---
title: "Cyber Security News Update, Week 19 of 2021 | DuoCircle"
description: "Cybercrimes in the post-COVID world are even more furious than before, and therefore."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-19-of-2021/"
---

Quick Answer

Cybersecurity stories from the week of May 10, 2021: the FluBot Android malware spread through fake missed-delivery SMS messages, harvesting banking credentials and propagating through victims' contacts. A ransomware attack on Swedish provider Elekta disrupted oncology operations at multiple US cancer hospitals using its cloud-hosted treatment-planning service. The ToxicEye remote-access trojan abused Telegram for command-and-control. UK Lloyds Bank customers were targeted with fake transaction-notification phishing emails. The new WickrMe ransomware variant attacked Microsoft SharePoint installations. And Eaton issued patches for several severe vulnerabilities in its Intelligent Power Manager software used in critical infrastructure deployments.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-19-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2019%20of%202021&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-19-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-19-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-19-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2019%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2019%20of%202021&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-19-of-2021%2F "Share via Email") 

![DuoCircle blog post image](https://media.mailhop.org/duocircle/images/2021/05/SMTP-email-7464.jpg) 

_Cybercrimes in the post-COVID world are even more furious than before_, and therefore, using **robust cybersecurity tools** is the only way to ensure a safe cyberspace. Following are the top security headlines from the bygone week to help you strengthen your organization’s cybersecurity posture.

## Beware Of Missed Delivery Texts From Flubot

How often do you check the SMS texts on your phone and respond to them? _This Android-based spyware sends out fake delivery messages with links to download a so-called missed package delivery app_. Once the user believes the text and reaches the link, the **spyware Flubot** gets downloaded on the smartphone, steals all banking credentials and personal details, removes passwords, and sends similar delivery texts to all numbers on the contact list. Such _Flubot attacks have been rapidly increasing in the U.K_.

Looking at the severity of the attacks, the NCSC and mobile network providers Vodafone and Three have issued alerts for all [Android users](https://web.archive.org/web/20210513025213/https://cyware.com/news/flubot-spyware-is-employing-smishing-attacks-87750bca/) on their network. Since mobile screens are smaller and SMSs come with limited characters, it becomes challenging to look for errors and sense the scam. Therefore, _users should take cybersecurity measures seriously and refrain from opening links received on SMS_, especially those directed towards downloading applications. Users must remember applications should only be downloaded from the official app store.

[![Ransomware Attack](https://media.mailhop.org/duocircle/images/2021/05/SMTP-email-7675.jpg)](https://media.mailhop.org/duocircle/images/2021/05/SMTP-email-7675.jpg)

## Ransomware Attack On Elekta Impacts Several U.S-Based Cancer Hospitals

What if radiotherapy were to stop for Cancer patients? Well, in a recent **ransomware attack** on Elekta (a Swedish oncology and radiology system provider), several of its customer hospitals were unable to deliver timely radiotherapy treatments to patients. _The attack had impacted Elekta’s first-generation cloud storage system_, and a subset of U.S. customers had their data encrypted in the process.

The service provider quickly executed its cybersecurity measures, informed law enforcement, and _investigated the breach to resolve the issue at the earliest and reinstate services_ for customers and their patients. All affected customers were informed about the situation. The impacts of the [security incident](https://www.infosecurity-magazine.com/news/cancer-patients-diverted-attack?&web%5Fview=true) vary from one hospital to another. While the Lifespan Cancer Institute and Rhode Island Hospital had just one afternoon of its appointments affected, the Connecticut-based Yale New Haven Health had to shut down its radiation equipment offline for a week and transfer patients to other providers. Attacks on third-party vendors are not really in the cybersecurity realm of hospitals or other institutions; therefore, adopting proactive cybersecurity tools such as **behavior-based security analytics** is vital to ensure protection from unknown threat factors.

## Once Again Telegram Becomes A Pawn At The Hands Of Adversaries (Toxiceye)

_ToxicEye is a popular malware strain that uses Telegram as C2 to steal sensitive data stored on user devices_. In a recent survey, researchers found **130 ToxicEye attack**s in just the past three months. In this cybersecurity scam, the adversaries first create a Telegram account and a bot (which remains concealed in the malware’s configuration). The malicious documents are attached as malicious .exe files and sent to targeted users via **phishing emails**. _Downloading the attached file enables the Telegram bot to connect the user’s device with the attacker’s C2_. The RAT can then access all [instant messages](https://web.archive.org/web/20230528033056/https://cyware.com/news/toxiceye-rat-is-exploiting-telegram-platform-1167e7e2) on the victim’s device, steal credentials, browser history, computer OS details, etc.

