---
title: "Cyber Security News Update, Week 46 of 2020 | DuoCircle"
description: "The cyber domain is live with news of data breaches, security patches, zero day vulnerabilities."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-46-of-2020/"
---

Quick Answer

Week 46 of 2020 covered six items. Researchers warned that Google Drive sharing notifications were being abused by phishers to deliver malicious links from a trusted Google domain, bypassing many email filters. Reports highlighted operational security risks during Zoom calls including visible documents, exposed personal items, and accidentally muted-on cameras. Swedish insurer Folksam disclosed that data on roughly one million customers had been shared with Facebook, Google, LinkedIn, Microsoft, and Adobe through analytics tracking, prompting an investigation. Iranian threat actors were observed targeting US voter registration data ahead of certification of the 2020 election. Chesapeake Regional Healthcare in Virginia disclosed a phishing-driven email account compromise exposing patient information. UK and US guidance reiterated that home networks remain a soft target for credential theft and lateral movement into corporate VPNs.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-46-of-2020%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2046%20of%202020&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-46-of-2020%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-46-of-2020%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-46-of-2020%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2046%20of%202020 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2046%20of%202020&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-46-of-2020%2F "Share via Email") 

![Cyber Security](https://media.mailhop.org/duocircle/images/2020/11/SMTP-email-server-6123.jpg) 

The cyber domain is live with news of data breaches, security patches, zero day vulnerabilities, among other cyber attacks but ensuring cybersecurity comes with the strenuous task of investing in [phishing prevention](/email/phishing-protection) measures. Despite this, _we can always check on the latest cybersecurity trends and stay prepared for such an incident at a personal level_. Here is the list of the latest updates from the cyber world from this past week.

## Google Drive Links May Not Be Safe After All

While Google tries to warn users of **spam emails**, the adversaries still manage to defy such [email security services](/). This time around, they use Google’s no-reply email address to send emails to users in Russian or inaccurate English. _The hackers are inviting users to collaborate on a Google doc that’s infected with malware_. Quite a believable way to approach somebody, isn’t it?

Well, here’s one scam we can now be wary of, Emails with catchy subjects, including Chrome Search contest 2020, personal notifications, or prize scams, need to be watched out for. These might be the ones downloading Trojan or spying on users secretly!

[![Trojan or spying ](https://media.mailhop.org/duocircle/images/2020/11/SMTP-email-server-7970.jpg)](https://media.mailhop.org/duocircle/images/2020/11/SMTP-email-server-7970.jpg)

## Watch Out Your Actions And Clothing While On Zoom Calls

In another lockdown induced Zoom attack, the attackers exploited a [zero-day vulnerability](/phishing-protection/stop-making-hackers-job-too-easy/) in the app to record the actions of users while on a Zoom video call. The episode became known after a video of renowned journalist Jeffrey Toobin masturbating while he was on a Zoom video call with the New Yorker and WNYC radio members went viral.

The latest Zoom [sextortion scam](/phishing-protection/theres-nothing-sexy-about-sextortion/) proves once again the importance of **phishing protection** while working online. The scammers are mainly targeting US-based users and sending them emails with subjects like “Regarding Zoom Conference call.” They are demanding a [ransom of $2000](https://www.infosecurity-magazine.com/news/cybercriminals-target-naked-zoom/?&web%5Fview=true) in bitcoin, _failing to pay, which would mean a publicly available clip of the victim in some compromising act_.

The scammers played the Covid card and said that it’s only because they lost their job due to the pandemic that they are exploiting the victim and threatening them. The attack serves as a lesson to all people whose job revolves around video conferencing to guard and _protect themselves from phishing_.

## Data Stored With Folksam Leaked

In the latest breach, the Swedish insurance provider, Folksam, _failed to protect their clients from phishing attacks by accidentally leaking the [private data](https://www.reuters.com/article/us-dataprotection-folksam-leak/folksam-leak-shares-data-of-1-million-swedes-with-tech-giants-idUSKBN27J1VA?&web%5Fview=true) of over a million of its customers_. Sensitive information such as the social security numbers, banking information, pregnancy insurance data, etc. of users was unintentionally shared with tech giants like Facebook, Google, Microsoft, and LinkedIn.

_The company has claimed that the data hasn’t been exploited by third parties so far_. They are working with Sweden’s data [watchdog](https://www.phishprotection.com/watchdog/) and keen on not letting such a **security breach** happen again.

