---
title: "Cyber Security News Update, Week 34 of 2021 | DuoCircle"
description: "There is not much you can do when one of the social media or messaging app giants you use was attacked by threat actors."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-34-of-2021/"
---

Quick Answer

Cybersecurity headlines for the week of August 20, 2021\. Researchers debated whether 'end-to-end encryption' messaging apps actually deliver on the promise after Apple's CSAM-scanning announcement. Surveys showed Americans and Britons remained skeptical of digital and virtual vaccination credentials. NortonLifeLock's announced acquisition of Avast was framed as a major consumer-cybersecurity consolidation. The shuttered AlphaBay dark-web market reappeared with new operators advertising drugs and stolen data. UK authorities warned about Flubot Android malware spreading via fake parcel-delivery SMS. The Poly Network attacker who stole around $600 million in cryptocurrency returned the funds after researchers traced exchange activity.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-34-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2034%20of%202021&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-34-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-34-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-34-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2034%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2034%20of%202021&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-34-of-2021%2F "Share via Email") 

![Cyber Security](https://media.mailhop.org/duocircle/images/2021/08/dkim-selector-1167.jpg) 

_There is not much you can do when one of the social media or messaging app giants you use was attacked by threat actors_, and all your critical information has now fallen into their hands. The need to adopt [cybersecurity measures](/email-security/why-it-is-crucial-for-smes-to-have-a-robust-cybersecurity-posture/) and maintain cyber hygiene is more than ever before. This week’s headlines discuss the newest security firm mergers, investments, and serious hacks, among other crucial developments in the cyber world.

## Are Messaging Apps Providing End-to-End Encryption?

When a _bug was detected in the group FaceTime calls on iOS in 2019_ (where the hackers could switch on the microphone and camera and [eavesdrop on the call recipient](https://www.wired.com/story/signal-facebook-messenger-eavesdropping-vulnerabilities/) without them clicking on anything), it made cybersecurity researcher Natalie Silvanovich curious. She explored if such bugs existed in other messaging apps like Facebook Messenger, Google Duo, Signal, etc. To her surprise, they did! Such interaction-less vulnerabilities are both interesting and dangerous. _When an attack can be launched without any action from the victim, then it’s probably the easiest way for malicious actors to get in_.

Silvanovich found multiple bugs in these messaging applications but received quick responses from their developers. All detected vulnerabilities are now fixed, but this speaks a lot about the privacy promises that applications make and fail to meet. _Developers must remember that they have ensured their users of encryption and privacy and design applications accordingly_. Here is a brief outline of what the attackers could do with the vulnerabilities in various applications:

- **Facebook Messenger**: Listen to audio from the victim’s device.
- **Signal**: Exposed victim’s audios.
- **Viettel Mocha**: Advanced access to audio and video.
- **Google Duo**: Access to video, albeit only for a few seconds.
- **JioChat**: Advanced access to audio and video.

[![Encryption](https://media.mailhop.org/duocircle/images/2021/08/dkim-selector-1168.jpg)](https://media.mailhop.org/duocircle/images/2021/08/dkim-selector-1168.jpg)

## Americans And Brits Unsure Of Virtual Vaccination Cards

Recently, the cybersecurity company Anomali conducted a poll in collaboration with The Harris Poll. _The poll was held for over 2000 American and 1000 British adults and asked them questions regarding virtual vaccination cards_. The poll results indicate that over 80% of Americans and 76% of Brits are apprehensive of using COVID-19 [digital vaccine cards](https://www.infosecurity-magazine.com/news/e-vax-card-cybersecurity-fears/) because they fear exposing their personal information to adversaries.

When asked their opinion on who they think would launch such attacks related to the virtual vaccination cards, **36% of Americans** hinted at nation-states like China, Russia, and North Korea. In contrast, around **42% of Brits** expected such attacks from organized crime cybercriminal groups. [Identity and data theft](/phishing-protection/recognizing-online-identity-thefts-and-how-enterprises-can-ensure-identity-theft-protection-for-their-employees/) were among the primary concerns of the respondents. Yet another fear attached to using virtual vaccination cards was that the adversaries might hack into their devices using fake digital vaccination cards.

## NortonLifeLock Acquiring Avast Might Be The Best Cybersecurity Update In Recent Times

Norton antivirus has been a household name for the last three decades, and it is now [merging with yet another giant](https://www.theverge.com/2021/8/11/22619667/nortonlifelock-avast-merger-deal-anti-virus-cyber-security-software) cybersecurity firm Avast. This merger of Avast and NortonLifeLockinvolved a deal **exceeding $8 billion** and shall lead to the creation of a much bigger cybersecurity firm that reaches the combined users of Norton and Avast.

