Local Melbourne technicians available

CareersRemote supportContact
All newsroom

Newsroom · Cyber Security

Agentic AI and Zimbra phishing: two access risks to review

ASD guidance on agent permissions and Zimbra phishing explains two different risks. Check AI access, mail-server patching and incident response ownership.

ASD’s guidance on agentic AI and the joint advisory on Zimbra phishing call for two separate reviews: what automated tools are allowed to do, and whether an organisation’s email platform is exposed to a known attack. They are different developments, not evidence that AI caused the Zimbra campaign.

What the AI guidance actually says

ASD’s 24 July 2026 notice describes a security evaluation involving OpenAI models. Higher-risk safeguards were intentionally not enabled for that evaluation. It should not be presented as evidence of normal deployed behaviour or as a customer data-breach announcement.

The practical issue is the authority an agent receives. A tool that can read a document is different from one that can change accounts, send information or alter production systems. ASD recommends starting with limited uses, restricting permissions, retaining human approval for sensitive actions and recording what agents do.

A practical review before connecting an AI agent

Podium IT’s suggested starting point is a short register of the agent’s purpose, owner, connected systems and permitted actions. Work through one ordinary task and one failure scenario before extending its access.

  • Separate read access from permission to send messages, change records or administer systems.
  • Use a controlled trial with non-sensitive information and an explicit approval point for consequential actions.
  • Confirm where action logs are kept, who reviews exceptions and how access can be revoked.
  • Document how staff would stop an incorrect action and recover affected work.

The Zimbra advisory needs its own technical check

The joint advisory concerns Russian state-supported actors targeting Zimbra Collaboration Suite webmail. It describes exploitation of CVE-2025-66376, which was patched in November 2025. A malicious email can execute its payload when viewed in vulnerable webmail; the advice therefore goes beyond avoiding suspicious links.

If your organisation uses Zimbra, ask the mail administrator or hosting provider to confirm the installed version and applicable patch status against the advisory. The guidance also covers compromise indicators, investigation and remediation. Patching alone should not be treated as proof that an earlier intrusion did not occur.

What this means for a Melbourne practice

First establish whether either issue applies. A practice using a different email platform should not assume it is affected by this specific Zimbra vulnerability. A practice without agents connected to operational systems has a different AI exposure from one that has granted them account access.

For a practice trialling an administrative agent, a useful exercise is to list the patient, employee and supplier information it could reach and remove access that the trial does not need. For a Zimbra customer, request a dated provider response identifying patch status, any investigation required and the person responsible for follow-up. These are planning examples, not findings about a particular practice.

Review note

Reviewed and expanded on 11 September 2026. This update separates the AI evaluation from the email campaign and adds practical checks. The original publication date and URL have been retained.

Talk to Podium IT

Need a clear next step?

Send a secure enquiry and tell us what you are planning. Please do not include passwords, patient information or other sensitive data.

Encrypted in transit Securely stored

This form uses server-side validation, bot protection and rate limiting. For urgent support, call us directly.

General information only. It is not legal, privacy or compliance advice; requirements should be assessed for your organisation.