---
title: "Google Looker Evades, Email Scam Collaboration, Firefox Zero-Day Patch Cybersecurity News [September 11, 2023] | DuoCircle"
description: "Cybersecurity is a rapidly evolving domain that requires you to be updated with information on the latest innovations to stay on top."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-37-of-2023/"
---

Quick Answer

Email security headlines for the week of September 11, 2023\. Check Point researchers found attackers abusing Google Looker Studio to host phishing pages with legitimate Google URLs that bypass SPF, DKIM, and DMARC checks at the receiving gateway. Microsoft attributed a new Microsoft Teams phishing campaign to Storm-0324, which uses chat messages and malicious file links to gain footholds that Sangria Tempest (ELBRUS, FIN7) then escalates to ransomware. Mozilla patched a critical zero-day, CVE-2023-4863, a heap buffer overflow in libwebp affecting Firefox, Thunderbird, and many Chromium-based browsers. Researchers disclosed several flaws in Proton Mail's web client that could expose ciphertext or session data, all reported responsibly and patched.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-37-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Google%20Looker%20Evades%2C%20Email%20Scam%20Collaboration%2C%20Firefox%20Zero-Day%20Patch%20Cybersecurity%20News%20%5BSeptember%2011%2C%202023%5D&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-37-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-37-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-37-of-2023%2F&title=Google%20Looker%20Evades%2C%20Email%20Scam%20Collaboration%2C%20Firefox%20Zero-Day%20Patch%20Cybersecurity%20News%20%5BSeptember%2011%2C%202023%5D "Share on Reddit") [ ](mailto:?subject=Google%20Looker%20Evades%2C%20Email%20Scam%20Collaboration%2C%20Firefox%20Zero-Day%20Patch%20Cybersecurity%20News%20%5BSeptember%2011%2C%202023%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-37-of-2023%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2023/09/dkim-record-check-1-1.jpg) 

[Cybersecurity](/) is a rapidly evolving domain that requires you to be updated with information on the latest innovations to stay on top. To help in the process of making email security and organizational cyber well-being possible, here are the **top cybersecurity headlines** from this week:

## Google Looker Studio Becomes the New Path to Evade Email Security

In a recent attack, malicious actors exploited **Google’s Looker Studio** [data visualization tool](https://web.archive.org/web/20240519234403/https://www.treasuredata.com/glossary/what-are-data-visualization-tools/) to send phishing lure pages to hundreds of businesses. These pages are designed to evade email security defenses and steal data and money.

Google Looker Studio is a web-based tool that converts slideshows, spreadsheets, etc., into visualized data like charts and graphs. The latest Business Email Compromise (BEC) scam uses Google Looker Studio to build **cryptocurrency-themed pages** to send to businesses as if from Google. These emails contain purported reports on strategies for cryptocurrency investing and require users to sign into their Google accounts for more details.

If users click on the sign-in link, they are redirected to a **spoofed Google Looker page**, which hosts a Google Slideshow informing them about the process of claiming more Bitcoin. It also creates a sense of urgency, leading users to a login page that steals their credentials. This [attack scheme](https://www.darkreading.com/endpoint/phishers-abuse-google-looker-studio-dmarc-email-security?utm%5Fsource=flipboard&utm%5Fcontent=DarkReading%2Fmagazine%2FDark+Reading) works because it can dodge malicious email scanning technology.

The messages fool the [Sender Policy Framework](/content/sender-policy-framework) (SPF) using the authorized sender IP address data-studio.bounces.google.com. They can also **evade any** **flags** arising in the [DKIM](/resources/what-is-dkim) authentication tool or [DMARC](/resources/what-is-dmarc) inspection as they come from the legitimate domain google.com they claim.

The incident makes one wonder whether traditional security measures can detect [sophisticated email attack vectors](https://www.techrepublic.com/article/israel-threat-actors-email-attacks/) like the one under discussion. Thus, the best thing to do is to install a robust **file-scanning** and **URL protection** system at an organizational level to detect and prevent [BEC attacks](/data-privacy/microsoft-uncovers-banking-aitm-phishing-and-bec-attacks-targeting-financial-giants/).

[![BEC Attacks](https://media.mailhop.org/duocircle/images/2023/09/dkim-record-check-2.jpg)](https://media.mailhop.org/duocircle/images/2023/09/dkim-record-check-2.jpg)

## Storm-0324 and Sangria Tempest Collaborate for Teams Phishing Email Scam

The threat actor group Storm-0324 has been using Microsoft Teams Email to send phishing emails to organizations since July 2023\. This [email-based](/email-hosting/the-top-three-email-based-threats-and-how-to-avoid-them/) initial infection strategy unfolds in **multi-layered exploitation**, wherein Storm-0324 gains unauthorized access to a network and hands it over to other threat actors. Storm-0324 works with the [ransomware-as-a-service (RaaS)](https://www.paloaltonetworks.com/cyberpedia/what-is-ransomware-as-a-service) actor Sangria Tempest to distribute the JSSLoader malware.

Storm-0324 uses **highly effective infection chains** involving invoice and payment lures. This collaboration between adversaries, wherein Storm-0324 distributes payloads from other adversaries, necessitates organizations to employ advanced [email security](/content/email-security-services/email-security-features) measures such as multi-layered scanning.

