---
title: "Cybersecurity News Update, Week 12 of 2023 | DuoCircle"
description: "Every week there are new developments in cyberspace, threats, and breaches."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-12-of-2023/"
---

Quick Answer

Week 12 of 2023 covered: a Ferrari breach disclosed via customer notification letters after attackers demanded ransom for stolen names, addresses, emails, and phone numbers (no payment data exposed); an Akamai-discovered Go-based Mirai variant called HinataBot targeting Realtek SDK, Huawei routers, and Hadoop YARN servers via CVE-2014-8361 and CVE-2017-17215, capable of HTTP and UDP flood DDoS up to a theoretical 3.3 Tbps; FBI arrest of Connor Brian Fitzpatrick (alias Pompompurin) as the alleged owner of BreachForums, released on $300,000 bond; Google Project Zero disclosing 18 zero-days in Samsung Exynos chipsets including 4 Internet-to-baseband RCE flaws exploitable with only the victim's phone number, with users advised to disable Wi-Fi calling and VoLTE until patches arrive; an Avast report on Redline information-stealer distributed through Adobe Acrobat Sign documents that lead to ZIP archives stealing credentials, crypto wallets, and payment card data; and Independent Living Systems (ILS) notifying 4,226,508 individuals of a breach that ran June 30 to July 5, 2022, exposing names, SSNs, and medical/insurance information.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-12-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cybersecurity%20News%20Update%2C%20Week%2012%20of%202023&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-12-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-12-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-12-of-2023%2F&title=Cybersecurity%20News%20Update%2C%20Week%2012%20of%202023 "Share on Reddit") [ ](mailto:?subject=Cybersecurity%20News%20Update%2C%20Week%2012%20of%202023&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-12-of-2023%2F "Share via Email") 

![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/03/SMTP-relay-5864.jpg) 

Every week there are new developments in cyberspace, threats, and breaches. This week’s cybersecurity news covers Ferrari’s Data Breach, the New HinataBot Botnet, Pompompurin’s arrest, Samsung’s 18 [Zero-Day Vulnerabilities](/email-security/two-zero-day-vulnerabilities-discovered-in-microsoft-exchange-server-patches-pending/), the Redline Info-Stealing Malware, and the ILS Healthcare Data Breach. Let’s get started.

## Ferrari Reveals Data Breach After Receiving Ransom Demand

Following a breach in some of its IT systems, Ferrari has revealed that it received a ransom demand from attackers.

In breach notification letters sent to customers, Ferrari expressed regret for the cyber incident, acknowledging that a limited number of systems in its **IT environment** had been accessed. While the luxury carmaker confirmed that the attackers demanded a ransom not to leak data stolen from its systems, it has not yet revealed whether this was a [ransomware attack](/resources/ryuk-ransomware-attacks) or an extortion attempt.

Ferrari explained that a [threat actor](/email-security/threat-actors-abuse-linkedins-smart-links-in-evasive-email-phishing-attacks/) had contacted Ferrari S.p.A, its **wholly-owned Italian subsidiary**, with a ransom demand related to specific client contact details. After receiving the ransom demand, Ferrari immediately initiated an investigation along with a leading international third-party cybersecurity enterprise.

Names, addresses, email addresses, and telephone numbers were among the customer information exposed in the incident, according to one of the world’s most significant and **popular vehicle manufacturers**. However, the organization has not found evidence that _payment details, bank account numbers, or other sensitive payment information_ were accessed or stolen.

[![cybersecurity](https://media.mailhop.org/duocircle/images/2023/03/spf-record-generator-6175.jpg)](https://media.mailhop.org/duocircle/images/2023/03/spf-record-generator-6175.jpg)

Ferrari [reassured](https://www.ferrari.com/en-EN/corporate/articles/cyber-incident-in-ferrari) its customers that the attack did not impact the organization’s operations, as measures have been taken to secure the compromised systems. The automaker also reported the attack to **relevant authorities** and is working with a [cybersecurity](/) organization to determine the extent of the impact.

