---
title: "Infrastructure Invoice Fraud, Zimbra’s Critical Zero-Day, Microsoft Cloud Breach, Cybersecurity News [24 July 2023] | DuoCircle"
description: "Here is a helpful compilation of noteworthy developments in the email security landscape which you might have overlooked."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-30-of-2023/"
---

Quick Answer

Email security headlines for the week of July 24, 2023\. Abnormal Security tracked a vendor email compromise (VEC) campaign in which one threat group used five hijacked vendor mailboxes to send invoice fraud emails to 15 people across five critical infrastructure organizations, including manufacturing, logistics, and healthcare. Zimbra warned of an actively exploited zero-day, CVE-2023-34192, in Zimbra Collaboration Suite 8.8.15 and shipped a manual fix. Wiz researchers reported that the stolen Microsoft MSA signing key behind the M365 Outlook breach could forge access tokens for SharePoint, OneDrive, Teams, and any app using 'Login with Microsoft.' A typo problem routed millions of US military emails to Mali's .ml domain over roughly a decade. Google began moving about 2,500 employees onto internet-restricted desktops to reduce attack surface. Lookout attributed Android spyware DragonEgg and WyrmSpy to APT 41 (Barium/Winnti).

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-30-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Infrastructure%20Invoice%20Fraud%2C%20Zimbra%E2%80%99s%20Critical%20Zero-Day%2C%20Microsoft%20Cloud%20Breach%2C%20Cybersecurity%20News%20%5B24%20July%202023%5D&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-30-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-30-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-30-of-2023%2F&title=Infrastructure%20Invoice%20Fraud%2C%20Zimbra%E2%80%99s%20Critical%20Zero-Day%2C%20Microsoft%20Cloud%20Breach%2C%20Cybersecurity%20News%20%5B24%20July%202023%5D "Share on Reddit") [ ](mailto:?subject=Infrastructure%20Invoice%20Fraud%2C%20Zimbra%E2%80%99s%20Critical%20Zero-Day%2C%20Microsoft%20Cloud%20Breach%2C%20Cybersecurity%20News%20%5B24%20July%202023%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-30-of-2023%2F "Share via Email") 

![cybersecurity news](https://media.mailhop.org/duocircle/images/2023/08/SMTP-providers.jpg) 

_Here is a helpful compilation of **noteworthy developments** in the_ [_email security_](/content/email-security-services/types-of-email-security) _landscape which you might have overlooked._

## VEC Campaign Targets Critical Infrastructure Organizations with Invoice Fraud Attack

According to new research by Abnormal Security, a single threat group infiltrated five **vendor email accounts**. They then used the compromised accounts to send [invoice fraud](https://www.bbc.com/news/uk-england-stoke-staffordshire-65167757) emails to 15 individuals in five critical infrastructure organizations. _The targeted establishments included a manufacturing organization, two logistics groups, and two healthcare establishments._

‘Abnormal’ says that although the emails contained grammatical errors, they possessed some features that made them look legitimate and **bypass traditional security defenses**. It is a classic example of a [vendor email compromise (VEC)](https://www.cloudflare.com/learning/email-security/what-is-vendor-email-compromise/) fraud attack. ‘Abnormal’ further added that it blocked the emails for its customers but other organizations might not have been so lucky.

## Zimbra Warns of a Critical Zero-Day Vulnerability in Its E-mail Software

Zimbra recently warned that its email software had a critical [zero-day vulnerability](/email-security/unpatched-dogwalk-a-new-microsoft-zero-day-vulnerability/) that malicious actors were actively exploiting. The **security flaw (CVE-2023-34192)** allowed a remote authenticated attacker to execute an arbitrary code. Since the specifics of the vulnerability are undisclosed, experts are concerned about its potential implications.

[![zero day attack](https://media.mailhop.org/duocircle/images/2023/08/anti-phishing-software.jpg)](https://media.mailhop.org/duocircle/images/2023/08/anti-phishing-software.jpg)

The vulnerability impacts Zimbra Collaboration Suite (ZCS) v.8.8.15, used by numerous businesses, government agencies, and universities. Following the discovery, Zimbra sent instructions to apply a **manual fix** and eliminate the attack vector. _It urged its customers to update to the **patched version** of ZCS as soon as possible_.

## Microsoft Cloud Attack Potentially Exposed More Than Just Outlook E-mails

Researchers at Wiz, a [cloud security](/email-security/cloud-security-strategies-businesses-need-to-follow-in-2022/) startup, warned organizations running Microsoft’s M365 platform about a **stolen Microsoft security key** that can give Chinese threat actors access to their data.

