---
title: "Cyber Security News Update, Week 22 of 2021 | DuoCircle"
description: "Among the most effective ways to evade the digital world’s endless cybersecurity challenges is staying abreast of the latest attack trends."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-22-of-2021/"
---

Quick Answer

Cybersecurity stories from the week of May 31, 2021: researchers disclosed FragAttacks, a set of Wi-Fi standard design flaws affecting nearly every Wi-Fi-enabled device since 1997, allowing frame injection and traffic interception. Japan introduced cybersecurity regulations for private-sector operators of critical infrastructure. Industry analysis examined why attackers continue to outpace defenders, citing automation, exploit kits, and slow patch cycles. A study estimated that adversaries can dwell undetected on enterprise networks for an average of about 11 days before exfiltration or ransomware deployment. Chrome added a feature that streamlines changing passwords flagged as compromised through Google's password checkup. And Google patched four vulnerabilities in Android, including critical remote-code-execution issues.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-22-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2022%20of%202021&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-22-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-22-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-22-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2022%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2022%20of%202021&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-22-of-2021%2F "Share via Email") 

![cyber security](https://media.mailhop.org/duocircle/images/2021/05/dkim-validation-6070.jpg) 

_Among the most effective ways to evade the digital world’s endless cybersecurity challenges is staying abreast of the latest attack trends_. Towards that end, here we bring you the most significant email security incidents in the past week

## Multiple Bugs Found In WiFi Standards

In a frightening security revelation, a _Belgium-based cybersecurity researcher has found multiple implementations and **design flaws** in the WiFi standard used by device manufacturers_. These fragmentation and aggregation attacks (FragAttacks) pose a risk for all WiFi devices developed using the WiFi standards commonly used (some of which date back to the 1990s).

The three principal vulnerabilities, CVE-2020-24586, CVE-2020-24587, and CVE-2020-24588, enable an attacker within the radio range of the WiFi device to control and intercept the user’s information. The researcher experimented with over 75 devices, and each of them was vulnerable to at least one attack.

On the other hand, the [implementation flaws](https://web.archive.org/web/20221107210300/https://cyware.com/news/fragattacks-affecting-millions-of-wi-fi-enabled-devices-c82bbd07) _enable the adversaries to inject a specially crafted frame into an unencrypted WiFi frame and steal user data_. The significant bugs include CVE-2020-26144 and CVE-2020-26145\. This sure is a scary discovery, but with the **right cybersecurity tools** and habits such as using strong passwords, having data back-up, etc., these vulnerabilities can be stopped from being exploited.

[![Multiple Bugs Found In WiFi Standards](https://media.mailhop.org/duocircle/images/2021/05/spf-record-generator-4021.jpg)](https://media.mailhop.org/duocircle/images/2021/05/spf-record-generator-4021.jpg)

## Japan Mandates Cybersecurity Regulations For Private Sector

As a [ransomware protection](/email/phishing-protection) measure after the recent Colonial Pipeline incident, _the Japanese government has introduced new regulations to strengthen its national cyber defense_. These regulations shall apply to 44 sectors, including finance, telecommunications, railroads, healthcare, electricity, and government services. These sectors will have to pay special attention to services and [equipment procured](https://www.zdnet.com/article/japan-to-restrict-private-sector-use-of-foreign-equipment-and-tech-report/?&web%5Fview=true) from overseas, such as cloud data storage.

In addition, the government will regulate organizations for compliance with these regulations. _It will have the authority to restrict them from using foreign equipment which does not meet their security standards_. The move comes now for private sectors, but all government undertakings in Japan had boycotted the use of **threat-posing** foreign equipment (like those from ZTE and Huawei) three years back!

## What Makes Hackers To Fast And Threat Detection So Slow?

[![Hackers To Fast And Threat Detection](https://media.mailhop.org/duocircle/images/2021/05/spf-permerror-4030.jpg)](https://media.mailhop.org/duocircle/images/2021/05/spf-permerror-4030.jpg)

The reason why ransomware attackers can attack organizations has been revealed. A cybersecurity research team from Palo Alto Networks recently conducted a study on 50 global enterprises and **50 million associated IP** addresses. _The study showed that if companies take an average of 12 hours to detect a vulnerability_, attackers take only one hour! This unbelievably colossal pace gap makes all the difference!

