---
title: "Cyber Security News Update, Week 6 of 2022 | DuoCircle"
description: "Cybersecurity is a significant issue facing all small and large businesses across the globe."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-6-of-2022/"
---

Quick Answer

Week 6, 2022 cyber news: FBI warns about Iranian firm Emennet Pasargad (formerly Net Peygard Samavat, Eeleyanet Gostar), which targets Drupal and WordPress hosts after attempting to disrupt the 2020 US election; macOS UpdateAgent has evolved over 14 months from infostealer to malware that drops adware backdoors and enables MITM ad-revenue theft; Finlands NCSC-FI flags Facebook Messenger phishing that asks for OTPs to hijack accounts; Wormhole DeFi bridge loses \~$322.8M in Ether and offers a $10M bug bounty; Trend Micro patches CVE-2022-23119 and CVE-2022-23120 in Deep Security and Cloud One; Walmart unpacks Sugar, a new Delphi-based RaaS using modified RC4.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-6-of-2022%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%206%20of%202022&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-6-of-2022%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-6-of-2022%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-6-of-2022%2F&title=Cyber%20Security%20News%20Update%2C%20Week%206%20of%202022 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%206%20of%202022&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-6-of-2022%2F "Share via Email") 

![Cyber Security](https://media.mailhop.org/duocircle/images/2022/02/365-to-365-migration-3184.jpg) 

_Cybersecurity is a significant issue facing all small and large businesses across the globe._ This week’s [cyber news headlines highlight](/announcements) the major cybersecurity incidents that have occurred recently.

## FBI Warns Private Industries to Stay Wary of Emennet Pasargad

_The FBI recently issued a warning notification for private industries cautioning them of the malicious activities of the Iranian cyber company, Emennet Pasargad_. In its notification, the [FBI mentions](https://www.securityweek.com/fbi-warns-hacker-attacks-conducted-iranian-cyber-firm) the threat actor’s tactics, techniques, and procedures (TTPs) and some **cybersecurity recommendations** to detect and prevent their attacks.

This is the same Iranian threat actor group that wanted to sabotage the 2020 presidential elections and was under the U.S. Treasury Department’s sanctions in November 2021\. The group has rebranded itself frequently in the past to evade U.S. sanctions, and some of its past names include Net Peygard Samavat and Eeleyanet Gostar. The FBI notes that Emennet Pasargad usually targets hosting services and websites or networks in specific sectors. Emennet also targeted popular content management systems like Drupal and WordPress, apart from the U.S. presidential elections.

## UpdateAgent: Infostealer Turned Malware

_Cybersecurity experts have uncovered an info stealer called UpdateAgent, working as a macOS malware for **over 14 months**_. It started circulating as an info stealer and emerged sometime in November or December 2020, but _it is becoming more malicious and constantly evolving to work like malware_. It now has advanced functionalities like a second-stage adware payload that installs a backdoor. The adware also facilitates **man-in-the-middle attacks,** _enabling adversaries to steal ad revenue from official website holders_. In addition, UpdateAgent can also gather system profile data and SPHardwaretype, which reveals the serial number of victims’ systems.

_UpdateAgent is a threat to cybersecurity because it tricks victims by impersonating legitimate software and exploiting Mac device functionalities_. The notorious malware abuses existing user permissions and then deletes all evidence of its malicious activities. Since modern-day work environments heavily rely on different operating systems, it is imperative to ensure [ransomware protection](/email-security/5-ways-you-protect-your-business-from-ransomware/) across all these platforms.

[![Phishing ](https://media.mailhop.org/duocircle/images/2022/02/365-to-365-migration-3185.jpg)](https://media.mailhop.org/duocircle/images/2022/02/365-to-365-migration-3185.jpg)

## NCSC-FI Warns of Phishing Campaign Exploiting Facebook Accounts

Have you ever received a text from a friend on Facebook asking for your number and an OTP? Have you complied with those random requests? _Finland’s National Cyber Security Center (NCSC-FI) warns citizens against sharing personal details with such friends on Facebook_, which could be a part of this new phishing campaign. Adversaries have taken to [Facebook to impersonate victims](https://www.bleepingcomputer.com/news/security/finland-warns-of-facebook-accounts-hijacked-via-messenger-phishing/)‘ friends on Facebook Messenger and ask for their contact numbers and a verification code delivered on their mobile phones. _Any unsuspecting user who shares these details with the adversaries will lose control of their Facebook accounts_ (as the malicious actors can immediately change your password). A **hijacked Facebook account** will then be used to spread the attack further among the victim’s friends.

