---
title: "Cyber Security News Update, Week 51-2 of 2021 | DuoCircle"
description: "This week’s major cyber news headlines reflect the cybersecurity warnings being circulated ahead of the Christmas holidays and a host of other significant."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-51-2-of-2021/"
---

Quick Answer

Holiday-week 2021 cyber news: Imperva reports 4.7 million web app attacks since October 2019, with RFI/RCE up 271%; AscendEX (formerly Bitmax) pledges to reimburse 77.7M stolen across Ethereum, Binance Smart Chain, and Polygon hot wallets; UK NCSC warns of holiday shopping scams; Google partners with PayPal and HackerOne on Android app hacking workshops; Ukrainian police arrest a 51-member group selling 90,000 GB of personal data on 300 million people; PM Modis Twitter account hijacked for a Bitcoin scam tweet.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-51-2-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2051-2%20of%202021&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-51-2-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-51-2-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-51-2-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2051-2%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2051-2%20of%202021&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-51-2-of-2021%2F "Share via Email") 

![Cyber Security](https://media.mailhop.org/duocircle/images/2021/12/spf-record-checker-4367.jpg) 

This week’s major cyber news headlines reflect the cybersecurity warnings being circulated ahead of the [Christmas holidays](/email-hosting/how-organizations-can-defend-themselves-against-bec-scams-during-the-holiday-season/) and a host of other significant updates. Here are the most important of those [security updates](/announcements).

## Imperva Reports a Surge in Web Application Attacks

Renowned security vendor Imperva recently released a [cybersecurity](https://web.archive.org/web/20220523134921/https://cyware.com/news/web-app-attacks-rise-by-251-in-two-years-4347b774) analysis report highlighting that there have been **over 4.7 million** web application attacks since October 2019\. Imperva’s findings reveal that web-app attacks are **increasing by 22%** every quarter. _Data breaches in the UK have increased significantly because of the rising attacks on businesses_ (**increased by 250%** between October 2019 and the present day).

Imperva notes that the use of RFI and RCE attacks in hijacking websites and stealing information has **increased by 271%**. The greater attack surface is suspected to be because of the craze among businesses to upgrade their digital setup and shift to newer technologies like cloud computing.

[![ransomware protection](https://media.mailhop.org/duocircle/images/2021/12/spf-record-2456.jpg)](https://media.mailhop.org/duocircle/images/2021/12/spf-record-2456.jpg)

To ensure [ransomware protection](/email-security/5-ways-you-protect-your-business-from-ransomware/) in times when attacks on web applications are rapidly increasing, organizations must implement robust mitigation measures. They must adopt **web security solutions** that match their requirements and develop effective web application firewalls, bot management solutions, etc.

## AscendEX to Reimburse $77.7 Million to Customers After Breach

Singaporean Crypto platform AscendEX (formerly known as Bitmax) underwent a cyberattack on 11th December, and its customers **lost around $77.7 million** to this attack. Apart from beginning a quick investigation and service restoration drive, AscendEX has pledged to [reimburse the entire amount](https://www.zdnet.com/article/after-77-million-hack-crypto-platform-ascendex-to-reimburse-customers/) to all affected customers. This move comes because of the platform’s strong belief in staying true to its community and users. 

As AscendEX resumes withdrawals, Ethereum will be the first in the queue to be up for the withdrawal of coins/tokens for users. It is estimated that the **$77.7 million** was [stolen from three](https://www.coindesk.com/business/2021/12/13/crypto-exchange-ascendex-hacked-losses-estimated-at-77m/) chains, $ 60 million from Ethereum, $9.2 million from Binance Smart Chain, and $8.5 million from Polygon. _Attackers made a lot of transfers from AscendEX’s hot wallets_, and seeing so many transfer requests simultaneously made the organization look for suspicious activities.

As part of its **cybersecurity** **measures**, AscendEX transferred all remaining funds to its cold wallets, which remained unaffected by the attack. It further hired external blockchain analytics organizations to investigate the breach and informed law enforcement. AscendEX also brought other crypto exchanges in the loop so that they, too, could blacklist the compromised wallets.

## NCSC Warns Customers to Beware of Online Shopping Scams This Christmas

_The weekend before Christmas is crazy as people look for last-minute shopping options and often get conned by malicious actors_. With Christmas just a week away, the National Cyber Security Center (NCSC) has [released a warning](https://www.infosecurity-magazine.com/news/government-experts-seasonal-scam/) notice reminding people to stay aware and take necessary [email security](/) and security measures. People are advised to check the amount of information they feed into e-commerce sites and check out as guests (without creating accounts) if possible.

_UK Finance reported that **around £22bn** was spent by citizens on online shopping during Christmas last year_. With 2021 being another year where pandemic restrictions make offline shopping difficult for many, authorities expect a similar (if not greater) threat factor targeting online consumers. The NCSC warns that attackers can target consumers via any vector, fake shipping notifications, [phishing emails](/phishing-protection/how-to-stop-phishing-emails-and-protect-your-organization-from-cyber-criminals/), fake warnings about compromised accounts, fraudulent gift cards, etc.

