---
title: "Malicious Windows Kernel Exploits, Crypto Phishing Inferno, Meta’s Data Transfer, Cybersecurity News | DuoCircle"
description: "Here is the latest weekly cybersecurity bulletin, with the latest cybersecurity news and feature announcements."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-20-of-2023/"
---

Quick Answer

Cybersecurity stories from the week of May 15, 2023: BlackCat (ALPHV) ransomware attacks were observed using malicious Windows kernel drivers signed through Microsoft's Hardware Compatibility Program to disable endpoint protection. Researchers identified Inferno Drainer, a phishing-as-a-service operation that defrauded thousands of crypto wallet holders through fake Web3 site interactions. The European Union's data-protection regulator fined Meta €1.2 billion ($1.3 billion) for transferring EU user data to US servers without adequate safeguards. Google announced it would delete inactive personal accounts after two years of inactivity to reduce account-hijack risk. Microsoft attributed Clop ransomware activity exploiting the GoAnywhere MFT zero-day to FIN7\. And Google launched a bug-bounty program specifically for Android applications.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-20-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Malicious%20Windows%20Kernel%20Exploits%2C%20Crypto%20Phishing%20Inferno%2C%20Meta%E2%80%99s%20Data%20Transfer%2C%20Cybersecurity%20News&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-20-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-20-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-20-of-2023%2F&title=Malicious%20Windows%20Kernel%20Exploits%2C%20Crypto%20Phishing%20Inferno%2C%20Meta%E2%80%99s%20Data%20Transfer%2C%20Cybersecurity%20News "Share on Reddit") [ ](mailto:?subject=Malicious%20Windows%20Kernel%20Exploits%2C%20Crypto%20Phishing%20Inferno%2C%20Meta%E2%80%99s%20Data%20Transfer%2C%20Cybersecurity%20News&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-20-of-2023%2F "Share via Email") 

![cyber security](https://media.mailhop.org/duocircle/images/2023/05/spf-record-generator-1.jpg) 

Here is the latest weekly [cybersecurity](/) bulletin, with the **latest** cybersecurity news and feature announcements.

## BlackCat Ransomware Attacks Exploit Malicious Windows Kernel Drivers

The BlackCat ransomware group (ALPHV) has been employing **signed malicious** Windows kernel drivers in their latest attacks to evade detection. 

Trend Micro [observed](https://www.trendmicro.com/en%5Fus/research/23/e/blackcat-ransomware-deploys-new-signed-kernel-driver.html) an improved version of the gang’s “POORTRY” [malware](/resources/malware-and-its-defense-mechanism) which was also observed in multiple ransomware attacks last year. Threat actors tried using a **Microsoft-signed** POORTRY driver that kept getting detected, leading to this improved one, which uses a **stolen or leaked** cross-signing certificate and helps the ransomware gang elevate privileges on compromised machines and stop all security agent processing activities.

_It is recommended that Windows users enable the “**Driver Signature Enforcement**” feature to protect their systems._ 

## Thousands of Victims Defrauded by Crypto Phishing Service, Inferno Drainer

Inferno Drainer, a new [crypto phishing](https://www.makeuseof.com/what-is-a-crypto-phishing-scam-and-how-can-you-spot-one/#:~:text=A%20crypto%20phishing%20scam%20is,to%20steal%20your%20digital%20assets.) and scam, duped 4,888 victims, stealing nearly $5.9 million in crypto. 

Scam Sniffer, a Web 3.0 anti-scam enterprise, [reported](https://drops.scamsniffer.io/post/5-9-million-stolen-by-scam-as-a-service-provider-called-inferno-drainer/) that the Inferno Drainer [phishing](/content/phishing-prevention/phishing-attacks) service has over **689 fake websites** that came online after March 2023\. These websites target 220 famous brands, promoting multichain fraud and Aaven and Art Blocks draining.

The malicious actors behind the toolkit provide a modern admin panel with customizations and trials, with the users **paying the threat actors** who developed [Inferno Drainer](https://decrypt.co/140877/inferno-drainer-scam-scammer-phishing-crypto-nfts) 20% of all proceeds. The cut for the threat actor increases for extra phishing site creations. Out of the millions of assets, the most significant amount was stolen from Mainnet at $4.3 million, followed by Arbitrum, Polygon, and BNB. 

_Individuals must stay vigilant while making **crypto transactions** and avoid disclosing personal information._

## Meta Fined $1.3 Billion by E.U. for Transferring Data to U.S. Servers

The Irish DPC (Data Protection Commission) has fined Meta $1.3 billion based on Article 46(1) of [GDPR](https://www.investopedia.com/terms/g/general-data-protection-regulation-gdpr.asp). 

Meta’s application, [Facebook](/email-security/meta-phish-facebook-phishing-campaign-stealing-login-credentials-and-pii-2/), **transfers the data** of EU-based citizens to the U.S., where data protection regulations are different for all states and inadequate to protect E.U. citizens’ rights.

