---
title: "CISA’s Internet Security Directive,Massive Phishing Campaign, Swiss Government Alerts: DDoS & Data Leak, Cybersecurity News [12 June 2023] | DuoCircle"
description: "This week in cybersecurity: a new CISA directive, ongoing phishing campaigns, Swiss cyber alerts, and more news from June 12, 2023."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-24-of-2023/"
---

Quick Answer

CISA issued Binding Operational Directive 23-02 ordering federal agencies to remove internet-exposed network management interfaces (firewalls, VPN concentrators, load balancers) within 14 days of discovery. Bolster researchers documented a phishing operation using more than 6,000 lookalike domains to impersonate over 100 brands, including Nike, Puma, and Casio. The Swiss government confirmed pro-Russian groups launched DDoS attacks and that ransomware crew Play stole and leaked data from supplier Xplain. Ukrainian hacktivists disrupted Russian banking IT provider Infotel. Australian law firm HWL Ebsworth disclosed it had refused to pay a BlackCat ransom; the gang then leaked 1.45TB of stolen data. And Google added passkey support and password warnings to Chrome's Password Manager.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-24-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=CISA%E2%80%99s%20Internet%20Security%20Directive%2CMassive%20Phishing%20Campaign%2C%20Swiss%20Government%20Alerts%3A%20DDoS%20%26%20Data%20Leak%2C%20Cybersecurity%20News%20%5B12%20June%202023%5D&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-24-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-24-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-24-of-2023%2F&title=CISA%E2%80%99s%20Internet%20Security%20Directive%2CMassive%20Phishing%20Campaign%2C%20Swiss%20Government%20Alerts%3A%20DDoS%20%26%20Data%20Leak%2C%20Cybersecurity%20News%20%5B12%20June%202023%5D "Share on Reddit") [ ](mailto:?subject=CISA%E2%80%99s%20Internet%20Security%20Directive%2CMassive%20Phishing%20Campaign%2C%20Swiss%20Government%20Alerts%3A%20DDoS%20%26%20Data%20Leak%2C%20Cybersecurity%20News%20%5B12%20June%202023%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-24-of-2023%2F "Share via Email") 

![cyber security news](https://media.mailhop.org/duocircle/images/2023/06/dmarc-alignment.jpg) 

Here’s the Weekly Cybersecurity Bulletin to keep you updated with the latest [cybersecurity](/) developments.

## CISA Directs Federal Agencies to Enhance the Security of Internet-Exposed Network Devices

CISA (Cybersecurity & Infrastructure Security Agency) has [issued](https://www.cisa.gov/news-events/alerts/2023/06/13/cisa-issues-bod-23-02-mitigating-risk-internet-exposed-management-interfaces) a binding operational directive, **BOD 23-02**, ordering federal civilian agencies to secure misconfigured or Internet-exposed networking equipment. 

This directive applies to routers, firewalls, proxies, and load balancers, granting **authorized users** access to network administrative tasks. CISA emphasizes reducing the attack surface caused by insecure or **misconfigured** management interfaces, and agencies must remove these interfaces from Internet exposure or protect them with separate [policy enforcement points](https://www.nextlabs.com/what-is-a-policy-enforcement-point-pep/).

_CISA will provide **technical expertise** and assist in remediation. The compliance reports will be submitted to the Director of the Office of Management and Budget and the Department of Homeland Security._ 

CISA plans to update the directive in two years. Additionally, it has launched the **Ransomware Vulnerability Warning Pilot** program for [critical infrastructure](https://www.cybersecuritydive.com/news/ransomware-critical-infrastructure-2022/645068/) organizations.

[![Ransomware Vulnerability](https://media.mailhop.org/duocircle/images/2023/06/spf-validator-7520.jpg)](https://media.mailhop.org/duocircle/images/2023/06/spf-validator-7520.jpg)

## Extensive Phishing Campaign Utilizes 6,000 Websites to Mimic 100 Brands

Since June 2022, a widespread **brand impersonation** campaign has targeted over a hundred popular apparel, footwear, and clothing brands. 

The campaign tricks users into sharing their account credentials and financial information on [fake websites](https://www.abc.net.au/news/2023-06-13/online-shopping-scams-and-how-to-spot-and-avoid-fake-websites/102448796). Brands such as Nike, Caterpillar, Puma, Vans, Adidas, and others have been impersonated by over 6,000 sites using a pattern of **brand name plus location** followed by “.com.”

The campaign displayed a significant surge in activity between January and February 2023, with **300 new fake sites** emerging monthly. Researchers [discovered](https://bolster.ai/blog/brand-impersonation-scam) that the domains, hosted by Packet Exchange Limited and Global Colocation Limited, had been in operation for up to two years.

These malicious domains have even been **indexed by Google Search**, giving them a higher ranking and appearing credible to users. The scam websites may not deliver purchased products or send counterfeit items while potentially storing credit card details for selling to [malicious actors](/data-privacy/malicious-actors-use-azure-serial-console-to-gain-unauthorized-access-to-microsoft-vms/).

_Users should **avoid promoted search results** and verify brand websites through trusted sources._

## Ongoing DDoS Attacks and Data Leak Alert Issued by Swiss Government

The Swiss government has faced a series of cyber threats recently. It was revealed that a [ransomware attack](/resources/ryuk-ransomware-attacks) on IT supplier Xplain, affecting various **government departments** and even the military, may have exposed sensitive data. 

The Play ransomware gang breached Xplain on May 23, 2023, and **published the stolen data** on June 1 after their extortion attempts failed. The Swiss government is [investigating](https://www.admin.ch/gov/en/start/documentation/media-releases.msg-id-95605.html) the extent of the data breach and the specific units affected.

