Cybersecurity’s attack surface is widening in several directions at once. Threat actors are disguising legitimate remote-management software as workplace updates, critical-infrastructure operators are confronting operational technology risks, and AI agents are inheriting excessive cloud permissions. Meanwhile, industry initiatives are targeting two essential defensive requirements: stronger cyber hygiene and openly available AI security tools.
Operation BlueDash weaponises fake Microsoft Teams updates
A Microsoft Teams-themed phishing campaign known as Operation BlueDash is using fake “secure document” notifications to install legitimate remote monitoring and management tools.
According to The Hacker News, victims are redirected through compromised infrastructure to a counterfeit Microsoft Store page claiming that Teams must be updated before a shared document can be opened. The downloaded loader launches a concealed PowerShell process that installs Level RMM and enrols the device using an attacker-controlled key.
The campaign also deploys ConnectWise ScreenConnect, giving its operators redundant remote access if one tool is detected or removed. Once connected, the attackers examine firewall profiles, disk protection, reboot status and membership of the local Administrators group.
Researchers have attributed the operation with moderate-to-high confidence to a Nigeria-based threat actor. Evidence indicates that the supporting infrastructure has been active since at least February 2026, while a related Zoom-themed lure has been used to distribute Tactical RMM.
The campaign demonstrates why signed, legitimate administration tools cannot automatically be treated as trusted. Organisations should maintain an inventory of approved RMM software, alert on unrecognised deployments and closely monitor PowerShell activity originating outside established IT workflows. These controls complement the identity verification and continuous monitoring principles discussed in HIPTHER’s coverage of Zero Trust cybersecurity.
Rail cybersecurity becomes an operational safety priority
The 13th Annual Rail Cybersecurity Summit will return to London on 9–10 March 2027, bringing together railway operators, infrastructure managers, government bodies, regulators, rolling-stock companies and cybersecurity specialists.
The event announcement highlights a programme spanning operational technology resilience, vulnerability management, threat detection, secure remote access and supply-chain risk. Regulatory and technical frameworks—including NIS2, the EU Cyber Resilience Act, CLC/TS 50701 and IEC 62443—are also expected to feature prominently.
Germany’s Federal Railway Authority, the Eisenbahn-Bundesamt, is among the organisations scheduled to participate. Its contribution is expected to examine the relationship between cybersecurity and railway safety oversight, including the coordination required between operators and public authorities.
For rail companies, the central challenge is that a cyber incident can affect much more than information confidentiality. Compromised signalling, maintenance, communications or operational systems can disrupt physical services and create safety consequences. Legacy equipment and long asset lifecycles make segmentation, compensating controls and carefully governed third-party access particularly important.
European transport organisations should also consider how sector-specific obligations interact with the wider compliance challenges examined in HIPTHER’s analysis of NIS2 and the IT channel.
Act Security launches with $60 million to tackle cloud access sprawl
Act Security has emerged from stealth with an “action-centric” cloud security platform and $60 million in total funding.
The company raised a $20 million seed round led by Team8 and Bessemer Venture Partners, followed by a $40 million Series A led by Notable Capital. According to the company’s announcement, Act was founded by members of the team behind medical-device security specialist Medigate, which Claroty acquired for $400 million.
Act argues that conventional cloud security platforms generate extensive lists of vulnerabilities and misconfigurations without removing the access paths that make those findings exploitable. Its platform instead seeks to enforce boundaries governing what human users, workloads and autonomous AI agents can reach.
The product is designed to identify and remove unnecessary access, enforce least privilege, prevent new violations from entering production through CI/CD pipelines and map controls to standards including NIST 800-53, PCI DSS and HIPAA.
This focus is becoming more relevant as AI agents gain access to production infrastructure. An agent that inherits broad human permissions can operate continuously and at machine speed, magnifying the consequences of dormant privileges and weak identity architecture.
The launch reflects a broader transition from vulnerability visibility to structural risk reduction. It also aligns with the cloud and generative AI security trends previously explored in HIPTHER’s report on Saudi Arabia’s evolving cyber landscape.
ConnectSecure and CIS turn cyber hygiene guidance into practice
ConnectSecure and the Center for Internet Security have introduced an Essential Cyber Hygiene Fundamentals bootcamp intended to help practitioners implement foundational safeguards.
The first virtual programme will run from 18–21 August 2026 through four half-day sessions, with subsequent bootcamps planned monthly. As detailed by Business Wire, the vendor-agnostic curriculum centres on CIS Implementation Group 1 Controls and Safeguards.
IG1 is intended to provide an essential security baseline for organisations of different sizes. The programme will focus on turning that guidance into practical, repeatable processes rather than teaching participants how to operate a particular security product.
Those who complete the programme and pass its final examination will receive a certificate and digital badge co-branded by CIS and ConnectSecure.
The initiative addresses a persistent industry gap: organisations often know which security fundamentals they should implement but struggle to operationalise them consistently. Asset inventories, secure configuration, access control, vulnerability remediation, backups and security awareness remain vital even as attention shifts toward AI-enabled threats.
Adobe backs an open approach to AI security
Adobe has joined the Open Secure AI Alliance, an industry initiative bringing together technology, cloud, cybersecurity and open-source organisations to develop and share AI security resources.
The company’s participation, highlighted by Yahoo Finance, places it alongside founding members including NVIDIA, Microsoft, IBM, Cisco, Cloudflare, Hugging Face, Red Hat and the Linux Foundation.
The alliance aims to give defenders open models, tools and agent harnesses that can be inspected, adapted and deployed under their own control. Its scope extends beyond securing models themselves to include agent identities, permissions, logs, evaluation systems and behavioural guardrails.
Adobe’s involvement is strategically relevant because generative AI is becoming embedded across creative and document workflows. As AI features gain access to user content, enterprise data and external tools, organisations will need stronger mechanisms for evaluating models, restricting agent permissions and tracing automated actions.
Open collaboration will not eliminate AI risk, but it can give defenders greater visibility into the systems they are expected to secure. The initiative also demonstrates that open-source development and cybersecurity are not opposing objectives when projects include transparent governance, testing and responsible disclosure.
The bigger picture: control legitimate tools, access and automation
This edition’s stories share a common theme: security failures increasingly arise from legitimate capabilities operating outside their intended boundaries.
Operation BlueDash turns trusted RMM products into persistent backdoors. Cloud access sprawl gives attackers and AI agents more reach than they require. Rail operators must manage authorised remote connectivity without exposing safety-critical systems. At the same time, training programmes and open security alliances are attempting to make defensive knowledge more accessible.
For security leaders, the priorities are clear:
- Identify unapproved remote-management software and investigate its deployment context.
- Reduce standing privileges across users, workloads and AI agents.
- Treat operational technology resilience as a safety and continuity issue.
- Implement foundational controls before investing exclusively in advanced detection.
- Require auditable identities, permissions and logs for autonomous systems.
The next stage of cyber resilience will depend not only on detecting malicious software, but also on controlling how legitimate tools, trusted identities and automated agents behave.











Got a Questions?
Find us on Socials or Contact us and we’ll get back to you as soon as possible.