The study further revealed that [most vulnerabilities](https://www.bleepingcomputer.com/news/security/hackers-scan-for-vulnerable-devices-minutes-after-bug-disclosure/?&web%5Fview=true) relate to the Remote Desktop Protocol (which is known for being an entry window to admin servers for adversaries), followed by [zero-day vulnerabilities](https://www.phishprotection.com/content/zero-day-attacks/), misconfigured database servers, and insecure remote access.

A crippling revelation was that in some instances, the adversaries’ scan frequency comes down to 15 minutes (when there is a **remotely exploitable bug** in the network) and 5 minutes (when the ProxyLogon bugs were found in Microsoft Exchange Server and Outlook Web Access). Palo Alto Networks suggests that this lag in **threat detection** occurs because of a flawed [vulnerability management process](https://www.designrush.com/agency/cybersecurity/trends/vulnerability-management-process) that scans the existing database for vulnerabilities.

## Interesting Study Suggests How Long Can Adversaries Hide In A Network

The UK based cybersecurity firm [Sophos](/resources/sophos-alternatives) recently published a report on the average time cyber attackers get within a breached network before being detected. While _Sophos says that adversaries get an **average of 11 days** before being seen_ (because they have deployed ransomware by then), Mandiant proposes a longer **time-to-detection of 24 days** on average. Sophos explains the shorter dwell time by suggesting that **ransomware attacks** are different from mere data breaches.

Going by the Sophos report, we can tell that the adversaries have a decent time of 11 days (264 hours) for all their malicious activities, including data exfiltration, lateral movement, credential dumping, reconnaissance, etc. And they don’t need more than a few minutes or hours for these activities. Therefore, it can be concluded that the attackers get ample time to [study a network](https://www.zdnet.com/article/this-is-how-long-hackers-will-spend-in-your-network-before-deploying-ransomware-or-being-spotted/?&web%5Fview=true) and its loopholes before being detected.

_The Sophos study also highlighted the use of Remote Desktop Protocol (RDP) in most (90%) of the cyberattacks_. It also mentioned the most active ransomware gangs in 2020, including Revil, Ryuk, Maze, Dharma, Netwalker, and Ragnarok.

## New Chrome Update Helps Change Compromised Passwords Effortlessly

First introduced in 2018, Google’s [Duplex technology](https://www.darkreading.com/mobile/google-chrome-makes-it-easier-to-update-compromised-passwords/d/d-id/1341071?&web%5Fview=true) will now _alert users every time Google detects a password compromise and help them to change the password for the particular site with ease_. This feature will be available on Google Assistant for Android and iOS, first for users in the US and eventually for other countries.

With the Duplex technology, users will be able to create a **strong password** for all password compromises that Chrome identifies. This comes as a great addition to users’ cybersecurity tools and can even be used manually.

## Four Vulnerabilities Detected In Android

Google’s May 2021 Android Security Bulletin revealed four **security vulnerabilities** in Arm and Qualcomm, which were previously patched. These vulnerabilities have been exploited as **zero days** in the wild and named CVE-2021-1905, CVE-2021-1906, CVE-2021-28663, and CVE-2021-28664.

There is no reason to believe the vulnerabilities have been widely exploited: there may have been limited and targeted exploitation. Adversaries could gain complete access to the [target device](https://thehackernews.com/2021/05/android-issues-patches-for-4-new-zero.html?&web%5Fview=true) upon exploiting these **cybersecurity flaws**, but it is uncertain how the process can be carried out. This update comes after Google notified about two vulnerabilities in Qualcomm chipsets (CVE-2020-11261) and Binder (CVE-2019-2215), respectively, back in March.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-22-of-2021%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2022%20of%202021&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-22-of-2021%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-22-of-2021%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 22 of 2021","description":"Among the most effective ways to evade the digital world’s endless cybersecurity challenges is staying abreast of the latest attack trends.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-22-of-2021/","datePublished":"2021-05-26T16:30:14.000Z","dateModified":"2025-05-20T16:44:46.000Z","dateCreated":"2021-05-26T16:30:14.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-22-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":902,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/05/dkim-validation-6070.jpg","caption":"cyber security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 22 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-22-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 22 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-22-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 22 of 2021","description":"Among the most effective ways to evade the digital world’s endless cybersecurity challenges is staying abreast of the latest attack trends.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-22-of-2021/","datePublished":"2021-05-26T16:30:14.000Z","dateModified":"2025-05-20T16:44:46.000Z","dateCreated":"2021-05-26T16:30:14.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-22-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":902,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/05/dkim-validation-6070.jpg","caption":"cyber security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
