---
title: "Cyber Security News Update, Week 30 of 2021 | DuoCircle"
description: "The cyber headlines are once again crowded with news of attacks, patches, mergers, and data theft."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-30-of-2021/"
---

Quick Answer

Seven items. Google announced Chrome will move toward an HTTPS-First mode, defaulting to HTTPS and warning on HTTP page loads. Microsoft introduced controls in Azure AD to prevent consent-phishing attacks where attackers trick users into granting OAuth permissions to malicious apps. Spanish authorities arrested 16 suspects linked to Mekotio and Grandoreiro banking trojan campaigns targeting Latin American victims. Kaspersky reported APT campaigns including LuminousMoth targeting government and telecoms across Southeast Asia. China's Cyberspace Administration finalized rules requiring data-security reviews for companies with more than 1 million users before listing on foreign exchanges. Microsoft's July Patch Tuesday fixed 117 flaws, including 13 critical and 4 actively exploited zero-days. And Romanian and Greek police arrested eight ATM-skimming suspects in a joint Europol operation.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-30-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2030%20of%202021&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-30-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-30-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-30-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2030%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2030%20of%202021&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-30-of-2021%2F "Share via Email") 

![DuoCircle blog post image](https://media.mailhop.org/duocircle/images/2021/07/phishing-protection-7071.jpg) 

The cyber headlines are once again crowded with news of attacks, patches, mergers, and data theft. Here are the top global **cybersecurity updates** of this week to help you keep abreast of the latest happenings in the cyber world so you can learn from the mistakes of others and adopt [cybersecurity practices](/email-security/email-security-best-practices-and-standards-organizations-must-implement/) in advance and keep your critical data from falling into the hands of cyber adversaries.

## Chrome To Get An HTTPS-First Mode

_Google is working on adding an HTTPS-First Mode to its Chrome web browser in an abundance of security_. This is to block adversaries from accessing or manipulating users’ web traffic. The HTTPS-First Mode endeavors to upgrade all webpages to HTTPS and warn users before loading a non-HTTPS site. _This cybersecurity measure notifies users before loading an HTTP site_.

The [HTTPS-First Mode](https://www.bleepingcomputer.com/news/security/google-chrome-will-add-https-first-mode-to-keep-your-data-safe/) shall be operational on Google Chrome 94 and is undergoing tests in the Chrome 93 Canary preview releases for Windows, Android, Mac, Linux, and Chrome OS. _Google’s latest protection measure aims to safeguard users from cyber threats such as **man-in-the-middle attacks**_. Google is also working on securing HTTP webpages by restricting their web platform features.

## Microsoft Has A Solution To Prevent Consent Phishing Attacks

[![Phishing Attacks](https://media.mailhop.org/duocircle/images/2021/07/phishing-protection-2127.jpg)](https://media.mailhop.org/duocircle/images/2021/07/phishing-protection-2127.jpg)

How often does it happen that _we grant permissions to a seemingly genuine app and later find that it has been spying on us and stealing our data_? These are called **consent phishing attacks**, and lately, their application has increased. Microsoft has introduced a new governance feature in its Microsoft Cloud App Security to ensure [email security](/) from such attacks, allowing system administrators and organizations to control which apps get permission on users’ devices.

The user consent settings in Azure Active Directory or Azure AD allow administrators to block end users from granting consent to potentially risky apps. Microsoft recommends this [security measure](https://www.microsoft.com/security/blog/2021/07/14/microsoft-delivers-comprehensive-solution-to-battle-rise-in-consent-phishing-emails/?web%5Fview=true) for organizations to **remove cyber threats** at their root.

## Spanish Authorities Arrest 16 Cybercriminals

As per the Spanish law enforcement agency Guardia Civil, _16 suspects associated with the Brazilian bank trojans Mekotio and Grandoreiro have been arrested_ in Ribeira, Villafranca de Los Barros, Seseña, Parla, Aranda de Duero, Móstoles and Madrid. The authorities seized devices from the accused’s residence. They found that the suspects had **over €276,470** (About $326,000) transferred to their bank accounts as part of the many cyberattacks linked to Mekotio and Grandoreiro.

The banking [trojans Mekotio and Grandoreiro](https://therecord.media/spain-arrests-16-for-distributing-the-mekotio-and-grandoreiro-banking-trojans/) primarily attack Windows computers with **spoofed emails** that impersonate legitimate organizations. _They remain hidden until the victim logs into their bank account and steals their credentials_. With the capacity to collect data from 30 different banks, these two trojans access e-banking portals and direct funds to their accounts. In a typical attack, the victims’ computers would restart multiple times before access was finally blocked. _Attacks culminate in the transfer of large amounts of money from victims’ accounts to multiple unknown accounts_. This is now twice in 2021 that Spanish authorities have made a bold arrest of cyberattackers and reinstated people’s belief in their cybersecurity measures.

