The last day brought a Russian state-sponsored group exploiting a “half-click” flaw in Outlook Web Access, a massive driver’s license breach, a genuinely wild AI worm crawling through Word documents, and updates on two stories we have been tracking all week. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT.

A Russian state-linked hacking group is breaking into Outlook mailboxes just by getting someone to open an email. The group known as Laundry Bear, also tracked as Void Blizzard, is exploiting CVE-2026-42897, a flaw in Outlook Web Access that runs malicious code the moment a specially crafted email is opened, no clicking required beyond that. Microsoft patched the underlying bug in May, but the group had built its attack infrastructure months earlier and used it to maintain mailbox access even after victims rotated their credentials. The campaign has hit government bodies and organizations in telecom, finance, hospitality, and aerospace across the US and Europe. If your business runs on-premises Exchange Server rather than cloud-hosted email, this is worth a same-day confirmation that the May patch is actually installed. Read more at BleepingComputer

A breach at an auto insurer exposed driver’s license numbers for 6.9 million people, the largest exposure of its kind this year. AssuranceAmerica confirmed that a phishing attack against a single employee led to a breach exposing names, driver’s license numbers, Social Security numbers, and auto insurance and claims details for millions of customers. The company is not offering identity theft protection and is instead telling affected people to monitor their own accounts. If your business carries commercial auto or fleet insurance, or if your employees’ personal auto policies could be affected, this is a reminder that one phished employee at a vendor can expose data belonging to millions of people who never had a direct relationship with the attacker. Read more at BleepingComputer

A hidden prompt in a Word document can turn Microsoft Copilot into a worm that spreads itself into other files. A security researcher demonstrated that white-on-white text hidden inside a Word document can carry a prompt that Copilot for Word reads and follows when someone asks it to draft or edit content based on that document. Copilot then edits the visible content and quietly copies the same hidden instructions into the file, so the next document that touches it through Copilot can get infected too. Microsoft has fixed two related flaws but this particular worm was still exploitable at last check. If your business uses Copilot for Word on documents that come from outside your organization, such as vendor contracts or client-submitted files, it is worth treating those the same way you would treat an email attachment from an unknown sender. Read more at The Register

Amazon has tied a major open source supply chain attack to North Korea, and the affected packages are downloaded billions of times a week. Amazon attributed the 2025 hijacking of popular npm packages including debug and chalk, together downloaded more than 2 billion times weekly, to a North Korean state-linked group known as Sapphire Sleet, which phished a maintainer through a lookalike npm domain and pushed a wallet-draining script into trusted packages. The attack predates this year but the attribution is new, and it is a useful reminder that a huge share of the software your business runs, even if you never write a line of code yourself, depends on a small number of open source maintainers who are now considered nation-state targets. If your development team uses npm packages, it is worth confirming your dependency scanning would have caught something like this. Read more at BleepingComputer

Microsoft patched a cloud database flaw that could have let any customer read or overwrite every other customer’s data, though it says no one exploited it. Security researchers at Wiz found a chain of bugs in Azure Cosmos DB, nicknamed CosmosEscape, that let anyone with a basic Cosmos DB account escape the service’s query sandbox and retrieve a single master key capable of accessing every database on the platform, not scoped to any customer, region, or product. Microsoft says it found no evidence of exploitation and that no customer action is required, but the flaw existed for roughly eight months between initial discovery and full remediation. If your business stores data in Azure Cosmos DB, there is nothing to do here, but it is a good example of why “the cloud provider handles security” is not the same thing as “nothing can go wrong,” worth keeping in mind when evaluating any vendor’s shared responsibility claims. Read more at The Hacker News


Follow up on Monday’s story: federal officials say the Minnesota water system attackers directly targeted the controllers running the plants, not just the networks around them. New details show attackers accessed programmable logic controllers at the affected Minnesota water systems and changed passwords to lock operators out, forcing several plants into sustained manual operation and prompting boil water notices in at least one community. The federal government has since issued a broader warning about cyber threats to water systems nationally. This confirms the incident was not just a network disruption, it was attackers reaching the physical equipment that treats the water itself. Read more at Cybersecurity Dive

Follow up on Wednesday’s story: EY has now confirmed the breach ShinyHunters claimed, and today is the extortion group’s deadline. EY acknowledged that attackers spent more than two weeks inside a third-party IT help-desk platform used by its tax practice, downloading documents containing Social Security numbers, financial account codes, and tax filing data before the intrusion was detected. ShinyHunters set today, July 31, as its deadline to publish the stolen files if EY does not respond, though similar deadlines from this group have slipped before. If your business works with EY on tax matters, this is worth checking on directly rather than waiting to see if the data actually gets published. Read more at Infosec.ge


Sponsored by Lucky 13 Solutions

Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.


Get the Business IT News Roundup in your inbox: