---
title: "Cyber Security News Update, Week 49 of 2021 | DuoCircle"
description: "Cyber adversaries’ ways of intruding into private networks only seem to be evolving."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-49-of-2021/"
---

Quick Answer

Week 49 of 2021 covered six items. Researchers warned that exposed cloud storage buckets and databases were now routine, with new scanning tooling cataloging tens of thousands of misconfigured S3 and Azure Blob assets every week. Ukrainian police arrested five members of the Phoenix gang, accused of using Specter spyware to compromise more than 100 phones a year for blackmail and extortion. Reports highlighted that internet-connected printers remain a frequently overlooked entry point for attackers because they ship with default credentials and rarely receive firmware updates. The FBI warned of an expected uptick in ransomware and BEC attacks during the holiday season when staffing is thin. The PerSwaysion phishing kit was tied to a sustained surge in Microsoft 365 credential theft using OneDrive-hosted lures. GoDaddy disclosed that its Managed WordPress breach affected additional resellers including tsoHost, Media Temple, and 123Reg.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-49-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2049%20of%202021&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-49-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-49-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-49-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2049%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2049%20of%202021&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-49-of-2021%2F "Share via Email") 

![cybersecurity news](https://media.mailhop.org/duocircle/images/2021/12/dkim-validation.jpg) 

Cyber adversaries’ ways of intruding into private networks only seem to be evolving. _The best way to stay ahead of them is to invest time and resources in acquiring the right cybersecurity tools_. Here are this week’s top [cyber news headlines](/announcements) to help the pursuit of creating safe cyberspace for all.

## Misconfigured Cloud Servers No Longer a Rarity

Cybersecurity experts at Palo Alto Networks’ Unit 42 recently _highlighted the widely known and ignored fact that cloud misconfigurations at the organization level have increased significantly_. As a result of [poorly configured cloud services](https://web.archive.org/web/20221207235244/https://cyware.com/news/common-cloud-misconfigurations-can-be-exploited-in-minutes-report-7396541a), more and more user data is getting compromised. Palo Alto Network conducted a detailed study on the frequency and origin of these attacks between July and August 2021\. _The study revealed that **80% of the networks** left vulnerable on purpose_ (honeypots) were compromised within just a day, and the period was seven days for the rest.

[![cloud security](https://media.mailhop.org/duocircle/images/2021/12/spf-record-check-8492.jpg)](https://media.mailhop.org/duocircle/images/2021/12/spf-record-check-8492.jpg)

The most attacked SSH honeypot was **targeted 169 times** on the same day. On average, each honeypot was compromised 26 times a day. Another shocking instance of attackers’ proactive spirit was that an adversary **compromised 96%** of the researchers’ honeypots within just half a minute! This experiment is a wake-up notification to all organizations leaving their **servers misconfigured**. While cloud services have increased the efficiency and accessibility of data, there is an increased risk of [data theft](/msp-email-security/critical-cybersecurity-steps-for-msps-to-secure-clients-confidential-data/) and targeted cyberattacks. As such, enterprises must take [cloud security](/cloud-email/why-your-organization-needs-cloud-email-security/) seriously and incorporate measures to check the accessibility of privileged ports.

## Ukrainian Investigators Arrest Five Members of the Phoenix Gang

_Ukrainian cybersecurity watchdogs recently arrested five members of the mobile hacking group Phoenix_. The attackers targeted users through Apple and Samsung **phishing sites**. Downloading an app from these sites gave adversaries remote access to the victim’s devices. The attackers could then withdraw funds and steal and sell users’ private files for **$200 per user** account.

Phoenix members also indulged in money-making by unlocking stolen and lost Apple devices and selling them through store chains in Kyiv and Kharkiv. _With **over 200 victims** and two years of operation_, [the arrested Phoenix members](https://www.infosecurity-magazine.com/news/ukrainian-cops-bust-mobile-device/) ran so-called telephone shops. The investigators searched their houses and these shops, which were underground technical centers in reality.

The search led the investigators to stolen devices and software, and hardware customized to hack accounts. A look into the attackers’ profiles revealed that they all graduated from higher technical colleges, which again hints at the _consequence of not having enough job opportunities for technology graduates in the Russian region_. These five Phoenix members now face charges under Article 361 of the criminal code for breaking **cybersecurity rules** and conducting illegal cyber activities.

## Did You Know That Printers Need to be Secured?

One might think that an external device plugged occasionally is not a threat to the organization’s security, but _recent research reveals that printers connected to the internet are vulnerable to DDoS attacks_. Cybersecurity experts warn that unprotected printers which are exposed on the internet are prone to a [series of attacks called ‘Printjack](https://web.archive.org/web/20221128010605/https://cyware.com/news/printjack-attacks-can-turn-printers-into-zombies-3c21988b).’ With such easy accessibility, the adversaries can launch remote execution and **DDoS attacks**.

Experts further highlight the incompatibility of many printers (used in professional setups) with the cybersecurity norms of IoT devices. Such printers are more vulnerable to the external threat, and this can be seen in excess power consumption and heat generation, sudden unresponsiveness and poor performance of devices, etc.

