---
title: "Cybersecurity News Update, Week 48 of 2022 | DuoCircle"
description: "Ransomware attacks have been rising in recent years, with numerous high-profile incidents affecting individuals, organizations, and government agencies."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-48-of-2022/"
---

Quick Answer

Week 48 of 2022 covered six items. Microsoft patched CVE-2023-21674, a Windows zero-day that ransomware operators were chaining for SYSTEM privilege escalation. NSA and CISA issued joint guidance on threats to 5G network slicing and recommended stronger authentication and monitoring across slice boundaries. The US Department of Health warned hospitals about Royal ransomware, a fast-spreading variant linked to former Conti operators encrypting healthcare networks. Apple released emergency updates for an actively exploited iOS zero-day in WebKit (CVE-2022-42856). The Belgian city of Antwerp's IT services were knocked offline for weeks after a Play ransomware attack disrupted municipal operations. Google's Threat Analysis Group disclosed that North Korean attackers were exploiting an Internet Explorer zero-day delivered through malicious Office documents themed around the Itaewon disaster in South Korea.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-48-of-2022%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cybersecurity%20News%20Update%2C%20Week%2048%20of%202022&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-48-of-2022%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-48-of-2022%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-48-of-2022%2F&title=Cybersecurity%20News%20Update%2C%20Week%2048%20of%202022 "Share on Reddit") [ ](mailto:?subject=Cybersecurity%20News%20Update%2C%20Week%2048%20of%202022&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-48-of-2022%2F "Share via Email") 

![weekly update](https://media.mailhop.org/duocircle/images/2022/12/365-to-365-migration.jpg) 

[Ransomware attacks](/resources/ryuk-ransomware-attacks) have been rising in recent years, with numerous high-profile incidents affecting individuals, organizations, and government agencies. This Weekly Cybersecurity Bulletin discusses top cybersecurity news from around the world, sharing multiple ransomware and **zero day news** and the CSA’s security advisory on 5G Network slices.

## Ransomware Dropping Windows Zero-Day Patched by Microsoft

Microsoft patched a security flaw that threat actors could use to deliver [Magniber ransomware](https://www.bleepingcomputer.com/news/security/magniber-ransomware-now-infects-windows-users-via-javascript-files/) and Qbot malware by bypassing the security features of its **Windows SmartScreen**. Called the [CVE-2022-44698](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-44698), this zero day vulnerability allowed threat actors to utilize standalone JavaScript files and bypass Windows alerts, notifying users to be cautious of Internet-downloaded files. Microsoft said that the zero-day could be exploited in three ways:

- A web-based case where threat actors could host **malicious websites** to exploit the security feature bypass.
- Threat actors could also send crafted URLs (Uniform Resource Locators) using emails or instant messages to exploit this bypass.
- Via compromised websites accepting or hosting user-provided content containing capabilities to **exploit the zero day**.

[![zero-day vulnerability](https://media.mailhop.org/duocircle/images/2022/12/spf-record-generator-5793.jpg)](https://media.mailhop.org/duocircle/images/2022/12/spf-record-generator-5793.jpg)

The Magniber ransomware being delivered using this [zero-day vulnerability](/email-security/two-zero-day-vulnerabilities-discovered-in-microsoft-exchange-server-patches-pending/) was also discovered by HP’s threat intelligence team back in October when SmartCheck showed an error due to the flaw and allowed threat actors to **execute malicious files** without throwing any security alerts.

Microsoft released the security patch recently and fixed another publicly disclosed zero-day, the CVE-2022044710, a vulnerability that allowed threat actors to gain System level privileges on computer systems running Windows 11.

## NSA and CISA Report: Mitigating 5G Network Slicing Threats

The NSA (National Security Agency), CISA (Cybersecurity and Infrastructure Security Agency), and ODNI (Office of the Director of National Intelligence) released a new report highlighting the risks of **5G network slicing** and advice to stay protected.