The NCSC-FI warns that users look at all messages with suspicion, irrespective of how well you know the sender in person. Another way to verify the authenticity of such texts is by _contacting the sender outside of Facebook_ (via call or SMS) and asking if they are aware of the messages. Scammers have used Messenger, WhatsApp and Instagram extensively in the past to give shape to their **phishing campaigns**; therefore, being wise and using **cybersecurity tools** while chatting on these platforms is essential.

## Hacker Exploits Vulnerability in Wormhole Cryptocurrency

_Hackers recently exploited a vulnerability in the web-based application Wormhole, allowing users to convert one cryptocurrency into another_. The adversaries reportedly stole **over $322.8 million** Ether currency from the platform. While Wormhole hasn’t [confirmed the breach](https://therecord.media/cryptocurrency-platform-wormhole-hacked-for-an-estimated-322-million/) yet, it is likely to be the largest attack on a crypto platform so far in 2022\. _The value of the stolen cryptocurrencies has dropped to $294 million_.

The crypto network has put its website under maintenance mode until investigations continue. In addition, _Wormhole has launched a bug bounty program worth $10 million_ wherein it is luring the adversaries to return the stolen funds and take home a **bounty of $10 million**. More comments from Wormhole are due after its [email security](/) experts finish the initial investigation.

## Trend Micro Patches Two High-Severity Vulnerabilities

_Trend Micro recently fixed two high-severity vulnerabilities_ tracked as CVE-2022-23119 and CVE-2022-23120, _impacting its Deep Security and Cloud One workload security solutions_. Cybersecurity researchers at Modzero first [discovered the vulnerabilities](https://www.securityweek.com/trend-micro-patches-vulnerabilities-hybrid-cloud-security-products) in September. Trend Micro quickly announced **patches for the flaws** and released them between October and December. Modzero also released an advisory and PoC exploits on 19th January 2022.

As per Modzero’s report, a directory traversal vulnerability in the Deep Security Agent for Linux enables adversaries to read arbitrary files. It also allows them to execute remote code and escalate privileges. But the _attacker needs to have access to the target system to exploit the flaw_. However, the attacker needs to access the targeted system, and exploitation is only possible if the agent has not been activated or configured. This is not the first time that flaws in Trend Micro products have been highlighted. Only last week, Trend Micro informed customers of a flaw in its Worry-Free Business Security small business product. But this was categorized as a low severity vulnerability.

[![Ransomware](https://media.mailhop.org/duocircle/images/2022/02/365-to-365-migration-3186.jpg)](https://media.mailhop.org/duocircle/images/2022/02/365-to-365-migration-3186.jpg)

## Watch Out For The New Ransomware Sugar

_Cybersecurity experts at the retail giant Walmart have discovered a new ransomware called Sugar_ which is available to attackers as a **ransomware-as-a-service** (RaaS). With its first glimpse in November 2021, Sugar gets its objects from other [ransomware families](https://www.securityweek.com/walmart-dissects-new-sugar-ransomware) and is written in Delphi.

_Sugar is different from other ransomware families that usually target enterprise networks_. It attacks individual computers but is in no way less dangerous. Its crypter employs a modified version of the **RC4 encryption**, but code from this crypter is also used in the ransomware, which could mean two things, _the ransomware and its crypter are created by the same developer_, or the crypter is offered to affiliates as part of the RaaS. Walmart researchers found similarities between the ransom note used by the REvil, Cl0p and Sugar ransomware gangs. They also found similarities between Sugar and GPLib which suggest that the SCOP **encryption algorithm** is used in encryption.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 6 of 2022","description":"Cybersecurity is a significant issue facing all small and large businesses across the globe.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-6-of-2022/","datePublished":"2022-02-10T17:44:45.000Z","dateModified":"2025-05-27T11:10:48.000Z","dateCreated":"2022-02-10T17:44:45.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-6-of-2022/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1007,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/02/365-to-365-migration-3184.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 6 of 2022","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-6-of-2022/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 6 of 2022","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-6-of-2022/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 6 of 2022","description":"Cybersecurity is a significant issue facing all small and large businesses across the globe.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-6-of-2022/","datePublished":"2022-02-10T17:44:45.000Z","dateModified":"2025-05-27T11:10:48.000Z","dateCreated":"2022-02-10T17:44:45.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-6-of-2022/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1007,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/02/365-to-365-migration-3184.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
