Italy's AGCM is investigating Microsoft over claims that fragmented notices left Microsoft 365 subscribers automatically moved to costlier plans once Copilot and Designer features were added without clear explanation of the changes.

The watchdog alleges the updates reached users through disjointed messages that did not clearly state what extra features were included in return for the increased fees.
Microsoft has spent the past year weaving Copilot into just about everything it sells, from Microsoft 365 to Windows, with pricing following close behind.
This investigation underscores how default opt-in mechanics for AI add-ons are drawing antitrust and consumer protection scrutiny across Europe, potentially forcing clearer disclosure standards for enterprise SaaS providers.
Tap a lens to see what this story means for you.
Liked this? The Brief brings you the whole day in tech, verified, every morning.
Two minutes, free forever. What's in The Brief →
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Microsoft Office Outlook has an integer overflow flaw, CVE-2026-100208, that could let an unauthorized attacker run code over a network. Microsoft scores it 7.5 (High), and an attack needs user interaction.
CISA added CVE-2026-65660, a Microsoft SharePoint code injection vulnerability, to its Known Exploited Vulnerabilities catalog on September 25, with a federal deadline of September 28. The flaw could let an authorized attacker execute code over a network and carries a Microsoft CVSS 3.1 score of 8.8.
Microsoft announced the Surface Pro 12-inch and Surface Laptop 13-inch with Snapdragon X2 Plus at the Snapdragon Summit, citing up to 95% faster on-device AI and 18% better battery efficiency. The devices maintain prior form factors while adding features such as Ink Canvas and a recycled-content enclosure, with the Pro model priced from $1149.99 and shipping October 13.
Microsoft has disclosed CVE-2026-85893, a high-severity use-after-free vulnerability in Edge that could let an attacker elevate privileges from Low to Medium Integrity Level after a user visits a malicious page and performs two tap gestures. The flaw affects versions prior to 153.0.4234.32 and is rated CVSS 8.8, though exploitation is assessed as unlikely.
Microsoft has published details on CVE-2026-62744, a heap-based buffer overflow in Windows Media Foundation that allows unauthorized remote code execution with a CVSS score of 8.8. The flaw requires a user to open a specially crafted media file and is included in the September 2026 security updates.