---
title: "Cybersecurity News Update, Week 13 of 2023 | DuoCircle"
description: "Discover the latest cybersecurity news from around the world with our latest cybersecurity bulletin sharing supply chain attacks, security updates from Apple."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-13-of-2023/"
---

Quick Answer

Week 13 of 2023 covered: a supply-chain attack ('Smooth Operator') against 3CX desktop softphone customers on Windows and macOS, with digitally signed trojanized installers connecting to attacker domains akamaicontainer.com, msedgepackageinfo.com, and azureonlinestorage.com, attributed by SentinelOne to North Korea-linked Labyrinth Collima and impacting customers including American Express, Coca-Cola, McDonald's, BMW, Honda, Air France, Toyota, Mercedes-Benz, IKEA, and the UK NHS; an $8.9 million SafeMoon liquidity-pool drain via a public 'burn' smart-contract function abused to inflate token prices on the WBNB pool; Apple's CVE-2023-23529 WebKit type-confusion patch back-ported to older iPhones and iPads; the Pwn2Own Vancouver 2023 contest with 27 zero-days exploited and over $1.035 million awarded (Team Synacktiv won 53 Master of Pwn points and a Tesla Model 3); the Australian Federal Police arresting four BEC actors who laundered $1.7 million through 180 bank accounts via Facebook Marketplace and Ponzi schemes; and OpenAI's disclosure of a Redis client bug that exposed names, emails, and partial payment-card details for about 1.2% of ChatGPT Plus members.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-13-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cybersecurity%20News%20Update%2C%20Week%2013%20of%202023&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-13-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-13-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-13-of-2023%2F&title=Cybersecurity%20News%20Update%2C%20Week%2013%20of%202023 "Share on Reddit") [ ](mailto:?subject=Cybersecurity%20News%20Update%2C%20Week%2013%20of%202023&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-13-of-2023%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2023/03/spf-record.jpg) 

Discover the latest cybersecurity news from around the world with our latest [cybersecurity](/) bulletin sharing [supply chain attacks](https://www.immuniweb.com/blog/5-biggest-supply-chain-attacks-in-2022-so-far.html), security updates from Apple, threat actors exploiting crypto bugs, hacking competitions, the arrest of an Australian BEC threat actor group, and ChatGPT’s data exposure. Let’s get into it.

## Supply Chain Attack Compromises 3CX Desktop Application

Customers of the VoIP IPBX software development enterprise 3CX are being targeted as part of an ongoing supply chain attack with the [threat actors](/email-security/threat-actors-attack-thousands-of-computers-following-the-ion-incident/) employing digitally signed, trojanized versions of the enterprise’s software.

**Sophos and CrowdStrike’s** security researchers [alerted](https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/) individuals that the threat actors target both Windows and macOS users of **3CX’s softphone application**. The supply chain attack is being dubbed “Smooth Operator” by SentinelOne and is not limited to individuals. Global organizations like _American Express, Coca-Cola, McDonald’s, BMW, Honda, Air France, Toyota, Mercedes-Benz, IKEA, and the UK’s National Health Service use the software._

All these organizations may be potential victims of the attack as well. Researchers suspect Smooth Operator to be the work of the North Korean state-backed hacker group Labyrinth Collima. [Smooth Operator malware](https://www.bleepingcomputer.com/news/security/hackers-compromise-3cx-desktop-app-in-a-supply-chain-attack/) is a highly sophisticated tool that steals information by **downloading encoded payloads** to computer systems and includes many advanced capabilities such as harvesting device information, **exfiltrating data**, and stealing stored credentials from multiple browsers.

The Smooth Operator malware connects to threat actor-controlled domains such as akamaicontainer.com, msedgepackageinfo.com, and azureonlinestorage.com. You need to stay vigilant if you are a user of 3CX’s desktop client software or connected to any organizations that do.

## SafeMoon Liquidity Pool Drained $8.9 Million Due to ‘Burn’ Bug Exploitation

Another significant loss in the crypto space took place, this time on the **SafeMoon token liquidity pool**, due to a threat actor exploiting a “burn” smart contact function to make away with $8.9 million.

