What to look out for today
- Business email platform risk (Zimbra): widely reported active exploitation means organisations running Zimbra (or hosted by a provider using it) should assume increased scanning and attempted break-ins.
- Identity and login platform risk (Keycloak): a reported password-reset weakness could allow account takeover where Keycloak is used for staff/customer logins.
- “AI power users” creating shadow systems: a small number of staff can unintentionally introduce major risk by wiring AI tools and add-ons into business workflows without IT review (e.g. automations connected to email, CRM, finance, customer data).
Why this matters to smaller businesses
For SMEs, email and identity systems are often the single point of failure: if attackers get into mailboxes or your login platform, they can reset passwords elsewhere, intercept invoices, harvest customer data, and impersonate staff. Separately, unapproved AI tools can create new data exposure paths (copying sensitive text into third-party services) and new supplier dependencies that no one is monitoring.
Warning signs
- Unexplained password reset emails, MFA prompts, or sudden logouts for multiple users.
- Mailbox rules you didn’t create (auto-forwarding, auto-deleting, moving sent items).
- Customers/suppliers receiving strange replies from your team, or “new bank details” messages you didn’t send.
- New “automation” tools showing up in workflows (CRM/email plugins, AI assistants, browser extensions) that IT didn’t approve.
- Unusual login locations or access times reported by your email/identity admin consoles.
How attackers may exploit the situation
- Email platform compromise: attackers target internet-facing email systems to gain access, then pivot to invoice fraud, data theft, and internal phishing from a trusted mailbox.
- Identity provider takeover: if an attacker can force or abuse password resets, they may seize accounts and then access downstream services connected to that login (apps, portals, VPN, cloud tools).
- Shadow AI/tooling risk: “helpful” AI integrations can quietly gain access to mailboxes, documents, or customer records, creating new pathways for data leakage and account compromise if misconfigured or breached.
What to do today
- Confirm whether you use Zimbra or Keycloak (directly or via an IT provider/hosted service). If you’re not sure, ask today.
- Hunt for mailbox tampering: check for unexpected forwarding rules, suspicious delegates, and new inbox rules on finance and senior accounts.
- Reinforce payment-change controls: require call-back to a known number for any bank detail change; don’t rely on email threads.
- Inventory AI tools and automations: identify who is using AI assistants, plugins, or connectors linked to business systems; remove/disable anything unapproved until reviewed.
- Make sure MFA is on for admin accounts and finance mailboxes, and that recovery options (backup email/phone) are accurate and controlled.
Ask your IT provider
- Do we run Zimbra anywhere (including for any hosted email customers)? If yes, what’s our current exposure and what monitoring is in place?
- Do we use Keycloak for any staff/customer logins? If yes, what’s the plan to reduce account-takeover risk from password-reset paths?
- What alerts are we watching for: mass password resets, suspicious mailbox rules, unusual admin actions, and abnormal sign-in patterns?
- What is our process for approving AI tools, browser extensions, and SaaS connectors that access email, files, CRM or finance data?
- If email or identity is compromised, what’s our rapid response: account lock-down, token/session revocation, and customer/supplier comms?
Patch watch - only one short paragraph, and only if relevant
Two items to flag for operational priority rather than “routine patching”: active exploitation is being reported against a Zimbra flaw, and a critical Keycloak password-reset issue has been disclosed. If you (or your provider) run either product, treat this as urgent and confirm remediation and monitoring are in place.
One action today
Ask your IT provider today to confirm whether your organisation (or any hosted service you rely on) uses Zimbra or Keycloak, and if so, what immediate steps they’ve taken to reduce compromise risk and monitor for suspicious account activity.
Related Actions On Cyber resource
Actions On Cyber: Supplier & SaaS risk quick checklist (questions to ask your IT provider/hosted services)
Sources
- CISA orders urgent patching of actively exploited Zimbra flaw (BleepingComputer)
- Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account (The Hacker News)
- The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk (The Hacker News)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.