Such threats exploiting Telegram are likely to increase in the near future. Therefore, users must use [email security services](/) to ensure that emails from suspicious sources get blocked directly.

## Lloyds Bank Customers Must Beware Of Fake Transaction Notifications

Britons have a new attack scheme to watch out for; this one claims to be from the Lloyds Bank and informs customers that they have “successfully scheduled a payment of £69.99 to payee MR ADAMS 28/04”. _It further asks them to click on the given (malicious) link if they didn’t schedule the mentioned payment_. Naturally, recipients would panic and quickly visit the link to stop Mr. Adams from stealing their £69.99\. But what happens upon clicking the link?

_A fraudulent website opens upon clicking the link_. This website is designed to **steal the personal information** of victims or download [harmful malware](https://www.express.co.uk/finance/personalfinance/1429524/Lloyds-Bank-scam-text-new-payee-confirmation-report-fraud-UK-2021?&web%5Fview=true) into their devices and, in some cases, do both! Britons must remember to be rational in responding to any text that claims to be from Lloyds Bank as the bank would never ask for customers’ account details or passwords. _The best thing to do upon receiving such a text is to delete it and never open the link!_ Customers can use the online banking facility to their advantage and cross-check any account activity that the text presents. The National Cyber Security Centre is doing its part and provides **cybersecurity guidelines** to all those who receive fake texts from Lloyds Bank.

## New Ransomware Wickrme Attacks Microsoft Sharepoint

_A new ransomware operator by the name of WickrMe or Hello has attacked the Microsoft SharePoint servers_. Microsoft SharePoint servers were abused as entry vectors into corporate networks. SharePoint became like Microsoft Exchange email servers, Palo Alto Network VPNs, Citrix gateways, Fortinet, F5 BIG-IP load balancers, Pulse Secure, etc., which ransomware gangs in the past have similarly exploited.

Hello/WickrMe used the CVE-2019-0604 [vulnerability in Microsoft’s SharePoint](https://www.scmagazine.com/home/security-news/ransomware/microsoft-sharepoint-vulnerability-and-china-chopper-web-shell-used-in-ransomware-attacks/) servers to control it and install a Cobalt Strike beacon as a web shell. _This backdoor ultimately downloads and installs the Hello ransomware_. SharePoint must update its systems to **ensure robust protection** against ransomware threats!

[![Ransomware](https://media.mailhop.org/duocircle/images/2021/05/SMTP-email-7646.jpg)](https://media.mailhop.org/duocircle/images/2021/05/SMTP-email-7646.jpg)

## Eaton Power Supply Fixes Siv Severe Vulnerabilities

In a move that encourages organizations to take [ransomware protection](/advanced-threat-defense) before the worst happens, _the Eaton power management solutions provider has recently released patches to address several vulnerabilities_ in its Intelligent Power Manager (IPM) software. These vulnerabilities, if left unattended, could have led to command execution, SQL injection, deleting arbitrary files, remote code execution, or uploading arbitrary files by adversaries.

Eaton’s IPM solution enabled organizations to manage, monitor, and ensure uninterruptible power supply (UPS) devices on their network; hence the patches were necessary to avoid power supply disruption. The [six patched vulnerabilities](https://www.securityweek.com/vulnerabilities-eaton-product-can-allow-hackers-disrupt-power-supply?&web%5Fview=true) fix security loopholes in Eaton IPM and IPM VA versions before 1.69, the IPP versions before 1.68, and ports 4679 and 4680.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-19-of-2021%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2019%20of%202021&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-19-of-2021%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-19-of-2021%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 19 of 2021","description":"Cybercrimes in the post-COVID world are even more furious than before, and therefore.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-19-of-2021/","datePublished":"2021-05-06T16:42:41.000Z","dateModified":"2025-06-02T10:52:31.000Z","dateCreated":"2021-05-06T16:42:41.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-19-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":997,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/05/SMTP-email-7464.jpg","caption":"DuoCircle blog post image","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 19 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-19-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 19 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-19-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 19 of 2021","description":"Cybercrimes in the post-COVID world are even more furious than before, and therefore.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-19-of-2021/","datePublished":"2021-05-06T16:42:41.000Z","dateModified":"2025-06-02T10:52:31.000Z","dateCreated":"2021-05-06T16:42:41.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-19-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":997,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/05/SMTP-email-7464.jpg","caption":"DuoCircle blog post image","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