The threat actor artificially inflated the token’s prices and sold them to innocent individuals at elevated prices to generate profit. The threat actor sold SafeMoon at the manipulated price leading to the large-scale drain from SafeMoon’s WBNB liquidity pool.

John Karony, SafeMoon’s CEO (Chief Executive Office), [confirmed](https://twitter.com/CptHodl/status/1640914110350016512) the cybersecurity incident, highlighting that the exploit has been successfully located and that SafeMoon has hired a **chain forensics consultant** to investigate the nature and extent of the attack. Karony went on to clarify that the tokens of its users are safe. No other tools, upgrades, or releases on the [DEX (Decentralized Exchange)](https://chain.link/education-hub/what-is-decentralized-exchange-dex#:~:text=A%20DEX%20%28decentralized%20exchange%29%20is,transfer%20and%20custody%20of%20funds.) were affected.

PeckShield’s researchers shed light on the attack, sharing that the “burn token” smart contract function was set to public with any restrictions which allowed the threat actor to exploit said function and cause this **large-scale crypto attack.**

## Apple Addresses Webkit Zero-Day on Older iPhones With New Fix

Apple is one of the most recognizable and prominent tech giants in the world, known for the **security of its devices**. However, the organization recently discovered a significant vulnerability, releasing a new patch.

[![Apple zero days](https://media.mailhop.org/duocircle/images/2023/03/spf-permerror-2.jpg)](https://media.mailhop.org/duocircle/images/2023/03/spf-permerror-2.jpg)

Apple launched a security update to patch the [CVE-2023-23529](https://support.apple.com/en-us/HT213673#:~:text=CVE%2D2023%2D23529%3A%20an%20anonymous%20researcher), a WebKit-type confusion vulnerability fixed for the latest iPhones and iPads, on 13 February 2023\. Any threat actor exploiting the vulnerability could trigger OS (Operating System) to crash and **gain code-executing capabilities** on Apple devices. After gaining access, threat actors could also [execute arbitrary codes](https://en.wikipedia.org/wiki/Arbitrary%5Fcode%5Fexecution), leading Apple users to malicious web pages. Apple received reports that the vulnerability was being actively exploited, which led to the fix.

The security update to take care of the vulnerability was released for older devices that received improved checks. Apple has not released any information regarding threat actors **exploiting the vulnerability**, which is the organization’s standard procedure. Apple restricts access to technical details so individuals can secure their devices, so any threat actors trying to exploit said vulnerability on older devices cannot. It is recommended that iOS users update their devices to the latest software that includes the security patch.

## Pwn2own Vancouver Sees Hackers Earn $1,035,000 for Exploiting 27 Zero-Days

The [Pwn2own hacking competition 2023](https://www.zerodayinitiative.com/blog/2023/3/21/pwn2own-vancouver-schedule-2023) took place in Vancouver from 22 March to 24 March 2023, where hackers showcased their talents by targeting devices in multiple categories.

The competition had multiple categories, such as Virtualization, Servers, Automotive, [EoP (Escalation of Privileges)](https://en.wikipedia.org/wiki/Privilege%5Fescalation), and more, with a prize pool of $1,000,000 and a Tesla Model 3\. The hackers exploited 27 zero-day vulnerabilities and multiple bug collisions in patched systems like _Windows 11, Microsoft Teams, Microsoft SharePoint, macOS, Ubuntu Desktop, VMware Workstation, Oracle VirtualBox, and the Tesla Model 3._

The Pwn2own competition was dominated by Team Synacktiv, who won 53 Master of Pwn points, winning nearly $530,000 from the competition and taking home the Tesla Model 3 during the three days when the contest lasted.

After the [zero-day vulnerabilities](/email-security/two-zero-day-vulnerabilities-discovered-in-microsoft-exchange-server-patches-pending/) were exploited and reported, the vendors now have 90 days to release security fixes to said vulnerabilities before **TrendMicro discloses** them to the public as part of its Zero Day Initiative.

