---
title: "Cyber Security News Update, Week 17 of 2021 | DuoCircle"
description: "Cyberattacks continue to disrupt the digital world. Today’s news proves that the dearth of cybersecurity tools can prove detrimental to even entire nations!"
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-17-of-2021/"
---

Quick Answer

Cybersecurity stories from the week of April 26, 2021: India sought US assistance to counter a wave of cyber operations attributed to Chinese groups. Google released two emergency Chrome patches for actively exploited zero-day flaws. CISA mandated patching of Microsoft Exchange Server vulnerabilities across federal agencies. A ransomware attack forced two Tasmanian casinos offline, halting slot machines and hotel bookings. Researchers detailed an account-takeover technique that lets attackers lock victims out of WhatsApp by abusing the registration and login flow. Reddit announced it was making its bug-bounty program public after running it privately, expanding the pool of researchers eligible to submit vulnerability reports.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2017%20of%202021&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2017%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2017%20of%202021&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2021%2F "Share via Email") 

![Hackers Can Lock You Out Of Whatsapp](https://media.mailhop.org/duocircle/images/2021/04/DMARC-generator-9070.jpg) 

_Cyberattacks continue to disrupt the digital world_. Today’s news proves that the dearth of **cybersecurity tools** can prove detrimental to even entire nations! Here are the top cybersecurity headlines from this week

## India Seeks Cyber Assistance from the US Against Attacks from China

_China’s obtrusive cybersecurity strategies have intimidated India’s top military officials_. The latter are now seeking help from the US and other countries to strengthen the country’s cyber defense against Chinese cyber-attacks. In a recent seminar in New Delhi, Bipin Rawat, the Chief of Defence Staff, said that the country is lagging in securing its cyber systems despite developments and hence the country sought assistance in AI and cybersecurity from the US defense secretary Lloyd Austin in his visit to India last month.

As authorities hope to get assistance from western nations catching up with China’s technology, they investigate a couple of cyberattacks. These attacks on Mumbai’s power supply system, various bank systems, and the country’s National Stock Exchange are suspected of having [Chinese ties](https://ciso.economictimes.indiatimes.com/news/india-seeks-us-help-as-china-backed-hacks-threaten-military/81984653).

## Google Releases Two Patches for Chrome

_Google Chrome users must immediately head to their account settings and get patches for two vulnerabilities that Google recently fixed_. One of these vulnerabilities, dubbed as CVE-2021-21220, is associated with insufficient validation of unreliable input in its V8 JavaScript. Though Google was quick to take [ransomware protection](/advanced-threat-defense), security researcher Rajvardhan Agarwal pointed out that the patch for one vulnerability in [Chromium-based browsers](https://thehackernews.com/2021/04/2-new-chrome-0-days-under-attack-update.html?&web%5Fview=true) is still not included in the recent Chrome release, via which attackers can still target users.

_Rajvardhan suspects that the second patch wasn’t applied to Chrome because both flaws can still be exploited_. While loopholes exist, Google tries hard to make its platform safe for users. As users, we must be quick to **get patches updated**, lest _attackers take over our systems exploiting these loopholes_!

[![ransomware protection](https://media.mailhop.org/duocircle/images/2021/04/dkim-record-check-9760.jpg)](https://media.mailhop.org/duocircle/images/2021/04/dkim-record-check-9760.jpg)

## Exchange Server Updates Mandated for Federal Agencies

_Microsoft has released patches for four significant Microsoft Exchange vulnerabilities_, leading to severe Microsoft Exchange server attacks. The CISA has now instructed all federal agencies to update the patches immediately to ensure [email security](/) and cybersecurity. The NSA discovered these Exchange vulnerabilities that were malicious enough to let attackers conduct remote code execution without authentication.

The vulnerabilities haven’t been [exploited so far](https://www.bleepingcomputer.com/news/security/cisa-gives-federal-agencies-until-friday-to-patch-exchange-servers/?&web%5Fview=true), but the _CISA warns of the possibility of attackers using reverse engineering on the patches to exploit them_. Considering the risk posed for federal agencies, the CISA has updated its Emergency Directive 21-02 to make it mandatory for all federal enterprises to install the **latest security updates** before EOD 16th April 2021.

