---
title: "Cyber Security News Update, Week 43 of 2021 | DuoCircle"
description: "Cybersecurity is an important aspect determining the smooth functioning of an organization."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-43-of-2021/"
---

Quick Answer

Week 43 of 2021 covered six items. Dutch police sent direct warning emails to roughly 30 buyers of stresser and DDoS-for-hire services, telling them they had been identified and would face consequences if they continued. Siemens and Schneider Electric released coordinated patches for vulnerabilities affecting industrial control products, including issues in Siemens SCALANCE and Schneider's modicon controllers. The UK's NCSC published guidance for employees using personal devices for work, covering MFA, patching, and account separation. Researchers warned of a wave of malicious browser extensions impersonating popular tools to inject ads and harvest browsing data. Microsoft expanded its bug bounty program with rewards up to $20,000 for vulnerabilities in Power Platform. A new ransomware operator dubbed Black Shadow was observed leaking data from Israeli targets after extortion attempts failed.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-43-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2043%20of%202021&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-43-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-43-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-43-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2043%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2043%20of%202021&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-43-of-2021%2F "Share via Email") 

![Cyber Security](https://media.mailhop.org/duocircle/images/2021/10/spf-record-check-6824.jpg) 

_Cybersecurity is an important aspect determining the smooth functioning of an organization_. The following headlines from the bygone week indicate just how essential adopting [cybersecurity tools](/email-security/why-adopt-a-company-wide-email-security-policy-with-the-right-security-solution/) are

## Dutch Police Very Particular About Cybersecurity, Send Warnings to Cybercriminals

The Dutch authorities recently [sent out final warning](https://www.bleepingcomputer.com/news/security/dutch-police-send-warning-letters-to-ddos-booter-customers/) notifications to 29 Dutch nationals for using a **distributed denial-of-service** (DDoS) website to launch DDoS attacks against anyone they wished to target. The Dutch police sent out these notifications to let the offenders know that their malicious actions won’t go unnoticed to ensure [ransomware protection](/email-security/5-ways-you-protect-your-business-from-ransomware/) for unsuspecting citizens.

[![cybersecurity measures](https://media.mailhop.org/duocircle/images/2021/10/dkim-record-check-6524.jpg)](https://media.mailhop.org/duocircle/images/2021/10/dkim-record-check-6524.jpg)

The notice gives them an ultimatum that they will be prosecuted if found indulging in any more illegal activity. The website at the root of all these attacks is minesearch.rip, and it has been on police radar since 2020\. Currently, the minesearch website is down for investigation. This isn’t the first time Dutch authorities have stepped in to stop young individuals from going in the wrong direction. Such intrusive and extreme [cybersecurity measures](/msp-email-security/cybersecurity-best-practices-every-msp-must-adopt/) are the need of the hour, and the Dutch police’s approach sets an example for nations worldwide.

## Siemens And Schneider Electric Release Advisories Patching Vulnerabilities

_The industrial giants Siemens and Schneider Electric recently released several cybersecurity advisories patching over 33 and 20 vulnerabilities_, respectively. These [vulnerabilities affected](https://www.securityweek.com/ics-patch-tuesday-siemens-and-schneider-electric-address-over-50-vulnerabilities) many of their products. For instance, among the **33 vulnerabilities fixed** in the five new advisories of Siemens were patches for arbitrary code execution flaws in its SINEC network management system. In addition, 15 flaws in the ArubaOS operating system of SCALANCE W1750D were fixed. Many of these vulnerabilities were marked as high severity flaws.

Schneider Electric, on its part, fixed 20 vulnerabilities in 6 new advisories, which include **11 Windows flaws** in the Conext solar power plant products. Furthermore, flaws in Schneider’s IGSS SCADA system, spaceLYnk, fellerLYnk products, Wiser For KNX, and the ConneXium network manager software were also patched.

## NCSC Issues Guidelines for Employees Working on Personal Devices

_The National Cyber Security Center recently issued guidelines for employees working on personal devices in the aftermath of the pandemic_. The remote working setup popularised by the [pandemic continues to persist](/email-security/global-email-security-opportunities-challenges-and-its-importance-post-covid-19/) in many organizations with a bring-your-own-device (BYOD) policy. This culture has attracted many cybercriminals as employees may not adopt the required **cybersecurity measures** on their devices.

The NCSC advisory discusses whether BYOD is safe for an organization and mentions the possible challenges. These include compliance of devices with enterprise policies and legal obligations, protection of confidential organization files, compatibility with the required OS and device types, etc. The NCSC further suggests that a [zero-trust architectural](/email-security/importance-of-zero-trust-model-for-email-security/) approach can be adopted in organizations where BYOD is deployed.

