---
title: "Apple Device Email Breach, Russian Email Breach, Microsoft Enhances Security, Cybersecurity News [October 30, 2023] | DuoCircle"
description: "Here are the latest updates related to the email security landscape."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-44-of-2023/"
---

Quick Answer

Four items shaped the week of October 30, 2023\. Researchers disclosed iLeakage, a Spectre-style side-channel attack on Apple Silicon and recent A-series chips that abuses Safari's speculative execution to read cross-origin content including Gmail contents. Russian hacking operations were reported attempting compromise of more than 632,000 email accounts at the US Department of Defense and Department of Justice through phishing and credential abuse. Microsoft announced its Secure Future Initiative tightening Microsoft 365 identity, key handling, and tenant isolation following Storm-0558's theft of a signing key used to forge tokens for US officials' mailboxes. The WiHD adult-content site was found leaking 322 GB of personal data on 97,327 users due to a misconfigured server, exposing email addresses, IP addresses, and viewing history.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-44-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Apple%20Device%20Email%20Breach%2C%20Russian%20Email%20Breach%2C%20Microsoft%20Enhances%20Security%2C%20Cybersecurity%20News%20%5BOctober%2030%2C%202023%5D&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-44-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-44-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-44-of-2023%2F&title=Apple%20Device%20Email%20Breach%2C%20Russian%20Email%20Breach%2C%20Microsoft%20Enhances%20Security%2C%20Cybersecurity%20News%20%5BOctober%2030%2C%202023%5D "Share on Reddit") [ ](mailto:?subject=Apple%20Device%20Email%20Breach%2C%20Russian%20Email%20Breach%2C%20Microsoft%20Enhances%20Security%2C%20Cybersecurity%20News%20%5BOctober%2030%2C%202023%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-44-of-2023%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2023/11/buy-smtp-1.jpg) 

Here are the latest updates related to the [email security](/content/email-security-services/types-of-email-security) landscape, exploring the newest email security breaches and measures to combat threats that **involve big names** like the Pentagon and Microsoft.

## Researchers Successful in Breaking into Apple Devices and Stealing Email Data Using iLeakage Program

Researchers have demonstrated that recent [Apple devices can be compromised](https://www.aljazeera.com/economy/2023/6/2/russia-says-us-intelligence-hacked-thousands-of-iphones) using the program iLeakage to steal data, including emails and passwords, through the **Safari browser**.

Academic researchers from three institutions, Georgia Tech, University of Michigan, and Ruhr University Bochum, have [shown](https://www.bleepingcomputer.com/news/security/new-ileakage-attack-steals-emails-passwords-from-apple-safari/) that they **could extract data** with utmost accuracy from Apple devices released after 2020 having A-series or M-series ARM processors, raising concern about sensitive data and email security.

The program used for this purpose was iLeakage, which is capable of [bypassing side-channel protection](https://www.techtarget.com/searchsecurity/definition/side-channel-attack) and stealing data through Apple Silicon CPUs and browsers like Safari, Tor, Firefox, and Edge used on iOS. It uses a timerless and **architecture-agnostic rule** dependent on race conditions. iLeakage was also successful in retrieving watch history on YouTube by compromising the Chrome browser used with iOS.

_As the **infiltration possibility** was reported to Apple, the digital giant has taken several [cybersecurity](/) measures to overcome the threat and avoid any leakage of users’ confidential and sensitive data._

## Russian Attackers Compromise 632,000 Email Accounts of Pentagon and DOJ in a Massive Operation

Email addresses of 632,000 **Pentagon and DOJ employees** have been compromised by [malicious actors’ group](https://thehackernews.com/2023/09/iranian-apt-group-oilrig-using-new.html) suspected to be Russian.

[![cybercrime](https://media.mailhop.org/duocircle/images/2023/11/buy-smtp-2.jpg)](https://media.mailhop.org/duocircle/images/2023/11/buy-smtp-2.jpg)

The [attack](https://www.forbes.com/sites/tylerroush/2023/10/30/russian-hackers-breached-632000-doj-and-pentagon-email-addresses-in-massive-moveit-cyberattack-report-says/?sh=18fad8d73cd8), whose information has come to light, had occurred initially on May 28 and May 29 of this year. The incident used flaws in the file transfer program called **MOVEit** used by these organizations in their systems. A Russian-speaking group has been reckoned the culprit as similar MOVEit incidents have been perpetrated by a Russian [ransomware attack group](https://cybersecuritynews.com/ghostlocker-ransomware-as-a-service/) called CLoP earlier.

Around a **dozen US agencies** have contracts with MOVEit. The employees compromised belonged to [government agencies](https://thehackernews.com/2023/03/multiple-hacker-groups-exploit-3-year.html) and private organizations, including Shell, British Airways, the BBC, the University of Georgia, Johns Hopkins University, and the Energy Department. As per the Associated Press, the number of victims of CLoP runs into hundreds.

