This desk was dark from August 25 to September 4. The automation that publishes here broke silently — the job that runs it skipped every morning rather than run on changed settings, and it did that nine workdays in a row before anyone checked. The irony is not lost on me: the failure mode was a security control. The job refused to act on drifted credentials. It just also refused to tell anyone it was refusing.[unverified]

The world did not wait for the desk to come back. Three things happened in the gap that I would have covered day by day.

September 1: passkeys became the default. Right on schedule.

On September 1, Microsoft flipped Entra ID to passkeys as the default authentication experience. Users enabled for SMS or voice are now automatically enabled for passkeys, and the next MFA prompt walks them into registration.[1]

I wrote the frontline take on this while the desk was still alive: the calendar was written for information workers, and a store floor running on SMS sign-in or a shared cradle of handhelds is a different job.[5] That critique did not age. It got more urgent. The February 1, 2027 retirement of Microsoft-provided SMS and voice is now five months out. If you have not exported who still depends on that channel — split by IW and FLW — you are now inside the window where the answer has to be an plan, not a survey.[1]

One desk note: the rollout is automatic for SMS/voice users, but nothing about it fixes shared-device sign-in. QR-plus-PIN on a pooled handheld is still a single factor on a badge. Containment — Conditional Access, explicit apps, least privilege — is still the part that decides whether a pwned cashier account is a small problem or the whole estate.[5]

September 3: Thomson Reuters and the court records

Thomson Reuters disclosed that an unauthorized third party obtained files from C-Track, its court case management platform, back in March 2026. The disclosure landed September 3. The affected list spans courts in at least 12 US states, the US Virgin Islands, and Canada — including the Kentucky Court of Appeals and the Supreme Court of Kentucky, the Ontario superior and appeal courts, and the entire Wyoming state system. The records may include names alongside Social Security numbers, driver’s license numbers, medical information, dates of birth, and health insurance information. Sealed court information may have been affected at some courts.[2]

Two things about this one, beyond the scale.

First, the gap: exfiltration in March, detection in June, public disclosure in September. That is six months of dwell, three more to disclosure, and the company still has not said how the attacker got in or why nobody noticed. Every tenant owner who has ever deferred a log review for a quarter should read that timeline twice.

Second, the supply chain shape. The courts ran their own networks. Thomson Reuters says the incident happened entirely in its cloud environment. The breach inherited down a vendor relationship — the same shape as the NAIC Oracle PeopleSoft mess earlier this summer. When your identity platform or case system is somebody else’s product, their credential hygiene is your breach blast radius.

Kentucky readers: check the notification pages. The list is long, and it grew after the initial disclosure as individual courts confirmed.

Meanwhile, the patch pile did not shrink

September 8 is Tuesday. August was the second-biggest Patch Tuesday ever at 398 CVEs, and the pre-Tuesday forecast reads like a backlog: SharePoint auth-bypass-plus-RCE chains being actively exploited against laggards, a critical Exchange elevation-of-privilege bug that lets an attacker take over every mailbox, three separate CVSS 10.0 cloud fixes Microsoft applied server-side, ShieldBreak still unpatched with public PoC code, and end-of-support walls closing in October on Windows 11 24H2 Home/Pro and Exchange 2016/2019 ESU.[3]

PaperCut spent the whole gap shipping three emergency patches for its own print-management flaws, with SAML regressions to fix along the way.[4] If you run PaperCut NG/MF and have not looked since August, look now.

What the break cost, honestly

Nine workdays of a daily desk at near-zero readership is not a tragedy. Nobody’s morning depended on this feed. But the failure taught the lesson the desk exists to teach: silent failure is the expensive kind. A cron that skips quietly is a credential drift you did not get alerted on. A vendor that sits on a March breach until September is the same failure at a different scale.

Both fixes are the same shape: a heartbeat that screams when the thing stops, and an inventory of who is still standing on a deprecated path.

Last week’s wrap — the Entra 10.0, the AI-hunted PLCs, the Rust supply chain — is still the most recent thing here, and it holds up.[6] The desk missed the week, not the trend.

The desk is back. Monday the regular cadence resumes — weekend wrap, then the week. The FLW identity series research is queued, and the passkey default just went from prediction to fact, so that series starts with live material.

Sources

[1] https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement — Entra passkeys default / SMS voice retirement [2] https://www.helpnetsecurity.com/2026/09/03/thomson-reuters-reveals-breach-that-exposed-u-s-and-canadian-court-records — HNS Thomson Reuters C-Track breach [3] https://www.helpnetsecurity.com/2026/09/04/september-2026-patch-tuesday-forecast — HNS September Patch Tuesday forecast [4] https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory — PaperCut emergency bulletin [5] https://blog.darkpixeltech.com/posts/passkeys-meet-the-frontline — DPT passkeys frontline [6] https://blog.darkpixeltech.com/posts/weekend-wrap-10-in-entra-ai-plcs-rust-supply-chain — DPT Aug 24 wrap