What's happening in email security: July 13 – July 19, 2026
When a password manager has to warn its own users about a phishing campaign wearing its name, you know brand impersonation is the whole game. LastPass did exactly that this week. Microsoft shipped a record Patch Tuesday with yet another crafted-email Exchange flaw, two Scattered Spider members got real prison time, and a flaw in an AI browser assistant quietly opened a path to reading Gmail. Plenty to get through.
Exchange OWA is back in Patch Tuesday, again
July's release was enormous. Krebs counted around 570 patches, other trackers logged 622 CVEs and three zero-days. The one email teams need to find in that pile is CVE-2026-55008, a critical spoofing flaw in Exchange OWA rooted in cross-site scripting, CVSS 9.6. An unauthenticated attacker sends a crafted email, and if the recipient opens it in OWA under the right conditions, JavaScript runs in their browser context. If that sounds familiar, it should. It's the same class of crafted-email OWA bug as CVE-2026-42897 from the spring.
It affects Exchange Server Subscription Edition RTM, 2019 CU14/CU15, and 2016 CU23, and it came with a set of companion Exchange fixes including an RCE (CVE-2026-55005). The two actively exploited zero-days this cycle were in SharePoint and ADFS, both added to CISA's KEV list. If you run Exchange on-prem, the OWA spoofing bug is your priority in an otherwise overwhelming patch set.
ACR Stealer rides ClickFix to your M365 files
ACR Stealer is being pushed through ClickFix lures, the ones that trick users into pasting attacker commands into the Windows Run dialog. Once running, it lifts saved browser passwords, session tokens, and Microsoft 365 documents synced locally from OneDrive and SharePoint. Microsoft saw a surge from late April through mid-June. One delivery chain is fileless, using mshta.exe and payloads hidden in JPEGs, and some lures pose as fake Claude and AI-tool pages. Neither chain exploits a vulnerability. They rely entirely on the user running the command. Session tokens plus M365 files is a straight line to account takeover and BEC.
SeasonalInvite turned eCards into RMM delivery
A six-month operation impersonated greeting-card services like BlueMountain, rotating its lures with the calendar, and delivered legitimately signed remote monitoring tools as the payload. Researchers found 959 domains and four weaponized RMM products, including ConnectWise ScreenConnect and Kaseya. The signed installers sailed past security checks, and the infrastructure showed signs of AI-generated code. Legitimate-tool abuse plus AI-assisted variant generation is a combination we'll keep seeing.
LastPass had to warn users about a fake LastPass
Attackers registered two lookalike domains, `lastpassnewsletter[.]com` to send from and `lastpasscompliance[.]com` to host the trap, and blasted out emails with the subject "Action Required: Review Updated LastPass Security Policies." The link led to a DocuSign-style compliance portal built to harvest master passwords and push a malware download. LastPass was clear that its own systems weren't touched. This was pure social engineering against its users.
Here's the uncomfortable part for defenders: LastPass's own DMARC, SPF, and DKIM did nothing to stop this, because the attacker never spoofed the real lastpass.com domain. They registered their own and authenticated that. So the useful question isn't "was our domain protected," it's "how fast can we find the imposter and get it killed." LastPass's response is the tell: they named the exact sending and landing domains, reconfirmed they never ask for master passwords, and pointed users at a way to report it. Speed of detection, a takedown process you can actually trigger, and a reporting channel people use, that's the half of the impersonation problem that lives outside your DNS records.
- A Claude for Chrome flaw could trigger Gmail reads
Manifold Security found that any browser extension with script rights on claude.ai could fire synthetic clicks at Claude's allowlisted prompts to invoke its Google integrations, including reading Gmail (CVSS 7.7, rising to 9.6 in full automation), and it was still unpatched with no CVE assigned at the time of writing, a reminder that as AI assistants gain mailbox access a rogue extension shouldn't be able to make one read your inbox.
- North Korea hid malware in SVG flag images inside fake coding tests
The Contagious Interview crew is still running fake job interviews at developers, tracked this round as REF9403. The initial contact came through a Slack #jobs channel in late May, and the payload, a variant of OtterCookie, was tucked into base64 blobs inside the HTML comments of SVG country-flag images in trojanized repos. It specifically hunts AI coding-tool config directories like `.claude`, `.cursor`, and `.gemini`. North Korean actors keep dressing malware up as hiring and recruitment workflows, a pattern we've flagged repeatedly through the summer. Treat unsolicited "coding test" repos as a phishing vector, especially for your engineers.
- Scattered Spider members sentenced for the TfL hack
Owen Flowers, 18, and Thalha Jubair, 20, each got 5.5 years for the 2024 Transport for London attack that took down 148 systems, forced 27,000 staff to reset passwords in person, and cost £29 million. Scattered Spider is synonymous with vishing and victim-branded credential-harvesting pages. The exact TfL entry point wasn't disclosed, but a custodial sentence for social-engineering operators is a signal worth noting.
Want email security news in your inbox every week?
Subscribe here and stay up to date with what's happening in email security.




