---
title: "Cyber Security News Update, Week 42 of 2021 | DuoCircle"
description: "This week’s cybersecurity headlines have had significant updates related to recent acquisitions, patches, and adversary actions."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-42-of-2021/"
---

Quick Answer

Week 42 of 2021 covered six items. Apache patched two severe path-traversal flaws in HTTP Server 2.4.49 and 2.4.50, including CVE-2021-41773 and CVE-2021-42013, both under active exploitation for remote code execution. Arizona opened a new state Cyber Command Center to coordinate incident response across agencies. Arctic Wolf acquired security awareness training firm Habitu8 to fold its content library into Arctic Wolf's managed offering. Coinbase Global confirmed that an authentication flaw in its SMS account recovery flow let attackers drain cryptocurrency from roughly 6,000 customers. Industry analysts forecast a global cybersecurity hiring resurgence as remote work, ransomware, and supply-chain attacks pushed budgets up. Google's October Android update fixed 41 vulnerabilities, none under active exploitation, including critical issues in System and Framework components.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-42-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2042%20of%202021&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-42-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-42-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-42-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2042%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2042%20of%202021&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-42-of-2021%2F "Share via Email") 

![Cyber Security](https://media.mailhop.org/duocircle/images/2021/10/spf-permerror-7485.jpg) 

This week’s cybersecurity headlines have had significant updates related to recent acquisitions, patches, and adversary actions. Here are the most important of those [cyber news headlines](/announcements):

## Apache Fixes Severe Vulnerabilities

In an abundance of caution, _Apache has released patches for two cybersecurity vulnerabilities in its HTTP server_. Adversaries actively [exploited the vulnerabilities](https://thehackernews.com/2021/10/apache-warns-of-zero-day-exploit-in.html) related to path traversal and file disclosure until 29th September, when Apache discovered the same in Apache HTTP Server 2.4.49.

Using the path traversal flaw (dubbed as CVE-2021-41773), attackers could map URLs to external files, often not protected by ‘require all denied.’ _The second vulnerability was detected in processing HTTP/2 requests_ (dubbed as CVE-2021-41524), which could be used to launch **denial-of-service** (DoS) attacks on the server. However, Apache’s timely move and insistence on users getting the patches as soon as possible is an indicator of the [cybersecurity awareness](/phishing-awareness-training) that’s slowly making its way into organizations’ priorities.

## Arizona Opens New Cyber Command Center

Over the last fifteen years, \_the Arizona government has **lost around $1.6 billion** to data breache\_s, and the compromised records exceed 10.9 million. With such a massive loss of assets and threat to citizens’ identities, the Ducey administration has opened a [new Cyber Command Centre](https://www.azmirror.com/blog/arizona-opens-new-cyber-command-center/) called the Arizona Information Sharing and Analysis Center (AZ-ISAC). The AZ-ISAC (previously known as the Arizona Cyber Information Program) aims at striking a balance between the [cyber threat](/phishing-protection/small-businesss-shocking-response-to-cyber-threats/) detection and response measures of local, state, and federal agencies.

This cybersecurity merger of the public and private sectors will see several departments working towards [ransomware protection](/email-security/5-ways-you-protect-your-business-from-ransomware/). These entities include the Arizona Department of Homeland Security, the Arizona Department of Administration, the FBI’s Cyber Crimes Task Force, the Arizona National Guard Cyber Response Team, the Arizona Department of Public Safety, and the Arizona Counter Terrorism Information Center. The creation of this fusion center in Arizona ensures that **data breaches** are tackled at their roots and detect existing cybersecurity loopholes that might expose citizens’ details.

[![ransomware protection](https://media.mailhop.org/duocircle/images/2021/10/smtp-service-7486.jpg)](https://media.mailhop.org/duocircle/images/2021/10/smtp-service-7486.jpg)

## Arctic Wolf Acquires Habitu8

_The cybersecurity company Arctic Wolf recently acquired the security training platform Habitu8_, giving the former access to around 60-70% of the latter’s customers. The deal terms remain undisclosed, but [this news](https://techcrunch.com/2021/09/30/arctic-wolf-acquires-hollywood-style-cybersecurity-training-startup-habitu8/) comes just 60 days after Arctic Wolf secured **$150 million** in Series F funding.

Habitu8 is a start-up founded in 2017 that uses live-action videos to impart **cybersecurity awareness**. Its Learning Platform will now be merged with Arctic Wolf’s Managed Security Awareness offering, thereby creating a [training and security awareness](/phishing-awareness-training) program delivered as a concierge service. Arctic Wolf views this acquisition as a leap in imparting cyber-risk awareness as Habitu8’s training does not subscribe to the dull approach that most other organizations follow. Its use of modern high quality and on-demand experiences which are engaging and retainable ensure that people do not forget the training concept as soon as they receive them. Both companies are hopeful that this acquisition will be an **effective solution** for all customers.

