Four Incidents, One Pattern: Trusted Platforms Are the New Perimeter
STATUS: Ongoing SEVERITY: 8/10 AUDIENCE: Government, Defense, Critical Infrastructure Security Leads
Jul 29, 2026
·Blog
·Secure Communications
%3Aquality(100)&w=3840&q=75)
A single week of reporting ties together espionage tooling that hides inside Microsoft 365, a cascading supply-chain compromise of collaboration software, hijacked edge devices used for military surveillance, and ten months of undetected access to a foreign ministry's personnel data.
What Happened
Four separate disclosures, the same underlying failure mode. Group-IB identified HOLLOWGRAPH, a Windows implant that turns a compromised Microsoft 365 mailbox's calendar into a covert command-and-control channel, moving tasking and stolen files through ordinary Microsoft Graph API traffic1. There is no vulnerability to patch — the malware abuses trust and permissions that organizations already grant.
Separately, South Korean researchers at ENKI WhiteHat documented Kimsuky (APT43) compromising two collaborative-work software vendors — one through an exploited mail-server flaw, one through employee social engineering — then using stolen vendor infrastructure data to breach the vendors' own downstream customers2. Tampered login pages and absent multifactor authentication both contributed to the cascade.
Dutch intelligence services AIVD and MIVD disclosed that a Russian intelligence service has been systematically hijacking internet-connected IP cameras across NATO states and Ukraine, using AI-assisted image analysis to track weapons shipments and military logistics — and, in Ukraine, to help target strikes on personnel and equipment3. None of the documented access required a zero-day; default credentials and exposed management interfaces were sufficient.
And South Korea's Ministry of Foreign Affairs disclosed that the Korea National Diplomatic Academy's online training platform was compromised for nearly ten months before detection, exposing personal data on at least 6,000 current and former diplomatic personnel, including roughly 350 attachés currently stationed abroad4. The breach was found by an outside agency, not the ministry itself.
What Attackers Gained – and What They Can Do with It
Attacker Gain | What It Enables | Operational Consequence | Post-Compromise Risk |
Legitimate M365 API access via a compromised mailbox | Route command-and-control traffic through ordinary, already-permitted Microsoft Graph API calls. | C2 traffic is indistinguishable from normal business activity to conventional network monitoring. | Removing the malware doesn't revoke the underlying account and app permissions that enabled the abuse in the first place. |
Stolen vendor infrastructure data | Use one compromised groupware vendor's data to breach that vendor's own downstream customers. | A single vendor compromise cascades into every organization that trusted that vendor. | Each downstream customer must independently verify their own exposure, since the vendor breach doesn't map directly to any one victim. |
Live video feeds of military logistics | Track weapons shipments, troop movements, and transport routes in near real time. | Adversary gains a persistent surveillance capability with no need for further intrusion. | Feed access can inform strike targeting even after the initial compromise is remediated elsewhere. |
Personal data on diplomatic personnel | Build a profile of current and former diplomatic staff and their postings. | Enables targeted follow-on operations — recruitment, coercion, or further phishing — against named individuals. | Exposed personnel remain a target for the remainder of their careers, regardless of when the breach is remediated. |
Why This Matters
Old Assumption | Current Reality | BlackBerry Response |
Perimeter defense and vulnerability patching are the primary defense | Three of four incidents this cycle involved no exploited vulnerability at all — just abused trust, weak credentials, or missing MFA | Comms and endpoint architecture built to operate outside shared, general-purpose trust boundaries, not dependent on patch cadence alone |
A single vendor compromise is contained to that vendor | Kimsuky used one groupware vendor's stolen infrastructure data to cascade into every downstream customer | Certified, narrow-scope platform with no shared multi-tenant vendor dependency to cascade through |
Detection happens close to the time of compromise | The Korea Diplomatic Academy breach ran undetected for nearly ten months before an outside agency flagged it | Continuous compliance monitoring designed to surface anomalous access rather than rely on periodic audit |
Recommended Actions
IMMEDIATE | Audit OAuth/Entra application permissions and Microsoft Graph API activity across your Microsoft 365 tenant for anomalous calendar or mailbox operations. |
IMMEDIATE | Inventory collaboration and groupware vendors with standing access to your infrastructure, and confirm MFA is enforced on every vendor-facing login. |
SHORT-TERM | Identify any internet-exposed cameras or IoT devices on organizational networks still running default credentials or open management interfaces. |
SHORT-TERM | Extend UEM compliance monitoring beyond core endpoints to training, administrative, and other lower-priority systems that hold sensitive personnel data. |
ONGOING | Build detection-timeline assumptions into resilience planning — treat "undetected for months" as the expected case for trusted-platform abuse, not the exception. |
BlackBerry Secure Communications Position
When four unrelated campaigns all bypass code entirely and exploit trust instead, the lesson isn't about any one platform. It's that shared, multi-tenant trust boundaries are now the primary attack surface, and the only durable defense is operating outside them.
Citations:
1. HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels (Group-IB, July 20, 2026).
2. Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant (ENKI WhiteHat, July 20, 2026).
3. Cybersecurity Advisory: Russian State Actors are Compromising IP Cameras in Europe for Military Purposes (General Intelligence and Security Service (AIVD) and Military Intelligence and Security Service (MIVD), July 10, 2026).