From now on, NortonLifeLock will acquire all Avast shares, and their services will be available to **over 500 million users**. Amidst all the news pertaining to cyber attackers and their increasing power, this merger of two of the most prevalent cybersecurity firms brings a ray of hope. We can now expect enhanced [ransomware protection](/email-security/5-ways-you-protect-your-business-from-ransomware/) with antivirus products rich in NortonLifeLock’s experience in identity and Avast’s emphasis on privacy, all in a single product and platform.

## The Return Of AlphaBay

_The revival of hacker groups is never good news_, and this time it’s the notorious [AlphaBay gang that has returned](https://www.cyberscoop.com/alphabay-dark-web-fbi-flashpoint/) four years after the FBI shut it down. AlphaBay had **stolen at least $1billion** from victims before shutting down, and now the adversaries are trying to relaunch a new and deadlier version of the same. This update comes from one of the former moderators of AlphaBay, who posted about it online last week and mentioned that the _offerings of the new AlphaBay would include the source code of a banking-related hacking tool_.

_AlphaBay is known as the Amazon.com of the dark web_. The US and European law enforcement agencies have struggled to ensure **ransomware protection** and regulate the actions of such cybercrime groups over the past year. This news might just be the beginning of a series of AlphaBay hack news we will soon hear about.

## Britons Beware of the Flubot Malware

_A special cybersecurity alert is in circulation for Britons because the adversaries are targeting them with the Flubot malware_. These malicious [attackers are impersonating](https://cybernews.com/news/britons-targeted-by-a-flubot-malware-scam/) delivery services like DHL, Amazon, Asda, and Argos and sending **phishing messages** to Britons. In case the recipients fall for the scam and download the malware, it spies on their banking details or other credentials and gives it to the threat actors. All network operators in Britain are affected by this [phishing scam](/resources/phishing-scams-and-the-simple-ways-you-can-protect-yourself), and therefore Britons must look at every delivery service text with suspicion.

All users who may have received such a delivery message that asks you to download an app to track your order or redirects you to a link to listen to a voicemail should immediately delete the message. _You are still safe if you accidentally open the text but do not follow the instructions and download the app_. But in case you have opened a link or downloaded the app indicated in the [phishing text](/phishing-protection/phishing-emails-just-became-even-harder-to-spot-with-invisible-text/), then _you must consider changing your banking password and passwords of all accounts_ you may have logged into after downloading the app. Such users are advised to contact their banks and **closely monitor** their banking and other accounts.

[![Cryptocurrency](https://media.mailhop.org/duocircle/images/2021/08/dkim-selector-1166.jpg)](https://media.mailhop.org/duocircle/images/2021/08/dkim-selector-1166.jpg)

## Hacker Return Stolen Cryptocurrency

Ever heard of threat actors returning the money they stole? Well, that’s what happened with the latest hack on the Chinese DeFi platform, Poly Network. _The adversaries had stolen **more than $600 million** in cryptocurrency by exploiting a vulnerability between contract calls on Poly Network_, which enabled them to control the funds transferring system. On 10th August, the [adversaries returned the stolen amount](https://www.bleepingcomputer.com/news/security/hacker-behind-biggest-ever-cryptocurrency-heist-returns-stolen-funds/) through the following tokens on the Polygon network:

- $256 million as Binance Smart Chain (BSC) tokens
- $3.3 million as Ethereum tokens
- $1 million as USD Coin (USDC)

Apart from this, _the attackers are yet to return another $84 million on Polygon and $269 million on Ethereum_. While returning the funds, the adversaries embedded their motives of hacking along with each transaction. However, what triggered them to return the **stolen cryptocurrency** is still a mystery. Soon after **discovering the attack** on Poly Network, cybersecurity experts at Binance, Tether, OKEx and Huobi had begun their investigations. These investigations must have led to some significant discoveries about the attackers, fearing the disclosure of which they are now returning the stolen cryptocurrency. Or, perhaps, these were whitehat hackers who wanted to bring vulnerabilities to Polys Network’s developers’ team. Whatever be the case, _this attack has been one of the largest heists ever to have taken place_.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-34-of-2021%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2034%20of%202021&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-34-of-2021%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-34-of-2021%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 34 of 2021","description":"There is not much you can do when one of the social media or messaging app giants you use was attacked by threat actors.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-34-of-2021/","datePublished":"2021-08-20T17:43:27.000Z","dateModified":"2025-05-19T14:28:39.000Z","dateCreated":"2021-08-20T17:43:27.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-34-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1155,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/08/dkim-selector-1167.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 34 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-34-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 34 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-34-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 34 of 2021","description":"There is not much you can do when one of the social media or messaging app giants you use was attacked by threat actors.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-34-of-2021/","datePublished":"2021-08-20T17:43:27.000Z","dateModified":"2025-05-19T14:28:39.000Z","dateCreated":"2021-08-20T17:43:27.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-34-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1155,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/08/dkim-selector-1167.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
