Cybersecurity’s boundaries are expanding faster than many organisations can redraw them.
Russian attackers are reportedly exploiting Microsoft Outlook Web Access installations, while US lawmakers are debating the future of CISA’s election-security and artificial intelligence work. Washington has also restricted imports of certain new Chinese robots and power inverters over national-security concerns.
Elsewhere, Arctic Wolf’s research exposes a gap between the adoption of AI in security operations and confidence in the technology. The US Department of Energy has appointed Andrew McClure to lead its cybersecurity and emergency-response office, while Corporate Technologies is marking 45 years of providing IT and security services to American small businesses.
Together, these stories show that cybersecurity now encompasses legacy software, democratic institutions, physical machines, energy systems, AI governance and the resilience of smaller companies.
Russian hackers reportedly exploit Microsoft OWA environments
Russian state-linked hackers are reportedly exploiting organisations through exposed Microsoft Outlook Web Access environments, placing another legacy enterprise service under scrutiny.
According to The Hacker News, the activity demonstrates how externally accessible email infrastructure can provide attackers with an entry point into sensitive organisations.
OWA allows employees to access Microsoft Exchange mailboxes through a browser. That convenience also means the service may be reachable from the public internet, making weak authentication, unpatched vulnerabilities and poorly monitored login activity especially dangerous.
Email accounts are valuable targets because they contain far more than messages. A compromised mailbox can expose internal conversations, contact networks, invoices, meeting invitations, password-reset links and sensitive attachments. Attackers can also use a trusted account to conduct convincing phishing campaigns against colleagues and business partners.
The threat is particularly acute where organisations continue to operate older Exchange infrastructure or assume that an internet-facing login page is adequately protected by a password. Defenders should treat external email access as a privileged service and apply several layers of protection:
- Enforce phishing-resistant multifactor authentication.
- Patch Exchange and its supporting infrastructure promptly.
- Disable outdated authentication protocols.
- Monitor unusual login locations, devices and session behaviour.
- Restrict administrative interfaces and unnecessary external access.
- Review mailbox forwarding rules and delegated permissions.
- Segment email infrastructure from critical internal systems.
Organisations should also remember that legitimate credentials do not make a session legitimate. Modern attackers frequently steal passwords, session cookies or authentication tokens, allowing malicious activity to resemble ordinary user access.
The campaign reinforces a broader lesson examined throughout HIPTHER’s Cybersecurity Hub: identity, access and continuous monitoring have become central components of infrastructure defence.
Republicans move to preserve CISA’s AI and election-security work
Republican lawmakers have intervened to protect elements of the Cybersecurity and Infrastructure Security Agency’s artificial intelligence and election-security responsibilities.
As Politico reports, the move is notable because CISA’s election-related activities have faced sustained political criticism. Some conservatives have accused the agency of exceeding its cybersecurity mandate through work involving misinformation and communications with technology platforms.
The latest development suggests lawmakers are attempting to separate disputed content-related activities from the agency’s core responsibility for protecting election infrastructure.
Voting machines, registration databases, election-management systems and local government networks remain potential targets for ransomware, espionage and disruption. Election officials also require threat intelligence, incident-response assistance and practical security guidance, particularly in smaller jurisdictions with limited personnel and budgets.
CISA’s AI remit raises a parallel challenge. Government agencies need to understand how artificial intelligence can improve vulnerability analysis and threat detection, but they must also prepare for AI-assisted phishing, impersonation, malware development and influence operations.
Preserving technical expertise is important because cyber capabilities cannot be rebuilt instantly after teams are dismantled. Institutional knowledge includes relationships with state officials, infrastructure operators, researchers and private-sector providers developed over years.
The political debate should therefore distinguish between legitimate questions about remit and oversight and the operational necessity of protecting critical systems. Accountability and capability are not opposing goals: clearly defined authority, transparent procedures and congressional supervision can strengthen both.
HIPTHER has previously examined the growing importance of coordinated disclosure and public-sector partnerships in its Cybersecurity Roundup covering Sophos Fusion, Ontinue and NSA-CISA vulnerability disclosure.
US restricts new Chinese robots and power inverters
The United States has banned imports of certain new Chinese-made humanoid robots, robotic dogs and power inverters over national-security and cybersecurity concerns.
The Al Jazeera report says the Federal Communications Commission added the affected product categories to its Covered List. The restrictions apply to new models that have not already received authorisation, while previously approved products are not automatically prohibited.
The inclusion of robots and power inverters illustrates how cybersecurity policy is moving into physical infrastructure.
Humanoid robots and robotic dogs incorporate cameras, microphones, wireless communications, cloud connections and software-update mechanisms. They are increasingly used in factories, warehouses, laboratories and inspection environments. If compromised, they could provide surveillance access, expose operational data or interfere with physical processes.
Power inverters present a different but equally consequential risk. They convert electricity produced by solar panels or stored in batteries into a form that can be used by homes, businesses and the grid. Modern inverters may include remote administration, monitoring and update capabilities.
A vulnerability or concealed access mechanism affecting a widely deployed inverter platform could consequently create risks extending beyond an individual device. Coordinated manipulation might affect energy availability, grid stability or the operation of data centres and industrial facilities.
The restrictions may benefit American robotics companies including Tesla, Figure AI, Agility Robotics and Boston Dynamics. However, limiting Chinese products does not automatically make alternative technology secure. Every connected machine requires supply-chain assessment, software inventories, secure update mechanisms, vulnerability reporting and lifecycle support.
Manufacturers should also provide customers with clarity about where data is stored, which remote services can control a device and how long security updates will remain available.
