| ~7 MIN READ |
|
This week's throughline is dwell time: spies who sat in mailboxes and VPN appliances for months before anyone noticed, and AI tools that are quietly compressing how long that patience needs to last. Here's what changed, what got worse, and one thing that actually helps.
PS — Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe → |
|
In this edition
|
Nation-State Espionage
📧 Russian Spies Read NATO's Mail for Months. The Patch Didn't Evict Them.
Intro
A patch closes a hole. It does not necessarily throw out whoever already crawled through it, and a Russian-linked espionage group just proved that the hard way.
What Happened
NSA, CISA, and partner agencies published a joint advisory on a group (tracked as Laundry Bear, Void Blizzard, and TA488 depending who you ask) exploiting a stored XSS bug in Zimbra's Classic UI since at least July 2025. A crafted email runs its payload the moment it's opened, no click required, stealing the CSRF token, the browser's saved password, and 2FA scratch codes, then exfiltrating 90 days of mail over DNS. Targets span NATO governments, Ukraine, and, per Proofpoint, US defense and nuclear-sector entities.
Why It Matters
The malware also mints a hidden app-specific password that survives a normal password reset, meaning the standard "we rotated your credentials" response doesn't actually end the intrusion.
The Other Side
Zimbra patched the underlying bug back in November and CISA added it to the Known Exploited Vulnerabilities list in March, so this is a story about incomplete cleanup, not an unpatched flaw.
TL;DR: Zimbra patched the hole in November; a Russian-linked group is still living in mailboxes it broke into before then.
Further reading: The Hacker News
|
|
AI help, without the trust tax.
Most AI tools ask you to trade your data for intelligence. Norton Neo doesn't. It's the first safe AI-native browser built by Norton, and it gives you powerful built-in AI without handing your privacy over to get it. Search, summarize, and write with AI built directly into your browser. Your data stays yours. Your context stays private.
Built-in VPN, anti-fingerprinting, and ad blocking come standard. No add-ons. No setup. No compromises.
Fast. Safe. Intelligent. That's Neo.
|
|
|
Why did one company's AI work, and another's didn't?
One had a dedicated owner. Resolution rate: 48.9%. One didn't: 0.38%. See the full breakdown.
Strange but real
🛏️ MyPillow's Mike Lindell Gets a Ransomware Deadline of His Own
Intro
Ransomware crews don't usually pick targets for the punchline, but the Play gang made an exception back in May. An election conspiracy theorist got the exact same extortion playbook as any other victim, deadline and all.
What Happened
The Play ransomware gang listed MyPillow on its leak site, claiming to have stolen client documents, payroll, IDs, and financial records, with a Friday deadline to pay up. Play has hit roughly 900 organizations by the FBI's count and previously breached Swiss government systems and semiconductor maker Microchip Technology, which reported $21.4 million in incident costs.
Why It Matters
Play doesn't pick targets for their politics. Brand recognition just makes the story travel further than the average small-manufacturer breach would.
The Other Side
MyPillow didn't respond to requests for comment at the time, so it's unclear whether any data actually left the building or this was an opportunistic bluff.
TL;DR: A ransomware gang gave MyPillow a payment deadline. The internet enjoyed the irony more than Mike Lindell did.
Further reading: The Register
|
Global hiring doesn't come with a playbook. Join Oyster's webinars and events to learn how leading companies are hiring, expanding, and staying compliant across borders.



