---
title: "Cyber Security News Update, Week 4 of 2021 | DuoCircle"
description: "New breaches are getting discovered as employees get back to the offices post the holidays."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-4-of-2021/"
---

Quick Answer

Week 4 of 2021 brought six developments. Iranian APT Charming Kitten ran a spear-phishing campaign during the holiday break, impersonating researchers to harvest credentials. A new Android remote-access trojan called Rogue surfaced, sold on hacker forums and capable of monitoring messages, location, and camera. Public health officials warned that COVID-19 vaccine rollouts were being targeted with cold-chain phishing and fake registration sites. Microsoft president Brad Smith called for international rules of the road for state-backed cyber operations following the SolarWinds incident. Mimecast disclosed that an attacker compromised a certificate it issues for Microsoft 365 Exchange Web Services connections, affecting a small number of customers and tied to the same actor behind SolarWinds. Adobe issued security updates patching critical flaws across Photoshop, Illustrator, and other products as Flash Player reached end of life.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-4-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%204%20of%202021&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-4-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-4-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-4-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%204%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%204%20of%202021&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-4-of-2021%2F "Share via Email") 

![Cyber Security](https://media.mailhop.org/duocircle/images/2021/01/spf-record-tester-2900.jpg) 

New breaches are getting discovered as employees get back to the offices post the holidays. While the attacks aren’t unprecedented, they speak volumes of the need to better utilize **cybersecurity tools**, particularly in the festive season.

## Charming Kitten Uses Holiday Break To Launch Spear-Phishing Campaign

Known for its malicious activities targeting the winter holiday breaks, the Iranian cyber-espionage group Charming Kitten has launched a sophisticated **spear-phishing campaign** that used both emails and SMS to trap victims. Cybersecurity firm CERTA says that Charming Kitten used the festive break when offices were functioning with reduced IT experts who could identify and block **security threats**. The group targeted political research centers, think tanks, university professors, environmental activists, and journalists in the US, Europe, and the Persian Gulf.

The text messages sent impersonated [Google security alerts](https://www.zdnet.com/article/iranian-cyberspies-behind-major-christmas-sms-spear-phishing-campaign/?&web%5Fview=true), and the **phishing emails** used previously hacked accounts to target a larger group with cunningly woven content. What’s surprising to note is that the adversaries could hide their **spear-phishing campaign** behind a legitimate Google URL ([https://www.google\\\[.\\\]com/url?q=https://script.google\\\[.\\\]com/xxxx](https://www.google%5C%5B.%5C%5Dcom/url?q=https://script.google%5C%5B.%5C%5Dcom/xxxx)). Such a scam often goes undetected by senior security experts, let alone employees working half-heartedly in the festive season! Gmail users must adopt [email protection](/) measures as this wasn’t the first time that Charming Kitten could successfully use Google URLs for its attacks!

[![Spear-Phishing Campaign](https://media.mailhop.org/duocircle/images/2021/01/spf-record-tester-2800.jpg)](https://media.mailhop.org/duocircle/images/2021/01/spf-record-tester-2800.jpg)

## New RAT, Rogue Targets Android Devices

_A new malware strain has surfaced, which is the combined work of Android malware authors Triangulum and HeXaGoN Dev_. Going by the name of Rogue, this new Mobile Remote Access Trojan (MRAT) attacks Android devices and works secretly to steal all user data. Triangulum’s social marketing skills, combined with HeXaGon Dev’s programming skills, have created malware _capable of causing irrevocable data loss_ to [Android users](https://www.securityweek.com/rogue-android-rat-can-take-control-devices-steal-data?&web%5Fview=true).

Rogue acts as a legitimate Google service and uses Google’s Firebase platform to hide its propaganda. It uses Cloud Messaging to infect a device and gain administrative permissions. _Removing the RAT after this becomes difficult as it threatens to erase all data if the user tries to restrict the granted permissions_. The only word of advice after this is: cyberattacks can come in any form. The best way to stay secure is to resort to cybersecurity solutions such as [email security as a service](/).

## Vaccine Release Is No Time For Complacence

The latest update on the data breach at the European Medicines Agency (EMA) is that the _adversaries have published all stolen data related to the vaccine_. The COVID-19 vaccine candidates Pfizer and BioNTech had their details breached in a security incident at EMA last month. EMA is taking [necessary measures](https://threatpost.com/hackers-leak-pfizer-covid-19-vaccine-data/163008/?web%5Fview=true) for email authentication and security while also notifying all involved individuals and entities whose data may have been leaked.

_The BNT162b2 vaccine is being circulated in the UK, and now is certainly not the time to lose data to cybercriminals_. While Pfizer and BioNTech have little role in the breach, this serves as a message to all companies working on the COVID-19 vaccines to take cybersecurity measures and implement privileged access to data for **enhanced security**.

