top of page
Frame 2.png
cybersecurity-concept-keylock-blue-colors-binary-code-lock-ai-generated 1.png
Trusted by 100.png

Weekly INK

Issue #209 - July 27, 2026

wi4.png

Stay informed on the threats, trends, and security developments that matter most to your business. Find practical insights to better understand risk and stay ahead of bad actors.

Talk to an expert
Frame 2.png
cybersecurity-concept-keylock-blue-colors-binary-code-lock-ai-generated 1.png
Trusted by 100.png

Issue #209 - July 27, 2026

Weekly INK

Free, practical resources to assess your status, understand risks, and enhance your security posture no sales pitch needed.

Talk to An Expert

Issue #209 - July 27, 2026

SE Asian Cybercriminal Syndicates Become a Global Power

Source: Dark Reading


Dark Reading reports that Southeast Asian cyber-fraud syndicates have evolved into global service-based crime networks, enabled by cryptocurrency, secure messaging, AI, satellite connectivity, trafficking, and corruption. The story highlights how enforcement pressure has displaced operations rather than dismantled them, creating a resilient ecosystem with major regional economic impact.


Link to article



Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

Source: BleepingComputer


BleepingComputer details a Laundry Bear campaign exploiting an Exchange Outlook Web Access XSS zero-day to deliver OWAReaper. Proofpoint says the malware can persist inside mailbox access paths, steal OAuth tokens, use multiple command-and-control methods, and maintain access even after endpoint cleanup or password rotation.


Link to article



Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack

Source: BleepingComputer


BleepingComputer reports that Minnesota activated statewide cyber response after more than 30 community water systems were targeted in coordinated operational technology attacks. Local utilities reported outages or equipment issues, while state and federal partners began investigation, containment guidance, and critical infrastructure hardening support.


Link to article



Unpatched Fastjson Vulnerability Exploited in Attacks

Source: SecurityWeek


SecurityWeek reports active exploitation of CVE-2026-16723, an unauthenticated Fastjson remote code execution flaw affecting unsupported 1.x versions under default conditions. Researchers observed attacks against multiple sectors and recommend migration to Fastjson 2.x, SafeMode, request blocking, or vulnerable-code removal when immediate migration is not possible.


Link to article



Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Source: The Hacker News


The Hacker News covers Certighost, a public exploit chain affecting Active Directory Certificate Services. Researchers showed that a low-privileged domain user can obtain a Domain Controller certificate under certain enrollment conditions, enabling dangerous Kerberos abuse. Microsoft patched the issue and warned that proof-of-concept availability increases exploitation risk.


Link to article

frame 17b.png
Frame 1597880632.png

Talk to a Blue INK expert

From strengthening security and preparing for audits to navigating privacy and governing AI, we'll connect you directly with the right expert.

How can we best help?
Frame 1597880632.png

Have questions?

Let us know the best way to reach you and we will be in touch as soon as possible to answer your questions.

How can we best help?
frame 17c.png
Frame 1597880632.png

Stay ahead of new threats

Cut through the noise and stay ahead of emerging threats most relevant to your business. Our Weekly INK curates everything you need to know about cybersecurity threats targeting businesses. 

bottom of page