You must remember that ‘too good to be true’ offers that pop up in our DMs or feed, especially during this time of the year, are probably cyber adversaries trying to get information and money out of us. The NCSC website mentions a range of **cybersecurity** **measures** that consumers can adopt to keep themselves safe from attacks. These include using [strong passwords](/phishing-protection/good-password-policy-protects-phishing/), verifying the authenticity of an organization/website found online, enabling 2FA and MFA, etc.

[![ensure cybersecurity](https://media.mailhop.org/duocircle/images/2021/12/spf-record-check-3514.jpg)](https://media.mailhop.org/duocircle/images/2021/12/spf-record-check-3514.jpg)

## Google Hosts Android App Hacking Workshops with PayPal and HackerOne

_Google constantly updates patches to fix vulnerabilities in its Google Play ecosystem._ However, an often-overlooked fact is that external security researchers have a significant role in Google’s proactive spirit to [ensure](/msp-email-security/cybercrimes-on-the-rise-how-msps-can-ensure-email-security-for-their-clients/) cybersecurity. There is an _active community of_ _cybersecurity_ _researchers out there who aspire to create a safe community_, and Google collaborates with these third-party researchers to fix thousands of bugs in its Android applications.

In exchange for notifying Google of flaws in its applications, security researchers receive **bug bounty rewards** and recognition. Google has collaborated with several industry partners like PayPal and HackerOne to host a series of Android App Hacking Workshops to take this culture a step further. The idea is to expand this community of white-hat threat actors and cybersecurity experts by training them to [find Android app vulnerabilities](https://security.googleblog.com/2021/12/empowering-next-generation-of-android.html).

These workshops have been fruitful in the past and led to budding researchers identifying bugs in applications. This particular workshop comes with rich resources like source codes of a custom-built Android application and enough guidance for learners to fall back upon in their learning journeys. _The workshop is ideal for both researchers and beginners with some experience_.

## Ukraine Police Arrests Cybercrime Group of 51 Members

_Ukraine’s police force recently arrested a cybercrime group of 51 members with charges of selling the data_ belonging to more than **300 million** Europeans, Americans, and Ukrainians. In addition to arresting the 51 accused in the operation called DATA, the police also shut down a renowned website facilitating the selling and buying of personal information. The operation DATA was a massive success as the Ukrainian police force was able to bring **90,000 GB of data** off the internet after extensive research involving over 177 searches.

_The police could also seize 100 databases_ _in the group’s possession._ These databases contained citizens’ banking and legal information, authorization emails, social networking profiles, contact numbers, vehicle registration numbers, etc. Since attacker groups like these are common in today’s world, it is advised to use **cybersecurity tools** like password managers to protect personal information from being accessed by adversaries.

## Twitter Account of Indian Prime Minister Hacked

_Hacking the Twitter accounts of renowned figures has become a trend among the threat actor’s communities_. This time around, an unidentified cyber-adversary has compromised the Twitter [account of the Indian Prime Minister](https://www.hackread.com/indian-pm-modi-twitter-account-hacked-bitcoin-scam/), Narendra Modi (@narendramodi). While the account was secured shortly after the breach was detected, the attacker posted a Tweet in the interim saying that the Indian government had finally recognized Bitcoin as an official legal tender.

_The tweet further informed the 73 million followers of Modi that the Indian government had purchased 500 BTC_, which it plans to distribute among the citizens. Cybersecurity experts in India are investigating the breach and have reached out to Twitter, who confirmed that there had been no suspicious activity in any of its networks.

The fake tweet was eventually brought down, and the Prime Minister’s office clarified in another tweet that Modi’s account was hacked and all tweets posted in that brief period should be ignored.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-51-2-of-2021%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2051-2%20of%202021&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-51-2-of-2021%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-51-2-of-2021%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 51-2 of 2021","description":"This week’s major cyber news headlines reflect the cybersecurity warnings being circulated ahead of the Christmas holidays and a host of other significant.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-51-2-of-2021/","datePublished":"2021-12-24T17:03:54.000Z","dateModified":"2025-05-26T17:46:58.000Z","dateCreated":"2021-12-24T17:03:54.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-51-2-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1132,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/12/spf-record-checker-4367.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 51-2 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-51-2-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 51-2 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-51-2-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 51-2 of 2021","description":"This week’s major cyber news headlines reflect the cybersecurity warnings being circulated ahead of the Christmas holidays and a host of other significant.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-51-2-of-2021/","datePublished":"2021-12-24T17:03:54.000Z","dateModified":"2025-05-26T17:46:58.000Z","dateCreated":"2021-12-24T17:03:54.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-51-2-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1132,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/12/spf-record-checker-4367.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