[![GDPR](https://media.mailhop.org/duocircle/images/2023/05/spf-record.jpg)](https://media.mailhop.org/duocircle/images/2023/05/spf-record.jpg)

The article from the GDPR (General Data Protection Regulation) forbids the **transfer of personal data** to countries or regions that do not have adequate legal remediation mechanisms and do not warrant safety. As a result, the DPC [imposed](https://www.dataprotection.ie/en/news-media/press-releases/Data-Protection-Commission-announces-conclusion-of-inquiry-into-Meta-Ireland) a $1.3 billion fine on Meta and has requested that all data transfers be **suspended within five months**. 

Meta will also **have to stop** processing and holding data transferred illegally to the U.S. within six months.

## Inactive for Over 2 Years? Google Will Delete Your Accounts

Google [announced](https://www.blog.google/technology/safety-security/updating-our-inactive-account-policies/) that it had updated its personal account policy and will **deactivate accounts** that have been inactive for over two years.

_After the maximum period of 2 years, the accounts containing all content, settings, saved data, and more may be deleted._ The account deletion policy will apply to all Google services like Gmail, Drive, Meet, Docs, Photos, YouTube, and more.

The new policy will not apply to organizational accounts or businesses. The new policy aims to boost **online security** as [inactive accounts](https://apnews.com/article/twitter-elon-musk-dead-users-inactive-accounts-49c96ee9c0723a60c82da55f3616c96d) may face cyber threats. The new policy has taken effect, and Google will start deleting accounts from December 2023\. 

For users looking to **save their accounts** from inactivity, Google recommends reading or sending an email, using Google Drive, watching a YouTube video, downloading apps, using Google Search, or merely signing in to a third-party app using the account.

## Clop Ransomware Attacks Linked to Return of Notorious FIN7 Hackers, Says Microsoft

FIN7, a financially motivated **threat actor group**, has been linked to the deployment of Clop [ransomware payloads](https://www.2-spyware.com/icedid-malware-transitioning-to-ransomware-payloads). 

Microsoft highlighted the new threat in a Twitter [thread](https://twitter.com/MsftSecIntel/status/1659347803989057541). FIN7 has been around since late 2021, but its recent deployment of clop ransomware saw a PowerShell-based POWERTRASH **malware dropper** that works from memory.

It also drops a post-exploitation tool that allows the [threat actors](/email-security/threat-actors-attack-thousands-of-computers-following-the-ion-incident/) to maintain a foothold on the target network, move laterally, and deploy the Clop ransomware using **OpenSSH**. This strain is the newest one FIN7 is using, as the threat actor gang has also used REvil and Maze ransomware before. 

Individuals and organizations should be on guard and practice **protective measures** to stay safe. 

[![Ransomware Attacks](https://media.mailhop.org/duocircle/images/2023/05/dmarc-report-7522.jpg)](https://media.mailhop.org/duocircle/images/2023/05/dmarc-report-7522.jpg)

## Bug Bounty Program for Android Applications Launched by Google

Google also launched a new [bug bounty program](https://en.wikipedia.org/wiki/Bug%5Fbounty%5Fprogram) called the Mobile VRP (Vulnerability Rewards Program) that will **reward security researchers** for the flaws they find in Android applications. 

Google [released](https://bughunters.google.com/about/rules/6618732618186752/google-mobile-vulnerability-reward-program-rules) the VRP with the primary goal of **speeding up** the process of taking care of vulnerabilities and flaws in its first-party Android applications. The qualifying vulnerabilities include ACE (Arbitrary Code Execution), theft of sensitive and chained weaknesses such as orphaned permissions, **zip path flaws**, or intent redirections that the threat actors can exploit. 

Google will reward up to $30,000 for the [ACE flaws](https://www.okta.com/identity-101/arbitrary-code-execution/) and up to $7,500 for bugs that threat actors can exploit to **steal data** remotely.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-20-of-2023%2F) [ ](https://twitter.com/intent/tweet?text=Malicious%20Windows%20Kernel%20Exploits%2C%20Crypto%20Phishing%20Inferno%2C%20Meta%E2%80%99s%20Data%20Transfer%2C%20Cybersecurity%20News&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-20-of-2023%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-20-of-2023%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Malicious Windows Kernel Exploits, Crypto Phishing Inferno, Meta’s Data Transfer, Cybersecurity News","description":"Here is the latest weekly cybersecurity bulletin, with the latest cybersecurity news and feature announcements.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-20-of-2023/","datePublished":"2023-05-15T11:57:18.000Z","dateModified":"2025-05-21T12:46:04.000Z","dateCreated":"2023-05-15T11:57:18.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-20-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":792,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/05/spf-record-generator-1.jpg","caption":"cyber security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Malicious Windows Kernel Exploits, Crypto Phishing Inferno, Meta’s Data Transfer, Cybersecurity News","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-20-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Malicious Windows Kernel Exploits, Crypto Phishing Inferno, Meta’s Data Transfer, Cybersecurity News","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-20-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Malicious Windows Kernel Exploits, Crypto Phishing Inferno, Meta’s Data Transfer, Cybersecurity News","description":"Here is the latest weekly cybersecurity bulletin, with the latest cybersecurity news and feature announcements.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-20-of-2023/","datePublished":"2023-05-15T11:57:18.000Z","dateModified":"2025-05-21T12:46:04.000Z","dateCreated":"2023-05-15T11:57:18.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-20-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":792,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/05/spf-record-generator-1.jpg","caption":"cyber security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