A [cybersecurity report](https://www.bitdefender.com/files/News/CaseStudies/study/404/BD-Security-Behavior-Report-Final-at.pdf) by Bitdefender brings forth some shocking revelations about the security blunders BYOD employees commit on a daily basis. For instance, _**27% of individuals** use simple passwords like 1234 to lock their devices, whereas 11% do not even lock their phones. **35% of individuals** did not use an antivirus, whereas 30% believed their mobile phone doesn’t need an antivirus_. Several other myths were uncovered, and one among them was found among 16% of the respondents who said that they always want cybersecurity to be an inbuilt feature in their devices! With such alarming statistics on [employees’ awareness](/phishing-awareness-training) of [email security](/) or cybersecurity, using the [BYOD approach](https://www.inforisktoday.com/uk-cybersecurity-agency-releases-new-byod-guidance-a-17722) to work is a conscious choice an organization makes!

## Beware of Malicious Browser Extensions

Are you familiar with browser extensions that block ads? What about the ones that block ads on the surface but infect devices? _Cybersecurity researchers at Imperva recently found a browser extension called AllBlock that blocks ads and runs a malicious script injecting a JavaScript code in Chrome tabs_. This code communicates with remote servers to download a payload connected to an [ad-injection scam](https://www.theregister.com/2021/10/14/ad%5Fblocker%5Finjects%5Fbad%5Fads/).

The AllBlock scam brings in ads from web pages and other sources linked to affiliates. _Google claims that the security of Chrome extensions is essential for them and urges all extensions to avoid engaging in malicious activities_, but this AllBlock incident might affect its image. Imperva seems to be taking this AllBlock scam personally and has introduced its chrome application that lets users install the Imperva.com homepage offline and visit previously opened pages.

## Rewards Await if You Can Spot Vulnerabilities in Power Platform

As part of the [microsoft dynamics 365 ERP](http://velosio.com/blog/microsoft-dynamics-365-erp/) and Power Platform Bounty Program, _Microsoft is **awarding $20,000** in bounty to anyone who can find valid vulnerabilities in the Power Platform_. These Power Platform products include Power Automate, Power Apps, Power Portals, and Power Virtual Agent.

This move is just another reflection of Microsoft’s concern for customer data protection. It is willing to pay $500-$20,000 as a [bug bounty](https://www.securityweek.com/microsoft-adds-power-platform-bug-bounty-program) for the vulnerabilities identified in Power Platform products. Reports suggest that _the highest rewards are reserved for remote code execution bugs with critical severity_. Microsoft plans on expanding the Dynamics 365 and Power Platform Bounty Program gradually if the reported bugs seem relevant and significant enough.

## New Ransomware Operator Detected

[![attacked a high-profile enterprise](https://media.mailhop.org/duocircle/images/2021/10/dkim-selector-6925.jpg)](https://media.mailhop.org/duocircle/images/2021/10/dkim-selector-6925.jpg)

_Broadcom’s Symantec Threat Hunter Team recently discovered a new ransomware strain called Yanluowang used in highly targeted attacks_. The ransomware came to notice when it [attacked a high-profile enterprise](https://www.bleepingcomputer.com/news/security/new-yanluowang-ransomware-used-in-targeted-enterprise-attacks/) using the AdFind command line Active Directory. Ransomware gangs usually use AdFind to access information through lateral movement in victim devices and networks.

Soon after discovering the ransomware, the adversaries began deploying it at a faster pace in various organizational systems. In a typical attack, a .txt file is created, which checks the command line. Further, a Windows Management Instrumentation (WMI) is used to see the processes running on remote machines. This data is then logged to processes.txt.

_Once in power, Yanluowang acts upon the hypervisor virtual machines and processed precursor tools_. It also encrypts files and alters the .yanluowang extension. The ransomware also leaves behind a ransom note titled README.txt for the victim. Although the message threatens victims against approaching law enforcement, affected organizations are advised to take adequate **ransomware protection** measures.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-43-of-2021%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2043%20of%202021&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-43-of-2021%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-43-of-2021%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 43 of 2021","description":"Cybersecurity is an important aspect determining the smooth functioning of an organization.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-43-of-2021/","datePublished":"2021-10-23T17:06:06.000Z","dateModified":"2025-05-27T11:15:34.000Z","dateCreated":"2021-10-23T17:06:06.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-43-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":987,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/10/spf-record-check-6824.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 43 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-43-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 43 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-43-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 43 of 2021","description":"Cybersecurity is an important aspect determining the smooth functioning of an organization.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-43-of-2021/","datePublished":"2021-10-23T17:06:06.000Z","dateModified":"2025-05-27T11:15:34.000Z","dateCreated":"2021-10-23T17:06:06.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-43-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":987,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/10/spf-record-check-6824.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
