The Email Was Never Opened. Nobody Clicked Anything. The Mail Server Was Still Compromised.
The employee didn't click a link. There wasn't one. They didn't open an attachment, enter a password, or even read the message. The email simply arrived. Under one specific, vulnerable configuration, that alone was enough.
You train every employee not to open a suspicious envelope.
What happens when the mailroom itself can be triggered by the envelope just arriving, before anyone carries it upstairs?
Nearly every piece of cybersecurity advice a small business hears starts the same way: don't click the link, don't open the attachment, don't enter your password on a fake page. It's good advice. It's also advice that assumes a human has to do something wrong first. Microsoft's security research team published findings on September 30, 2026 describing a vulnerability where that assumption simply doesn't apply.
What makes this one different
Microsoft tracked active, in-the-wild exploitation of CVE-2026-73570, a flaw in Zimbra Collaboration Suite, a widely used email and collaboration platform. The vulnerability sits in how a specific optional component processes incoming mail. A specially crafted email reaching a vulnerable server could trigger command execution on that server directly, with no authentication and no action required from anyone who uses it.
What happened once the door opened
Microsoft's research describes a full attacker playbook once initial access was achieved, not a one-off proof of concept:
The timeline is the part that should worry you most
The SMB translation: two different defenses for two different problems
This is the real lesson, and it's bigger than one mail server product. Employee security training, phishing awareness, multi-factor authentication, and careful clicking habits are genuinely effective defenses. They are effective against attacks that require a human to make a mistake. They do nothing against a vulnerability that attacks the technology directly, before any human is involved at all.
Know what mail and collaboration software your business actually runs.
If you or your IT provider can't immediately answer "are we running Zimbra, and which version," that's the first gap to close, independent of this specific vulnerability.
Confirm patches are applied, not just available.
A fix being released is not the same as a fix being installed. Verify the current version against what the vendor has published as patched.
Treat exposure scanning as a complement to training, not a substitute for it, or the other way around.
Human-focused defenses and technical exposure scanning cover different attack paths. A business strong in one and weak in the other is still exposed on the weak side.
Don't wait for a public disclosure date to start checking.
In this case, exploitation activity began before the vulnerability was publicly announced. Patch-and-verify cycles that wait for headlines are, by definition, already behind.
The short version
No employee made a mistake here. No password was stolen, no link was clicked, no attachment was opened. A message simply arrived, and under one specific vulnerable configuration, arriving was the entire attack. Security training solves a different problem than this one. Both matter. Neither covers for the other.
Know whether the internet-facing systems behind your email are running known-vulnerable software right now.
View the Threat Intelligence feed → Find Out More About ThreatAngel →📚 Credential Security Series → Read the full series

Comments
Post a Comment