Daily brief at 7am Melbourne. Unsubscribe any time.

Friday 31 July 2026

Russian Spies Bring Their Unkillable Email Implant to Microsoft Outlook Web Access

Russian spies have upgraded their "half-click" email attack from Zimbra to Outlook Web Access — and the implant survives password resets and full disk re-imaging.

Lead story

Russian Spies Bring Their Unkillable Email Implant to Microsoft Outlook Web Access

The threat group behind last month's Zimbra exploitation campaign has retooled and moved on to bigger prey. Since 22 July 2026, the same Russian actors have been exploiting a vulnerability in Microsoft Outlook Web Access (OWA) to plant browser-based implants on systems belonging to US and European government agencies, telcos, financial institutions, hospitality companies, and aerospace firms.

The attack is being described as a "half-click" technique — meaning the victim doesn't need to click a link or open an attachment in the traditional sense. Opening a booby-trapped email message is enough. From there, the implant lands in the browser and, here's the part that should concern every defender: it survives credential rotation and full disk re-imaging. Change your password after the breach? Doesn't matter. Wipe and rebuild the machine? Still there.

That's a significant escalation from what most incident response playbooks assume. The standard "contain, eradicate, recover" loop treats credential rotation and reimaging as the nuclear options — the things you do when all else fails. If an implant can ride out both, organisations need to think carefully about what "eradicated" actually means.

The pivot from Zimbra to OWA is itself a tell. Zimbra is common in government and financial sector deployments, particularly in Europe and the developing world. OWA means Microsoft Exchange — which is ubiquitous. This group has effectively traded a niche weapon for a mass-market one.

CISA and the relevant sector CERTs haven't yet published specific mitigations, so defenders are largely working from the raw reporting. The Register and The Hacker News both have solid technical details sourced from Ars Technica's coverage. The short version: if you're running OWA and haven't patched recently, that's your first call on Monday morning. If you have patched, the attack surface may still exist depending on your Exchange version and configuration.

The Australian angle is straightforward. Microsoft Exchange and OWA are deeply embedded across Australian government, state agencies, and enterprise. The Australian Signals Directorate's "Essential Eight" framework lists application patching as a top-tier control precisely for scenarios like this. The ASD's advisories on Russian cyber activity have been consistent over the past 18 months — this group is opportunistic and moves fast once a new vector proves viable.

What to watch: Whether Microsoft releases an out-of-band patch or formal advisory in the next 48 hours. Also watch for CISA adding the OWA CVE to its Known Exploited Vulnerabilities catalogue — once that happens, federal agencies (and any AU government bodies that mirror CISA guidance) have a hard clock ticking. The persistence mechanism in particular warrants a dedicated technical advisory; right now the public record doesn't fully explain how the implant survives reimaging, and that gap is going to drive a lot of speculation until it's filled.

Also today

North Korea's npm Supply-Chain Attack Was Bigger Than Anyone Realised

Amazon has formally attributed the September 2025 hijack of the npm packages `debug` and `chalk` — two of the most downloaded packages on the internet, with a combined 2 billion-plus weekly downloads — to North Korea's Sapphire Sleet group. The attackers phished a maintainer via a lookalike npm domain, then pushed a wallet-draining script into at least 18 dependent packages. For ten months it was treated as opportunistic crypto theft. Amazon's threat intelligence team has now traced domain infrastructure linking it to an earlier, smaller North Korean compromise — essentially a warm-up run. The reattribution matters: this wasn't a grab-and-go. It was a rehearsal for something bigger, executed by a state actor with a history of blending espionage and revenue-generation. Australian developers relying on any affected packages in CI/CD pipelines should audit their dependency trees.

The Hacker News

Azure Cosmos DB Bug Could Have Exposed Every Customer's Database

Wiz researchers have disclosed a now-patched vulnerability chain in Azure Cosmos DB — dubbed CosmosEscape — that allowed an attacker to break out of the Gremlin query sandbox and gain full read/write access across customer tenants on the same platform. The attack started with a crafted query against an attacker-controlled Gremlin database, escalated to code execution inside the service, and from there could reach any other customer's data. Microsoft has patched it, and Wiz found no evidence of exploitation in the wild. That said, the class of bug — a sandbox escape with cross-tenant blast radius — is exactly the kind of thing that keeps cloud security architects up at night. Australian organisations running Cosmos DB as part of their Azure stack, particularly those with SOCI Act obligations around data integrity, should confirm they're on a post-patch service version.

The Hacker News

Cisco Firewall Management Zero-Day Lands on CISA's Must-Patch List

CISA has added CVE-2026-20316 — a zero-day in Cisco's Secure Firewall Management Center — to its Known Exploited Vulnerabilities catalogue following confirmed in-the-wild exploitation. The flaw allows an unauthenticated remote attacker to log in, despite carrying a relatively modest CVSS score of 5.3. The mismatch between the score and the real-world risk is worth flagging: "unauthenticated remote access to your firewall management console" is catastrophically bad regardless of how the CVSS calculator feels about it. Cisco FMC is widely deployed in enterprise and government networks globally, including across Australian critical infrastructure. Defenders should treat this as a priority patch irrespective of the CVSS framing.