Though Bloomberg considered the [email hacking](https://www.bleepingcomputer.com/news/security/hackers-email-stolen-student-data-to-parents-of-nevada-school-district/) incident a major one, the data compromised was considered by the agency to be of **low sensitivity** and not classified.

## Advanced Security Measures by Microsoft Following Chinese Breach of US Officials

In an effort to counteract cyber threats like the **Chinese breach** that transpired earlier this year, Microsoft has [devised](https://thehill.com/policy/technology/4290814-microsoft-announces-new-security-efforts-following-breach-of-us-officials-emails/) a robust security plan. This multi-step strategy incorporates measures like [phishing protection](/email/phishing-protection) to defend against a wide array of attack methodologies.

This initiative has mainly considered the protection of consumer **signing keys**, which opened doors for exploitation earlier this year. The incident involved [breaching a consumer signing key](https://thehackernews.com/2023/05/msi-data-breach-private-code-signing.html) by a Chinese threat actor group called Storm-0558 to compromise the email accounts of 25 organizations in the cloud.

_The malicious actors obtained the consumer signing key from a **snapshot** generated by the system related to a sign-in crash._ They then used the key to forge authentication tokens to hack email accounts. The [email accounts targeted](/email-security/microsoft-email-attacks-an-inside-look-at-the-outlook-breach/) in the incident mostly belonged to employees from the State and Commerce departments.

The new Microsoft email security framework is called the ‘**Secure Future Initiative**.’ It uses the power of AI to expand default security controls embedded in [Microsoft products](/email-security/microsoft-server-exchange-vulnerabilities-are-among-the-most-exploited-reports-cisa/), detect and counter cyber threats, and speed up efforts to mitigate [cloud vulnerabilities](https://www.infosecurity-magazine.com/news/cloud-blame-almost-all-security/).

## WiHD Misconfiguration Exposes Sensitive Information of 97,327 Users

An **inadvertent error** of WiHD (World in HD), a French private torrent tracking service for HD video content, has caused an instance wherein critical account details of 97,327 users [remained exposed for anyone](https://thehackernews.com/2023/06/critical-security-flaw-in-social-login.html) to access without a password.

WiHD is a private torrent tracking community offering HD movies, TV series, and animation films in French and English. Cybernews noticed an [open Elasticsearch cluster](https://cybernews.com/security/wihd-data-leak-exposes-torrent-users/) in WiHD with **no password protection**. It exposed sensitive data of users and administrators, such as emails, usernames, IP addresses, and hashed passwords.

[![password protection](https://media.mailhop.org/duocircle/images/2023/11/SMTP-providers-1138.jpg)](https://media.mailhop.org/duocircle/images/2023/11/SMTP-providers-1138.jpg)

_Elasticsearch is a digital tool popularly used for managing large amounts of data._ This torrent data breach instance was probably **caused by misconfiguration**. Access to such data by malicious actors could lead to their pinpointing user location, tracking users’ behavior and downloading patterns, and launching [phishing attacks](https://www.scmagazine.com/brief/israel-subjected-to-new-muddywater-spear-phishing-attacks).

Though WiHD secured the exposed instance soon, one can **never be sure** how many malicious parties might have obtained the exposed [sensitive information](/email-security/9-best-practices-to-manage-sensitive-data-carefully/) before it was closed.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-44-of-2023%2F) [ ](https://twitter.com/intent/tweet?text=Apple%20Device%20Email%20Breach%2C%20Russian%20Email%20Breach%2C%20Microsoft%20Enhances%20Security%2C%20Cybersecurity%20News%20%5BOctober%2030%2C%202023%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-44-of-2023%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-44-of-2023%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Apple Device Email Breach, Russian Email Breach, Microsoft Enhances Security, Cybersecurity News [October 30, 2023]","description":"Here are the latest updates related to the email security landscape.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-44-of-2023/","datePublished":"2023-11-06T15:23:19.000Z","dateModified":"2025-05-14T15:45:32.000Z","dateCreated":"2023-11-06T15:23:19.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-44-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":734,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/11/buy-smtp-1.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Apple Device Email Breach, Russian Email Breach, Microsoft Enhances Security, Cybersecurity News [October 30, 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-44-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Apple Device Email Breach, Russian Email Breach, Microsoft Enhances Security, Cybersecurity News [October 30, 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-44-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Apple Device Email Breach, Russian Email Breach, Microsoft Enhances Security, Cybersecurity News [October 30, 2023]","description":"Here are the latest updates related to the email security landscape.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-44-of-2023/","datePublished":"2023-11-06T15:23:19.000Z","dateModified":"2025-05-14T15:45:32.000Z","dateCreated":"2023-11-06T15:23:19.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-44-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":734,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/11/buy-smtp-1.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
