---
title: "Cyber Security News Update, Week 10 of 2020 | DuoCircle"
description: "We always get excited when we stumble upon a vulnerability that affects a billion of anything. Today’s star? Kr00k. It’s crime?"
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-10-of-2020/"
---

Quick Answer

Week 10 of 2020 covered: the Kr00k vulnerability in Broadcom and Cypress Wi-Fi chips, exposing data on roughly a billion devices from Amazon, Apple, Google, Samsung, Raspberry Pi Foundation, Xiaomi, Asus, and Huawei; a phishing campaign using a fake Norton LifeLock document to install a remote access tool, leveraging the brand as a trust signal; phishing pages served via Google Translate redirects that mimic the Google login form; Help Net Security findings that defense-evasion behavior appeared in over 90% of 2,000 modern malware samples, with attackers using standard application protocols and secondary C2 channels; APWG/PhishLabs data showing nearly three-quarters of phishing sites now use SSL certificates, removing HTTPS as a reliable trust indicator; the Munson Healthcare breach in northern Michigan exposing PHI through multiple compromised employee email accounts over 2.5 months; the Tennessee Orthopedic Alliance phishing attack affecting over 81,000 patients via two compromised employee accounts; and a Walgreens mobile app messaging leak exposing PII and limited health data.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-10-of-2020%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2010%20of%202020&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-10-of-2020%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-10-of-2020%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-10-of-2020%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2010%20of%202020 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2010%20of%202020&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-10-of-2020%2F "Share via Email") 

![DuoCircle blog post image](https://media.mailhop.org/duocircle/images/2020/03/dkim-selector-5456.jpg) 

_We always get excited when we stumble upon a vulnerability that affects a billion of anything_. Today’s star? Kr00k. It’s crime? [Exposed Data from Over a Billion Wi-Fi Devices](https://www.securityweek.com/kr00k-vulnerability-exposed-data-over-billion-wi-fi-devices).

“_Kr00k impacts devices using some Wi-Fi chips made by Broadcom and Cypress_. The vulnerability has been found to affect smartphones, tablets, laptops, IoT devices, routers and access points made by Amazon, Apple, Google, Samsung, Raspberry Pi Foundation, Xiaomi, Asus, and Huawei.” Don’t say we didn’t warn you.

## Norton LifeLock Phishing Scam

_I thought Norton LifeLock was supposed to protect you from scams_. Now it’s being used to phish you. From [Bleeping Computer](https://www.bleepingcomputer.com/news/security/norton-lifelock-phishing-scam-installs-remote-access-trojan/), “Cybercriminals behind a recently observed **phishing campaign** used a clever ruse in the form of a bogus Norton Lifelock document to fool victims into installing a remote access tool (RAT) that is typically used for legitimate purposes. _The malicious activity has the hallmarks of a seasoned threat actor familiar with evasion techniques and offensive security frameworks that help install the payload_.”

This is very typical of today’s **phishing attacks**. The idea is to use trust signals, like Norton Lifelock, to get you to let your guard down. And once you do…

[![Phishing Attack](https://media.mailhop.org/duocircle/images/2020/03/dkim-selector-5457.jpg)](https://media.mailhop.org/duocircle/images/2020/03/dkim-selector-5457.jpg)

## Phishing Attack Via Google Translate

Need to translate something? _You might want to steer clear of Google Translate. It’s being used to phish you_.

According to an [online article](https://ehikioya.com/forums/topic/beware-phishing-attack-via-google-translate/), “Here’s how the trick works: _You get an email stating that something has gone wrong with your Google account_. They may say that someone is trying to access your account. They may then provide a link that is actually a **malicious URL** for you to click on. If you click it, you will be redirected through Google Translate to a page that looks like the Google login form.” Here’s a tip. **Don’t login**.

## Phishing Phrontier

_The scary thing is, malware is starting to get really smart_. Smart as in it’s learning to **avoid detection**. From [Help Net Security](https://www.helpnetsecurity.com/2020/02/27/malware-evasive-behaviors/), “Modern malware is increasingly leveraging evasive behaviors. _Defense evasion behavior was seen in more than 90 percent of the 2,000 samples they analyzed._”

The article continues, “Cyber criminals continue to leverage standard application protocols in network deployments to operate under the radar and blend in with standard business traffic. They are also deploying secondary C2 methods on sleep cycles, allowing them to wake up a new method of C2 upon discovery or prevention of their primary method.” It’s an arms race and keeping up is getting exhausting.

## SSL Certificate on Phishing Sites

There used to be a time, _that to protect yourself from phishing, all you had to do is make sure any website you visited has **SSL protection**_ (i.e., HTTPS). Not anymore. From a Help Net Security [article](https://www.helpnetsecurity.com/2020/02/26/phishing-ssl/), “_Almost three-quarters of all phishing sites now use SSL protection_.”