5G network slicing is a configuration that allows **multiple virtual networks** to run on top of a common infrastructure. Each slice is an isolated end-to-end network per application. The [report](https://media.defense.gov/2022/Dec/13/2003132073/-1/-1/0/POTENTIAL%20THREATS%20TO%205G%20NETWORK%20SLICING%5F508C%5FFINAL.PDF) shares a framework for the development of **preventive and defensive** measures implemented by 5G network providers and operators.

The guidelines provided highlight the complexity of such networks and how there are **critical security gaps** that need to be addressed with the adoption of 5G networks. The report highlights the three most significant threat vectors for this are:

- [DoS (Denial of Service)](https://www.a10networks.com/blog/5-most-famous-ddos-attacks/) on centralized controls
- Misconfigured control system attacks
- MitM (Man in the Middle) attack on unencrypted channels

> The report mentions, “Improper network slice management may allow malicious actors to access data from different network slices or deny access to prioritized users” and promotes **zero-trust architectures** to protect and validate all users and endpoints. 

## US Health Department Warming: Healthcare under attack by Royal Ransomware

The HHS (US Department of Health and Human Services) is warning the country’s citizens and healthcare organizations about the surge in ransomware operations, with the [Royal ransomware gang](https://www.bleepingcomputer.com/news/security/royal-ransomware-claims-attack-on-intrado-telecom-provider/) being the primary attackers.

The HHS released a new [advisory](https://www.hhs.gov/sites/default/files/royal-ransomware-analyst-note.pdf) stating, “Due to the **historical nature** of ransomware victimizing the healthcare community, Royal should be considered a threat to the HPH sector.” The US healthcare sector has been suffering at the hands of the Royal gang’s threat actors since September. The Royal Ransomware gang started out using encryptors from BlackCat but later switched to their in-house **Zeon encryptor**.

[![phishing emails](https://media.mailhop.org/duocircle/images/2022/12/spf-permerror-4789.jpg)](https://media.mailhop.org/duocircle/images/2022/12/spf-permerror-4789.jpg)

The [threat actors](/data-privacy/threat-actors-target-1000-zimbra-servers-exploiting-an-rce-and-zero-day-vulnerability/) of the Royal ransomware gang make first contact via [phishing emails](/content/phishing-prevention/phishing-email), impersonating software providers or food delivery services, and utilizing **social engineering tactics** to trick corporate and healthcare employees into installing remote access software. After encrypting all systems and halting enterprise activities, the gang is known to demand a ransom between $250,000 and $2 million.

The HHS also warned about [Venus ransomware](https://www.bleepingcomputer.com/news/security/us-health-dept-warns-of-venus-ransomware-targeting-healthcare-orgs/) last month. With this new warning, it is clear that threat actors are continuously targeting the **US healthcare sector**. Individuals are advised to keep minimal healthcare, financial, and personal data on healthcare websites or portals.

## iOS Zero-Day for hacking iPhones, Apple Releases Fix

Apple released a new security update for its **10\*\*\*\*th** **zero day vulnerability of 2022**, a hack that was targeting iPhones worldwide.

The zero-day exploit tracked as the [CVE-2022-42856](https://support.apple.com/en-us/HT213531#:~:text=Google%20V8%20Security-,WebKit,-Available%20for%3A%20iPhone) was a type of confusion vulnerability in the **Webkit web browser engine** in Apple products. Using this, threat actors could maliciously craft web content and perform arbitrary code execution on victim devices, allowing them to execute operating system commands, deploy **malware and spyware**, or carry out other harmful intents. Apple addressed the zero day vulnerability with its new patch that contains improved state handling and is available for _iPhone, iPad, and iPod models._

_Apple disclosed the zero-day but did not share any details on cyberattacks resulting from said vulnerability_. As discovered by Clément Lecigne of Google’s Threat Intelligence Team, the details of the attacks and more about the zero day will arrive in the future since it is a common approach for organizations to keep such details closed until a majority of devices have **installed the security update**.