## Massive 3.3 Tbps DDoS Attacks Possible with New ‘HinataBot’ Botnet

Researchers from Akamai recently discovered a novel botnet that targets **Realtek SDK**, Huawei routers, and Hadoop YARN servers. The [malware botnet](https://www.bleepingcomputer.com/news/security/realtek-and-cacti-flaws-now-actively-exploited-by-malware-botnets/) seeks to harness devices into a [DDoS (Distributed Denial of Service)](https://www.a10networks.com/blog/5-most-famous-ddos-attacks/) swarm, which can lead to massive attacks. The botnet operates by exploiting old vulnerabilities such as CVE-2014-8361 and CVE-2017-17215.

The botnet, called HinataBot, appears to be a **Go-based variant** of the notorious Mirai strain and is distributed by either **brute-forcing SSH endpoints** or using infection scripts and RCE payloads for known [vulnerabilities](https://en.wikipedia.org/wiki/Vulnerability%5F%28computing%29). After infecting devices, the malware runs quietly, waiting for commands from the command and control server.

HinataBot is still under active development, with functional improvements and anti-analysis additions. Although earlier versions of HinataBot supported **HTTP, UDP, ICMP, and TCP floods**, the newer variants only feature HTTP and UDP attacks. Nevertheless, the botnet has the potential to execute powerful DDoS attacks. Akamai researchers [suggest](https://www.akamai.com/blog/security-research/hinatabot-uncovering-new-golang-ddos-botnet) that HinataBot is still in development and may implement more exploits and widen its targeting scope.

Its ongoing development increases the likelihood of more potent versions being circulated in the wild soon. It is hoped that the authors of HinataBot will move on to other activities before the botnet becomes more widespread.

## Cybercrime Charges Lead to Arrest of Alleged BreachForums Owner Pompompurin

On Wednesday, US law enforcement apprehended a New York man suspected to be the owner of BreachForums, a hacking forum, who goes by the name **Pompompurin**.

During the arrest, the accused revealed his real name as **Connor Brian Fitzpatrick** and confirmed that he is indeed Pompourin, the owner of BreachForums. FBI Special Agent John Longmire stated that Fitzpatrick had been released on a $300,000 bond and would appear in the Eastern District of Virginia District Court on 24 March.

Until his court appearance, Fitzpatrick has relinquished his documents and can only travel within certain areas for **legal proceedings**. Additionally, he is [prohibited](https://www.documentcloud.org/documents/23713130-pompourin-affidavit-govuscourts) from contacting witnesses, co defendants, or co conspirators. In the absence of Pompompurin, a forum admin has announced that BreachForums will continue to function with full access to the **site’s infrastructure**.

Pompompurin has been a significant player in the underground cybercriminal world, focused on **breaching organizations** and selling or leaking stolen data through forums and social media. He was also a prominent member of the RaidForums cybercrime forum until the FBI seized it in 2022.

## Google Detects 18 Zero-Day Vulnerabilities in Samsung Exynos Chipsets

Google’s Project Zero recently uncovered and reported 18 zero-day vulnerabilities in Samsung’s Exynos chipsets.

Four of the 18 vulnerabilities are deemed the most serious, as they allow for [RCE (Remote Code Execution)](https://www.checkpoint.com/cyber-hub/cyber-security/what-is-remote-code-execution-rce/) from the Internet and can be exploited by attackers to compromise devices without user interaction. The remaining 14 vulnerabilities **require local access** or a malicious mobile network operator to be used. Samsung has acknowledged these vulnerabilities and provided security updates for other vendors.

However, the patches are not yet public and cannot be applied by all affected users. There’s a security issue with Wi-Fi calling and **VoLTE (Voice-over-LTE)** that you need to be aware of. For now, it’s recommended that you disable these features until patches become available to **prevent potential attacks**.

> According to Project Zero’s Head, Tim Willis, the only information that attackers need to execute the exploit is your phone number. With minimal research, [malicious actors](https://www.itprotoday.com/career-development/dark-web-developer-wanted-malicious-actors-join-it-talent-hunt) could easily create an exploit to compromise devices remotely without raising any red flags.