## Australian Police Apprehend Four BEC Actors Responsible for $1.7 Million Theft

The **AFP (Australian Federal Police)** arrested four members of a threat actor syndicate laundering $1.7 million stolen from nearly 15 individuals between 2020 and now.

[![BEC (Business Email Compromise)](https://media.mailhop.org/duocircle/images/2023/03/spf-record-tester-5692.jpg)](https://media.mailhop.org/duocircle/images/2023/03/spf-record-tester-5692.jpg)

AFP had been investigating the threat actors since 2021, following a [BEC (Business Email Compromise)](https://www.bleepingcomputer.com/news/security/microsoft-business-email-compromise-attacks-can-take-just-hours/) attack on an Indonesian business that led to a loss of $100,000.

The threat actor syndicate comprises 4 young adults, two men, and two women, that were arrested from Brisbane, Adelaide, and Melbourne. The threat actors conducted **large-scale BEC attacks** targeting individuals that utilized the Facebook Marketplace, offering them fraudulent superannuation investments and Ponzi schemes.

The threat actors laundered the money using 180 bank accounts, some of which were opened using impersonated identities. The threat actors now [face](https://web.archive.org/web/20230401140743/https://www.afp.gov.au/news-media/media-releases/cybercrime-syndicate-dismantled-after-allegedly-laundering-17-million) charges for multiple accounts, such as producing or processing false documents, money laundering, dealing in proceeds of crime, and a couple more. Two threat actors may receive a **maximum penalty of 10 years**, while the other faces up to 20 years.

AFP has highlighted the ongoing need to stay protected and urges organizations and individuals to exercise caution when **dealing with online transactions**. Educating yourself on the latest scans is also crucial to staying protected.

## OpenAI Acknowledges Open-Source Bug as Cause of ChatGPT Payment Data Leak

OpenAI revealed that a bug in its Redis client open source code library was the cause of its outage on its **AI (Artificial Intelligence) product**, ChatGPT, on Monday (20 March 2023).

ChatGPT has taken the world by storm and is one of the most popular and widely used AI chatbot services; that allows individuals to generate content by **asking the chatbot queries**. Multiple individuals reported seeing random chat queries in their chat that were later found to be of other individuals using the ChatGPT platform when ransom email addresses started appearing on the subscription pages too.

OpenAI took its service offline to [investigate](https://openai.com/blog/march-20-chatgpt-outage) the issue causing the ruckus and released a report highlighting the cause of the incident. The report shed light on the incident, sharing that a bug in its Redis client caused the exposure of 1.2% of ChatGPT Plus members, revealing their names, email addresses, and payment addresses. The expiration dates and the last four digits of customer credit card numbers were also exposed.

Since the number of people affected by the incident is low, OpenAI took action to **keep exposure to a minimum** and is contacting all affected users, apologizing for the incident.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-13-of-2023%2F) [ ](https://twitter.com/intent/tweet?text=Cybersecurity%20News%20Update%2C%20Week%2013%20of%202023&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-13-of-2023%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-13-of-2023%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cybersecurity News Update, Week 13 of 2023","description":"Discover the latest cybersecurity news from around the world with our latest cybersecurity bulletin sharing supply chain attacks, security updates from Apple.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-13-of-2023/","datePublished":"2023-03-28T14:55:20.000Z","dateModified":"2025-05-19T12:31:49.000Z","dateCreated":"2023-03-28T14:55:20.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-13-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1210,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/03/spf-record.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cybersecurity News Update, Week 13 of 2023","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-13-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cybersecurity News Update, Week 13 of 2023","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-13-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cybersecurity News Update, Week 13 of 2023","description":"Discover the latest cybersecurity news from around the world with our latest cybersecurity bulletin sharing supply chain attacks, security updates from Apple.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-13-of-2023/","datePublished":"2023-03-28T14:55:20.000Z","dateModified":"2025-05-19T12:31:49.000Z","dateCreated":"2023-03-28T14:55:20.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-13-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1210,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/03/spf-record.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
