In partnership with

~7 MIN READ
Fact 65% of organizations hit by ransomware this year say AI made the attack more effective, and 38% of staff actually engaged with the AI-crafted lure. (Proofpoint 2026 AI-Era Ransomware Report, surveying 953 security professionals across 12 countries)
The Signal
 
This week's throughline is dwell time: spies who sat in mailboxes and VPN appliances for months before anyone noticed, and AI tools that are quietly compressing how long that patience needs to last. Here's what changed, what got worse, and one thing that actually helps.

PS — Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe

In this edition
  📌 Big Cyber News
  🚨 Can't Miss
  🤖 AI in Cyber
  🕵️ Threat Intel
  🛠️ Tools & Tactics
  🧪 Strange Cyber
📌 Big Cyber News
 
Nation-State Espionage
📧 Russian Spies Read NATO's Mail for Months. The Patch Didn't Evict Them.
Intro
A patch closes a hole. It does not necessarily throw out whoever already crawled through it, and a Russian-linked espionage group just proved that the hard way.
What Happened
NSA, CISA, and partner agencies published a joint advisory on a group (tracked as Laundry Bear, Void Blizzard, and TA488 depending who you ask) exploiting a stored XSS bug in Zimbra's Classic UI since at least July 2025. A crafted email runs its payload the moment it's opened, no click required, stealing the CSRF token, the browser's saved password, and 2FA scratch codes, then exfiltrating 90 days of mail over DNS. Targets span NATO governments, Ukraine, and, per Proofpoint, US defense and nuclear-sector entities.
Why It Matters
The malware also mints a hidden app-specific password that survives a normal password reset, meaning the standard "we rotated your credentials" response doesn't actually end the intrusion.
The Other Side
Zimbra patched the underlying bug back in November and CISA added it to the Known Exploited Vulnerabilities list in March, so this is a story about incomplete cleanup, not an unpatched flaw.
 
👉 Takeaway
If you're on Zimbra and this CVE touched your org, a password reset alone is not remediation. Check for orphaned app passwords and active sessions.
TL;DR: Zimbra patched the hole in November; a Russian-linked group is still living in mailboxes it broke into before then.
Further reading: The Hacker News
🚨 Can't Miss
 
 
Financial Fraud
Spanish police, working with Interpol and Europol, dismantled a BEC and investment-fraud operation that laundered money through 800+ personal and 120 business bank accounts. Four arrests across Spain, Portugal, and Panama; two suspects were extradited after running the scheme remotely from abroad. €94 million has been confirmed laundered, with another €61 million linked to the network.
Industrial fraud looks less like a lone hacker and more like a logistics company with a very bad business model.
 
Vendor Breach
Medical business management vendor MCBS notified 1.2 million people this week that ransomware group PEAR breached its systems last September, hitting seven healthcare organizations that rely on it. PEAR claims to have stolen over 3TB of files and has now claimed more than 100 victims since emerging in mid-2025.
One vendor breach, seven downstream victims. Ask your healthcare vendors how many share their blast radius.
 
Zero-Day
Arista patched an unauthenticated command-injection flaw (CVE-2026-16812, CVSS 10.0) in on-premises VeloCloud Orchestrator deployments, already under active exploitation. CISA has given federal agencies until July 30 to remediate. No authentication is required, and a successful hit exposes managed edge devices, credentials, and cryptographic keys.
If you self-host VCO, this is a today problem, not a this-sprint problem.

AI help, without the trust tax.

Most AI tools ask you to trade your data for intelligence. Norton Neo doesn't. It's the first safe AI-native browser built by Norton, and it gives you powerful built-in AI without handing your privacy over to get it. Search, summarize, and write with AI built directly into your browser. Your data stays yours. Your context stays private.

Built-in VPN, anti-fingerprinting, and ad blocking come standard. No add-ons. No setup. No compromises.

Fast. Safe. Intelligent. That's Neo.

🤖 AI in Cyber
 
 
AI Security
An operator pointed the open-source Hermes AI agent, running with human-approval prompts disabled, at Thailand's Ministry of Finance and let it work unattended for days: scanning for privilege escalation, running LinPEAS, crawling personnel records back to 2012. Researchers only found it because the operator left the agent's own logs on an open directory.
The scary part isn't a rogue AI. It's an AI nobody was supervising, running on infrastructure nobody was watching.
 
AI Security
Proofpoint surveyed 953 security professionals across 12 countries and found that over a third of ransomware incidents still start with a plain phishing email, and 40% of organizations say employees now trust AI-crafted lures more than the old ones. Two-thirds of victims also had data stolen outright, not just encrypted.
The technology making your defenses smarter is making the other side's social engineering better too. Budget for that arms race, not just the tooling half of it.
🕵️ Threat Intel
 
 
Espionage
Kimsuky (APT43) compromised South Korean collaborative-work software vendors via an exploited mail server, then used that foothold to move laterally into customer networks, harvest credentials, and stage secondary attacks. Researchers found the group's Gomir malware sitting on a SaaS customer's server, missing MFA the whole way through.
Vendor compromise is customer compromise. Ask your software vendors what's stopping this from happening to you.
 
Vulnerability
New research traces the SonicWall SMA1000 zero-days back to first exploitation on June 22, weeks before public disclosure, attributed to a threat actor Volexity tracks as UTA0533. The full chain ends in root access via three custom malware components, including a Java webshell built to run whatever payload comes next.
A month of silent root access is the actual cost of a "zero-day disclosed" headline. Assume compromise, not just exposure, on anything you patched late.
🛠️ Tools & Tactics
 
 
Practical play
Sophos surveyed 2,158 IT and security leaders and found nearly 80% of ransomware attacks now start with stolen or compromised credentials, not exploited software. MFA was in place for almost every one of those cases anyway. What actually worked: two-thirds of victims recovered from backup, the highest rate in three years, even as average cleanup costs (excluding any ransom) hit $1.7 million.
If your ransomware plan leans entirely on MFA stopping the initial break-in, the data says pour that energy into backup testing instead.

Why did one company's AI work, and another's didn't?

One had a dedicated owner. Resolution rate: 48.9%. One didn't: 0.38%. See the full breakdown.

🧪 Strange Cyber
 
Illustration of a giant chained pillow crate under a neon ransom countdown sign in a dark warehouse, with a hooded hacker silhouette typing on a laptop
Strange but real
🛏️ MyPillow's Mike Lindell Gets a Ransomware Deadline of His Own
Intro
Ransomware crews don't usually pick targets for the punchline, but the Play gang made an exception back in May. An election conspiracy theorist got the exact same extortion playbook as any other victim, deadline and all.
What Happened
The Play ransomware gang listed MyPillow on its leak site, claiming to have stolen client documents, payroll, IDs, and financial records, with a Friday deadline to pay up. Play has hit roughly 900 organizations by the FBI's count and previously breached Swiss government systems and semiconductor maker Microchip Technology, which reported $21.4 million in incident costs.
Why It Matters
Play doesn't pick targets for their politics. Brand recognition just makes the story travel further than the average small-manufacturer breach would.
The Other Side
MyPillow didn't respond to requests for comment at the time, so it's unclear whether any data actually left the building or this was an opportunistic bluff.
 
👉 Takeaway
Ransomware gangs are agnostic about who they extort. Assume you're a target regardless of how newsworthy your name is.
TL;DR: A ransomware gang gave MyPillow a payment deadline. The internet enjoyed the irony more than Mike Lindell did.
Further reading: The Register

Global hiring doesn't come with a playbook. Join Oyster's webinars and events to learn how leading companies are hiring, expanding, and staying compliant across borders.

Keep Reading