---
title: "Cyber Security News Update, Week 46 of 2021 | DuoCircle"
description: "While cyber adversaries aspire to rob netizens of their credentials and monetary assets, much progress is also occurring in the cybersecurity realm."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-46-of-2021/"
---

Quick Answer

Week 46 of 2021 covered six items. Cybersecurity training institutes saw rapid growth as employers worldwide sought to fill an estimated multi-million-person workforce gap. Iran accused the US and Israel of orchestrating a cyberattack that disrupted state-subsidized fuel distribution by knocking out card readers at gas stations nationwide. Europol announced the arrest of 12 individuals tied to ransomware operations including LockerGoga, MegaCortex, and Dharma that hit roughly 1,800 victims across 71 countries. A Sydney man was sentenced for stealing and reselling thousands of customer credentials harvested through credential-stuffing attacks. Microsoft committed to investing $20 million over four years in cybersecurity training at US community colleges to expand the talent pipeline. Google's November Android update fixed 39 vulnerabilities including critical remote code execution issues in the System and Media Framework components.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-46-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2046%20of%202021&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-46-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-46-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-46-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2046%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2046%20of%202021&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-46-of-2021%2F "Share via Email") 

![DuoCircle blog post image](https://media.mailhop.org/duocircle/images/2021/11/SMTP-server-mail-6943.jpg) 

While cyber adversaries aspire to rob netizens of their credentials and monetary assets, much progress is also occurring in the cybersecurity realm. This [week’s headlines](/announcements) highlight some significant **cybersecurity measures** that organizations are adopting to tackle the menace of cyber attacks.

## Are Cyber Security Institutes the Next Big Revolution?

_Marshall University has recently launched its Cyber Security Institute_. The university envisions creating an academic and research-based institute that facilitates [cybersecurity-related programs](https://www.securityweek.com/marshall-university-launches-new-cybersecurity-institute). Jerome Gilbert, the Marshall President, says that having a space to _teach and research cybersecurity will help them expand and strengthen their position in the cyber arena_.

This new cybersecurity institute will reportedly address the emerging [email security](/) needs and create cyber-conscious citizens. Housed at Marshall University’s Applied Engineering Complex, _the new department will help students take up cybersecurity as a career option_ by bringing them in contact with the top cybersecurity experts in the region.

## Iran Suspects US and Israel of Targeting its Fuel Stations

_It has been over a decade since Iran’s nuclear program was targeted by a computer virus_, and since then, Iran has not shared very good cyber relations with the United States and Israel. Once again, its _fuel distribution at 3,200 service stations has been disrupted by a cyberattack_, and [Iran believes](https://www.securityweek.com/iran-suspects-israel-and-us-behind-fuel-cyber-attack) it to be a work of its arch-foes Israel and the United States. An Iranian General claims that this recent attack looks very similar to previous attacks (the Shahid Rajaei port and the railway accident) on the nation’s systems launched by its enemies Israel and the United States. While the Shahid Rajaei port attack took place in May 2020, _the computer systems of Iran railways were hacked in July 2021_.

The recent attack at service stations disrupted the distribution of petrol and caused traffic jams on major Tehran routes. As part of its **cybersecurity measures**, the oil ministry had to bring the service stations offline and distribute petrol manually. The Iran government accuses the adversaries of trying to turn Iranians against the government by disrupting its services. As many as 3,200 of the 4,300 service stations had a service failure because of this breach.

[![Cybercriminals](https://media.mailhop.org/duocircle/images/2021/11/SMTP-server-mail-3294.jpg)](https://media.mailhop.org/duocircle/images/2021/11/SMTP-server-mail-3294.jpg)

## Europol Arrests Twelve Cybercriminals

_Europol recently arrested 12 individuals associated with cybercrime activities_. Reportedly, these adversaries have targeted **over 1,800 individuals** in 71 countries so far. Europol has confiscated **over $52,000 in cash** and five luxury cars from [the 12 accused](https://gizmodo.com/europol-captures-12-suspects-believed-to-have-used-rans-1847971832). Currently, their devices are undergoing forensic analysis. Europol revealed that this arrest comes after a two-year investigation involving threat actors from various cybercriminal groups across the world.

Although the law agency has not revealed much about the nature of attacks led by these arrested cyberattackers, it is known that they usually target large businesses. The accused can be called high-value targets as they are on the radar of law enforcement across jurisdictions.

## Sydney-based Man Penalised for Credentials Theft

_A Sydney-based individual was recently penalized by the Australian Federal Police (AFP) for stealing the log-in credentials of streaming service customers_. The culprit is to pay an **AUD 1.66 million penalty** for stealing the usernames and passwords of customers’ Netflix, Hulu, and Spotify accounts. Reportedly, the Sydney-based culprit teamed up with another individual to give shape to [this credential theft](https://www.zdnet.com/article/afp-confiscates-au1-7m-from-sydney-man-who-stole-netflix-spotify-hulu-accounts/). They later sold the stolen details at a cheaper rate online.

