---
title: "Cyber Security News Update, Week 48 of 2021 | DuoCircle"
description: "Threat actors continue to launch cyber attacks on organizations around the world. This week’s headlines cover some of these, among other cyber news."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-48-of-2021/"
---

Quick Answer

Week 48 of 2021 covered six items. Security awareness vendor SoSafe addressed concerns about its phishing simulation app after researchers raised questions about how user data was handled. Threat intelligence firm Team Cymru acquired attack surface management vendor Amplicy. New Zealand's National Cyber Security Centre warned that attacks against the country were increasing in volume and sophistication, with state-aligned actors targeting government and critical infrastructure. Netgear patched a high-severity authentication-bypass flaw affecting several SOHO routers, urging immediate firmware updates. New research highlighted cloud security gaps in K-12 school districts, including widespread misconfiguration of Microsoft 365 and Google Workspace tenants. Researchers reported the return of RedCurl, a corporate espionage group targeting law firms and consulting companies in Russia, the UK, Germany, and other countries with custom malware delivered via phishing.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-48-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2048%20of%202021&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-48-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-48-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-48-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2048%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2048%20of%202021&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-48-of-2021%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2021/11/spf-record-tester-7478.jpg) 

_Threat actors continue to launch cyber attacks on organizations around the world_. This week’s headlines cover some of these, among other [cyber news](/announcements).

## If You Have The SoSafe App, Then This Should Interest You

_Pakistan-based threat actors running the GravityRAT remote access trojan have recently developed a chat application called SoSafe chat_ which **spreads malware** under the disguise of a ‘safe messaging platform.’ Cybersecurity experts say that the malware is currently [targeting high-profile individuals from India](https://web.archive.org/web/20221129113738/https://cyware.com/news/updated-gravityrat-variant-is-targeting-indian-mobile-devices-14b6af65). Although the download link and registration for this malicious site remain un-operational, it is very much online.

Apparently, _the adversaries circulated malvertising campaigns via chats and social media posts on the SoSafe site_. The malware seeks **42 user permissions**, and the hackers were able to get 13 of these to perform actions like procuring users’ location, reading mobile data, etc. Reportedly, the earlier versions of GravityRAT targeted Windows machines, and the current version is targeting mobile devices. To ensure [ransomware protection](/email-security/5-ways-you-protect-your-business-from-ransomware/), users should refrain from downloading random apps, especially from third-party sources.

[![ransomware protection](https://media.mailhop.org/duocircle/images/2021/11/spf-record-7479.jpg)](https://media.mailhop.org/duocircle/images/2021/11/spf-record-7479.jpg)

## Threat Intelligence Firm Cymru Acquires Threat Surface Management Firm Amplicy

_Cymru is a threat hunting firm providing detailed intelligence on the different types of malware and threats circulating on the dark web_. Amplicy, on the other hand, is a threat surface management firm that provides a detailed analysis of a network’s **vulnerability to threat**. These two cybersecurity players have recently come together to work on their shared vision of [creating safe cyberspace](https://www.securityweek.com/threat-hunting-firm-team-cymru-acquires-attack-surface-management-firm-amplicy) for all. Cymru acquired Amplicy and hopes to better inform and _prepare its clients against possible threats and possible vulnerabilities that threat actors could exploit._

With two such essential **cybersecurity services** available on one platform, _users will be better able to identify and protect themselves against cyberattacks_. Team Cymru frequently expands its data lake of [security information](/content/email-security-services/email-security-in-information-security), and this acquisition is likely to play a significant role in amplifying Cymru’s work and position among [email security](/) vendors.

Amplicy comes with real-time Internet asset discovery. Cymru can use that to conduct real-time third-party infrastructure analysis, thereby empowering its clients and eliminating the threat from blind spots in their network. Overall, this acquisition aims to provide organizations with a broader view of the cyber risks they might encounter and prepares them to evade these risks.

## Cyberattacks Targeting New Zealand Are Increasing: NCSC

The National Cyber Security Centre (NCSC), _New Zealand, recently revealed in its annual report that there had been a 15% increase in the number of cyberattacks against the country’s national organizations_. While **352 attacks** were recorded the previous year, the period from 1st July 2020 to 30th June 2021 saw **over 400 attack** attempts. What’s more alarming is that the proportion of hackers making it to the post-compromise stage where they can access and move through networks has doubled from 15% to 33%.

