Microsoft is adding two extra file types to its Outlook block list to strengthen security. The file types are .msix and .msixbundle, used for Windows application packages and bundles. The change affects New Outlook for Windows and Outlook on the Web in Exchange Online. By default, users of the affected clients will no longer be able to download or open attachments with these extensions, which is no bad thing because blindly installing a malicious .msix package could compromise a device. That said, although Microsoft noted that the file types were "infrequently used," there are legitimate reasons for their presence in emails. Administrators who need to permit these attachments can add the extensions to the AllowedFileTypes property of the relevant OwaMailboxPolicy before the rollout, scheduled for early to mid-November 2026. "This update is part of our ongoing efforts to strengthen security and help protect organizations from potentially unsafe file attachments," Microsoft said. The Windows giant's application packaging system has come under fire over the years. Microsoft disabled the ms-appinstaller protocol handler by default in December 2023 after attackers abused it to distribute malware. The attachment block adds another layer of protection, unless administrators explicitly allow these file types. Other file types blocked by Outlook on the Web include .py Python files, .ps1 PowerShell files, and .cab files. It's a little surprising that it has taken until now for .msix and .msixbundle to be added to the list, considering the havoc malicious packages can wreak on a system. Renaming an attachment's extension or sending a download link may get around the attachment restriction, but neither makes the package safe. Persuading someone to download and install it remains a route for miscreants, even with Windows' other protections in place. ®
Microsoft has blamed extra work created by AI bug-finders for the delayed release of a major Cumulative Update to Exchange Server Subscription Edition (SE). Redmond’s Exchange team made that admission last Thursday in a post titled “Where is Exchange SE CU1 anyway?” that reveals the software giant is “getting questions from our customers on when they can expect us to release Exchange SE Cumulative Update 1 (CU1).” “After all, in the past we mentioned that it would be released by the end of the first half of calendar year 2026, later updated to ‘second half of 2026’. What is the deal? Where is CU1?” For those of you who came in late, Exchange SE is the subscription version of Microsoft’s email server, and a Cumulative Update (CU) is a new version of the package that includes all recent bug fixes, plus other changes such as new features or removing deprecated code. Microsoft publishes CUs once or twice a year. Some users prefer applying CUs to applying every patch. As Exchange SE is a subscription product, not getting CU in a timely fashion isn’t a great example of why pay-as-you-go software is a great idea. Microsoft explained delays to the arrival of CU1 by referring to the fact that “Over the last few months, various Microsoft execs made statements explaining how Microsoft is leveraging a variety of AI tools to help find vulnerabilities in our products.” The post says the Exchange development team is “working through reported issues – which includes validation that they are real security issues, reproducing, fixing, testing for regressions / issues after fixes are deployed and releasing updates monthly.” Redmond’s missive also points to Microsoft’s pledge to “prioritize security above all else” as a reason for delays. A reminder: Microsoft adopted that stance after flaws in Exchange led to an attack on Exchange by suspected Chinese operatives, earning it a tongue-lashing from the US government. The Exchange team says that while trying to stay on top of bugs, it is also working on CU1. “We are regularly rolling our monthly security payload into our internal CU1 build and plan to release Exchange SE CU1 as soon as we get a reasonable stable point and have a month without pressing security payload.” The Exchange team has adopted that stance because it doesn’t want to publish CU1 and then find it needs to replace it with another that includes new security updates. “That would create double the update work for many organization administrators,” the post explains. “Even internally, trying to ensure that two major releases (Security Update and a CU) get appropriately tested so we can ensure high quality and nothing falls through the cracks would be very challenging as CU1 must be all inclusive of everything that we released since the RTM.” Exchange admins will likely appreciate the fact that Microsoft doesn’t want to burden them with two major updates to implement. They may also wonder when Microsoft will find a month in which there is no “pressing security payload” that takes priority over CU1. Microsoft’s post offers little certainty because it concludes: “In short: Exchange SE CU1 is coming; we do not have a date to give you. But we did not forget about it.” Nor, it seems, did Microsoft plan for how AI-powered bug-finding would impact product development teams. ®