Apple also fixed a zero day, the [CVE-2022-42827](https://nvd.nist.gov/vuln/detail/CVE-2022-42827), a flaw in its iOS Kernel back in October. It would be best for Apple users to keep their devices up to date, so that any security updates are installed to protect them.

## Play Ransomware hits Belgium City of Antwerp

A ransomware attack recently hit the Belgium city of Antwerp, and the Play ransomware gang has claimed responsibility.

**Digipolis**, an IT enterprise that manages the city’s IT systems, suffered a ransomware attack. The attack aimed to disrupt all IT, email, and cell services in Antwerp, with local media reporting that the city’s applications went down due to the cyberattack. Furthermore, almost all services were **disrupted or delayed**, including library usage, new agreements, and job applications within the city.

On the other side, [Play ransomware](https://www.trendmicro.com/en%5Fus/research/22/i/play-ransomware-s-attack-playbook-unmasks-it-as-another-hive-aff.html) added Antwerp to its list of victims on its website, an entry that shows that nearly 557 GB of data was stolen during the ransomware attack that includes personal information, passports, financial documents, and IDs. The data has not been leaked yet, but the threat actors added the entry on 11 December, claiming that all data would be leaked in 7 days, i.e., 19December 2022, unless their ransom demand is paid.

Play ransomware is a new operation that was launched in June and became known after their most significant attack on **Argentina’s Judiciary of Córdoba**. What is going to become of the critical data remains to be known.

## Hackers Exploiting Internet Explorer Zero-Days, Says Google

The **TAG (Threat Analysis Group)** at Google has revealed that APT37, a North Korean group of hackers, is exploiting a zero-day vulnerability in Internet Explorer. The North Korean threat actors have leveraged this exploit to target **South Korean targets** with malware.

The threat actor group employs a [malicious Microsoft Office document](https://www.virustotal.com/gui/file/926a947ea2b59d3e9a5a6875b4de2bd071b15260370f4da5e2a60ece3517a32f/) that downloads an **RTF (Rich Text File)** remote template, which downloads the malicious payload by rendering HTML (Hyper Text Markup Language). _The downloaded content allows the threat actors to exploit the Internet Explorer zero day vulnerability even if the web browser is not their default._

Tracked as the CVE-2022-41128, the zero day is a weakness in Internet Explorer’s JavaScript engine that allows the threat actors to **execute arbitrary code** while rendering malicious websites or URLs.

Microsoft released a patch for the vulnerability, but Google could not analyze the malicious payload that the hackers distributed. [APT37](https://blog.google/threat-analysis-group/internet-explorer-0-day-exploited-by-north-korean-actor-apt37/) has been active for nearly a decade, abuses legitimate cloud services as **C2 (Command and Control)** channels, and has also been linked to the North Korean government.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-48-of-2022%2F) [ ](https://twitter.com/intent/tweet?text=Cybersecurity%20News%20Update%2C%20Week%2048%20of%202022&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-48-of-2022%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-48-of-2022%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cybersecurity News Update, Week 48 of 2022","description":"Ransomware attacks have been rising in recent years, with numerous high-profile incidents affecting individuals, organizations, and government agencies.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-48-of-2022/","datePublished":"2022-12-16T17:34:08.000Z","dateModified":"2025-05-27T13:04:46.000Z","dateCreated":"2022-12-16T17:34:08.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-48-of-2022/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1229,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/12/365-to-365-migration.jpg","caption":"weekly update","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cybersecurity News Update, Week 48 of 2022","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-48-of-2022/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cybersecurity News Update, Week 48 of 2022","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-48-of-2022/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cybersecurity News Update, Week 48 of 2022","description":"Ransomware attacks have been rising in recent years, with numerous high-profile incidents affecting individuals, organizations, and government agencies.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-48-of-2022/","datePublished":"2022-12-16T17:34:08.000Z","dateModified":"2025-05-27T13:04:46.000Z","dateCreated":"2022-12-16T17:34:08.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-48-of-2022/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1229,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/12/365-to-365-migration.jpg","caption":"weekly update","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
