This Week In Email — July 29, 2026
Russian state hackers spent a year inside Zimbra webmail — no click required. Amazon is walking away from hosted business email entirely. Substack just bet its brand on detecting AI-written newsletters. Plus: Apple finally patches Hide My Email 13 months late, police take down the Kratos phishing kit, DKIM2 clears real milestones at IETF 126, and the EU AI Act's transparency rules bite this Saturday. It's a lot. Let's get into it.
In This Issue
Laundry Bear exploited a Zimbra zero-day for a year — view the email, lose the mailbox
AWS WorkMail is dead — full shutdown March 31, 2027, and the SES/SPF entanglement is the sharp edge
Substack ships AI detection on every post — the opposite bet from beehiiv
Apple fixes Hide My Email — 13 months after first report, one week after the lawsuit
Kratos phishing kit dismantled — ~1,800 paying customers gone dark
DKIM2 at IETF 126 — DNS spec adopted, hackathon interop, two Vienna sessions
EU AI Act Article 50 — transparency obligations apply August 2
Top Stories
Russian "Laundry Bear" Exploited a Zimbra Zero-Day for a Year — No Click Required
Security & Anti-Abuse. On July 23–24, Western cyber agencies (with a CISA warning attached) disclosed that Russian state-backed group Laundry Bear had been exploiting a Zimbra Collaboration Suite zero-day — CVE-2025-66376, a stored XSS in webmail — since July 2025. The mechanism is the nasty part: simply viewing the email triggered the exploit. No click, no attachment, no credential prompt. Victims across government, defense, energy, media, and NGO targets lost up to 90 days of mail plus 2FA recovery codes. The flaw sat unpatched for roughly five months.
Same week, Zimbra shipped fixes for a critical SNMP command injection and four more XSS bugs (July 21). Following this month's Roundcube exploitation, the pattern is unmistakable: self-hosted webmail is squarely in the espionage crosshairs. If you run Zimbra, patch now — and assume 90 days of exposure, because that's what the attackers assumed too.
Sources: The Hacker News, CyberScoop, Zimbra patches, Risky Business
Amazon Is Retiring AWS WorkMail — Full Shutdown March 31, 2027
Infrastructure & MTAs. AWS confirmed end of support for WorkMail: no new customers since April 30, 2026, and after March 31, 2027 every mailbox, console, and byte of stored data — mail, contacts, calendars — becomes permanently inaccessible. AWS is pointing customers at third-party alternatives (Kopano Cloud, Zoho Mail, Zoom Mail) and, to their credit, warning about the genuinely sharp operational edge: migrations that touch shared SPF/DKIM/DMARC records can break application-generated mail for customers who pair WorkMail with SES.
The through-line: only giants and specialists survive in mailbox hosting. Notion Mail died two weeks ago. Gmailify and POP fetching sunset in January 2027. Now one of the three biggest cloud providers on Earth has decided hosted business email isn't worth running. If your org is on WorkMail, the migration itself is the easy part — untangling your DNS authentication records from SES without breaking transactional mail is the project. Start now, not in Q1 2027.
Sources: AWS documentation, emailexpert
Substack Ships AI Detection: Pangram-Powered "Scan for AI" on Every Post
Platforms & Marketing. On July 21–22, Substack launched a Pangram-integrated tool that lets readers scan any post, comment, or reply (100+ words, published from July 21 onward) for an estimate of how much was AI-written, plus a new author statement space for disclosing AI use. CEO Chris Best's framing: undisclosed AI "undermines trust in authorship and threatens the livelihoods of writers."
This is the exact opposite bet from beehiiv's Copilot push we covered last issue. Newsletter platforms are now diverging philosophically on AI — one selling you the drafting tools, the other selling your readers a lie detector. The risk to watch: detection-tool false positives on legitimate writers, which Pangram's track record hasn't fully escaped. If your platform lets readers scan your work, your platform has made your writing process part of your product. Whether you agreed to that or not.
Sources: TechCrunch, Axios, Engadget
Security & Anti-Abuse
Apple Finally Fixes the Hide My Email Bug — 13 Months After First Report
Following up on the California class action we covered last week: Apple has patched the Hide My Email flaw that exposed users' real addresses in mail logs (reported July 21). The fix landing one week after the lawsuit was filed writes its own timeline — June 2025 report, a claimed March 2026 fix that never shipped, July 2026 litigation, then an actual patch.
For senders, the operational advice stands: treat aliases as permanent inboxes. For Apple, the class action now proceeds against a fixed-but-13-months-late backdrop, which is not the posture you want in front of a judge. Nothing motivates a patch like a filing date.
Source: The Hacker News
Police Dismantle Kratos Phishing Kit — ~1,800 Paying Customers, M365 Session Theft, MFA Bypass
Law enforcement shut down the infrastructure behind Kratos, a widely-used phishing-as-a-service platform built to steal Microsoft 365 sessions and bypass MFA, used by roughly 1,800 paying customers monthly (July 22). Two weeks after Forg365 showed device-code phishing being rented for $400/month, this is the other side of the market.