This convergence of energy and cybersecurity reflects the issues explored in HIPTHER’s coverage of evolving cybersecurity threats to hydropower dams. Digital security is now inseparable from physical reliability.
Arctic Wolf finds an AI adoption and trust gap
Organisations are adopting artificial intelligence within security operations, but confidence in allowing AI to make consequential decisions remains limited.
Research covered by Industrial Cyber indicates a widening gap between experimentation with AI and trust in its output.
Security teams have strong reasons to embrace automation. They face more alerts than analysts can investigate manually, while attackers are using automation to scale reconnaissance, phishing and exploitation. AI can assist with log analysis, alert correlation, malware classification, vulnerability prioritisation and incident summaries.
Yet adoption does not equal autonomy.
Security leaders remain concerned about inaccurate conclusions, insufficient context, opaque reasoning and actions that may disrupt legitimate operations. A model that incorrectly labels activity as malicious could block an important account or isolate a production system. A false negative could allow an attack to continue unnoticed.
The practical response is not to reject AI, but to design graduated levels of authority. Low-risk tasks such as summarising alerts can be automated extensively. Recommendations involving account suspension, network isolation or deletion should require stronger evidence and human approval.
Organisations evaluating AI-powered cybersecurity tools should ask:
- Which data is used to generate each recommendation?
- Can analysts examine the supporting evidence?
- How are false positives and false negatives measured?
- Can automated actions be reversed?
- Does the system learn from sensitive customer information?
- How are model and policy changes documented?
- Who remains accountable when the system is wrong?
AI systems also require monitoring after deployment. Threat patterns, business environments and models change over time, meaning performance during a controlled trial may not represent performance six months later.
HIPTHER’s Cybersecurity Roundup on AI governance gaps and emerging threats offers additional context on why oversight must evolve alongside automation.
Andrew McClure takes leadership of DOE’s CESER office
Andrew McClure has joined the US Department of Energy as director of the Office of Cybersecurity, Energy Security and Emergency Response, commonly known as CESER.
The appointment, reported by Homeland Security Today, places McClure at the head of an office responsible for strengthening the resilience of America’s energy infrastructure.
CESER’s remit sits at the intersection of cybersecurity, emergency management, government policy and private-sector coordination. Electricity, oil and natural-gas systems are largely operated outside the federal government, meaning effective protection depends on sustained cooperation with utilities, technology providers, state authorities and infrastructure owners.
The leadership change comes as energy operators confront ransomware, state-sponsored intrusion, supply-chain exposure, extreme weather and rapidly changing electricity demand. Distributed energy resources, cloud-connected platforms and digitally managed equipment are also increasing the number of systems that defenders must understand and protect.
McClure’s challenge will therefore involve more than acquiring new security products. Resilience requires tested response plans, reliable communications, workforce development and an understanding of how cyber incidents can affect physical operations.
Energy organisations must be able to operate safely when digital systems are unavailable or untrusted. That means maintaining manual procedures where appropriate, segmenting operational technology, controlling vendor access and conducting exercises that include both technical and executive teams.
The appointment underscores a broader policy shift: cybersecurity is increasingly treated as a fundamental part of energy security rather than a supporting IT function.
Corporate Technologies marks 45 years of managed IT services
Corporate Technologies is celebrating 45 years as a provider of managed IT and cybersecurity services to small and medium-sized US businesses.
Founded in Fargo, North Dakota, in 1981 and now headquartered in Eden Prairie, Minnesota, the company says it serves more than 2,000 customers across 18 states and 21 markets.
According to its company announcement, Corporate Technologies provides managed IT, cybersecurity, cloud, compliance and disaster-recovery services, supported by a 24-hour US-based help desk.
The company reports that it resolves 93% of support issues remotely and offers a 99.9% cloud-uptime service-level commitment. It also says its systems blocked 12,977 ransomware attempts during one quarter. These figures are vendor-reported, but they illustrate the operational scale now expected of managed service providers.
Small businesses face many of the same threats as large enterprises without comparable internal security teams. They may depend on a single IT administrator or an external provider to manage identity, endpoints, backups, cloud accounts, compliance and incident response.
This makes an MSP’s own security particularly important. A compromised provider may offer attackers access to multiple customers through remote-management tools and privileged credentials.
Businesses selecting an MSP should examine its use of multifactor authentication, privileged-access controls, network segmentation, independent security testing and incident-notification procedures. They should also confirm who owns operational data and how access can be recovered if the commercial relationship ends.
HIPTHER’s broader cybersecurity coverage has repeatedly emphasised that resilience depends on governance as well as technology. Its analysis of Zero Trust adoption provides a useful framework for limiting the damage caused by compromised accounts and service providers.
The bigger picture: cybersecurity now governs digital and physical trust
These six developments appear to cover very different environments, but they share a common principle: connectivity creates dependency, and dependency creates risk.
Microsoft OWA connects employees to organisational communications. CISA connects federal expertise with state and local infrastructure. Robots and inverters connect software to physical activity. AI connects automated analysis with security decisions. CESER connects cyber preparedness to energy reliability, while managed service providers connect smaller businesses to specialist technology capabilities.
Every connection can generate efficiency, but it also establishes a path through which failure or compromise can spread.
The next stage of cybersecurity will therefore depend less on building isolated defences and more on controlling relationships between identities, systems, suppliers and decision-makers. Organisations need to know what is connected, who can control it, which actions can be automated and how operations will continue when trusted technology becomes unavailable.












Got a Questions?
Find us on Socials or Contact us and we’ll get back to you as soon as possible.