Microsoft has issued three out-of-band updates in January 2026, a rare break from its usual Patch Tuesday schedule due to pressing threats. The most critical is CVE-2026-21509, a Microsoft Office vulnerability being actively exploited. Organisations should accelerate testing and deployment of these patches, prioritising protection of critical systems without skipping validation. Notify end users to minimise workflow disruptions and review Office macro permissions. Firms handling sensitive data or in high-profile sectors must act with urgency, as attackers target delays in patch deployment. These unexpected releases signal an increasingly dynamic threat landscape—remain vigilant with patching and cautious with email, even internal communications.
Related Articles
128: BT Prepares for Change as Next CEO Allison Kirkby Takes the Helm
- News Summariser
- January 15, 2024
- 0
Allison Kirkby is set to become the new CEO of BT, the UK’s largest telecommunications provider, taking over from Philip Jansen on February 1. Having […]
128: Sturnus Android Trojan: Beyond Banking – Now Exfiltrating Encrypted Chat Messages
- News Summariser
- November 20, 2025
- 0
The Android banking trojan Sturnus now threatens more than financial data, exfiltrating chat messages from encrypted apps like Signal, WhatsApp, and Telegram. Its advanced capabilities […]
128: Azure Virtual Desktop Hybrid with Arc-enabled On-Prem Hosts: Operational Benefits and Considerations
- News Summariser
- February 14, 2026
- 0
Microsoft Azure Virtual Desktop (AVD) now supports Azure Arc-enabled on-premises servers as session hosts, enabling hybrid desktop virtualisation. This advancement benefits organisations with strict compliance, […]

