The week's security news is not really about Excel, Android malware, a Check Point flaw and a DeFi hack. It is about the widening gap between the moment a defect is found and the moment it is actually closed. In each case, the damage or the risk comes less from the underlying flaw than from the patch, the exploit tooling or the smart contract logic that sits between discovery and resolution.
Microsoft's Patch Breaks What It Fixes
Microsoft has fixed a known issue that causes copy-and-paste failures for some Excel users after installing the September 2026 KB5002914 security update, as BleepingComputer reported. The detail matters more than the inconvenience. A security update, issued to close a vulnerability, introduced a functional regression that disrupted everyday work for a subset of users. That is the patch gap in miniature: defenders must weigh the risk of leaving a known flaw unpatched against the risk of deploying a fix that breaks production.
For US technology companies, this is a recurring cost of doing business on patched infrastructure. Excel remains deeply embedded in finance, accounting, logistics and public-sector workflows. When a routine security update degrades basic functions, the operational fallout spreads through organisations that treat the spreadsheet as a system of record. The story is not that Microsoft fixed the bug; it is that the fix cycle itself has become a source of risk.
Android Malware Learns to Navigate
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices, according to BleepingComputer. The significance is not the existence of another remote-access trojan. It is that the tooling around exploitation is becoming easier to operate, lowering the skill required to turn an initial compromise into sustained control.
That shift has direct consequences for US consumers and enterprises. Mobile devices carry corporate email, multi-factor authentication prompts and payment credentials. A malware family that automates device control compresses the time between infection and meaningful access. For US companies, it reinforces a hard truth: endpoint security assumptions built for desktops do not translate cleanly to phones, and the mobile threat model is maturing faster than many defensive programmes.
A Critical Flaw in Security Infrastructure
Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems, as BleepingComputer reported. Here the patch gap is at its most acute. The affected systems are not ordinary endpoints; they are the consoles and management layers that organisations use to enforce security policy.
When the tooling that protects a network becomes the target, the trust chain inverts. An attacker who reaches root on a management system can potentially reconfigure defences rather than merely evade them. For US enterprises, this is the same lesson that has defined the last several years of security architecture: concentration of privileged control is efficient, and efficiency is exactly what attackers seek. The vendor has shipped fixes, but the exposure window between disclosure and full enterprise deployment is where risk lives. Large US organisations rarely patch critical infrastructure on the day an update lands, and the management plane is often the last place change control allows.

