All issues
Tech & Security Intelligence Issue 014 · 24 Aug 2026

The Weekly
Brief

The NCSC says the money lost to cybercrime halved last quarter — and the hard cases went up anyway. Four flaws are confirmed under attack, an Exchange deadline closes this month, and researchers got Copilot to explain its own weak spot.

Paul, Director of Node-Red
Curated by Paul
Editor · Node-Red

4 stories · 7 min read

In this issue

01 New Zealand

Losses halved last quarter — and the incidents needing real help went up anyway

On 20 August the NCSC published its Cyber Security Insights report for the second quarter of 2026 — the three months from 1 April to 30 June. The headline figures look like good news. 1,129 incidents were reported. Direct financial losses came to $2.7 million, a 52% fall on the previous quarter. Scams and fraud made up 348 of the reports and around $860,000 of the damage; unauthorised access accounted for roughly $1.3 million.

The number that actually matters is smaller and moving the other way. 92 incidents needed the NCSC’s specialist technical support, up from 77 the quarter before. Overall reporting volumes barely moved, so what changed is the mix: a larger share of what came in was serious enough to warrant hands-on intervention, and the agency notes that incidents with the potential for national impact are increasing even while the totals stay flat. Two techniques are called out as emerging. Malware scams, where the victim is talked into installing the malicious software themselves rather than being hacked in any technical sense. And QR code phishing — a code on a poster, an invoice or in an email that leads to a credential-harvesting page.

02 Threat Alert

Four flaws went from patched to actively exploited — SharePoint is the one to check

On 18 August the US cyber agency CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalogue — the list of flaws confirmed to be under attack in the real world, as opposed to the tens of thousands that merely could be. It is the closest thing the industry has to a “stop what you’re doing” list, and it is free to read. All four are in software plenty of New Zealand businesses run: Microsoft SharePoint, Windows, VMware vCenter and Apple macOS. US federal agencies were given until 21 August — three days — to fix them.

The one most likely to matter here is CVE-2026-55040, a weak-authentication flaw in Microsoft SharePoint rated CVSS 9.1, which lets an unauthenticated attacker over the network bypass a security feature. It affects SharePoint Server 2016, 2019 and Subscription Edition — the versions you run on your own server. SharePoint Online inside Microsoft 365 is Microsoft’s to patch, so this is a problem for the businesses still hosting their own. Alongside it: CVE-2026-33824, a double-free in the Windows Internet Key Exchange service extensions, which is the plumbing underneath VPN connections; CVE-2026-59310, a path-traversal flaw in VMware vCenter, where a single compromise hands over an entire virtual estate; and CVE-2026-65400, an authentication flaw in macOS. That makes 18 additions to the catalogue in the first three weeks of August alone.

03 Microsoft 365

If anything still talks to your mailboxes the old way, this month is your last chance to say so

Exchange Web Services is a roughly twenty-year-old interface that lets other software talk to Microsoft 365 mailboxes. Almost nobody buys it deliberately — it is the plumbing underneath things you did buy: backup and archiving tools, email signature managers, room-booking panels, the multifunction printer that scans to email, and older CRM or practice-management integrations. Microsoft first said it was going away in 2018. The timetable is now firm: from 1 October 2026 EWS begins being disabled tenant by tenant, finishing with a complete shutdown in 2027.

The mechanism is the part to understand, because it defaults against you. Every tenant has an EWSEnabled setting with three possible values, and today most sit on Null — which quietly means “everything allowed”. Any tenant still on Null on 1 October has it flipped to False as the change rolls out, and every application using EWS stops working at that moment. There is an opt-out: configure an AppID allow list and set EWSEnabled to True, and if you do it before the end of August, your tenant is excluded from the automatic switch entirely. Miss the window and you are not stuck — an administrator can turn it back on afterwards — but there is an outage first. Microsoft says it will pre-populate an allow list, based on each tenant’s own observed usage, for customers who haven’t built one before September.

04 AI Security

Researchers asked Copilot why an attack wouldn’t work until it explained how to make it work

On 18 August Varonis Threat Labs published CoSnitch — a critical one-click flaw in Microsoft Copilot Personal, tracked as CVE-2026-24301 and patched by Microsoft the same day. The bug itself is interesting; how it was found is more so. Rather than reverse-engineering anything, the researchers repeatedly asked Copilot why automatic prompt execution wasn’t possible, treating each polite refusal as the setup for the next question. In the course of explaining why the attack could never work, Copilot mapped out its own architecture and eventually named the undocumented parameter that made it work. Varonis calls the technique meta-hacking — social-engineering the model’s reasoning rather than attacking its code.

The attack chained three weaknesses. First, an undocumented URL parameter caused a prompt to run the instant the page loaded — no click, no keystroke, no confirmation. Second, Copilot’s ability to fetch URLs was turned into an exfiltration channel, sending data to a server the attacker controlled, drawn from whatever the victim had connected: Gmail, Google Drive, Calendar. Third, web summarisation was used to poison Copilot’s persistent memory, so the attacker’s instructions outlived the session. Varonis demonstrated pulling email contents including plaintext credentials, calendar titles and attendees, Drive file metadata, and chat history. It was disclosed to Microsoft in December 2025. There is no evidence it was ever used in the wild.

Tip of the week

Find out what’s still plugged into your accounts — and unplug what isn’t earning its place

Two of this week’s stories come back to the same thing: software you granted access to once and then stopped thinking about. The Exchange deadline is about old applications still reaching into mailboxes; CoSnitch is about connected accounts quietly feeding an assistant. They are the same audit, and it takes about fifteen minutes. For Microsoft 365: an administrator can open the Microsoft Entra admin centre → Enterprise applications and sort by date added. You are looking for three things — anything you don’t recognise, anything from a supplier you no longer use, and anything holding broad permissions such as reading all mailboxes or all files. Individual staff can check their own at myapps.microsoft.com. For Google accounts: myaccount.google.com/permissions lists every third-party app with access, and revoking one is a single click. What turns up is remarkably consistent: the trial of a product somebody evaluated two years ago, a signature tool from a previous IT provider, a scanning app one person installed for themselves, and — increasingly — two or three AI assistants nobody mentioned. Each one is a live key to your data, held by a company you may no longer have any relationship with. Remove what you don’t recognise or don’t use. If something does break, you will know inside a day exactly what it was, and you can grant it again with the right permissions this time — which is a far better position than never having looked. If we manage your tenant, we can run this report for you and send back a plain-English list of what has access and what we’d remove; just ask.

Node-Red

Want all of this handled for you?

We keep an eye on the threats, the updates and the fine print so you don't have to. Book a free, no-obligation IT checkup.

Book your free IT checkup