---
title: "Cyber Security News Update, Week 6 of 2021 | DuoCircle"
description: "Cybersecurity tools are often unable to protect an organization from data theft if the employees aren’t aware of cyber threats."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-6-of-2021/"
---

Quick Answer

Week 6, 2021 cyber news: Nefilim ransomware abused a deceased employees still-active account for over a month to exfiltrate hundreds of GB before encrypting 100+ systems; an Android malware spreads via WhatsApp auto-replies pushing a fake Huawei Play Store app; Apple patches three iOS/iPadOS/tvOS zero-days (CVE-2021-1782 privilege escalation, CVE-2021-1870 and CVE-2021-1871 in WebKit); Norway fines Grindr $11.7M for sharing user data with ad networks; \~2,000 industrial domains receive Sunburst payloads from the SolarWinds supply-chain compromise; UK FCA warns of clone-company investment scams that have cost investors over $107M.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-6-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%206%20of%202021&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-6-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-6-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-6-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%206%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%206%20of%202021&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-6-of-2021%2F "Share via Email") 

![Cyber Security](https://media.mailhop.org/duocircle/images/2021/02/spf-record-checker-8642.jpg) 

_Cybersecurity tools are often unable to protect an organization from data theft if the employees aren’t aware of cyber threats_, as they remain the **first line of defense** in today’s threat landscape. The following cybersecurity headlines from this past week have been written to instigate the importance of using **robust cybersecurity** tools in today’s times, always to remain a step ahead of threat actors and keep yours as well your organization’s information assets from falling into the wrong hands!

## Ghost Account Haunts As Nefilim Ransomware

What happens to the account of an employee who leaves the organization or dies? _Many companies keep using such ghost accounts to store information and keep services running_. It’s a pity that cybercriminals have noticed the operation of these ghost accounts. In a recent Nefilim **ransomware attack**, the adversaries _brought down over 100 systems of an organization and encrypted their files_, exploiting one such ghost account.

The research revealed that this account belonged to an employee who expired three months before this cybersecurity incident, but his account remained in use for some services. The adversaries used this account for over a month to exploit the company’s network and steal [hundreds of GBs](https://threatpost.com/nefilim-ransomware-ghost-account/163341/?web%5Fview=true) of data. After stealing everything of value, _the attackers infected the systems of the organization with the Nefilim ransomware_. Well, the dead are safe in their graves, but for those alive, it is advised to replace ghost accounts with service accounts or at least **disable interactive logins**!

## Beware Of Malicious App Spread Through Whatsapp

Family WhatsApp groups probably circulate the maximum forwarded messages, but here’s a forward message to stay away from, _The adversaries are using the app’s [auto-reply feature](https://www.hackread.com/android-malware-spreads-through-whatsapp/?web%5Fview=true) to spread malware by using a **phishing link** that leads users to a phished Playstore webpage and downloads a fake Huawei app_. The security flaw was discovered by researchers Lukas Stefanko and ReBensk, who warn that downloading the phony app might cause several **security threats**.

[![ransomware protection](https://media.mailhop.org/duocircle/images/2021/02/spf-record-5871.jpg)](https://media.mailhop.org/duocircle/images/2021/02/spf-record-5871.jpg)

Any user who skips the terms and conditions and allows the fake app to view notifications, draw over other apps and run in the background enables the adversaries to send unwanted ads, make involuntary subscriptions, spy on the user and steal their credentials. So much for clicking on forwarded WhatsApp links! What’s amusing is that the _adversaries can change the link URL whenever they realize that the existing one has been brought down_. Cybersecurity tools can stop malware from downloading itself, but when we deliberately give storage and other permissions to apps downloaded from unreliable sources, there is not much [ransomware protection](/advanced-threat-defense) services can do!

## Apple Warns Of Zero-Day Vulnerabilities

_Three [zero-day vulnerabilities](https://www.phishprotection.com/content/zero-day-attacks/) have been found in iOS, iPadOS, and tvOS_. An unnamed researcher recently reported the vulnerabilities dubbed CVE-2021-1782, CVE-2021-1870, and CVE-2021-1871 to Apple. Though the details of the **security flaws** haven’t been revealed, Apple says that the vulnerabilities are now fixed. _An attacker who managed to exploit these vulnerabilities could have gained access to remote code execution_.

While the CVE-2021-1782 vulnerability let adversaries elevate their privileges (race condition), the CVE-2021-1870 and CVE-2021-1871 vulnerabilities were found in the [WebKit browser](https://thehackernews.com/2021/01/apple-warns-of-3-ios-zero-day-security.html?&web%5Fview=true) engine functioning as logic issues. Thankfully for users, Apple has fixed all three vulnerabilities through improved restrictions and locking. Apple users are advised to take cybersecurity measures seriously because there are high chances of the attackers using these flaws to launch **watering hole attacks**.