While the general notion is such that we overlook the prospect of securing our endpoint systems, we must remember that these are indeed systems that can open backdoors for criminals and cause much disruption to the functioning of an enterprise.

## FBI Warns of Cyber Attacks Ahead of Holiday Season

As the [holiday season](/email-hosting/how-organizations-can-defend-themselves-against-bec-scams-during-the-holiday-season/) approaches, _the Federal Bureau of Investigation (FBI) issues its much-needed notice warning netizens of cyber frauds coming ahead of the holiday season_. Online shoppers tend to be very active online during this time of the year when prices of goods are unreasonably lower. However, many malicious actors thrive on this innocent impulse of people to gain from holiday offers and sales. The FBI estimates that **over $53 million** will be lost to [holiday-related scams](https://securityaffairs.co/wordpress/124972/cyber-crime/fbi-warns-online-shoppers-holiday-season.html) this year.

_Over **17,000 fraud sale cases** were reported with the FBI Internet Crime Complaint Center (IC3) last year_, and this year too, the numbers are expected to be equally high, if not greater. Among the many lures that adversaries use, the feds expect strategies like **fraudulent emails** and advertisements giving out misinformation, fake shopping websites, misleading social media posts, etc. All of these tactics are designed to steal victims’ personally identifiable information (PII) and financial details.

Thus, the FBI released a list of [cybersecurity best practices](/content/protection-from-phishing) for shoppers this holiday season, including a range of tips from being skeptical of random offers and site links to changing passwords and avoiding public WiFis.

## PerSwaysion and the Increase in Phishing Campaigns

_Cybersecurity experts at Group-IB had identified a phishing campaign called PerSwaysion in January 2020_, which [has been operational](https://web.archive.org/web/20220706130336/https://cyware.com/news/perswaysion-phishing-kit-from-the-past-continues-to-hit-targets-actively-37eb93b3) at least since 2017\. With its active presence across the UK, Germany, Hong Kong, and Germany, the campaign has targeted over 156 high-ranking officials so far.

Recent research by URLscan revealed that _PerSwaysion now has a global presence with **over 444 phishing attempts** targeting 14 industrial sectors and 7400+ people_. Victims of PerSwaysion include US government organizations and departments, among others. The increased use of the malicious campaign is attributed to its easy implementation across Microsoft services like Sway, OneNote, SharePoint, etc.

[![ransomware protection](https://media.mailhop.org/duocircle/images/2021/12/sender-policy-framework-5793.jpg)](https://media.mailhop.org/duocircle/images/2021/12/sender-policy-framework-5793.jpg)

Over time several important revelations have been made about the **phishing campaign**. Some of these include spoofed templates of popular brands, use of JavaScript to pack malicious codes, use of a malicious setup to evade analysis by Chrome’s Developer Tools, and use of URL shorteners to avoid detection by [email filters](/content/email-filtering-service/email-filtering-security) etc. These recent findings signify that [ransomware protection](/email-security/5-ways-you-protect-your-business-from-ransomware/) measures need to be upgraded to handle the increasing PerSwaysion-based attacks.

## More Victims in GoDaddy Breach

_The recent [GoDaddy breach](https://www.phishprotection.com/blog/learn-from-latest-godaddy-phishing-attack/), which had initially affected an estimated 1.2 million people_, has affected the customers of [several other brands](https://threatpost.com/godaddy-breach-widens-reseller-subsidiaries/176575/) that resell its Managed WordPress. These subsidiaries of GoDaddy include Domain Factory, 123Reg, Host Europe, Heart Internet, tsoHost, and Media Temple. GoDaddy confirmed that a few active and inactive Managed WordPress users across these brands had been affected by the breach, but no other brands were impacted. _The concerned brands have already approached their affected customers with breach notifications and recommendations as part of their **cybersecurity measures**_.

The user details stolen in the incident include the email IDs, usernames, passwords, and customer numbers of **over 1.2 million** Managed WordPress users. GoDaddy is now issuing new certificates for the victims and doing everything in its capacity to limit the effects of the attack.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-49-of-2021%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2049%20of%202021&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-49-of-2021%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-49-of-2021%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 49 of 2021","description":"Cyber adversaries’ ways of intruding into private networks only seem to be evolving.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-49-of-2021/","datePublished":"2021-12-02T18:20:55.000Z","dateModified":"2025-05-27T12:08:19.000Z","dateCreated":"2021-12-02T18:20:55.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-49-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1116,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/12/dkim-validation.jpg","caption":"cybersecurity news","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 49 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-49-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 49 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-49-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 49 of 2021","description":"Cyber adversaries’ ways of intruding into private networks only seem to be evolving.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-49-of-2021/","datePublished":"2021-12-02T18:20:55.000Z","dateModified":"2025-05-27T12:08:19.000Z","dateCreated":"2021-12-02T18:20:55.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-49-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1116,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/12/dkim-validation.jpg","caption":"cybersecurity news","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