Additionally, the government is now dealing with distributed denial of service (DDoS) attacks by the pro-Russian hacktivist group NoName. These attacks have caused **access issues** to several Federal Administration websites and online services. NoName has been targeting **NATO-aligned countries**, Europe, Ukraine, and North America, since early 2022\. 

[![DDoS Attacks](https://media.mailhop.org/duocircle/images/2023/06/dmarc-record.jpg)](https://media.mailhop.org/duocircle/images/2023/06/dmarc-record.jpg)

Furthermore, NoName targeted the [parliament website](https://english.alarabiya.net/News/world/2023/05/03/-Hacktivists-target-Sweden-s-parliament-website-) during discussions on Switzerland’s neutrality and potential **aid to Ukraine**. 

## Service Provider for Russian Banks Disrupted by Ukrainian Threat Actors

The Ukrainian malicious group Cyber.Anarchy.Squad has [claimed](https://www.epravda.com.ua/news/2023/06/8/700979/) responsibility for an attack that brought down **Russian telecom provider** JSC Infotel8\. 

Based in Moscow, Infotel provides connectivity services to the Russian Central Bank, other Russian banks, online stores, and credit institutions. As a result of the attack, **central banks** in Russia lost access to the country’s [banking systems](https://web.archive.org/web/20250522214324/https://www.itsecuritynews.info/cyber-attack-projected-on-us-and-european-banking-systems/), preventing them from making online payments.

Infotel confirmed the incident on its website, stating that it is **working on restoring** its damaged systems. _The Ukrainian adversaries released screenshots of their access to Infotel’s network, including a network diagram and a compromised email account._ 

This malicious group has previously targeted [Russian organizations](https://thehackernews.com/2022/08/new-woody-rat-malware-being-used-to.html) and leaked stolen employee and **customer information databases**.

## Australian Commercial Law Giant Successfully Thwarts BlackCat Ransomware Extortion Attempt

Australian **law firm** HWL Ebsworth has [confirmed](https://www.abc.net.au/news/2023-06-09/russian-linked-hackers-taunt-hwl-ebsworth-over-data-breach/102461608) that the AlphV ransomware gang, also known as BlackCat, targeted it in a cyberattack. 

The law firm, one of Australia’s largest, suffered a data breach, with the [threat actors](/email-security/threat-actors-attack-thousands-of-computers-following-the-ion-incident/) leaking 1.45 terabytes of data containing over a million documents allegedly stolen from their systems in April 2023\. The gang has **threatened to release more data** if their demands are unmet.

[![](https://media.mailhop.org/duocircle/images/2023/07/Ransomware-Data-Breach-Statistics-410x1024.jpg)](https://media.mailhop.org/duocircle/images/2023/07/Ransomware-Data-Breach-Statistics.jpg)

Despite the threat, HWL Ebsworth has stated that they will not give in to the extortion demands, prioritizing their ethical and moral duties. The **leaked documents** raise concerns about exposing sensitive or confidential information, potentially impacting clients such as ANZ banking groups and various [government entities](https://thehackernews.com/2023/02/purecrypter-malware-targets-government.html). 

The **indexed database** on BlackCat’s site allows easy exploration of the leaked documents, posing additional risks.

## Enhanced Safeguards Introduced for Your Credentials in Google Chrome Password Manager

Google Chrome is introducing new security features for its **built-in Password Manager** to enhance user safety and protect against [account hijacking](https://thehackernews.com/2023/05/critical-oauth-vulnerability-in-expo.html) attacks. 

The Password Manager, an **integral part** of Google’s services, enables users to manage and autofill credentials across various apps. While storing credentials on the browser can pose risks, following sound security practices minimizes concerns.

Google has [announced](https://blog.google/products/chrome/google-chrome-password-manager-new-features/) **five new features** to bolster Password Manager security. These include a dedicated desktop shortcut for easy access, **biometric authentication** on the desktop, saving custom notes with login credentials, importing passwords from other managers, and Password Checkup for flagging weak and reused passwords on the mobile iOS app. 

These features aim to **enhance user account safety** in an environment where storing passwords in browsers carries inherent risks.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"CISA’s Internet Security Directive,Massive Phishing Campaign, Swiss Government Alerts: DDoS & Data Leak, Cybersecurity News [12 June 2023]","description":"This week in cybersecurity: a new CISA directive, ongoing phishing campaigns, Swiss cyber alerts, and more news from June 12, 2023.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-24-of-2023/","datePublished":"2023-06-12T16:09:19.000Z","dateModified":"2025-05-21T12:20:35.000Z","dateCreated":"2023-06-12T16:09:19.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-24-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":886,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/06/dmarc-alignment.jpg","caption":"cyber security news","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"CISA’s Internet Security Directive,Massive Phishing Campaign, Swiss Government Alerts: DDoS & Data Leak, Cybersecurity News [12 June 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-24-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"CISA’s Internet Security Directive,Massive Phishing Campaign, Swiss Government Alerts: DDoS & Data Leak, Cybersecurity News [12 June 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-24-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"CISA’s Internet Security Directive,Massive Phishing Campaign, Swiss Government Alerts: DDoS & Data Leak, Cybersecurity News [12 June 2023]","description":"This week in cybersecurity: a new CISA directive, ongoing phishing campaigns, Swiss cyber alerts, and more news from June 12, 2023.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-24-of-2023/","datePublished":"2023-06-12T16:09:19.000Z","dateModified":"2025-05-21T12:20:35.000Z","dateCreated":"2023-06-12T16:09:19.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-24-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":886,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/06/dmarc-alignment.jpg","caption":"cyber security news","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
