top of page
Untitled design.png

Weekly INK

Each week we compile an advisory on the latest threats, trends and newsworthy topics from the cyber security industry affecting small and medium enterprises. Join our subscribers below and help us prevent cybersecurity breaches.

watermark4.png

Issue #209 - July 27, 2026

  • Jul 27
  • 2 min read

SE Asian Cybercriminal Syndicates Become a Global Power

Source: Dark Reading

Dark Reading reports that Southeast Asian cyber-fraud syndicates have evolved into global service-based crime networks, enabled by cryptocurrency, secure messaging, AI, satellite connectivity, trafficking, and corruption. The story highlights how enforcement pressure has displaced operations rather than dismantled them, creating a resilient ecosystem with major regional economic impact.




Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

Source: BleepingComputer

BleepingComputer details a Laundry Bear campaign exploiting an Exchange Outlook Web Access XSS zero-day to deliver OWAReaper. Proofpoint says the malware can persist inside mailbox access paths, steal OAuth tokens, use multiple command-and-control methods, and maintain access even after endpoint cleanup or password rotation.




Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack

Source: BleepingComputer

BleepingComputer reports that Minnesota activated statewide cyber response after more than 30 community water systems were targeted in coordinated operational technology attacks. Local utilities reported outages or equipment issues, while state and federal partners began investigation, containment guidance, and critical infrastructure hardening support.




Unpatched Fastjson Vulnerability Exploited in Attacks

Source: SecurityWeek

SecurityWeek reports active exploitation of CVE-2026-16723, an unauthenticated Fastjson remote code execution flaw affecting unsupported 1.x versions under default conditions. Researchers observed attacks against multiple sectors and recommend migration to Fastjson 2.x, SafeMode, request blocking, or vulnerable-code removal when immediate migration is not possible.




Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Source: The Hacker News

The Hacker News covers Certighost, a public exploit chain affecting Active Directory Certificate Services. Researchers showed that a low-privileged domain user can obtain a Domain Controller certificate under certain enrollment conditions, enabling dangerous Kerberos abuse. Microsoft patched the issue and warned that proof-of-concept availability increases exploitation risk.




 
 

Help us Prevent Breaches.

We will never share or sell your information. Unsubscribe at any time.

Email: *

Received.

bottom of page