## Southeast Asians Users Beware Of APT Campaigns

_A large-scale advanced persistent threat (APT) campaign with ties to LuminousMoth and HonetMyte was recently uncovered_. Cybersecurity experts reveal that the [APT campaign has already targeted](https://www.bleepingcomputer.com/news/security/chinese-cyberspies-wide-scale-apt-campaign-hits-asian-govt-entities/) hundreds of Southeast Asians, including government entities from the Philippines and Myanmar.

Both these hacker groups launch wide-scale attacks aiming to land a small subset of suitable victims. While tracking the cyberespionage attacks of LuminousMoth, _researchers discovered that the group had **targeted over 1400** and 100 victims in the Philippines and Myanmar_, respectively, since October 2020\. LuminousMoth and HonetMyte typically use [spear-phishing emails](/content/spear-phishing-protection/spear-phishing-examples) embedded with [malicious Dropbox](/phishing-protection/steps-for-effective-protection-from-dropbox-scams/) download links to enter the victims’ systems. Once inside, _the malware attempts to infect other systems using removable USB drives and previously stolen files_.

## China All Set To Implement New Cybersecurity Regulations

The [Chinese government has recently released](https://therecord.media/chinese-government-lays-out-new-vulnerability-disclosure-rules/) a _new set of regulations that provides strict instructions for all **vulnerability disclosure** procedures in the country_. Some of the controversial articles in these new regulations prevent cybersecurity researchers from highlighting the details of a vulnerability before giving the vendor enough time (and also to adversaries to exploit the same) to fix the issues. _The regulations further instruct researchers to report a bug to the state authorities within two days of spotting it_.

In addition, _the regulations make vendors chargeable if they fail to fix bugs and release patches on time_. These new regulations will be operational from 1st September 2021, but work on these new rules has continued since 2017\. Last week, Beijing officials released new **cybersecurity laws** for all companies with _over a million users that they must mandatorily undergo a security audit before listing their shares overseas_.

## Microsoft Fixes 117 Flaws In Its Patch Tuesday Updates For July

_Microsoft’s Patch Tuesday updates are out_, and this month’s update contains patches for more than the combined total of the last two months. A total of **117 security vulnerabilities**, with 13 critical, 103 important, and a moderate severity flaw, were patched. Nine [zero-day vulnerabilities](https://www.phishprotection.com/content/zero-day-attacks/) were also fixed among these vulnerabilities.

The [updates apply to all Microsoft](https://thehackernews.com/2021/07/update-your-windows-pcs-to-patch-117.html) products, Exchange Server, Windows, Windows DNS, Bing, Visual Studio Code, Dynamics, Office, and Scripting Engine. The major security flaws patched in the July Update have been dubbed as CVE-2021-34527, CVE-2021-31979, CVE-2021-33771, and CVE-2021-34448\. The zero-day vulnerabilities include, CVE-2021-34448, CVE-2021-34523, CVE-2021-33781, CVE-2021-33779, and CVE-2021-34492\. If you haven’t updated your Microsoft apps and software yet, here is a quick reminder to do it at the earliest!

[![cybercriminals ](https://media.mailhop.org/duocircle/images/2021/07/phishing-protection-1444.jpg)](https://media.mailhop.org/duocircle/images/2021/07/phishing-protection-1444.jpg)

## Romanian And Greek Police Make 8 Arrests

_The Romanian and Greek police recently [arrested eight cybercriminals](https://portswigger.net/daily-swig/eight-arrests-made-as-eurojust-dismantles-2-million-e-commerce-fraud-operation) from an organized crime group_. These attackers had defrauded online shoppers of **over $2.4 million** and set up around 300 bank accounts in Poland, Spain, Hungary, the Netherlands, and Germany using fake IDs.

In their raids, the authorities seized mobile phones, $261,000 in cash, and travel documents from 30 locations. The cybersecurity experts revealed that the adversaries used **phishing scams**, fake advertisements, payment, and transport companies to trick unsuspecting users. These attacks also stored the personal details, bank and card information, and login credentials of users. The same was later circulated among the cybercriminals’ networks.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 30 of 2021","description":"The cyber headlines are once again crowded with news of attacks, patches, mergers, and data theft.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-30-of-2021/","datePublished":"2021-07-22T17:33:06.000Z","dateModified":"2025-05-15T16:00:42.000Z","dateCreated":"2021-07-22T17:33:06.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-30-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1019,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/07/phishing-protection-7071.jpg","caption":"DuoCircle blog post image","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 30 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-30-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 30 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-30-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 30 of 2021","description":"The cyber headlines are once again crowded with news of attacks, patches, mergers, and data theft.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-30-of-2021/","datePublished":"2021-07-22T17:33:06.000Z","dateModified":"2025-05-15T16:00:42.000Z","dateCreated":"2021-07-22T17:33:06.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-30-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1019,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/07/phishing-protection-7071.jpg","caption":"DuoCircle blog post image","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