## Coinbase Global Inc. Customers Affected By Data Breach

Coinbase Global Inc. recently sent out a [data breach notification](https://www.reuters.com/business/finance/coinbase-says-hackers-stole-cryptocurrency-least-6000-customers-2021-10-01/) to around **6,000 customers**, informing them of an intrusion that happened between March and May 2021\. _The adversaries exploited a flaw in the company’s SMS account recovery process and gained access to user accounts_. Soon after, they transferred funds to crypto wallets outside of Coinbase.

Coinbase has approached customers with reimbursements of their stolen funds, but this is no assurance of [email security](/) as the adversaries already have their phone numbers, email addresses, and passwords. The company says it has no evidence of the data being compromised from its servers in its defense. However, the flaw is now fixed, and one can only hope that Coinbase and other exchanges **take cybersecurity seriously** because the attackers won’t be keeping away from the crypto world!

[![email security](https://media.mailhop.org/duocircle/images/2021/10/dkim-selector-7488.jpg)](https://media.mailhop.org/duocircle/images/2021/10/dkim-selector-7488.jpg)

## A Global Cybersecurity Resurgence?

Global cybersecurity concerns are increasing, and the latest [arrest of two cyber criminals](https://thehill.com/policy/cybersecurity/575242-international-coalition-arrests-prolific-hackers-involved-in-ransomware) by Europol is evidence. These _threat actors were arrested in Ukraine recently and have been behind laundering some **5-70 million euros**_ from entities across the European Union, the USA, France, and Ukraine. The accused have been involved in a series of [ransomware attacks](/phishing-protection/ransomware-attacks-your-organizations-ability-to-function/) since April 2020, where they _threatened victims of leaking their data if the ransom wasn’t paid_.

Seven property searches were conducted along with these arrests, which revealed that the threat actors owned **over $1.3 million** in cryptocurrencies, $375,000 in cash, and two expensive luxury vehicles. This investigation saw Europol collaborate with Interpol’s Cyber Fusion Centre, the French National Cybercrime Centre of the National Gendarmerie, the FBI’s Atlanta Field Office, and the Cyber Police Department of the National Police of Ukraine.

Too many major [ransomware attacks](/email-security/ransomware-attacks-must-be-met-with-advanced-technology/) have happened in the recent past, including the Colonial Pipeline and JBS attacks. World governments are worried about this emerging cyberthreat, and therefore US president Biden had urged Russian President Putin to impose restrictions on their state-sponsored threat actor groups. The October [Cybersecurity Awareness](/phishing-awareness-training) Month will witness president Biden convene a meeting of 30 nations with hopes of combating the growing number of cybercrimes.

## Google Fixes 41 Unexploited Vulnerabilities in October

On the fifth of every month, Google releases its [security updates](https://www.bleepingcomputer.com/news/security/android-october-patch-fixes-three-critical-bugs-41-flaws-in-total/), and this month, it has **fixed 41 vulnerabilities** affecting Android versions 8.1 to 11, all of which range between high and critical severity. While the high-severity flaws include denial of service, remote code execution, elevation of privilege, and information disclosure issues, the critical **severity flaws** affect Qualcomm’s WLAN component and include a remote code execution issue.

Fortunately, none of these 41 vulnerabilities were exploited before the release of the patches. Newer Android versions that support the update are still safe if they get the patches on time, but devices that have reached end-of-life remain at risk. Such users must either consider changing their device or getting a third-party Android distribution application that delivers the monthly **cybersecurity patches**.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-42-of-2021%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2042%20of%202021&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-42-of-2021%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-42-of-2021%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 42 of 2021","description":"This week’s cybersecurity headlines have had significant updates related to recent acquisitions, patches, and adversary actions.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-42-of-2021/","datePublished":"2021-10-15T12:50:08.000Z","dateModified":"2025-05-15T13:07:33.000Z","dateCreated":"2021-10-15T12:50:08.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-42-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":968,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/10/spf-permerror-7485.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 42 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-42-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 42 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-42-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 42 of 2021","description":"This week’s cybersecurity headlines have had significant updates related to recent acquisitions, patches, and adversary actions.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-42-of-2021/","datePublished":"2021-10-15T12:50:08.000Z","dateModified":"2025-05-15T13:07:33.000Z","dateCreated":"2021-10-15T12:50:08.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-42-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":968,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/10/spf-permerror-7485.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