“The researchers at APWG member PhishLabs documented the rising use of SSL certificates on **phishing websites**. This was the highest percentage since tracking began in early 2015, and is a clear indicator that _users can’t rely on SSL alone to understand whether a site is safe or not._” Those days are gone.

## Body Count

It’s not uncommon to see healthcare companies be victims of a data breach. They’re usually caused by an employee getting their email hacked if they do not have [email security service](/). What we don’t usually see is a data breach at a healthcare company where _“several” employees got their email hacked_. But, that is the case with the [Munson Healthcare](https://www.scmagazine.com/home/security-news/data-breach/munson-healthcare-data-breach-exposes-phi/) data breach.

“The northern-Michigan based Munson Healthcare group reported **several employee email accounts** were hacked and being accessed for two and a half months last year exposing PHI. The accounts contained PHI that included names, dates of birth, insurance information along with treatment and diagnostic information. In some cases, patient financial account numbers, driver’s license numbers and Social Security numbers were involved.” The more the merrier I suppose.

## Tennessee Orthopedic Alliance Phishing Attack

Not to be outdone, the Tennessee Orthopedic Alliance phishing attack impacted over [81,000 patients](https://www.hipaajournal.com/tennessee-orthopaedic-alliance-phishing-attack-impacts-over-81000-patients/). \[The\] “Alliance has discovered unauthorized individuals have gained access to the email accounts of two employees.” Do you see a theme here? _More than one employee’s email account being compromised_.

“Patients were notified about the breach on February 14, 2019\. Individuals whose Social Security number was potentially compromised have been offered complimentary credit monitoring and **identity theft protection** services. While PHI in the accounts could have been accessed by the attackers, TOA found no evidence to indicate patient information has been misused.” Yet.

[![Data Breach](https://media.mailhop.org/duocircle/images/2020/03/dkim-selector-5458.jpg)](https://media.mailhop.org/duocircle/images/2020/03/dkim-selector-5458.jpg)

## PHI Data Breach

Our final installment of the PHI data breach trilogy comes courtesy of…Walgreens. Not just Walgreens, but more specifically, their mobile app. According to [SC Magazine](https://www.scmagazine.com/home/security-news/walgreens-mobile-app-leaked-pii-phi-on-small-percentage-of-customers/), “_A leak in the Walgreens mobile app’s messaging service exposed personal information_, including what the company said was ‘limited health-related data’, on a ‘small percentage’ of customers who used the app between Jan. 9-15.”

“Because the leak included PII and potentially protected health information (PHI), Walgreens might find that it’s run afoul of regulations like HIPAA and CCPA and now possibly faces costly penalties.” _At least it was only a small percentage of customers_.

And that’s the week that was.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-10-of-2020%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2010%20of%202020&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-10-of-2020%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-10-of-2020%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Spam](https://media.mailhop.org/duocircle/images/2016/05/spf-permerror-3256.jpg)  April Spam Filtering Uptime Report News ](/blog/announcements/april-spam-filtering-uptime-report/)
- [ ![Spam Filtering](https://media.mailhop.org/duocircle/images/2023/02/spf-record-tester-7226.jpg)  Changes to Spam Filtering Technology News ](/blog/announcements/changes-to-spam-filtering-technology/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2020/01/spf-permerror-7312.jpg)  Cyber Security News Update, Week 1 of 2020 News ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 1m  April Spam Filtering Uptime Report  May 4, 2016 ](/blog/announcements/april-spam-filtering-uptime-report/)[  News 2m  Changes to Spam Filtering Technology  Feb 8, 2023 ](/blog/announcements/changes-to-spam-filtering-technology/)[  News 4m  Cyber Security News Update, Week 1 of 2020  Jan 3, 2020 ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 10 of 2020","description":"We always get excited when we stumble upon a vulnerability that affects a billion of anything. Today’s star? Kr00k. It’s crime?","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-10-of-2020/","datePublished":"2020-03-07T15:14:33.000Z","dateModified":"2025-05-27T12:35:24.000Z","dateCreated":"2020-03-07T15:14:33.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-10-of-2020/"},"articleSection":"announcements","keywords":"","wordCount":852,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2020/03/dkim-selector-5456.jpg","caption":"DuoCircle blog post image","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 10 of 2020","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-10-of-2020/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 10 of 2020","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-10-of-2020/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 10 of 2020","description":"We always get excited when we stumble upon a vulnerability that affects a billion of anything. Today’s star? Kr00k. It’s crime?","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-10-of-2020/","datePublished":"2020-03-07T15:14:33.000Z","dateModified":"2025-05-27T12:35:24.000Z","dateCreated":"2020-03-07T15:14:33.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-10-of-2020/"},"articleSection":"announcements","keywords":"","wordCount":852,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2020/03/dkim-selector-5456.jpg","caption":"DuoCircle blog post image","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
