---
title: "Email Forwarding Exploited, AI Threatens Email, Chinese Key Theft, Cybersecurity News [September 04, 2023] | DuoCircle"
description: "In this edition of the weekly newsletter, you get to closely examine the four latest stories involving email security and associated cybersecurity news."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-36-of-2023/"
---

Quick Answer

Email security headlines for the week of September 4, 2023\. University of California San Diego researchers found that legacy email-forwarding behavior in providers like iCloud, Outlook, Gmail, and Zohomail can be abused to spoof messages from high-profile domains, including federal agencies, banks, and major news outlets, evading SPF and DMARC checks. Generative AI tools are being used to craft phishing emails that lack the grammar errors and tonal mistakes that traditional filters rely on. Microsoft's investigation into the Storm-0558 Exchange Online intrusion confirmed Chinese threat actors stole an MSA consumer signing key, then used a token-validation bug to forge tokens for enterprise mailboxes. Researchers exposed 'The Five Families,' a loose collaboration of cybercrime groups (ThreatSec, GhostSec, Stormous, Blackforums, SiegedSec) coordinating attacks and data leaks.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-36-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Email%20Forwarding%20Exploited%2C%20AI%20Threatens%20Email%2C%20Chinese%20Key%20Theft%2C%20Cybersecurity%20News%20%5BSeptember%2004%2C%202023%5D&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-36-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-36-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-36-of-2023%2F&title=Email%20Forwarding%20Exploited%2C%20AI%20Threatens%20Email%2C%20Chinese%20Key%20Theft%2C%20Cybersecurity%20News%20%5BSeptember%2004%2C%202023%5D "Share on Reddit") [ ](mailto:?subject=Email%20Forwarding%20Exploited%2C%20AI%20Threatens%20Email%2C%20Chinese%20Key%20Theft%2C%20Cybersecurity%20News%20%5BSeptember%2004%2C%202023%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-36-of-2023%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2023/09/check-DMARC-record-1.jpg) 

In this edition of the weekly newsletter, you get to closely examine the four **latest stories** involving email security and associated [cybersecurity](/) news.

Online scammers exploit **email forwarding** **vulnerabilities**, allowing them to impersonate high-profile domains, including government agencies, financial institutions, and major news organizations. These vulnerabilities expose users to malware and spyware risks. It requires users to re-evaluate their [email security practices](/email-security/email-security-best-practices-and-standards-organizations-must-implement/).

In another new development, the **transformative power of generative AI** threatens the email security market. With sophisticated tools available, malicious actors quickly fix grammar and language flaws that used to be a sign of phishing emails. **Foolproof emails** are now a challenge for traditional detection methods to identify.

In a unique incident, Chinese threat actors have carried out an audacious theft of a Microsoft signing key in a recent incident, leading to the [compromise of government email accounts](https://gizmodo.com/microsoft-china-cyberattack-government-email-accounts-1850631322). This **security loophole** is a stark reminder of securing sensitive keys and the potential consequences of lapsed security. 

This update also covers the appalling development of five threat groups collaborating to become one unified malicious entity, ready to wreak havoc on organizations on a **large scale**. 

[![ email security](https://media.mailhop.org/duocircle/images/2023/09/spf-permerror-7507.jpg)](https://media.mailhop.org/duocircle/images/2023/09/spf-permerror-7507.jpg)

## Scammers Exploit Email Forwarding Vulnerabilities

The University of California, San Diego researchers reveal that [malicious actors](/data-privacy/malicious-actors-use-azure-serial-console-to-gain-unauthorized-access-to-microsoft-vms/) can now easily send **fraudulent emails** due to vulnerabilities in the email forwarding process. The integrity of emails sent by various domains is under scrutiny as attackers can impersonate these organizations. _The affected entities include financial institutions, governmental agencies, and significant news establishments._

As the attackers impersonate these organizations using a flaw in email forwarding processes, they can **evade email provider safeguards**. It could lead to [spyware being installed](https://www.cpomagazine.com/cyber-security/module-installed-in-over-100-android-apps-contained-spyware-infected-over-421-million-downloads/) or malware infections.

These vulnerabilities stem from **outdated email validation** protocols that do not account for organizations outsourcing their email infrastructure to third-party providers like Outlook and Gmail. Although these providers authenticate their users, [email forwarding](/content/email-forwarder-free/best-email-forwarding-service) can still bypass them.

For instance, a threat actor can **forward a spoofed email** through an Outlook account. The process would make it appear legitimate when the target receives it. The threat can affect several domains. While existing defense mechanisms can temporarily mitigate the risks, research suggests that more robust [email security](/content/email-security-services/types-of-email-security) measures are required to address the issue.