## Time To Set International Cyber Rules, Says Microsoft President

Addressing the alarming _security incidents capable of taking over systems across nations_, Microsoft President Brad Smith says at the Consumer Electronics Show (CES) 2021 that it’s time to view cybersecurity as a world peace parameter. He comments on our increasing [dependence on technology](https://www.infosecurity-magazine.com/news/microsoft-president-collaboration/?&web%5Fview=true) and the corresponding rise of data breaches and security incidents.

Smith feels that it’s about time we took _some proactive measures to understand the present security threats to protect the future_. He also highlighted the importance of monitoring our usage of artificial intelligence (AI) technology until new guardrails are created to keep humanity over technology. We are talking of a world where machine learning tools and facial recognition technology have taken over people’s lives. Privacy becomes a myth as we let our fundamental rights take a backseat in the pursuit of one-click access and convenience. However, Smith is optimistic that we can still change the picture and address the ever-increasing cybersecurity issues with global collaboration and brainstorming.

## Cyberattack Hits A Mimecast-Issued Certificate

_In a recent cyberattack, a Mimecast-issued certificate used to authenticate connections made to Mimecast Internal Email Protect, Sync and Recover, and Continuity Monitor, was compromised_. Consequently, attackers gained access to customers’ Microsoft 365 exchange servers and are probably intercepting the traffic and exfiltrating communications.

Vice president (Solutions Architecture at Cerberus Sentinel), Chris Clements points out two [possible outcomes](https://threatpost.com/mimecast-certificate-microsoft-supply-chain-attack/162965/?web%5Fview=true) of this certificate compromise:

- Attackers can decipher the **encrypted data** by launching a man-in-the-middle attack (that is if the stolen certificate is used to verify Mimecast users’ server validity).
- In a much worse scenario where security controls are limited, and the stolen certificate can authenticate to Microsoft 365 from Mimecast servers, the adversaries can access all customer data by connecting directly to Microsoft.

There are other much worse possible outcomes of this compromise, but Mimecast is maintaining discretion on the cybersecurity incident’s specifics. Customers are advised to consider [email security services](/) whether or not Mimecast informs them of a compromise. _The users must re-establish their connections with the new Mimecast certificate for enhanced security_.

[![ email security services](https://media.mailhop.org/duocircle/images/2021/01/spf-record-tester-3000.jpg)](https://media.mailhop.org/duocircle/images/2021/01/spf-record-tester-3000.jpg)

## Adobe Releases Security Updates As Flash Goes Down

After Flash reached its end-of-service on 31st December 2020, Adobe took on the task of **fixing vulnerabilities**. It released the first round of security updates for the year by patching [eight vulnerabilities](https://www.securityweek.com/adobe-releases-first-security-updates-2021-it-blocks-flash-content?&web%5Fview=true) in its products like Bridge, Photoshop, Animate, Illustrator, Captivate, Campaign Classic, and InCopy.

Two critical out-of-bounds write bugs in Bridge, a privilege escalation bug in Captivate, a critical SSRF issue in Campaign Classic, and one critical arbitrary code execution flaw each in Animate, Photoshop, InCopy, and Illustrator were patched. The good thing over and above these cybersecurity tools’ upgrade is that none of the vulnerabilities were exploited before the patch release!

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-4-of-2021%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%204%20of%202021&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-4-of-2021%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-4-of-2021%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Spam](https://media.mailhop.org/duocircle/images/2016/05/spf-permerror-3256.jpg)  April Spam Filtering Uptime Report News ](/blog/announcements/april-spam-filtering-uptime-report/)
- [ ![Spam Filtering](https://media.mailhop.org/duocircle/images/2023/02/spf-record-tester-7226.jpg)  Changes to Spam Filtering Technology News ](/blog/announcements/changes-to-spam-filtering-technology/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2020/01/spf-permerror-7312.jpg)  Cyber Security News Update, Week 1 of 2020 News ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 1m  April Spam Filtering Uptime Report  May 4, 2016 ](/blog/announcements/april-spam-filtering-uptime-report/)[  News 2m  Changes to Spam Filtering Technology  Feb 8, 2023 ](/blog/announcements/changes-to-spam-filtering-technology/)[  News 4m  Cyber Security News Update, Week 1 of 2020  Jan 3, 2020 ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 4 of 2021","description":"New breaches are getting discovered as employees get back to the offices post the holidays.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-4-of-2021/","datePublished":"2021-01-22T18:20:56.000Z","dateModified":"2025-05-16T12:08:37.000Z","dateCreated":"2021-01-22T18:20:56.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-4-of-2021/"},"articleSection":"announcements","keywords":"","wordCount":958,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/01/spf-record-tester-2900.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 4 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-4-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 4 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-4-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 4 of 2021","description":"New breaches are getting discovered as employees get back to the offices post the holidays.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-4-of-2021/","datePublished":"2021-01-22T18:20:56.000Z","dateModified":"2025-05-16T12:08:37.000Z","dateCreated":"2021-01-22T18:20:56.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-4-of-2021/"},"articleSection":"announcements","keywords":"","wordCount":958,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/01/spf-record-tester-2900.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
