---
title: "Cyber Security News Update, Week 21 of 2021 | DuoCircle"
description: "Cybersecurity headlines are insightful for their coverage of a wide variety of cyberattacks, the latest security updates, recommendations, and attack trends."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-21-of-2021/"
---

Quick Answer

Cybersecurity stories from the week of May 24, 2021: researchers disclosed cryptographic and design flaws in Apple's AirTag, allowing the small tracker to be reflashed and abused for phishing or stalking. The DarkSide ransomware crew was tied to the Colonial Pipeline attack that disrupted US East Coast fuel supply, prompting an emergency federal response. The FBI and Australian Cyber Security Centre issued joint Avaddon ransomware advisories with indicators of compromise. The FBI also warned of search-engine ad scams pushing fake banking and crypto sites to the top of paid results. The UK NCSC announced its Cyber Threat Warning service, previously limited to government, would expand to UK private organizations. And researchers identified a fake Chrome update on Android that installed banking malware.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-21-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2021%20of%202021&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-21-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-21-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-21-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2021%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2021%20of%202021&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-21-of-2021%2F "Share via Email") 

![Cyber Security](https://media.mailhop.org/duocircle/images/2021/05/spf-validator-5697.jpg) 

_Cybersecurity headlines are insightful for their coverage of a wide variety of cyberattacks_, the latest security updates, recommendations, and attack trends. This week’s headlines are just as informative and justify why you must immediately upgrade your [ransomware protection](/advanced-threat-defense) measures.

## AirTag Comes With Major Security Vulnerability

What would you do if a hacker exploited the item tracker on your device to spy on you? Scary, right? Well, _the new Apple AirTag has been out for only a week, and two **security vulnerabilities** have been spotted already_! A user found that the item tracker can be easily used to stalk people. He also rebuilt a thinner card version of the AirTag that goes into wallets. In [another incident](https://9to5mac.com/2021/05/09/airtag-hacked-for-the-first-time-by-security-researcher-video/?&web%5Fview=true), security researcher Stack Smashing could hack the microcontroller of the AirTag, which enabled him to modify the NGC URL for its microcontroller of the AirTag, Lost Mode.

_The modified AirTag could be easily used in phishing scams, says Smashing_. The modified item tracker leads to an unrelated URL (which can have phishing motives, such as logging in to accounts to track devices, making payments, etc.) instead of the regular destination, Find My Website. We hope that Apple is deploying its **cybersecurity tools** to block this loophole in the item tracker!

## Darkside Ransomware Gang Responsible For Colonial Pipeline Attack

_The FBI has attributed the recent attack on the Colonial Pipeline network to the DarkSide ransomware gang_. Colonial Pipeline had a [major shutdown](https://thehill.com/policy/cybersecurity/552656-fbi-confirms-darkside-ransomware-group-behind-pipeline-hack?&web%5Fview=true) of all its pipeline operations because of this attack.

As investigations by the company, the FBI, and government partners continue, Colonial Pipeline has worked out a **ransomware protection** scheme that aims to restore operations in a phased manner. While it’s only now that the FBI has confirmed that DarkSide was responsible for the attack, the Associated Press had concluded the same much before.

## The FBI & The ACSC Release Avaddon Alerts For Organizations

[![several networks](https://media.mailhop.org/duocircle/images/2021/05/sendgrid-alternative-6953.jpg)](https://media.mailhop.org/duocircle/images/2021/05/sendgrid-alternative-6953.jpg)

_Avaddon attacks are on the rise, and the FBI and ACSC warned U.S. and Australian citizens of the same via a cybersecurity alert recently_. The Federal Bureau of Investigation (FBI) mentions that the **ransomware operators** primarily target healthcare, manufacturing, and other private sector organizations. The Australian Cyber Security Centre (ACSC) adds that these attacks target [several networks](https://www.bleepingcomputer.com/news/security/us-and-australia-warn-of-escalating-avaddon-ransomware-attacks/?&web%5Fview=true), including finance, government, energy, health, law enforcement, and I.T. sectors. It also mentions the countries targeted by Avaddon so far, including the U.S., the U.K., China, Germany, India, UAE, Brazil, Spain, and France, among others.

The ACSC further acknowledges the Avaddon attacks that have already hit Australian enterprises and warns organizations of the **denial-of-service** (DDoS) attacks that Avaddon promises to launch for its victims. However, the FBI has made no comments on the probability of DDoS attacks after the Avaddon attacks.