## Generative AI Poses New Threats to Email Security

Generative AI, such as OpenAI’s ChatGPT, is **revolutionizing** email phishing attacks. As email security flaws are detected, malicious actors leverage sophisticated technology to generate [flawless and convincing emails](https://www.wsj.com/articles/generative-ai-could-revolutionize-emailfor-hackers-5a8c725c#:~:text=Now%20generative%20AI%20tools%2C%20including,personalized%20emails%20in%20just%20seconds.).

Traditionally, phishing emails could be detected through common mistakes in spelling and grammar. However, with AI now accessible to adversaries, they are creating highly **personalized and perfectly structured** messages. Thus, traditional detection systems find it increasingly challenging to detect phishing attempts.

Malicious actors not only use [generative AI](/email-security/how-generative-ai-is-changing-email-security-threat-landscape/) to create emails that appear legitimate and more convincing but also to **analyze public data** and gain more specific inputs about their targets. The impact of this threat extends beyond the email security market. Attackers can also leverage AI to create [deepfake audio and video for attacks](https://www.infosecurity-magazine.com/news/martin-lewis-deepfake-investment/) in the future.

[![AI-generated content](https://media.mailhop.org/duocircle/images/2023/09/check-DMARC-record-1-1.jpg)](https://media.mailhop.org/duocircle/images/2023/09/check-DMARC-record-1-1.jpg)

_With the attack vectors evolving, it’s time to spearhead cybersecurity strategies capable of **identifying AI-generated content** in phishing attacks._

## Chinese Malicious Actors Steal Microsoft Signing Key

The Chinese threat group Storm-0558 stole a Microsoft signing key from a [Windows crash dump](https://logixconsulting.com/2020/05/19/the-purpose-of-windows-dump-files-and-how-they-work/). The incident has led to the compromise of the email accounts of several organizations, including the government. The attackers have apparently **exploited a zero-day validation** issue to impersonate accounts within targeted organizations.

_The breach started with the corporate account of a Microsoft engineer being compromised._ Thus, attackers gained access to the **debugging environment** that had the signing key. While it remains unclear how they carried out the exfiltration, the key appeared in a crash dump. It was then moved to an internet-connected environment.

This incident highlights the importance of [securing sensitive keys](https://www.csoonline.com/article/649571/mongodb-rolls-out-queryable-encryption-to-secure-sensitive-data-workflows.html) in organizations. It also points to the potential consequences or even lapses in security. Microsoft has taken steps to address the issue and **enhance its logging capabilities** to detect problems in the future. 

## Five Families, Collaboration Among Threat Actors

A new collective of malicious groups, named the “Five Families,” has emerged, claiming to mastermind some recent [online attacks](https://www.financialexpress.com/life/technology-beware-chatgpt-doppelganger-wormgpt-is-helping-cybercriminals-launch-online-attacks-3177862/). Five organizations form this **new collaboration**: Blackforums, GhostSec, SiegedSec, Stormous, and ThreatSec.

Five Families recently appeared in the headlines after successfully breaching a **Brazilian software development organization**, Alpha Automation. They accessed a massive 230 GB of data, which included financial information, customer data, [business software](https://www.bleepingcomputer.com/news/security/alphv-gang-claims-ransomware-attack-on-constellation-software/), and internal documents of the organization. _They also encrypted their cloud systems and servers._

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-36-of-2023%2F) [ ](https://twitter.com/intent/tweet?text=Email%20Forwarding%20Exploited%2C%20AI%20Threatens%20Email%2C%20Chinese%20Key%20Theft%2C%20Cybersecurity%20News%20%5BSeptember%2004%2C%202023%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-36-of-2023%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-36-of-2023%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Email Forwarding Exploited, AI Threatens Email, Chinese Key Theft, Cybersecurity News [September 04, 2023]","description":"In this edition of the weekly newsletter, you get to closely examine the four latest stories involving email security and associated cybersecurity news.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-36-of-2023/","datePublished":"2023-09-12T14:51:31.000Z","dateModified":"2025-05-19T12:05:17.000Z","dateCreated":"2023-09-12T14:51:31.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-36-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":751,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/09/check-DMARC-record-1.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Email Forwarding Exploited, AI Threatens Email, Chinese Key Theft, Cybersecurity News [September 04, 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-36-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Email Forwarding Exploited, AI Threatens Email, Chinese Key Theft, Cybersecurity News [September 04, 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-36-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Email Forwarding Exploited, AI Threatens Email, Chinese Key Theft, Cybersecurity News [September 04, 2023]","description":"In this edition of the weekly newsletter, you get to closely examine the four latest stories involving email security and associated cybersecurity news.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-36-of-2023/","datePublished":"2023-09-12T14:51:31.000Z","dateModified":"2025-05-19T12:05:17.000Z","dateCreated":"2023-09-12T14:51:31.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-36-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":751,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/09/check-DMARC-record-1.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
