State-Sponsored Hackers Are Reading Email Without a Single Click
On July 23, the NSA, FBI, and CISA — along with 15+ allied intelligence agencies — issued a joint warning about a Russian state-backed group (tracked as "LAUNDRY BEAR") actively exploiting a webmail vulnerability. The unsettling part: victims don't have to click a link or open an attachment. Simply viewing a malicious email in a vulnerable webmail inbox is enough to trigger it, silently exfiltrating up to 90 days of email history and your organization's contact directory.
Why this matters to you: This campaign has been running since mid-2025 and continues today. It specifically targets business and government email systems — exactly the kind of infrastructure that stores client communications, financial details, and sensitive documents.
Your defense: If your business runs its own mail server or a hosted webmail platform (rather than Gmail/Microsoft 365, which aren't affected), make sure it's fully patched now. For everyone else: this is a good reminder that email is a prime espionage target — enable MFA on your inbox if you haven't, and be suspicious of "read receipts" or odd account activity.
|