepingComputer, with affected users saying that removing or rolling back the update restores normal functionality. The important detail is not the bug itself. It is the remedy. The documented workaround is to uninstall a security update, which means users are being asked to choose between a working spreadsheet and a patched one.
That trade-off lands hardest on the least equipped. For a large enterprise with imaging, staging rings, and a help desk, a bad Office patch is an annoyance measured in tickets. For a small US business running the same Excel build across a handful of machines, it is a day of lost work and a decision about whether to undo a security fix. Microsoft has not, in the material available, offered a fixed build; the interim guidance is rollback. Every hour that guidance stands, the population of unpatched Excel installations grows, and the vulnerability the update was meant to close stays open.
This is the quiet cost of patch velocity. Security teams have spent a decade being told that speed matters, and it does. But speed without staged rollout discipline converts a defensive control into an outage vector. The same update channel that delivers protection also delivers the disruption, and it does so at the scale of the vendor's entire install base.
The test server that should never have been reachable
Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet, as BleepingComputer reported. The pattern here is familiar and instructive. The compromised asset was not a production service. It was internal testing infrastructure - the very environment in which engineers rehearse changes before they reach customers.
A test server is supposed to be a place where mistakes are cheap. When one is reachable from the open internet, mistakes become expensive, and the rehearsal space becomes an entry point. For US consumers, the value proposition of a VPN is trust: the provider is asking to sit between the user and everything they do online. An incident at a testing system does not automatically mean user traffic was exposed, and the reporting does not say it was. But it does mean the boundary between internal and external was not maintained.
For US technology companies, the lesson is structural rather than moral. Configuration drift is not an exotic attack. It is the ordinary condition of fast-moving infrastructure, and the control that catches it is asset inventory and continuous exposure management - the unglamorous work that rarely gets funded compared with detection tooling. A company whose product is privacy carries a higher burden here, because its customers have no independent way to verify the boundary.
Malware that does more than one job
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims, according to BleepingComputer. The bundling is the story. Mobile malware historically specialised: one family harvested credentials, another sent premium-rate messages, another locked the screen. Mantax Otax does not specialise.
For US consumers, this changes the damage profile of an ordinary bad download. A single infection can mean locked files, exfiltrated data, and sustained harassment, which implies an operator on the other end rather than an automated payload. For US carriers and app store operators, it widens the surface they must police, because the harm is no longer confined to one category of loss.