Reportedly, Storm-0324 and Sangria Tempest have been collaborating [since 2019](https://gbhackers.com/microsoft-teams-storm-0324-group-hack-corporate-networks/). Storm-0324 gains access to victim systems, distributes **JSSLoader** and then hands it over to Sangria to steal information and encrypt the systems.

In a typical attack, Storm-0324 sends a [phishing email](https://cybernews.com/news/chatgpt-phishing-emails-could-weaponize-realism/) with a payment or invoice link to a victim. Clicking on this leads users to a SharePoint site with a ZIP archive. This archive has a file embedded with JS code, and opening the file infects the system with the JSSLoader variant DLL. _To protect against such_ _email vulnerabilities, Microsoft has upgraded its **Accept/Block feature** in one-on-one chats within Teams._

## Mozilla Patches a Critical Zero-Day Vulnerability in its Firefox Web Browser

Mozilla recently found a [zero-day vulnerability](/email-security/unpatched-dogwalk-a-new-microsoft-zero-day-vulnerability/) in its Firefox web browser and Thunderbird email client. Tagged [CVE-2023-4863](https://www.scmagazine.com/news/mozilla-patches-critical-zero-day-that-targeted-its-firefox-browser-and-thunderbird-email-client), the flaw allows remote attackers to perform an **out-of-bounds memory write** through a spoofed HTML page. So far, a CVSS score has not yet been assigned to the vulnerability, but it is reported to be critical.

Mozilla talked about the [zero-day flaw](https://thehackernews.com/2023/09/microsoft-releases-patch-for-two-new.html) in its advisory dated September 12, 2023, and said it was also being exploited in the wild in other products. These include Google’s Chrome browser as well. However, Chrome was patched against this vulnerability a day before the advisory was released. Firefox 117.0.1, Firefox ESR 102.15.1, Firefox ESR 115.2.1, Thunderbird 115.2.2, and Thunderbird 102.15.1 have also been patched similarly.

Zero-day attacks like this [exploit browser vulnerabilities](https://tech.hindustantimes.com/tech/news/2-billion-google-chrome-users-hit-by-browser-security-flaw-protect-yourself-now-71673710024322.html) and target all major browsers like Firefox, Chrome, Safari, and Edge. A **browser compromise** leads to infiltration of any cloud-based service accessible to that browser. _Thus, users must ensure that_ _their web browsers are updated with the latest patches._

[![phishing email](https://media.mailhop.org/duocircle/images/2023/09/spf-record-tester-7492.jpg)](https://media.mailhop.org/duocircle/images/2023/09/spf-record-tester-7492.jpg)

## Several Vulnerabilities Detected in Proton Mail’s Web Client

Cybersecurity experts recently found [critical code vulnerabilities](https://cybersecuritynews.com/sap-security-vulnerabilities/) in the renowned privacy-focused webmail service, Proton Mail. These vulnerabilities pose a severe threat to the privacy and confidentiality of user data. The vulnerabilities exist in Proton Mail’s web client, where messages get decrypted for users.

A significant **loophole in the service’s encryption system** comes to light via these vulnerabilities: though its email security works fine for messages in transit and at rest, the vulnerabilities can be exploited to steal decrypted messages and impersonate users.

An attacker can trick Proton Mail users into interacting with their malicious messages and clicking on links embedded in these emails. The research team at SonarSource notified Proton Mail of these email security loopholes in June 2022, and the organization took immediate [corrective measures](https://cybersecuritynews.com/proton-mail-vulnerabilities/). Owing to Proton Mail’s proactive security steps, no known exploits of the vulnerabilities have been recorded.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-37-of-2023%2F) [ ](https://twitter.com/intent/tweet?text=Google%20Looker%20Evades%2C%20Email%20Scam%20Collaboration%2C%20Firefox%20Zero-Day%20Patch%20Cybersecurity%20News%20%5BSeptember%2011%2C%202023%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-37-of-2023%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-37-of-2023%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Google Looker Evades, Email Scam Collaboration, Firefox Zero-Day Patch Cybersecurity News [September 11, 2023]","description":"Cybersecurity is a rapidly evolving domain that requires you to be updated with information on the latest innovations to stay on top.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-37-of-2023/","datePublished":"2023-09-20T09:27:29.000Z","dateModified":"2025-05-16T11:46:27.000Z","dateCreated":"2023-09-20T09:27:29.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-37-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":830,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/09/dkim-record-check-1-1.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Google Looker Evades, Email Scam Collaboration, Firefox Zero-Day Patch Cybersecurity News [September 11, 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-37-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Google Looker Evades, Email Scam Collaboration, Firefox Zero-Day Patch Cybersecurity News [September 11, 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-37-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Google Looker Evades, Email Scam Collaboration, Firefox Zero-Day Patch Cybersecurity News [September 11, 2023]","description":"Cybersecurity is a rapidly evolving domain that requires you to be updated with information on the latest innovations to stay on top.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-37-of-2023/","datePublished":"2023-09-20T09:27:29.000Z","dateModified":"2025-05-16T11:46:27.000Z","dateCreated":"2023-09-20T09:27:29.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-37-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":830,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/09/dkim-record-check-1-1.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