And there's data to back the strategy: Microsoft's Q2 threat report (in the links below) shows its March disruption of Tycoon2FA drove a sustained 92% decline in linked phishing volume. Takedowns work. They suppress specific kits while the category persists — but suppressing specific kits at scale is a lot better than filter whack-a-mole. Counter-programming to the doom coverage, and worth having in your pocket next budget cycle.
Source: The Hacker News
Deliverability & Authentication
DKIM2 Clears IETF 126: DNS Spec Adopted, Hackathon Interop, Two Vienna Sessions
Following up on the spec-04 coverage from last issue: the DKIM working group met twice at IETF 126 (July 21 and 24, Vienna) after a July 18 hackathon interop session, and draft-ietf-dkim-dkim2-dns-00 — the standalone DNS/key-record spec, adopted from draft-chuang-dkim2-dns — was published July 20. The work is modularizing into spec + motivation + DNS + BCP documents, and the mailing list shows live threads on deployment profiles and post-quantum threat models.
That modularization is what a standard on a real deployment path looks like. The nuance worth knowing: the DNS doc explicitly plans for DKIM and DKIM2 to co-exist "for at least some period" — so nobody's flag-day nightmare is on the table. If you're tracking the Q4 2026 experimental-rollout target, this was a good week for it.
Regulatory & Compliance
EU AI Act Article 50 Transparency Obligations Bite August 2
The European Commission published final Article 50 transparency guidelines on July 20 — two weeks before the obligations apply on August 2. This Saturday. Providers and deployers of AI systems must disclose when people are interacting with AI and when content has been generated or altered by it. That reaches AI-drafted marketing email, AI chat agents replying to customers, and synthetic content in campaigns aimed at EU audiences.
If your team leans on Copilot, Gemini, or beehiiv-Copilot-style drafting for EU-facing sends, the question for counsel is "what does disclosure look like" — and the time to ask is this week, not after the enforcement letters start. don't wait on this one.
Source: emailexpert
Events & Community
MailCon New York — August 3, NYC. Performance-email conference covering deliverability, automation, AI, and omnichannel. Last call. Details
ZeroBounce deliverability webinar — August 6, 11 AM ET. Free vendor webinar on intent signals, deliverability, and program ROI. Details
M3AAWG 68 CFP deadline — August 10. Proposals for the 68th General Meeting (October 26–29, Paris) are due; hotel group rate cuts off September 30. If you have a session in you, the clock is short. Details
CSA webinar: "From DKIM to DKIM2: What Senders Need to Know Now" — Tuesday, August 25, 9:00 AM US Central. Sebastian Kluth (CSA), Kieran Cooper (Halon), and Bron Gondwana (Fastmail, a DKIM2 co-author). Free registration. Register
Links Worth Your Time
Microsoft's Q2 2026 email threat landscape — the Tycoon2FA disruption in March drove a sustained 92% decline in linked phishing volume through Q2. Rare provider-scale evidence that infrastructure takedowns beat filter whack-a-mole. Microsoft Security Blog
Zeta Global closes a $1B credit facility — BofA-led, $250M Term Loan A plus a $750M undrawn revolver, explicitly for M&A and buybacks. After Infobip/SocketLabs, another well-capitalized acquirer shopping in martech. Watch where the revolver gets drawn. Business Wire, emailexpert analysis
Thele v. Google reaches its decision point — the ~21-day window to amend the dismissed Gemini-in-Gmail wiretap complaint expires right around press time. Refile or die; check the docket. Case background, emailexpert's three-case tracker
"Modern email can be built from borrowed parts" — an essay proposing an email successor assembled from HTTP, JMAP, and modern crypto hit the HN front page (192 points, 139 comments). The comments are the story: network effects, why every replacement scheme since the '90s failed, and whether incremental fixes beat clean-slate designs. Hacker News, essay
Spam Resource on the "context box" — Al Iverson on the line reminding recipients why they're getting your mail. Cheap, honest complaint-rate hygiene — but only if you don't fake the permission claim. Spam Resource
Troubleshooting 554 5.7.5 DMARC rejections — a walkthrough of the cryptic "permanent error evaluating DMARC policy" class: broken record, DNS timeout, or alignment failure. Bookmark it for the next on-call escalation. Spam Resource
What it took a 153-year-old community bank to reach DMARC enforcement — the messy middle (shadow senders, staged policy ratchets) that vendor marketing skips. Good ammunition for getting enforcement projects funded. emailexpert
CNIL pixel deadline aftermath — emailexpert maps who's exposed now that the transitional window has closed, with Italy's Garante mirror deadline (October 28) as the next date on the wall. emailexpert
Litmus on preference centers — preference collection as the practical answer to AI-mediated inboxes and stricter complaint thresholds. Pairs neatly with the context-box post as a consent-hygiene theme. Litmus
Gmail's "Help me write" gains free-form refinement — custom follow-up instructions instead of preset Polish/Formalize options, rolled out ~July 20 for Gemini-enabled Workspace editions. More recipient-side drafting means more machine-shaped replies in your engagement data. Google Workspace Updates
That's the week. If something is wrong, reply and tell me — I read every response. Better yet, hit "forward" and send this to a colleague who runs mail for a living.
— John
This Week In Email — thisweekin.email