## Grindr App To Pay $11.7 Million As Data Breach Penalty

Exemplifying what happens to those who disregard cyber norms, _the **Data Protection** Authority of Norway has imposed a fine of $11.7 million on the U.S-based dating app Grindr_. Grindr is a [dating app](https://ciso.economictimes.indiatimes.com/news/grindr-faces-11-7-million-fine-in-norway-for-breach-of-data-privacy/80464803) for members of the LGBTQ+ community which recently made it to the headlines for sharing sensitive user data with advertising firms.

The app has time till the 15th of February to present its case, post which the DPA will make a final verdict on the case. The Norwegian Consumer Council (NCC) calls the fine imposed on Grindr a historic victory for privacy and a lesson for organizations to treat user privacy and [email protection](/) cautiously.

## Solarwinds Attack Found Distributing Sunburst Malware

_The historical SolarWinds attack that infected **over 18k organizations** with trojan now has a new dimension of damage linked to it_. Many organizations are receiving **Sunburst malware** as a consequence of the supply chain attack on SolarWinds. Because of the malware, the adversaries will be able to access and misuse the files stored on the victims’ systems. An [estimated](https://www.securityweek.com/hundreds-industrial-organizations-received-sunburst-malware-solarwinds-attack?&web%5Fview=true) two thousand domains (related to industrial organizations) spread across Europe, Asia, America, and Africa have been impacted by Sunburst.

[![email security services](https://media.mailhop.org/duocircle/images/2021/02/spf-record-check-7664.jpg)](https://media.mailhop.org/duocircle/images/2021/02/spf-record-check-7664.jpg)

This revelation foretells future cyber threats for the involved organizations, and hence they must use [email security services](/) and have a robust incident response procedure ready.

## UK Watchdogs Warn Of Clone Company Scams

New forms of cyberattacks have gained momentum ever since the COVID 19 outbreak. One such attack spreading _across the UK is the clone company scam where the adversaries [extract money](https://www.zdnet.com/article/national-crime-agency-warns-green-and-veteran-traders-alike-of-rise-in-clone-company-scams/?&web%5Fview=true) from those seeking investment opportunities_. The Financial Conduct Authority and National Crime Agency have warned the public to beware of clone companies that look exactly like legitimate investment companies. What makes these clone companies seem reliable is the use of the actual company credentials (name, address, FRN, etc.).

Since the first lockdown, investors have collectively **lost over $107 million**, and this figure will keep rising if investors do not pay heed to the following cybersecurity measures:

- Investors must not believe offers from unsolicited sources, either online or on calls.
- They must seek independent and impartial advice before investing.

Since these clone companies are hard to spot and have successfully conned even experienced investors, the FCA and NCA have released this alert.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-6-of-2021%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%206%20of%202021&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-6-of-2021%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-6-of-2021%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Spam](https://media.mailhop.org/duocircle/images/2016/05/spf-permerror-3256.jpg)  April Spam Filtering Uptime Report News ](/blog/announcements/april-spam-filtering-uptime-report/)
- [ ![Spam Filtering](https://media.mailhop.org/duocircle/images/2023/02/spf-record-tester-7226.jpg)  Changes to Spam Filtering Technology News ](/blog/announcements/changes-to-spam-filtering-technology/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2020/01/spf-permerror-7312.jpg)  Cyber Security News Update, Week 1 of 2020 News ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 1m  April Spam Filtering Uptime Report  May 4, 2016 ](/blog/announcements/april-spam-filtering-uptime-report/)[  News 2m  Changes to Spam Filtering Technology  Feb 8, 2023 ](/blog/announcements/changes-to-spam-filtering-technology/)[  News 4m  Cyber Security News Update, Week 1 of 2020  Jan 3, 2020 ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 6 of 2021","description":"Cybersecurity tools are often unable to protect an organization from data theft if the employees aren’t aware of cyber threats.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-6-of-2021/","datePublished":"2021-02-05T21:14:33.000Z","dateModified":"2025-05-26T12:58:21.000Z","dateCreated":"2021-02-05T21:14:33.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-6-of-2021/"},"articleSection":"announcements","keywords":"","wordCount":944,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/02/spf-record-checker-8642.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 6 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-6-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 6 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-6-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 6 of 2021","description":"Cybersecurity tools are often unable to protect an organization from data theft if the employees aren’t aware of cyber threats.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-6-of-2021/","datePublished":"2021-02-05T21:14:33.000Z","dateModified":"2025-05-26T12:58:21.000Z","dateCreated":"2021-02-05T21:14:33.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-6-of-2021/"},"articleSection":"announcements","keywords":"","wordCount":944,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/02/spf-record-checker-8642.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
