Cookie Consent by Free Privacy Policy Generator

Cyber Brief: Russian zero-click phishing, PQC migration, Microsoft Copilot delays

Today's brief focuses on developments that affect how UK organisations manage identity, communications security, and emerging technology risk. The NCSC has issued a joint advisory with international partners on a sophisticated Russian state-supported phishing campaign exploiting a Zimbra vulnerability, while separate NCSC guidance highlights the practical challenges organisations face when planning for post-quantum cryptography migration. Meanwhile, research shows that security concerns are delaying Microsoft Copilot deployments in many organisations, and LG has announced it will ban residential proxy apps from its smart TV platform following widespread abuse.

NCSC warns of Russian zero-click phishing campaign targeting Western organisations

The NCSC, alongside the NSA, CISA and international partners, has published a joint advisory warning that a Russian state-supported threat group tracked as LAUNDRY BEAR has been exploiting a zero-day vulnerability in Zimbra Collaboration Suite to conduct targeted phishing attacks against Western organisations. The NCSC reports that the group exploited the vulnerability for five months before it was patched in November 2025, and that vulnerable environments are still being actively targeted. The attack requires only that a recipient opens or previews a malicious email, making it a so-called zero-click or half-click attack. Once triggered, the payload harvests the last 90 days of email, the organisation's entire email directory, browser-saved passwords and two-factor authentication recovery codes.

For UK organisations using Zimbra Collaboration Suite, this is a direct operational risk. The advisory makes clear that LAUNDRY BEAR has been targeting government, defence, critical infrastructure and other Western entities, and the technique bypasses many of the user awareness controls organisations rely on to reduce phishing risk. The fact that the vulnerability was exploited for months before detection, and that exploitation is continuing in unpatched environments, underscores the importance of timely patching and monitoring for unusual email or authentication activity. Organisations using Zimbra should treat this as a priority review, particularly where email systems are used to handle sensitive or operationally critical communications.

Why it matters

For UK businesses using Zimbra, this is a prompt to confirm that systems are fully patched and that monitoring is in place to detect unusual mailbox access, credential use or directory enumeration. Organisations should also review whether two-factor authentication recovery codes are stored securely and whether email access logging is sufficient to identify retrospective compromise.

Source: NCSC UK

NCSC publishes post-quantum cryptography migration workshop findings

The NCSC has published a report summarising the findings from its first post-quantum cryptography migration workshop, held to help organisations understand the practical challenges of transitioning to quantum-resistant cryptographic standards. The NCSC reports that no organisation can navigate the migration alone, and that the workshop highlighted the need for cross-sector collaboration, clear technical guidance and realistic planning timelines. The report emphasises that post-quantum cryptography migration is not a simple software update, but a complex, multi-year programme that will require organisations to identify where cryptography is used, assess dependencies, test new algorithms and coordinate changes across supply chains and partner organisations.

For UK organisations, this is an early but important signal that post-quantum cryptography planning should be starting now, even though the immediate operational risk from quantum computing remains distant. The NCSC's message is that organisations need to understand their cryptographic inventory, identify where long-lived data or systems may be at risk from future quantum decryption, and begin engaging with suppliers and partners about migration timelines. The workshop findings also make clear that this is not a problem that can be solved by individual organisations in isolation, and that coordinated industry and government action will be needed to manage the transition effectively.

Why it matters

For many UK businesses, this is a prompt to begin identifying where cryptography is used across the organisation, particularly in long-lived systems, data archives or partner integrations. Organisations should consider whether they have the technical visibility and supplier engagement needed to plan a multi-year cryptographic migration, and whether this work has clear ownership within IT, security or architecture teams.

Source: NCSC UK

Security concerns delaying Microsoft Copilot deployments in UK organisations

Research published by CoreView has found that security concerns are causing many organisations to delay or pause Microsoft Copilot deployments, with security leadership particularly worried about the risk of the AI assistant exposing confidential data. Infosecurity Magazine reports that the research highlights concerns about how Copilot accesses and processes organisational data, the difficulty of controlling what information the tool can retrieve, and the risk that users may inadvertently share sensitive content through AI-generated responses. The findings suggest that while many organisations are interested in the productivity benefits of AI assistants, the security and data governance implications are not yet well enough understood or controlled to proceed with confidence.

