---
title: "Cyber Security News Update, Week 25 of 2021 | DuoCircle"
description: "Cybersecurity is a sensitively dynamic arena."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-25-of-2021/"
---

Quick Answer

Six stories. Inky reported a 974% surge in dynamite phishing, where attackers blast generic credential-harvesting emails to corporate domains in volume. Adobe issued patches for 41 vulnerabilities across Photoshop, Acrobat, and Reader. The FBI issued an alert on BEC attacks against U.S. construction firms, where attackers impersonate suppliers and reroute invoice payments. Researchers Zimperium and Cybernews found that 73% of finance and banking apps tested had insecure data storage and weak encryption. The Operation Diànxùn campaign by Chinese-linked actors targeted a Southeast Asian government with the Victory backdoor. And Intel patched 73 vulnerabilities across BIOS, drivers, and the NUC line.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2025%20of%202021&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2025%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2025%20of%202021&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2021%2F "Share via Email") 

![Cyber Security](https://media.mailhop.org/duocircle/images/2021/06/sendgrid-alternative-7498.jpg) 

_Cybersecurity is a sensitively dynamic arena_. For most security managers and IT admins, to be able to sail through each day without having their organization’s information assets’ **attacked by cyber adversaries** is nothing less than a challenge! Imagine how challenging it could be for the regular consumers of the internet to keep their PII (Personally Identifiable Information) from falling into the hands of cyber adversaries, who can then use it for various nefarious purposes. This is what makes it _crucial to keep yourself updated on the latest cyber news to stay a step ahead of malicious actors_ and keep your crucial information assets as secure as possible. Here are the latest headlines this week with global **updates on cybersecurity.**

## Dynamite Phishing Attacks Have A 974% Surge

A recent study suggests that [Business Email Compromise](/email-security/top-strategies-to-avoid-business-email-compromise-and-upgrade-email-security/) (BEC) attacks have increased by **over 974 percent**. These attacks use suggestive materials and mainly target working professionals. A typical dynamite **phishing email** addresses the victim by his name and implores him to click on an embedded link. _These emails hope to scare the victim or make them panic and lose the ability to make sensible choices_.

The links embedded in such emails usually redirect users to a [fake website](https://web.archive.org/web/20221205004635/https://cyware.com/news/scams-and-phishing-attacks-witness-explosion-bcb23dad) to steal their information, download malware, or spy on them for a follow-up attack. Additionally, the adversaries use email pass-through to trick their victims, which means that _clicking on an embedded link on the phishing email automatically sends the email address to the linked site_. When **phishing attacks** are surging at such an alarming rate, it is vital for stakeholders to (re)consider their cybersecurity strategies.

[![Cyber Security](https://media.mailhop.org/duocircle/images/2021/06/spf-record-generator-7497-1.jpg)](https://media.mailhop.org/duocircle/images/2021/06/spf-record-generator-7497-1.jpg)

## Update Your Adobe Software Immediately

If you are a loyal user of Adobe’s products, you should get all your apps **updated immediately**. _The Adobe Patch Tuesday rollout for June fixes and notifies some significant vulnerabilities in its software products_. The top among these products is Adobe Acrobat and Reader, Adobe Creative Cloud Desktop Application, Adobe Photoshop, Adobe Experience Manager, Adobe Connect, and Adobe Robohelp Server.

Getting the Adobe Acrobat and Reader update fixes [five memory corruption](https://www.securityweek.com/adobe-patches-major-security-flaws-pdf-reader-photoshop?&web%5Fview=true) vulnerabilities that _could lead to remote code execution attacks_. Hence, users must prioritize getting this patch updated. If you think that your organizational cybersecurity tools can detect such bugs and protect you, then you must still let your guard down as, for these vulnerabilities, _the adversaries can take complete control of your Windows or macOS machine without any or much of your action_. The **risk is even greater** for unpatched machines!

## FBI Warns Of BEC Attacks Targeting Construction Companies

[Business email compromise](/email-security/the-newest-business-email-compromise-request-gift-cards/) (BEC) attacks frequently impersonate construction companies to redirect payments from private sector companies, warns the FBI. The FBI’s latest update asks private sector companies to take [email security](/) measures as such scams have already targeted many US critical infrastructure sectors. _Such attacks have increased since March this year, **costing millions of dollars** to victims_.

