---
title: "Cyber Security News Update, Week 15 of 2022 | DuoCircle"
description: "Cyberspace transforms by the minute, and a key player in changing the cybersecurity landscape is the phishing attacks that happen every day."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-15-of-2022/"
---

Quick Answer

Week 15 of 2022 covered: an FBI Private Industry Notification warning local US governments of rising ransomware exposure, with smaller counties and municipalities the second-most targeted group after academia and often unable to recover from backups; the arrest and guilty plea of Christopher Doyon (aka Commander X) for the December 2010 DDoS attack against Santa Cruz County's website that caused $4,060 in damage, with sentencing set for June 28, 2022; the WhiteSource Spring4Shell Detect free CLI tool for finding the Spring Framework vulnerability CVE-2022-22965 (CVSS 9.8) compared to Log4j; the Australian Department of Home Affairs developing a national data-security action plan covering accountability, security, and control mandates for individuals, businesses, and governments; Ukraine's SSSCIP warning about UAC-0094 phishing that impersonates Telegram security alerts to harvest credentials and SMS one-time codes; and Australia's REDSPICE program committing $9.9 billion over a decade to the Australian Signals Directorate ($4.2 billion in the first four years), creating 1,900 new jobs.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-15-of-2022%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2015%20of%202022&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-15-of-2022%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-15-of-2022%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-15-of-2022%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2015%20of%202022 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2015%20of%202022&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-15-of-2022%2F "Share via Email") 

![Cyber Security](https://media.mailhop.org/duocircle/images/2022/04/spf-permerror-5798.jpg) 

Cyberspace transforms by the minute, and a key player in changing the cybersecurity landscape is the phishing attacks that happen every day. Following are the significant hacks, cyber developments, and updates this week:

## FBI Warns Local Government Agencies of Ransomware Attacks

In its recent Private Industry Notification (PIN), the [Federal Bureau of Investigation](https://www.fbi.gov/investigate/cyber) (FBI) warned local government entities of possible ransomware attacks. [Ransomware attacks](/email-security/ransomware-report-2022-the-top-5-ransomware-and-malware-groups-making-strides-this-year/) on local governments have increased because the sector is known for managing critical public services such as education and other emergency services. These local government entities are the second most frequently targeted group after academia and **cause financial loss** and risk to public safety.

According to the FBI, in 2021, the smaller counties and municipalities were the primary local government agencies targeted by ransomware. The agency noted that these counties are targeted because of their limited access to [cybersecurity resources](/msp-email-security/critical-cybersecurity-steps-for-msps-to-secure-clients-confidential-data/) and possible budget constraints. Another independently-conducted survey revealed that local governments could not tackle ransomware attacks and _recover systems from backups_ which compels them to pay the demanded ransom to regain access to their data.

[![deployment strategies](https://media.mailhop.org/duocircle/images/2022/04/what-is-DKIM-6247.jpg)](https://media.mailhop.org/duocircle/images/2022/04/what-is-DKIM-6247.jpg)

Towards the end of the PIN, the FBI predicted that the ransomware attacks targeting the local US government agencies would probably continue due to the evolving malware [deployment strategies](https://www.securityweek.com/fbi-warns-ransomware-attacks-targeting-local-governments?) among adversaries.

## Cyberattacker to Get Sentenced Ten Years After Committing Crime

Law enforcement recently arrested a 57-year old former resident of California, Christopher Doyon, who had attacked the California County’s website over a decade ago. Doyon had _initially pleaded not guilty to being involved in the DDoS attack_ on 16th December 2010 and had fled the country. He was indicted on 21st September 2011 for attempting to compromise the protected computer network of Santa Cruz County.

Doyon’s attack reportedly cost the Santa Cruz County officials damage of $4060\. Known as Commander X, Doyon was first arrested in 2011 and eventually released on a $35,000 bond. However, he failed to appear for a federal court hearing in February 2012\. Nine years after this episode, the county’s immigration authorities finally arrested Doyon on 11th June 2021\. He was deported to the US and handed over to the FBI on 12th June 2021, proving that [cybersecurity laws](/email-security/why-cybersecurity-compliance-is-of-utmost-importance-when-youre-starting-with-your-online-business/) cannot be messed with after all!  
Recently, Doyon appeared before the district judge Beth Labson Freeman and pleaded guilty to being involved in the attack mentioned above, along with several other **cyberattacks** against servers in Orlando, Florida, in 2011\. He is to be served a 15-year custodial term on [28th June 2022](https://www.infosecurity-magazine.com/news/activist-california-county-website/).

## WhiteSource Releases Free CLI Tool For Spring4Shell Vulnerability

WhiteSource recently launched a free command-line interface (CLI) tool called the WhiteSource Spring4Shell Detect, which helps to detect vulnerable open source libraries for Spring4Shell (dubbed CVE-2022-22965). The CVE-2022-22965 exists in Spring, a popular **open-source framework** for Java applications. While details about this vulnerability are not yet out, it has a severity score of 9.8, and reportedly its impact is similar to [Log4j](/email-hosting/apache-log4j-zero-day-vulnerability-how-to-detect-it-precautions-you-need-to-take/).