While this situation is definitely concerning, Samsung and Google are already taking steps to address the issue. Samsung has confirmed the workaround suggested by Project Zero and is urging everyone to update their devices immediately to stay protected.

## Redline Info-Stealing Malware Pushed Through Adobe Acrobat Sign

Avast researchers have recently uncovered a new cybercrime trend, in which criminals are taking advantage of Adobe Acrobat Sign’s online document signing service to distribute malware that **steals sensitive information** from unsuspecting users.

For those who don’t know, Adobe Acrobat Sign is a cloud-based e-signature service that enables individuals to send, sign, track, and manage [electronic signatures](https://www.adobe.com/in/sign/electronic-signatures.html) easily. Unfortunately, cybercriminals are now exploiting this service to carry out their **nefarious activities**, which is a major cause for concern.

Threat actors utilize the service to register and send emails to individuals they are targeting, which includes a link to a document stored on **Adobe’s servers**. The link within the document leads to a website that requires visitors to solve a CAPTCHA to confirm legitimacy.

Once verified, the website provides a ZIP archive that contains the [Redline information stealer](https://www.bleepingcomputer.com/news/security/adobe-acrobat-sign-abused-to-push-redline-info-stealing-malware/), malicious software that has the capability of stealing various types of data, including account credentials, cryptocurrency wallets, and credit card details stored on the device that has been breached. Avast has [identified](https://blog.avast.com/adobe-acrobat-sign-malware) highly focused attacks that use this method, one instance where the target was the owner of a popular YouTube channel with a **large number of subscribers**.

## ILS Healthcare Provider Warns 4.2 Million People of Data Breach

Miami-based healthcare administration and managed care solutions provider **ILS (Independent Living Systems)** experienced a [data breach](/email-security/how-to-respond-to-an-email-security-or-data-breach/) that compromised the personal information of 4,226,508 individuals.

The healthcare organization [discovered](https://www.documentcloud.org/documents/23707983-ils-notice-of-data-event-me?responsive=1&title=1) that its network had been hacked on 5 July 2022\. After an investigation, it was found that the hackers had access to ILS systems between 30 June and 5 July 2022, during which they could access the data. The threat actors may have accessed **patients’ personal information**, such as their names, [SSNs (Social Security Numbers)](https://www.investopedia.com/terms/s/ssn.asp), and medical and health insurance information.

[![phishing attacks](https://media.mailhop.org/duocircle/images/2023/03/spf-permerror-6582.jpg)](https://media.mailhop.org/duocircle/images/2023/03/spf-permerror-6582.jpg)

The breach could lead to [phishing attacks](/content/email-phishing-protection/how-to-mitigate-phishing-attacks) against the affected individuals. ILS completed its internal review of the breach on 17 January 2023, over six months after the discovery of the breach, and notified affected individuals in September. The organization has offered Experian’s free identity protection services to those affected by the breach for one year. The announcement comes amid a string of notable data breaches in the **healthcare sector this year**.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-12-of-2023%2F) [ ](https://twitter.com/intent/tweet?text=Cybersecurity%20News%20Update%2C%20Week%2012%20of%202023&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-12-of-2023%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-12-of-2023%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cybersecurity News Update, Week 12 of 2023","description":"Every week there are new developments in cyberspace, threats, and breaches.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-12-of-2023/","datePublished":"2023-03-21T18:41:34.000Z","dateModified":"2025-05-27T12:06:16.000Z","dateCreated":"2023-03-21T18:41:34.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-12-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1251,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/03/SMTP-relay-5864.jpg","caption":"Cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cybersecurity News Update, Week 12 of 2023","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-12-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cybersecurity News Update, Week 12 of 2023","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-12-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cybersecurity News Update, Week 12 of 2023","description":"Every week there are new developments in cyberspace, threats, and breaches.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-12-of-2023/","datePublished":"2023-03-21T18:41:34.000Z","dateModified":"2025-05-27T12:06:16.000Z","dateCreated":"2023-03-21T18:41:34.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-12-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1251,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/03/SMTP-relay-5864.jpg","caption":"Cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