The FBI had notified the AFP (back in 2028) of a now-defunct website selling stolen account credentials called _wickedgen.com_. This website was also selling the details of Australian and global Netflix, Hulu, and Spotify users. The Sydney culprit was the primary beneficiary of this and three other credential selling websites. This threat actor had **over 150,000 registered users** who came to him to access these streaming services illegally.

In October last year, this Sydney-based individual pleaded guilty to stealing log-in credentials. The AFP’s Criminal Assets Confiscation Taskforce (CACT) got restraining orders over his fake PayPal, cryptocurrency, and bank accounts. _AUD 1.2 million of the AUD 1.66 million collected from him was procured in cryptocurrency_. The AFP said that the Department of Home Affairs plans to redistribute these funds to support law enforcement, crime prevention, and community-safety-related cybersecurity initiatives. _The culprit and his ally are likely to face a twenty-six months prison sentence_.

## Microsoft to Invest in Training Community College Students in Cybersecurity

_Microsoft Corp (MSFT.O) has recently announced that it plans to invest in community colleges throughout the United States_ and **fill 250,000** hitherto cybersecurity jobs. This massive goal of educating, training, and hiring cybersecurity professionals shall be implemented over the next four years.

Microsoft will extend its [financial aid to students](https://www.reuters.com/technology/microsoft-work-with-community-colleges-fill-250000-cyber-jobs-2021-10-28/), provide teacher training and free materials at **over 150 community colleges** across the US. Microsoft’s president Brad Smith _revealed that the company plans to invest tens of millions of dollars in this new initiative_. This move comes after some severe cyberattacks (including the SolarWinds attack) have targeted the US. In August this year, Joe Biden had met Microsoft and other renowned tech companies to discuss the **nation’s security** position. Microsoft perceives this new move as the much-needed solution to the massive number of cyberattacks targeting its customers. It believes that these _attacks can be mitigated or prevented with a bit of expertise in cybersecurity_. These cybersecurity jobs pay well (over $105,000), and a lot of these job positions remain unfilled. _Microsoft hopes to make a significant difference in the number of unfilled cybersecurity job positions by training students_.

[![Cybersecurity](https://media.mailhop.org/duocircle/images/2021/11/SMTP-server-mail-6123.jpg)](https://media.mailhop.org/duocircle/images/2021/11/SMTP-server-mail-6123.jpg)

## Google Fixes Several Critical Flaws in its November Update

_Google’s monthly security update for Android is out, and it fixes 39 flaws this month_. Six [zero-day vulnerabilities](https://www.phishprotection.com/content/zero-day-attacks/) have been patched, which include the use-after-free vulnerability (dubbed as CVE-2021-1048). Adversaries could conduct a local privilege escalation attack and execute arbitrary codes to access victim systems if they were to exploit these vulnerabilities. Cybersecurity experts believe this bug is already being exploited and warn users of the same in Google’s November advisory.

In addition, two other critical remote code execution (RCE) vulnerabilities, CVE-2021-0918 and CVE-2021-0930 have been patched. This is along [with the patches](https://thehackernews.com/2021/11/google-warns-of-new-android-0-day.html) for two critical flaws in Qualcomm closed-source components ,

CVE-2021-1924 and CVE-2021-1975\. On the whole, the November security update fixes some severe issues in Android Systems. These also include a critical flaw in Android TV (dubbed as CVE-2021-0889) that lets adversaries execute arbitrary code on users’ TV without any user interaction. Users are advised to get the November patch at the earliest.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-46-of-2021%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2046%20of%202021&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-46-of-2021%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-46-of-2021%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 46 of 2021","description":"While cyber adversaries aspire to rob netizens of their credentials and monetary assets, much progress is also occurring in the cybersecurity realm.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-46-of-2021/","datePublished":"2021-11-14T01:05:56.000Z","dateModified":"2025-05-14T15:07:39.000Z","dateCreated":"2021-11-14T01:05:56.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-46-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1057,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/11/SMTP-server-mail-6943.jpg","caption":"DuoCircle blog post image","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 46 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-46-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 46 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-46-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 46 of 2021","description":"While cyber adversaries aspire to rob netizens of their credentials and monetary assets, much progress is also occurring in the cybersecurity realm.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-46-of-2021/","datePublished":"2021-11-14T01:05:56.000Z","dateModified":"2025-05-14T15:07:39.000Z","dateCreated":"2021-11-14T01:05:56.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-46-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1057,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/11/SMTP-server-mail-6943.jpg","caption":"DuoCircle blog post image","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