4. Personal Data of 10,000 Diplomats Leaked in Suspected Cyberattack (The Korea Times, July 21, 2026).
Four Incidents, One Pattern: Trusted Platforms Are the New Perimeter
STATUS: Ongoing SEVERITY: 8/10 AUDIENCE: Government, Defense, Critical Infrastructure Security Leads
Jul 29, 2026
·Blog
·Secure Communications
%3Aquality(100)&w=3840&q=75)
A single week of reporting ties together espionage tooling that hides inside Microsoft 365, a cascading supply-chain compromise of collaboration software, hijacked edge devices used for military surveillance, and ten months of undetected access to a foreign ministry's personnel data.
What Happened
Four separate disclosures, the same underlying failure mode. Group-IB identified HOLLOWGRAPH, a Windows implant that turns a compromised Microsoft 365 mailbox's calendar into a covert command-and-control channel, moving tasking and stolen files through ordinary Microsoft Graph API traffic1. There is no vulnerability to patch — the malware abuses trust and permissions that organizations already grant.
Separately, South Korean researchers at ENKI WhiteHat documented Kimsuky (APT43) compromising two collaborative-work software vendors — one through an exploited mail-server flaw, one through employee social engineering — then using stolen vendor infrastructure data to breach the vendors' own downstream customers2. Tampered login pages and absent multifactor authentication both contributed to the cascade.
Dutch intelligence services AIVD and MIVD disclosed that a Russian intelligence service has been systematically hijacking internet-connected IP cameras across NATO states and Ukraine, using AI-assisted image analysis to track weapons shipments and military logistics — and, in Ukraine, to help target strikes on personnel and equipment3. None of the documented access required a zero-day; default credentials and exposed management interfaces were sufficient.
And South Korea's Ministry of Foreign Affairs disclosed that the Korea National Diplomatic Academy's online training platform was compromised for nearly ten months before detection, exposing personal data on at least 6,000 current and former diplomatic personnel, including roughly 350 attachés currently stationed abroad4. The breach was found by an outside agency, not the ministry itself.
What Attackers Gained – and What They Can Do with It
Attacker Gain | What It Enables | Operational Consequence | Post-Compromise Risk |
Legitimate M365 API access via a compromised mailbox | Route command-and-control traffic through ordinary, already-permitted Microsoft Graph API calls. | C2 traffic is indistinguishable from normal business activity to conventional network monitoring. | Removing the malware doesn't revoke the underlying account and app permissions that enabled the abuse in the first place. |
Stolen vendor infrastructure data | Use one compromised groupware vendor's data to breach that vendor's own downstream customers. | A single vendor compromise cascades into every organization that trusted that vendor. | Each downstream customer must independently verify their own exposure, since the vendor breach doesn't map directly to any one victim. |
Live video feeds of military logistics | Track weapons shipments, troop movements, and transport routes in near real time. | Adversary gains a persistent surveillance capability with no need for further intrusion. | Feed access can inform strike targeting even after the initial compromise is remediated elsewhere. |
Personal data on diplomatic personnel | Build a profile of current and former diplomatic staff and their postings. | Enables targeted follow-on operations — recruitment, coercion, or further phishing — against named individuals. | Exposed personnel remain a target for the remainder of their careers, regardless of when the breach is remediated. |
Why This Matters
Old Assumption | Current Reality | BlackBerry Response |
Perimeter defense and vulnerability patching are the primary defense | Three of four incidents this cycle involved no exploited vulnerability at all — just abused trust, weak credentials, or missing MFA | Comms and endpoint architecture built to operate outside shared, general-purpose trust boundaries, not dependent on patch cadence alone |
A single vendor compromise is contained to that vendor | Kimsuky used one groupware vendor's stolen infrastructure data to cascade into every downstream customer | Certified, narrow-scope platform with no shared multi-tenant vendor dependency to cascade through |
Detection happens close to the time of compromise | The Korea Diplomatic Academy breach ran undetected for nearly ten months before an outside agency flagged it | Continuous compliance monitoring designed to surface anomalous access rather than rely on periodic audit |
Recommended Actions
IMMEDIATE | Audit OAuth/Entra application permissions and Microsoft Graph API activity across your Microsoft 365 tenant for anomalous calendar or mailbox operations. |
IMMEDIATE | Inventory collaboration and groupware vendors with standing access to your infrastructure, and confirm MFA is enforced on every vendor-facing login. |
SHORT-TERM | Identify any internet-exposed cameras or IoT devices on organizational networks still running default credentials or open management interfaces. |
SHORT-TERM | Extend UEM compliance monitoring beyond core endpoints to training, administrative, and other lower-priority systems that hold sensitive personnel data. |
ONGOING | Build detection-timeline assumptions into resilience planning — treat "undetected for months" as the expected case for trusted-platform abuse, not the exception. |
BlackBerry Secure Communications Position
When four unrelated campaigns all bypass code entirely and exploit trust instead, the lesson isn't about any one platform. It's that shared, multi-tenant trust boundaries are now the primary attack surface, and the only durable defense is operating outside them.
Citations:
1. HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels (Group-IB, July 20, 2026).
2. Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant (ENKI WhiteHat, July 20, 2026).
3. Cybersecurity Advisory: Russian State Actors are Compromising IP Cameras in Europe for Military Purposes (General Intelligence and Security Service (AIVD) and Military Intelligence and Security Service (MIVD), July 10, 2026).
4. Personal Data of 10,000 Diplomats Leaked in Suspected Cyberattack (The Korea Times, July 21, 2026).
%3Aquality(100)&w=3840&q=75)