## U.S. Voters’ Data Targeted By Iranian Hackers

As is customary, _several cybersecurity incidents are emerging with the U.S. elections in action_. The CISA and the FBI have collectively released an advisory for voters asking them to stay vigilant of Iranian hackers spoofing Proud Boys’ email. These state-sponsored [Iranian APT groups](https://web.archive.org/web/20230327140053/https://cyware.com/news/iranian-hackers-using-spoofed-emails-to-steal-election-data-81036fd7) are stealing voter registration data from several election sites in the U.S. by _exploiting vulnerabilities such as web shell uploads, directory traversal, SQL injection, etc_.

To further enhance their shield against [anti-phishing protection](/email/phishing-protection) measures, the adversaries used paid VPN services like HQSERV, NordVPN, CDN77, and M247\. FBI reports state that these hacker groups could extract voter registration data from September 29 to October 17\. Voters are advised to update and patch applications, audit networks regularly and disable unused services and ports.

## Data Breach At Chesapeake Regional Healthcare

_Third-party service vendor Blackbaud discovered and stopped a **ransomware attack**_ affecting around [23000 patients](https://www.wtkr.com/news/chesapeake-regional-healthcare-alerts-over-23k-patients-after-data-security-incident?&web%5Fview=true), employees, and donors of Chesapeake Regional Healthcare. Although professor Gregg Tennefoss from Tidewater Community College says that such cybersecurity incidents are a way of life in 2020, for victims, nothing justifies the breach of their personal information such as name, email address, mail address, demographics, and relationship history with the organization.

Blackbaud claims that the damage is minimal, considering the fact that no social security numbers, bank account or credit card information, or other personal identification information were compromised in the breach. Affected persons have been notified, but further details aren’t disclosed, _keeping in mind the anti-phishing norms_.

[![Data Breach](https://media.mailhop.org/duocircle/images/2020/11/SMTP-email-server-2408.jpg)](https://media.mailhop.org/duocircle/images/2020/11/SMTP-email-server-2408.jpg)

## Is Working From Home Safe?

A report by Cyberchology suggests that [80 percent](https://www.infosecurity-magazine.com/news/stress-factor-pandemic-cybercrime/?&web%5Fview=true) of _businesses are experiencing **increased cybersecurity risk** triggered by human factors in the 2020 pandemic_. The report further revealed that 75 percent of companies operate with staff hitherto, not in charge of many responsibilities. _Over two-thirds of the surveyed consumers were clueless about cybersecurity norms_. The research suggests that enterprises must adopt [anti-phishing solutions](/email/phishing-protection) based on individual profiles by identifying the personality types most vulnerable to cyberattacks.

Cybersecurity specialist Jake Moore highlights the absence of a more centralized security system, which in turn, echoes _the security shortcomings of the work-from-home setup_. John Hackston from the Myers-Briggs Company hints towards creating a more collective security approach where I.T. and H.R. work together to identify the employees best suited for specific security roles, now that is some perspective for all security experts!

And that’s the week that was.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-46-of-2020%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2046%20of%202020&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-46-of-2020%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-46-of-2020%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Spam](https://media.mailhop.org/duocircle/images/2016/05/spf-permerror-3256.jpg)  April Spam Filtering Uptime Report News ](/blog/announcements/april-spam-filtering-uptime-report/)
- [ ![Spam Filtering](https://media.mailhop.org/duocircle/images/2023/02/spf-record-tester-7226.jpg)  Changes to Spam Filtering Technology News ](/blog/announcements/changes-to-spam-filtering-technology/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2020/01/spf-permerror-7312.jpg)  Cyber Security News Update, Week 1 of 2020 News ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 1m  April Spam Filtering Uptime Report  May 4, 2016 ](/blog/announcements/april-spam-filtering-uptime-report/)[  News 2m  Changes to Spam Filtering Technology  Feb 8, 2023 ](/blog/announcements/changes-to-spam-filtering-technology/)[  News 4m  Cyber Security News Update, Week 1 of 2020  Jan 3, 2020 ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 46 of 2020","description":"The cyber domain is live with news of data breaches, security patches, zero day vulnerabilities.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-46-of-2020/","datePublished":"2020-11-13T19:34:12.000Z","dateModified":"2025-05-14T15:38:23.000Z","dateCreated":"2020-11-13T19:34:12.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-46-of-2020/"},"articleSection":"announcements","keywords":"","wordCount":859,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2020/11/SMTP-email-server-6123.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 46 of 2020","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-46-of-2020/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 46 of 2020","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-46-of-2020/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 46 of 2020","description":"The cyber domain is live with news of data breaches, security patches, zero day vulnerabilities.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-46-of-2020/","datePublished":"2020-11-13T19:34:12.000Z","dateModified":"2025-05-14T15:38:23.000Z","dateCreated":"2020-11-13T19:34:12.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-46-of-2020/"},"articleSection":"announcements","keywords":"","wordCount":859,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2020/11/SMTP-email-server-6123.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