NCSC mentions that [exploiting vulnerabilities](https://portswigger.net/daily-swig/number-of-cyber-attacks-infiltrating-critical-new-zealand-networks-soars) in public-facing applications and identification via automated scanning were the most frequently seen attack techniques. One of the reasons for the increase in cyberattacks, pointed out by NCSC, is that _the adversaries were too quick to exploit software flaws_. No matter how skilled the cyber risk management team was, the attackers managed to **exploit a zero-day** within a day of its public disclosure. The NCSC further notes that _phishing is no longer the most commonly used attack mode_. More and more organizations are getting their employees **trained in cybersecurity** and identifying and handling [phishing emails](/phishing-protection/how-to-stop-phishing-emails-and-protect-your-organization-from-cyber-criminals/). NCSC also mentions that financially motivated cyberattacks outnumber state-sponsored ones.

## High Severity Flaw Detected in Netgear’s SOHO Devices

_Several small office/home office (SOHO) devices of Netgear were vulnerable to a code execution flaw until recently_. Netgear has recently released a patch for the [high severity vulnerability](https://securityaffairs.co/wordpress/124716/security/netgear-cve-2021-34991-soho-devices.html) dubbed CVE-2021-34991, which has a CVSS **score of 8.8**. The flaw was found in SOHO devices’ Universal Plug-and-Play (UPnP) _upnpd_ daemon functions and could be exploited on the local area network (LAN) for remote code execution. The UPnP function essentially helps in handling unauthenticated HTTP (un) subscribe requests from clients.

Cybersecurity researchers at GRIMM detected the vulnerability and mentioned what makes the exploitation of this **stack overflow critical**. A range of SOHO devices, including routers, modems, and WiFi range extenders, were affected by this vulnerability. For a detailed list of affected devices, users are advised to visit the Netgear website. _Netgear is currently working on strengthening its cybersecurity tools and has already released patches for the vulnerability in several devices_.

[![phishing emails](https://media.mailhop.org/duocircle/images/2021/11/buy-smtp-7480.jpg)](https://media.mailhop.org/duocircle/images/2021/11/buy-smtp-7480.jpg)

## New Research Reveals Interesting Facts About Cloud Security in K-12 School Districts

A new study by EdWeek Research Center reveals that _American K-12 school districts are vulnerable to cloud-based data breaches_. Cyber-attacks are targeting [data in cloud applications](https://www.infosecurity-magazine.com/news/k12-school-districts-failing-at/), according to new research. An online survey was administered to **around 214 district-level administrators** between 14th July to 15th September to know about their cybersecurity strategies. The precise division of survey takers shows participation from 52 district superintendents, 54 technology officers, and 30 curriculum and instruction directors.

While 30% of K-12 school districts did not have access to **cloud security platforms**, _50% were either unaware of the implementation of cloud security platforms in the district or didn’t have one_.

Around 31% of the respondents were clueless about the consistency and efficiency of their [cloud security measures](/resources/trend-micro-alternatives). This lack of awareness of the district’s cybersecurity measures was accompanied by an interest in implementing cloud-based learning management systems (LMS) in **around 86%** of the respondents. When asked about their cybersecurity sanctions, district administrators revealed that they have a budget of approximately **$20,000 annually** and 20% of that is to be directed towards protecting cloud applications from 2022\. To ensure these systems meet specific institutional needs, many are turning to [custom lms development services](https://anyforsoft.com/e-learning/lms-development/) for tailored, secure solutions.

## RedCurl is Back With Attacks

_The RedCurl hacker group, which was exposed in August last year, is back with its notorious schemes_. The hacker group is now [conducting new intrusions](https://therecord.media/redcurl-hacking-group-returns-with-new-attacks/) with over four companies as its victims this year. Cybersecurity firm Group-IB found that two Russian companies along with two other unidentified companies were targeted by RedCurl this year. If we look at this attack history, the evil group has completed **over 30 attacks** since 2018 with victims across nations like the UK, Canada, Russia, Germany, Ukraine, and Norway.

Group-IB investigations reveal that RedCurl members consist of Russians engaged in commercial and employee **data theft** from world companies and corporate espionage. Interestingly, the hacker group has not altered its intrusion tactics, which means that one may be able to predict their moves and **ensure ransomware protection**.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-48-of-2021%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2048%20of%202021&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-48-of-2021%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-48-of-2021%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 48 of 2021","description":"Threat actors continue to launch cyber attacks on organizations around the world. This week’s headlines cover some of these, among other cyber news.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-48-of-2021/","datePublished":"2021-11-24T18:26:40.000Z","dateModified":"2025-05-14T13:38:26.000Z","dateCreated":"2021-11-24T18:26:40.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-48-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1078,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/11/spf-record-tester-7478.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 48 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-48-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 48 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-48-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 48 of 2021","description":"Threat actors continue to launch cyber attacks on organizations around the world. This week’s headlines cover some of these, among other cyber news.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-48-of-2021/","datePublished":"2021-11-24T18:26:40.000Z","dateModified":"2025-05-14T13:38:26.000Z","dateCreated":"2021-11-24T18:26:40.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-48-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1078,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/11/spf-record-tester-7478.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