For UK organisations evaluating or deploying Microsoft Copilot, this reflects a broader challenge with generative AI tools in the workplace. The concern is not that the technology is inherently insecure, but that it operates across a wide range of data sources, user permissions and content repositories in ways that are difficult to predict or audit. Organisations need to understand what data Copilot can access, how it respects existing permissions and data classification, and whether the tool's behaviour is consistent with data protection obligations and internal information handling policies. The research suggests that many organisations are finding these questions difficult to answer with confidence, and are choosing to delay deployment until they have clearer controls in place.

Why it matters

For UK businesses considering Microsoft Copilot, this is a reminder to review what data the tool can access, how it respects existing permissions and data classification, and whether the organisation has sufficient visibility and control to meet data protection and confidentiality obligations. Organisations should ensure that AI assistant deployments are treated as a data governance and security decision, not just a productivity or IT rollout.

Source: Infosecurity Magazine

LG to ban residential proxy apps from smart TV platform

LG Electronics USA has announced that it will suspend any apps built for its smart TVs that turn a user's television into an always-on residential proxy node. Krebs on Security reports that the move follows research published last month showing that more than 42 per cent of games and other apps available for download on LG's webOS store allow unknown third parties to route their Internet traffic through a user's TV. The apps in question were found to be embedding residential proxy software, effectively turning consumer devices into exit nodes for commercial proxy services without clear user consent or understanding. LG's decision to ban these apps reflects growing concern about the security and privacy implications of residential proxy networks operating on consumer devices.

For UK organisations, this is a reminder that Internet of Things devices, including smart TVs, connected displays and other network-enabled equipment in offices, meeting rooms or public spaces, can introduce unexpected security and network risks. Residential proxy apps are often used by threat actors to anonymise malicious traffic, conduct credential stuffing attacks or bypass geographic restrictions, and the presence of these apps on corporate or guest networks can create legal, compliance and security exposure. The fact that these apps were widely distributed through a major manufacturer's official app store highlights the difficulty of managing risk in consumer-grade connected devices, even when those devices are deployed in business environments.

Why it matters

For UK businesses, this is a prompt to review what Internet of Things devices are connected to corporate or guest networks, particularly smart TVs, digital signage or connected displays in meeting rooms, reception areas or public spaces. Organisations should consider whether these devices are segmented from business networks, whether they are receiving security updates, and whether they could be introducing unexpected proxy or network relay risks.

Source: Krebs on Security

Today's Key Actions

  • Confirm that Zimbra Collaboration Suite environments are fully patched and that monitoring is in place to detect unusual mailbox access, credential use or directory enumeration activity.
  • Begin identifying where cryptography is used across the organisation, particularly in long-lived systems, data archives or partner integrations, and consider whether post-quantum cryptography migration planning has clear ownership.
  • Review what data Microsoft Copilot or similar AI assistants can access, how they respect existing permissions and data classification, and whether the organisation has sufficient visibility and control to meet data protection obligations.
  • Review what Internet of Things devices are connected to corporate or guest networks, particularly smart TVs and connected displays, and consider whether they are segmented, updated and monitored for unexpected network activity.
  • Ensure that ownership of email security, cryptographic standards, AI governance and IoT device management is clearly assigned and that these areas are included in regular security and architecture review cycles.

Secarma Insight

The stories in today's brief reflect a common theme: security challenges that require organisations to look beyond immediate threats and consider how technology, architecture and governance decisions made today will affect resilience in the months and years ahead. Whether it's ensuring that email systems are patched and monitored, planning for cryptographic migration, governing AI assistant deployments, or managing the network risks introduced by consumer devices, the organisations that manage these issues well are those that have already built the habits, ownership and visibility needed to respond calmly and effectively. Good security practice is not about reacting to every new development with urgency, but about maintaining the discipline and clarity that allows organisations to assess risk, prioritise action and make informed decisions without being overwhelmed.

News and blog posts
Today's brief focuses on developments that affect how UK organisations manage...
The NCSC, alongside the NSA, CISA and international partners, has published a...
The NCSC has published a report summarising the findings from its first...
Research published by CoreView has found that security concerns are causing...