WhiteSource’s new CLI tool is available on GitHub and helps developers **locate the vulnerabilities** and directs them to suitable cybersecurity solutions for speedy remediation. WhiteSource CEO, Rami Sass advises cybersecurity teams and organizations to view the Spring4Shell vulnerability with the same urgency as the Log4j vulnerability. WhiteSource recommends organizations use its free detection tool to look through their application list to detect all instances of CVE-2022-22965\. It further instructs organizations to update their Spring Framework to the latest version to get the [latest patches](https://www.helpnetsecurity.com/2022/04/05/whitesource-spring4shell-detect/).

## Australian Home Affairs Dept Works On National Data Security Action Plan

The [Australian Department of Home Affairs](https://www.homeaffairs.gov.au/) is working on the new national [data security](/legal/data-security-policy) action plan introduced as part of the government’s digital economy strategy. Home Affairs Minister Karen Andrews claims that the action plan aims to protect citizens’ data from adversaries. This action plan would add to the Morrison government’s vision of ensuring the security of Australians’ data against data theft, hacks, and ransomware attacks.

The Home Affairs department released its intentions regarding the plan, which includes establishing **data security** settings and mandates for individuals, businesses, and governments. These cybersecurity mandates would focus on accountability, security, and control. The Home Affairs Department has put up some parts of the action plan for [public consultation](https://www.zdnet.com/article/australia-to-develop-a-data-security-framework/?&web%5Fview=true). The inputs of businesses and state and territory governments seek to improve the nation’s data security.

## Ukraine’s SSSCIP Warns of Telegram Account Hacks

The State Service of Special Communication and Information Protection (SSSCIP) of Ukraine has warned of a new wave of [cyberattacks](/email-security/impending-cybersecurity-threats-to-businesses-in-2022-and-beyond/) trying to compromise users’ Telegram accounts. Attackers send messages with malicious links to users, which redirects them to a fake Telegram website and tries to gain access to their accounts and a one-time password that comes as an SMS. Falling under a threat cluster called “UAC-0094,” these Telegram attacks initially notify users of a suspicious login from a new device in Russia and urges users to verify their accounts by clicking on the given link.

[![ransomware protection](https://media.mailhop.org/duocircle/images/2022/04/dkim-record-check-6482.jpg)](https://media.mailhop.org/duocircle/images/2022/04/dkim-record-check-6482.jpg)

The URL leads users to the phished website, which aims to steal their login credentials. This attack represents the strategy involved in a recent Telegram scam [targeting Indian users](https://thehackernews.com/2022/04/ukraine-warns-of-cyber-attack-aiming-to.html?&web%5Fview=true). Thus, the SSSCIP advises Ukrainian Telegram users to reason if such a **phishing link** reaches them and recommends adopting [ransomware protection](/email/phishing-protection) measures for security.

## Australian Government to Dedicate $9.9 Billion To Enhance Cyber Defense Capabilities

In its 2022-23 financial budget, the Australian government has revealed its plans of **investing $9.9 billion** in strengthening the country’s offensive and defensive cyber capabilities. The funding shall be released over the next decade, wherein the Australian Signals Directorate (ASD) shall first receive an initial fund of $4.2 billion in the coming four years. This is the most significant cybersecurity investment in Australia’s history, and the funding pledge has been dubbed REDSPICE, which stands for ‘Resilience, Effects, Defense, Space, Intelligence, Cyber, and Enablers.’

Australia’s foreign signals intelligence and security agency, the Australian Signals Directorate (ASD), will receive the funding over the next decade, with the _first $4.2bn to be spent in the next four years_. The funding is expected to help the ASD keep up with advancements in cyberattacks and ensure a secure Indo-Pacific region. The latest funding shall enable the ASD to expand its size and cyber offense capabilities. It shall also add next-generation artificial intelligence and data science capabilities to the nation’s cybersecurity milieu.

While ASD already has 2300 employees at the moment, the [REDSPICE program](https://www.infosecurity-magazine.com/news/australian-government-to-invest/?&web%5Fview=true) shall create **1900 more job opportunities**. These will include positions for corporate staff, software engineers, data analysts, computer programmers, and other technologists. While the program is futuristic in itself, the opposition doubts its ability to fill all the new vacancies given the nation’s already stretched cybersecurity talent market.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-15-of-2022%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2015%20of%202022&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-15-of-2022%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-15-of-2022%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 15 of 2022","description":"Cyberspace transforms by the minute, and a key player in changing the cybersecurity landscape is the phishing attacks that happen every day.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-15-of-2022/","datePublished":"2022-04-15T21:07:06.000Z","dateModified":"2025-05-27T11:49:02.000Z","dateCreated":"2022-04-15T21:07:06.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-15-of-2022/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1106,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/04/spf-permerror-5798.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 15 of 2022","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-15-of-2022/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 15 of 2022","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-15-of-2022/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 15 of 2022","description":"Cyberspace transforms by the minute, and a key player in changing the cybersecurity landscape is the phishing attacks that happen every day.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-15-of-2022/","datePublished":"2022-04-15T21:07:06.000Z","dateModified":"2025-05-27T11:49:02.000Z","dateCreated":"2022-04-15T21:07:06.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-15-of-2022/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1106,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/04/spf-permerror-5798.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