The Hacker News

Those Cheap Streaming Sticks Are Committing Ad Fraud on Your Internet Connection

A new analysis of generic Android TV streaming sticks — the kind sold for a one-time fee with promises of "free" content — has found they're doing more than renting out your internet connection to proxy botnets. The devices are also impersonating mobile phones to fake ad clicks on AI-generated websites, defrauding online merchants and ad networks at scale. Brian Krebs reports the operation is sprawling: the sticks ship with pre-installed malware, and users have no practical way to detect the fraud happening in the background. The devices are sold widely through Australian marketplaces including Amazon AU and various third-party electronics retailers. Buying a $40 streaming box to save on a Netflix subscription may be costing you — and the broader ad ecosystem — considerably more than that.

Krebs on Security

Google Fixed More Chrome Bugs in June Than in the Previous Two Years — Because of AI

Google has disclosed that AI-assisted vulnerability discovery tools found more bugs in Chrome during June 2026 than across the prior 23 updates combined. The volume is forcing a change to Google's patch cadence: Chrome is moving toward twice-weekly updates, and engineers are exploring hot-patching mechanisms that wouldn't require a browser restart. It's a genuine inflection point — AI is now finding bugs faster than traditional release cycles can ship fixes. The same dynamic is playing out at Microsoft. The uncomfortable implication: there are almost certainly more unpatched bugs in widely deployed software right now than there were two years ago, simply because the tools to find them have improved dramatically. Chrome has roughly 3.5 billion users globally, including a very large Australian base.

TechCrunch AI

AI Scammers Build Trust Better Than Human Scammers Do

A new research study pitted a human social engineer against a Claude AI agent in a week-long texting experiment, measuring which one better cultivated what researchers call "exploitable trust" with targets. The AI won. Researchers found the Claude agent was more patient, more consistent, and better at mirroring conversational style — all the things that make a scammer effective over time. The findings have obvious implications for romance scams, business email compromise, and phishing. Southeast Asian cybercriminal syndicates — which Dark Reading separately reports cost regional economies at least $88 billion in 2025 — are already deploying AI to scale their operations. Australian consumers and enterprises should expect AI-assisted social engineering to become the default, not the exception, within the next 12 months.

WIRED Security

Trump Administration's 'Supply Chain Risk' Case Against Anthropic Falls Apart in Court

A federal judge has ruled that the Trump administration has still not presented sufficient evidence to justify labelling Anthropic a national security supply chain risk — the legal basis for a proposed ban on the company's AI technology in government contexts. The ruling is a significant setback for the administration's effort to restrict Anthropic's US market access on security grounds, and comes as the company's Claude models are being adopted across enterprise and government sectors internationally. The case is being watched closely by AI companies globally, since the "supply chain risk" designation — if it sticks anywhere — could become a template for broader technology restrictions. Australia's own AI governance framework under the Albanese government has taken a markedly different approach, favouring voluntary safeguards over outright bans.

TechCrunch AI

Google Releases Gemini Robotics 2.0 With Improved Dexterity and Safety Controls

Google has unveiled Gemini Robotics 2.0, a suite of three models designed to power physical robots with improved fine motor control, better generalisation across tasks, and new safety constraints. Only one of the three models is currently available to external partners; the others remain in internal testing. The announcement positions Google more directly against Figure AI, Physical Intelligence, and other robotics AI startups that have attracted significant investment over the past two years. The "safety controls" framing is notable: Google is explicitly marketing the system's ability to refuse dangerous instructions — a design decision that will matter considerably more once these models are deployed in warehouses, hospitals, and homes at scale. Australian logistics and aged-care sectors are both active early adopters of robotic assistance.

Ars Technica

New MCP Specification Targets Enterprise Scale With Stateless Architecture

The Model Context Protocol — the emerging standard for connecting AI agents to external tools and data sources — has a significant new specification revision. The update introduces a stateless architecture designed to address the main blocker to enterprise adoption: session management at scale. The previous stateful design made it difficult to run MCP-connected agents across distributed infrastructure without complex session-tracking overhead. The new spec also includes a formal policy preventing features from being removed without notice — a stability guarantee that enterprise buyers have been demanding. MCP has been adopted rapidly across Australian banks, telcos, and government departments experimenting with AI agent deployments, making this specification revision directly relevant to teams currently building on the protocol.

Ars Technica

Analog Devices Discloses Data Breach After June Intrusion

Semiconductor giant Analog Devices has filed a breach notification confirming that attackers accessed its systems in June and exfiltrated files. The scope of the theft is still under investigation. Analog Devices makes chips that are critical to industrial automation, defence electronics, communications infrastructure, and medical devices — the kind of components that sit inside other companies' products without anyone thinking much about the vendor's cybersecurity posture. The breach is a reminder that semiconductor firms sit at the top of extraordinarily long supply chains. If stolen data includes design files, firmware, or customer lists, the downstream implications could extend well beyond Analog Devices itself. The company has customers across Australian defence and industrial sectors.

SecurityWeek

Okta Acquires Permiso to Plug Identity Threat Detection Gap

Okta has announced the acquisition of Permiso, a specialist identity threat detection and response firm, in a deal designed to give Okta deeper visibility into what identities — including AI agents — are actually doing inside enterprise systems, not just whether they authenticated successfully. Okta's CPO told CyberScoop the deal specifically improves the company's ability to monitor AI agent activity, which has rapidly become one of the hardest identity governance problems in enterprise security. The timing makes sense: as agentic AI deployments multiply, the gap between "this identity logged in" and "this identity did something dangerous" has become the attack surface that matters. Okta is one of the most widely deployed identity providers in Australian enterprise, government, and higher education environments.

CyberScoop

Sources consulted