Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

Browser-hiding malware linked to ransomware, plus Exchange Online mailbox quarantine disruption

What small and medium-sized businesses should look out for today.

High Thursday 23 July 2026, 15:29 UK time
Today’s look-out: Ransomware pre-cursor malware + Microsoft 365 email disruption scams

What to look out for today

Two things to brief staff and ops teams on:

  • Ransomware-linked malware hiding activity through Chrome/Edge (a backdoor reported as “msaRAT”) designed to blend in by routing its command traffic via the web browser.
  • Microsoft Exchange Online disruption where mailboxes are being mistakenly quarantined, which can interrupt email access and create confusion attackers may exploit.

Why this matters to smaller businesses

  • Harder-to-spot compromise: if malicious traffic appears to come from Chrome/Edge, it may look “normal” and stay undetected longer—giving attackers time to steal data or prepare ransomware.
  • Business disruption risk: if Exchange Online quarantines a mailbox, staff may miss invoices, approvals, customer queries and password reset emails.
  • Scam opportunity: whenever email is unstable, criminals commonly send “fix your email / re-authenticate” messages or pose as IT support to harvest passwords and MFA codes.

Warning signs

  • Users report sudden loss of access to their mailbox, repeated login prompts, or messages about quarantine/blocked access they weren’t expecting.
  • An unusual spike in urgent ‘IT support’ calls or emails asking users to “confirm password”, “approve MFA”, or “install a quick tool”.
  • Browser oddities: Chrome/Edge becomes unusually slow, crashes, or behaves differently (new extensions, altered settings) alongside other account issues.
  • Finance teams see missing invoice emails, broken approval chains, or suppliers claiming “you didn’t reply” when you never received their message.

How attackers may exploit the situation

  • Hide in normal-looking traffic: malware that “lives off the browser” aims to make malicious communications look like everyday web browsing activity.
  • Use disruption as cover: during an Exchange Online incident, attackers may send fake Microsoft 365 alerts, “mailbox quarantine release” links, or request MFA approvals claiming they’re needed to restore service.
  • Ransomware staging: a stealthy backdoor can be used to explore your network, identify backups, and prepare encryption and extortion steps later.

What to do today

  • Send a 2-minute staff warning: “If you get any email or call about mailbox quarantine, password resets, MFA approvals, or ‘re-authentication’, do not click—report it internally.”
  • Confirm your Microsoft 365 service status and impacts: identify which mailboxes are affected, and agree a temporary comms plan (phone/Teams/alternate mailbox) for urgent customer and supplier issues.
  • Protect finance workflows: pause or add a second check for new bank details / payment changes while email is unstable or staff are distracted.
  • Check for persistence signals: review recent sign-ins and risky sign-in alerts; prioritise admin and finance accounts.

Ask your IT provider

  • Have you confirmed whether any of our mailboxes are quarantined due to the current Exchange Online issue, and what is our workaround?
  • What extra monitoring are you doing today for unusual Chrome/Edge activity patterns and suspicious outbound connections that may blend with browser traffic?
  • If a device is suspected, what is the isolation and investigation process (who decides, how fast, and how do we keep the user working)?
  • Do we have tight controls on remote access and admin actions (especially for tools that can be abused before ransomware)?

Patch watch - only one short paragraph, and only if relevant

There’s reporting on a Linux/XFS local privilege escalation flaw (CVE-2026-64600). For most SMEs, the practical question is whether any key systems (servers, NAS devices, security appliances) rely on Linux and are managed by your IT provider—ask them to confirm they’re tracking it and that privileged access to Linux boxes is tightly controlled.

One action today

Send a same-day internal note: “No one should approve unexpected MFA prompts or click ‘mailbox quarantine release’ links—report to IT by phone/Teams first.”

Related Actions On Cyber resource

Actions On Cyber: Business Email Compromise (BEC) & invoice fraud quick checklist

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.