## Beware Of Search Engine Ads And Scams, Says FBI

_Cyber adversaries frequently use search engine ads and search results to launch phishing attacks on users_. These attacks have gained momentum since March 2021, and therefore the Federal Bureau of Investigation has released a warning alert for users. Millions of dollars were already lost to such schemes where the threat actors impersonate legitimate financial institutions.

There are two variants of this attack scheme, the FBI warns. One, where search engine ads are deployed, and the other, organic search results lead to a **phished website**. Both these schemes require users to enter their account details and contact numbers to reach their account landing page. However, since it’s a **phished site**, the login page doesn’t lead them to their account. The users then receive a call from the adversaries where they [pretend to be employees](https://therecord.media/fbi-warns-of-cybercriminals-abusing-search-ads-to-promote-phishing-sites/?web%5Fview=true) of the financial institution. As customers engage in a long conversation with this fake representative regarding account restoration, a second person from the gang uses the entered credentials to make illicit wire transfers.

By the time victims figure all this out, the money is long gone from their accounts. Perhaps the best way to go about online transactions is the age-old [cybersecurity tip](https://www.phishprotection.com/content/phishing-prevention/) in circulation: _always visit the official portal directly_.

## NCSC’s Cyber Threat Warning Service To Be Available To All U.K. Institutions

At the Annual CyberUK Conference on 12th May, _the National Cyber Security Centre (NCSC) announced that U.K. businesses are to get free access to Early Warning_, its latest **cyber-threat warning service**. The said Active Cyber Defence (ACD) service previously operated as an alpha version and was available to select parties only. But the new beta version shall be made available to all U.K. organizations without cost. _This move is initiated keeping in mind the many institutions that do not have a cybersecurity budget and are therefore exposed to threats online_.

The pre-pandemic CyberUK Conference emphasized the need to boycott services from the Chinese firm Huawei in U.K.’s 5G rollout. This year’s online conference again discussed the U.K.’s vision of creating a secure, free, peaceful, and open cyberspace for all in contrast to the digital wars led by Russia, Chine, N. Korea, and Iran. The [conference suggested](https://portswigger.net/daily-swig/uk-government-releases-free-cyber-threat-warning-tool-at-annual-cyberuk-conference?&web%5Fview=true) **investing £22 million** in _strengthening cyber capacity in the Indo-Pacific and African region_ over an unspecified time as a possible solution.

## Beware Of Fake Chrome App

_Devices in Europe are being hit by a new type of attack where an Android malware impersonates the Google Chrome app_ and steals user credentials. Cybersecurity researchers at Pradeo describe the processes involved in the attack, saying that it begins with victims receiving an SMS requesting custom fees to release a package delivery. Falling for this text makes an update for Chrome pop up.

[![email security services](https://media.mailhop.org/duocircle/images/2021/05/SMTP-email-6824.jpg)](https://media.mailhop.org/duocircle/images/2021/05/SMTP-email-6824.jpg)

Anyone who falls for this [second scam](https://threatpost.com/fake-chrome-app-worming-smish-cyberattack/166038/?web%5Fview=true) clicks the link to update Chrome. _He/She is taken to a fake website that downloads a malicious version of Chrome on their phones_. Users are advised to use [email security services](/) and verify update notifications before following a random link.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-21-of-2021%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2021%20of%202021&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-21-of-2021%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-21-of-2021%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 21 of 2021","description":"Cybersecurity headlines are insightful for their coverage of a wide variety of cyberattacks, the latest security updates, recommendations, and attack trends.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-21-of-2021/","datePublished":"2021-05-21T14:04:02.000Z","dateModified":"2025-05-27T11:36:01.000Z","dateCreated":"2021-05-21T14:04:02.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-21-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":959,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/05/spf-validator-5697.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 21 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-21-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 21 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-21-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 21 of 2021","description":"Cybersecurity headlines are insightful for their coverage of a wide variety of cyberattacks, the latest security updates, recommendations, and attack trends.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-21-of-2021/","datePublished":"2021-05-21T14:04:02.000Z","dateModified":"2025-05-27T11:36:01.000Z","dateCreated":"2021-05-21T14:04:02.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-21-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":959,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/05/spf-validator-5697.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