The adversaries use the results obtained from a Google search about construction companies to impersonate them, and then create a **fake website** using legitimate logos and graphics. These become the threat actors’ [weapons](https://www.bleepingcomputer.com/news/security/fbi-warns-of-bec-scammers-impersonating-construction-companies/?&web%5Fview=true) at targeting the public and private sector clients of these construction companies. The end goal is to redirect all pending and future payments to a new bank account linked to the attacker(s).

## Are Financial Apps Really Protecting Your Confidential Information?

Ever since the outbreak of the COVID-19 pandemic, the use of financial apps and mobile contactless payments has increased. However, _a recent study indicates that over 77% of financial apps are vulnerable_ to one (or more) critical or high **severity vulnerability**. Furthermore, while the use of such financial applications has increased by 49%, there has been a simultaneous **rise of 118% in attacks** on payment, lending, banking, and trading apps.

Cryptographic issues are the predominant cybersecurity **threats for 88%** of the analyzed apps from the US, EU, UK, India, and Southeast Asia. Failing a [cryptographic test](https://www.tutorialspoint.com/security%5Ftesting/cryptography%5Foverview.htm) means that the adversaries can easily [break through](https://www.helpnetsecurity.com/2021/06/09/mobile-finance-apps/?web%5Fview=true) the encryption of these apps and expose sensitive payment and customer data. The take-away from this study is that strengthened [cybersecurity practices](/content/protection-from-phishing) must accompany the growing use of financial apps.

[![email security](https://media.mailhop.org/duocircle/images/2021/06/smtp-service-7499.jpg)](https://media.mailhop.org/duocircle/images/2021/06/smtp-service-7499.jpg)

## Malware Backdoor Victory Used Against A Southeast Asian Government

_The Chinese APT group SharpPanda is using a malware backdoor called Victory to target a Southeast Asian government._ Exploiting older vulnerabilities in Office security, the adversaries are sending [spear-phishing emails](/content/spear-phishing-protection/spear-phishing-examples) to various employees of the government entity. These spoofed emails come with malicious Word documents to gain initial access. These documents download .RTF files on the victims’ device and ultimately install the backdoor malware Victory.

In defiance of the positive attribute of its name, _Victory steals information and enables the adversaries to access the infected device_. Its other malicious operations include manipulating files, taking screenshots, collecting data on top-level opened windows, and [shutting down](https://web.archive.org/web/20210616074715/https://cyware.com/news/victory-backdoor-targeting-southeast-asian-governments-a9490f21/) the computer. The malware can also access CD-ROM drives data, TCP/UDP tables, registry keys info, etc. Since malware and other **cybersecurity threats** continue to pose a severe risk for governments and national security, enough caution must be _adopted at an enterprise level to protect against these threats_.

## Intel Fixes 73 Vulnerabilities

_The June 2021 Patch released by Intel addresses 73 security vulnerabilities_, including some high severity vulnerabilities affecting Intel’s Security Library and the BIOS firmware for Intel processors. Intel published about these **73 vulnerabilities** in 29 security advisories. It says that its internal proactive security researchers discovered [55% of the detected vulnerabilities](https://www.bleepingcomputer.com/news/security/intel-fixes-73-vulnerabilities-in-june-2021-platform-update/?&web%5Fview=true). All those who wish to see the list of vulnerabilities fixed must go through these security advisories.

The significant fixes include those for **five high severity vulnerabilities** in the Intel Virtualization Technology for Directed I/0 (VT-d) products, the Intel Security Library, and the BIOS firmware for Intel processors. In addition, eleven other high severity security vulnerabilities were fixed in Intel Driver and Support Assistant (DSA), Intel NUCs, Intel RealSense ID, Intel Thunderbolt controllers, Intel Field Programmable Gate Array (FPGA) Open Programmable Acceleration Engine (OPAE) driver for Linux, etc. _Intel advises all users to install patches for the affected products at the earliest_.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2021%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2025%20of%202021&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2021%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-25-of-2021%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 25 of 2021","description":"Cybersecurity is a sensitively dynamic arena.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-25-of-2021/","datePublished":"2021-06-17T12:54:51.000Z","dateModified":"2025-05-16T12:57:22.000Z","dateCreated":"2021-06-17T12:54:51.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-25-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1005,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/06/sendgrid-alternative-7498.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 25 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-25-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 25 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-25-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 25 of 2021","description":"Cybersecurity is a sensitively dynamic arena.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-25-of-2021/","datePublished":"2021-06-17T12:54:51.000Z","dateModified":"2025-05-16T12:57:22.000Z","dateCreated":"2021-06-17T12:54:51.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-25-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1005,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/06/sendgrid-alternative-7498.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
