← All issues

This Week in Email: July 29, 2026

Independent coverage of the full email ecosystem. This Week: Russian state hackers spent a year inside Zimbra webmail — no click required. Amazon is walking away from hosted business email entirely. Substack just bet its brand on detecting AI-written newsletters.

Russian state hackers spent a year inside Zimbra webmail — no click required. Amazon is walking away from hosted business email entirely. Substack just bet its brand on detecting AI-written newsletters. Plus: Apple finally patches Hide My Email 13 months late, police take down the Kratos phishing kit, DKIM2 clears real milestones at IETF 126, and the EU AI Act's transparency rules bite this Saturday. It's a lot. Let's get into it.

In This Issue

Top Stories

Russian "Laundry Bear" Exploited a Zimbra Zero-Day for a Year — No Click Required

Security & Anti-Abuse. On July 23–24, Western cyber agencies (with a CISA warning attached) disclosed that Russian state-backed group Laundry Bear had been exploiting a Zimbra Collaboration Suite zero-day — CVE-2025-66376, a stored XSS in webmail — since July 2025. The mechanism is the nasty part: simply viewing the email triggered the exploit. No click, no attachment, no credential prompt. Victims across government, defense, energy, media, and NGO targets lost up to 90 days of mail plus 2FA recovery codes. The flaw sat unpatched for roughly five months.

Same week, Zimbra shipped fixes for a critical SNMP command injection and four more XSS bugs (July 21). Following this month's Roundcube exploitation, the pattern is unmistakable: self-hosted webmail is squarely in the espionage crosshairs. If you run Zimbra, patch now — and assume 90 days of exposure, because that's what the attackers assumed too.

Sources: The Hacker News, CyberScoop, Zimbra patches, Risky Business

Amazon Is Retiring AWS WorkMail — Full Shutdown March 31, 2027

Infrastructure & MTAs. AWS confirmed end of support for WorkMail: no new customers since April 30, 2026, and after March 31, 2027 every mailbox, console, and byte of stored data — mail, contacts, calendars — becomes permanently inaccessible. AWS is pointing customers at third-party alternatives (Kopano Cloud, Zoho Mail, Zoom Mail) and, to their credit, warning about the genuinely sharp operational edge: migrations that touch shared SPF/DKIM/DMARC records can break application-generated mail for customers who pair WorkMail with SES.

The through-line: only giants and specialists survive in mailbox hosting. Notion Mail died two weeks ago. Gmailify and POP fetching sunset in January 2027. Now one of the three biggest cloud providers on Earth has decided hosted business email isn't worth running. If your org is on WorkMail, the migration itself is the easy part — untangling your DNS authentication records from SES without breaking transactional mail is the project. Start now, not in Q1 2027.

Sources: AWS documentation, emailexpert

Substack Ships AI Detection: Pangram-Powered "Scan for AI" on Every Post

Platforms & Marketing. On July 21–22, Substack launched a Pangram-integrated tool that lets readers scan any post, comment, or reply (100+ words, published from July 21 onward) for an estimate of how much was AI-written, plus a new author statement space for disclosing AI use. CEO Chris Best's framing: undisclosed AI "undermines trust in authorship and threatens the livelihoods of writers."

This is the exact opposite bet from beehiiv's Copilot push we covered last issue. Newsletter platforms are now diverging philosophically on AI — one selling you the drafting tools, the other selling your readers a lie detector. The risk to watch: detection-tool false positives on legitimate writers, which Pangram's track record hasn't fully escaped. If your platform lets readers scan your work, your platform has made your writing process part of your product. Whether you agreed to that or not.

Sources: TechCrunch, Axios, Engadget

Security & Anti-Abuse

Apple Finally Fixes the Hide My Email Bug — 13 Months After First Report

Following up on the California class action we covered last week: Apple has patched the Hide My Email flaw that exposed users' real addresses in mail logs (reported July 21). The fix landing one week after the lawsuit was filed writes its own timeline — June 2025 report, a claimed March 2026 fix that never shipped, July 2026 litigation, then an actual patch.

For senders, the operational advice stands: treat aliases as permanent inboxes. For Apple, the class action now proceeds against a fixed-but-13-months-late backdrop, which is not the posture you want in front of a judge. Nothing motivates a patch like a filing date.

Source: The Hacker News

Police Dismantle Kratos Phishing Kit — ~1,800 Paying Customers, M365 Session Theft, MFA Bypass

Law enforcement shut down the infrastructure behind Kratos, a widely-used phishing-as-a-service platform built to steal Microsoft 365 sessions and bypass MFA, used by roughly 1,800 paying customers monthly (July 22). Two weeks after Forg365 showed device-code phishing being rented for $400/month, this is the other side of the market.

And there's data to back the strategy: Microsoft's Q2 threat report (in the links below) shows its March disruption of Tycoon2FA drove a sustained 92% decline in linked phishing volume. Takedowns work. They suppress specific kits while the category persists — but suppressing specific kits at scale is a lot better than filter whack-a-mole. Counter-programming to the doom coverage, and worth having in your pocket next budget cycle.

Source: The Hacker News

Deliverability & Authentication

DKIM2 Clears IETF 126: DNS Spec Adopted, Hackathon Interop, Two Vienna Sessions

Following up on the spec-04 coverage from last issue: the DKIM working group met twice at IETF 126 (July 21 and 24, Vienna) after a July 18 hackathon interop session, and draft-ietf-dkim-dkim2-dns-00 — the standalone DNS/key-record spec, adopted from draft-chuang-dkim2-dns — was published July 20. The work is modularizing into spec + motivation + DNS + BCP documents, and the mailing list shows live threads on deployment profiles and post-quantum threat models.

That modularization is what a standard on a real deployment path looks like. The nuance worth knowing: the DNS doc explicitly plans for DKIM and DKIM2 to co-exist "for at least some period" — so nobody's flag-day nightmare is on the table. If you're tracking the Q4 2026 experimental-rollout target, this was a good week for it.

Sources: IETF Datatracker, ietf-dkim archive, adoption call, session schedule

Regulatory & Compliance

EU AI Act Article 50 Transparency Obligations Bite August 2

The European Commission published final Article 50 transparency guidelines on July 20 — two weeks before the obligations apply on August 2. This Saturday. Providers and deployers of AI systems must disclose when people are interacting with AI and when content has been generated or altered by it. That reaches AI-drafted marketing email, AI chat agents replying to customers, and synthetic content in campaigns aimed at EU audiences.

If your team leans on Copilot, Gemini, or beehiiv-Copilot-style drafting for EU-facing sends, the question for counsel is "what does disclosure look like" — and the time to ask is this week, not after the enforcement letters start. don't wait on this one.

Source: emailexpert

Events & Community

Links Worth Your Time

That's the week. If something is wrong, reply and tell me — I read every response. Better yet, hit "forward" and send this to a colleague who runs mail for a living.

— John

This Week In Email — thisweekin.email

Enjoyed this issue?

Subscribe to This Week in Email and get future issues delivered to your inbox.