## Ransomware Attack Shuts Down Two Tasmanian Casinos

_Two casinos run by the Tasmanian casino operator Federal Group recently underwent a **ransomware attack**_. Consequently, the two casinos (Country Club and Wrest Point) had to shut down their hotel booking systems. Besides, the slot machines (pokies) in both venues became in-operational. Although the Federal Group hasn’t notified customers on a tentative date of restoring services, they are doing their bit to ensure cybersecurity for all. The Federal Group is investigating the incident with external experts and has also informed the Australian Cyber Security Centre about it.

Federal Group’s **robust cybersecurity strategies** have contained the attack. Still, credit card details from [historical transactions](https://www.infosecurity-magazine.com/news/cyberattack-shutters-half/?&web%5Fview=true) and the customer details stored in the hotel booking system may have been compromised. The casino operator is yet to find out whether any financial data was exposed in the breach. They haven’t disclosed the **ransom demand** details or informed about their plans of paying either. Terry Aulich, the former federal senator and Tasmanian minister, feels that Tasmanians choose to be oblivious of the **cyber threats** facing them and the world, and it is something one cannot disagree with!

[![](https://media.mailhop.org/duocircle/images/2021/04/what-is-DKIM-4077.jpg)](https://media.mailhop.org/duocircle/images/2021/04/what-is-DKIM-4077.jpg)

## Hackers Can Lock You Out Of Whatsapp

Whatsapp was one app where account take-overs weren’t a cybersecurity concern. Still, _the latest malicious scheme of hackers enables them to suspend our Whatsapp account with just our phone number_. All they need is the phone number to exploit loopholes in two WhatsApp processes. The attackers can enter the number to create a new WhatsApp account, and the verification code will by default reach the given phone number. But the twist here is that one may keep ignoring the verification codes assuming them to be bugs, while the attackers keep requesting this code enough times for WhatsApp to block codes and the account for 12 hours.

The adversaries will then create a fake email account and request Whatsapp to deactivate the number. All WhatsApp asks for **identity verification** is the phone number, and that is already with the attackers. Consequently, _one gets logged out of their account and cannot request an account reactivation code because codes are already disabled for 12 hours_! The worst part is, if attackers try to abuse this 12-hour cycle thrice in a row, then it would crash WhatsApp and show the user a message “try again after -1 seconds” instead of allowing them to log in after 12 hours. The only way to move [out of this](https://www.welivesecurity.com/2021/04/13/whatsapp-flaw-lets-anyone-lock-you-out-account/?&web%5Fview=true) is to contact some personal acquaintance working at Whatsapp and asking them to help. This attack scheme sure seems out-of-the-box now, but there will be more of these unusual scams in the future, so _we must all reconsider enabling two-step verification PIN for WhatsApp_, no matter how irritating or tiresome the process may seem.

## Reddit Bug Bounty Programs Now To Be Public

Reddit and HackerOne’s private bug bounty program is quite renowned, but _the social news site has made its [bug bounty program](https://www.scmagazine.com/home/security-news/reddit-takes-bug-bounty-program-public/?web%5Fview=true) open to the public for the first time_. They hope that this move shall enable them to address vulnerabilities quickly and ensure [protection against ransomware](/) and other such cyber threats. With over 300 reports and bounty payments **exceeding $140,000**, Reddit now expands its platform to welcome participation from anyone keen on making a meaningful cybersecurity impact.

_Since the bug bounty program has helped Reddit find some of its finest security experts in the past,_ it is optimistic about opening the program to a more significant portion of cyber enthusiasts.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2021%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2017%20of%202021&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2021%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2021%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 17 of 2021","description":"Cyberattacks continue to disrupt the digital world. Today’s news proves that the dearth of cybersecurity tools can prove detrimental to even entire nations!","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-17-of-2021/","datePublished":"2021-04-20T17:16:17.000Z","dateModified":"2025-05-23T14:52:55.000Z","dateCreated":"2021-04-20T17:16:17.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-17-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1003,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/04/DMARC-generator-9070.jpg","caption":"Hackers Can Lock You Out Of Whatsapp","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 17 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-17-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 17 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-17-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 17 of 2021","description":"Cyberattacks continue to disrupt the digital world. Today’s news proves that the dearth of cybersecurity tools can prove detrimental to even entire nations!","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-17-of-2021/","datePublished":"2021-04-20T17:16:17.000Z","dateModified":"2025-05-23T14:52:55.000Z","dateCreated":"2021-04-20T17:16:17.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-17-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1003,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/04/DMARC-generator-9070.jpg","caption":"Hackers Can Lock You Out Of Whatsapp","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
