News 2026-07-25
IAM & Security Weekly Briefing
Russian state-sponsored group exploited a Zimbra zero-click zero-day to steal email, browser passwords, and 2FA recovery codes from Western mailboxes.
Open report
IAM & Security Weekly Briefing
Week of: 2026-07-19 to 2026-07-25 Reporting window: Most recently completed Sunday–Saturday (excludes the in-progress week).
1. Executive Summary (TL;DR)
- Russian state-sponsored group exploited a Zimbra zero-click zero-day to steal email, browser passwords, and 2FA recovery codes from Western mailboxes.
- Police dismantled the Kratos phishing-as-a-service kit that specialized in stealing Microsoft 365 sessions and bypassing MFA.
- A default-enabled Azure Automation setting allowed cross-tenant identity takeover via flawed code chains; Microsoft addressed it.
- Researchers revealed exploitable flaws in Microsoft’s passkey implementation that could let attackers impersonate privileged users.
- A new AD certificate abuse technique (Certighost) lets low-privileged users impersonate a Domain Controller and extract krbtgt via DCSync.
- Hotel Wi-Fi DNS hijacking campaigns are actively redirecting guests to fake Microsoft 365 login pages to steal credentials.
- AI agents are being weapon
More from News
🌍 World & Geopolitics Briefing
2026-08-08
IAM & Security Weekly Briefing
2026-08-08
AI Model & Benchmark Watch — August 7, 2026
2026-08-07
AI Projects - August 7, 2026
2026-08-07
AI Tool Updates - August 7, 2026
2026-08-07
General AI News - August 7, 2026
2026-08-07
MCP Protocol News - August 7, 2026
2026-08-07
Science & Space Digest — Aug 7, 2026
2026-08-07
🏛️ Tech Policy & Regulation Watch
2026-08-06
Cool Websites — August 6, 2026
2026-08-06
⚡ Energy Industry Briefing
2026-08-05
🛡️ Cybersecurity Vulnerability Watch
2026-08-01