> Wiz researcher Shir Tamari said their researchers discovered that the perpetrators could use the compromised MSA key to create **fake access tokens** for various [Azure Active Directory](https://www.bleepingcomputer.com/news/microsoft/microsoft-rebrands-azure-active-directory-to-microsoft-entra-id/) applications, like SharePoint, OneDrive, and Teams.

He added that the threat actors could also access Microsoft **customer applications** supporting the “Login with Microsoft” functionality. Therefore, Wiz has urged organizations using Microsoft services and Azure to immediately assess any potential impact that is more than breached email security.

## A Typo Causes ‘Millions of E-mails’ For US Military to Get Routed To .ml Addresses

According to a recent finding, millions of emails meant for .mil [US military](https://www.internationalnewsandviews.com/chinas-cyber-threat-looms-over-us-military-infrastructure-white-house-in-crisis-mode/) addresses got redirected to **.ml addresses**, a top-level domain of Mali (Africa), for a decade! As a result of the typographical error, maps of military installations, identity documents, bookings for high-ranking military leaders, travel itineraries, medical data, and other important information were sent to the .ml addresses rather than the .mil ones.

Responding to questions about why the US military **could not detect** the [email leaks](https://www.bloomberg.com/news/articles/2023-02-22/pentagon-and-microsoft-investigating-leak-of-military-emails) for so long, the US Department of Defense said it was aware of the mistake and considered any disclosures of Controlled National Security Information or Controlled Unclassified Information by unauthorized parties seriously.

## Google to Restrict Internet Access to Employees for Reducing Cyber Attack Risk

[![Cyber Attack](https://media.mailhop.org/duocircle/images/2023/08/phishing-protection-7970.jpg)](https://media.mailhop.org/duocircle/images/2023/08/phishing-protection-7970.jpg)

Google recently started a new campaign to restrict employees to **internet-free desktop** PCs. Initially, Google selected around 2,500 employees to participate but later revised the campaign to allow employees to opt-out or volunteers to enter.

_The selected desktops **will not have internet** access, but Google-owned websites like Gmail, Google Drive, and internal web-based tools will work_. Employees who need the internet for doing their jobs will be exempted, Google said in a report. The organization is running the program to reduce [cyberattack risks](https://www.spglobal.com/marketintelligence/en/news-insights/latest-news-headlines/russian-cyberattack-risk-may-spur-us-cybersecurity-investments-69025221) for its employees.

## Chinese Espionage Group Responsible for Advanced Android Spyware

[Cybersecurity firm](/) ‘Lookout’ recently said that APT 41 (a Chinese espionage group) was behind the **advanced Android spyware** dubbed DragonEgg and WyrmSpy. Also called Barium and Winnti, the Chinese spyware group has been active since 2012.

They have been targeting multiple private entities for financial gain and government organizations for espionage. The experts opine that if an advanced Chinese spyware group like **APT 41** focuses on mobile devices, it shows that they are [high-value targets](https://www.securityweek.com/cybercrime-gang-uses-screenlogger-to-identify-high-value-targets-in-us-germany/) with coveted data.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-30-of-2023%2F) [ ](https://twitter.com/intent/tweet?text=Infrastructure%20Invoice%20Fraud%2C%20Zimbra%E2%80%99s%20Critical%20Zero-Day%2C%20Microsoft%20Cloud%20Breach%2C%20Cybersecurity%20News%20%5B24%20July%202023%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-30-of-2023%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-30-of-2023%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Infrastructure Invoice Fraud, Zimbra’s Critical Zero-Day, Microsoft Cloud Breach, Cybersecurity News [24 July 2023]","description":"Here is a helpful compilation of noteworthy developments in the email security landscape which you might have overlooked.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-30-of-2023/","datePublished":"2023-08-02T19:27:36.000Z","dateModified":"2025-05-15T15:43:46.000Z","dateCreated":"2023-08-02T19:27:36.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-30-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":662,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/08/SMTP-providers.jpg","caption":"cybersecurity news","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Infrastructure Invoice Fraud, Zimbra’s Critical Zero-Day, Microsoft Cloud Breach, Cybersecurity News [24 July 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-30-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Infrastructure Invoice Fraud, Zimbra’s Critical Zero-Day, Microsoft Cloud Breach, Cybersecurity News [24 July 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-30-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Infrastructure Invoice Fraud, Zimbra’s Critical Zero-Day, Microsoft Cloud Breach, Cybersecurity News [24 July 2023]","description":"Here is a helpful compilation of noteworthy developments in the email security landscape which you might have overlooked.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-30-of-2023/","datePublished":"2023-08-02T19:27:36.000Z","dateModified":"2025-05-15T15:43:46.000Z","dateCreated":"2023-08-02T19:27:36.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-30-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":662,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/08/SMTP-providers.jpg","caption":"cybersecurity news","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
