All issues
Tech & Security Intelligence ● Issue 020 · 12 Oct 2026

The Weekly
Brief

Police and the NCSC say North Korean IT workers are getting hired by New Zealand organisations, and tell you how to spot one. Ten cyber agencies describe break-ins that began with flaws up to twelve years old. Microsoft has started switching off an old way into your mailbox. And Copilot is getting a meter, which stays off until an administrator says otherwise.

Paul, Director of Node-Red
Curated by Paul
Editor · Node-Red

4 stories · 8 min read

In this issue

01 NZ Advisory

Police and the NCSC: check who your remote IT contractor really is

On 1 October the National Cyber Security Centre and New Zealand Police published a joint advisory on North Korean IT workers trying to get hired by New Zealand organisations. The background is blunt. North Korea has sent thousands of skilled IT workers out into the world to look for work in software development, website design, graphic design and IT services, and the money they earn goes back to the regime, including to its nuclear weapon and ballistic missile programmes. The advisory says there have been instances of these workers attempting, and succeeding, in getting work in New Zealand and overseas. One of them was in the NCSC’s Cyber Threat Report 2026: a large New Zealand business hired a remote IT contractor who was later identified as North Korean, and who, once let go, claimed to hold commercially sensitive information and demanded payment.

The method is a false identity, built carefully. The advisory lists stolen or purchased identities, including doctored New Zealand driver licences and passports, fabricated CVs and references, fake business email addresses set up to pass referee checks, and deepfake or AI-assisted interview answers. The workers operate mainly from China, Laos and Russia, hiding their location behind VPNs and remote-desktop tools. New Zealanders have been drawn in without knowing it: letting their address be used to receive a company laptop, logging in and setting up remote access so the work appears to come from New Zealand, or receiving payments into their own bank account and passing them on. The workers are also known to go through recruitment agencies to look more legitimate, which is why the advisory says not to rely on an agency to do your identity checks for you.

02 Threat Advisory

Ten agencies, one warning: the break-ins began with flaws up to twelve years old

On 9 October the NCSC joined nine partner agencies from the United States, United Kingdom, Australia, Canada, Japan and Spain in publishing a detailed advisory on Chinese government-linked hackers. It centres on Integrity Technology Group, a China-based company with links to the Chinese government, and the hacking groups it supports, whose methods match activity publicly known as Flax Typhoon. The information comes from evidence recovered in FBI investigations. Victims were found across government, manufacturing, healthcare and IT in the United States, along with law enforcement, education and religious organisations, and organisations across Southeast Asia, Africa and North America.

What stands out is how ordinary the methods are. The groups run automated scanners across the internet looking for websites and web applications with known weaknesses; one of their tools holds more than 1,300 ready-made test scripts, with WordPress among the targets. They use a freely available tool to guess passwords against Microsoft 365 and Exchange email accounts, trying each address through every sign-in route the mail system offers. Once inside, they install a legitimate VPN program, renamed to look like a normal Windows file, so they can come back whenever they like, and then use scripts to copy out email, calendars and contacts. The advisory lists eight vulnerabilities the groups exploited successfully. The oldest dates from 2014 and the newest from 2023. In the agencies’ words, the reliance on freely available tools suggests the attackers tend to look for the more vulnerable targets.

03 Microsoft 365

Microsoft has started switching off an old way into your mailbox

Exchange Web Services, or EWS, is an older connection method that lets other programs read and send email, and work with calendars and contacts, in Microsoft 365. We flagged its retirement in Issue 014, and the switch-off has now begun. From 1 October, in a phased rollout, any Microsoft 365 organisation that had never made a choice about EWS has it turned off by default, which blocks it for every app. If something important breaks, an administrator can turn it back on for now. That option ends on 1 April 2027, when EWS is disabled permanently for everyone, and Microsoft’s Exchange team is plain about it: “There will be no exceptions past April 2027.” Microsoft also says it may run short tests where EWS is switched off and back on. Businesses running their own Exchange Server on site are not affected.

Most people will notice nothing. Microsoft says its own apps have moved off EWS or are close to it, and many other software makers have done the same. The risk sits with older or unmaintained software that connects to your mailboxes: for example a calendar or room-booking display, a CRM or practice-management system that files emails, an email archiving or migration tool, or a custom integration somebody built years ago. When EWS goes, these tend to stop syncing without a clear error. You do not have to guess which apps are involved. The Microsoft 365 admin centre has an EWS usage report (Reports → Usage → Exchange → EWS usage) that lists every app still using it.

04 AI & Copilot

Copilot is getting a meter, and it stays off until an admin says yes

When Microsoft relaunched Copilot last month (Issue 018), it had not said how the new features would be charged. A message centre notice published on 25 September (MC1479276) fills in part of the answer. There will be two tracks. Everyday AI stays covered by the existing Copilot licence, priced per user per month. Advanced AI, including the newest “frontier” models, can be charged by usage, through what Microsoft calls Copilot Credits. Staff will meet this in two places: when they pick a frontier model or an advanced feature, and when they hit a usage limit and are offered the option to keep going on credits. The rollout begins in the last quarter of 2026. The notice gives no prices.

The important part is the safeguard. The pay-per-use options will be visible to users by default, but Microsoft says they are not enabled or functional until an administrator creates a spending policy in the Microsoft 365 admin centre. A spending policy sets limits and alerts, and can decide which models different groups of staff are allowed to use. Users will be able to see their own credit use and what is left, with banners as they approach a limit. One gap to be aware of: the notice talks about Enterprise tenants and does not spell out how this will work on the Business plans most small firms use.

Tip of the week

List every outsider who has a login to something of yours

The advisory in story 1 suggests auditing the remote workers you already have. Here is a wider version that takes about fifteen minutes. Write down every person outside your own staff who can sign in to something of yours: the web developer, the bookkeeper or accountant, a software supplier’s support login, the marketing agency, a previous IT provider, the contractor from last year’s project. Then ask three questions about each one. Do they still need it? If nobody can say what a login is for, remove it. Is it their own named login with MFA, or a shared password that several people know? Does it have only the access the job needs, or is it a full administrator because that was quicker at the time? The places to look are the user and guest lists in Microsoft 365 or Google Workspace, the admin users on your website, the users in your accounting software, your domain name account and the page roles on your social media. Most businesses find at least one login that should have been closed long ago. Managed clients: ask us for a list of the accounts and guests in your Microsoft 365 to start from.

Node-Red

Want all of this handled for you?

We keep an eye on the threats, the updates and the fine print so you don't have to. Book a free, no-obligation IT checkup.

Book your free IT checkup