---
title: "Cyber Security News Update, Week 7 of 2022 | DuoCircle"
description: "Following are this week’s significant updates from the world of cybersecurity that would make you realize the importance of keeping yourself updated about the."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-7-of-2022/"
---

Quick Answer

Week 7, 2022 cyber news: Proofpoint counts 1,200+ MFA-bypass phishing toolkits (Evilginx2, Muraena/Necrobrowser, Modlishka) using transparent reverse proxies to steal session cookies in real time; Bitdefender finds RCE flaws in Nooie Baby Cam (50K-100K installs) plus exposed AWS credentials for cloud video; HP traces RedLine infostealer dropped via fake windows-upgraded.com Windows 11 installers; Poland stands up a Cyber Defense Force under Brig. Gen. Karol Molenda; Google auto-enrolls 150 million Gmail users in 2-step verification (account hacks via passwords down 50%); the Sugar RaaS expands across the US, Canada, Thailand, Israel, and Lithuania; DHS sets up a Cyber Safety Review Board.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-7-of-2022%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%207%20of%202022&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-7-of-2022%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-7-of-2022%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-7-of-2022%2F&title=Cyber%20Security%20News%20Update%2C%20Week%207%20of%202022 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%207%20of%202022&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-7-of-2022%2F "Share via Email") 

![cybersecurity update](https://media.mailhop.org/duocircle/images/2022/02/hosted-email-server.jpg) 

Following are this week’s significant updates from the world of cybersecurity that would make you realize the importance of keeping yourself updated about the [recent cyber happenings](/announcements) around the world.

## Phishing Attacks Can Violate MFA

_Multi-Factor Authentication(MFA) is considered a standard security protocol in most organizations_. However, threat actors have devised a way to breach into organizational or individual networks using MFA. Reportedly, there are **over 1200 phishing toolkits** that can [intercept MFA security codes](https://web.archive.org/web/20220211020459/https://cyware.com/news/be-careful-phishing-kits-bypassing-mfa-are-growing-in-popularity-e27a9631). These toolkits have been in operation mainly in Europe and North America.

Cybersecurity experts at Proofpoint have explained the use of a new **phishing toolkit** that uses a transparent reverse proxy mechanism to lead victims to **spoofed websites**. Resultantly, Man-in-the-Middle (MitM) attacks could be launched against victims to steal their session cookies, usernames, and passwords in real-time. _The stolen cookies can be used further to access targeted accounts without an MFA token_. The Proofpoint researchers also listed the three most frequently used phishing kits in recent times, Evilginx2, Muraena/Necrobrowser, and Modlishka. Though these tools are not new, their _efficacy in evading threat detection measures is frightening_. The need of the hour for SMEs is to enhance their [cybersecurity posture](/email-security/why-it-is-crucial-for-smes-to-have-a-robust-cybersecurity-posture/) so that adversaries cannot exploit the vulnerabilities in their information systems.

## Beware of Security Issues in Nooie’s Baby Cam Monitoring Devices

With around 50k-100k installations, [Nooie’s Cam software](https://portswigger.net/daily-swig/zero-day-vulnerabilities-in-nooie-baby-monitors-could-allow-video-feed-hijack) is well-known, particularly among its Baby Cam users. However, some _new security vulnerabilities have been detected in its software, allowing threat actors to access camera feeds_ and affect vulnerable devices with malicious code.

Cybersecurity experts from the infosec firm Bitdefender identified two **remote code execution** possibilities in two models of Nooie’s Baby Cam infant monitoring devices. They indicate that other devices from the same range might also be vulnerable to these codes. The security experts tracked a flaw used to access arbitrary cameras’ RTSPS (audio-video) feed, and Nooie’s baby cameras are linked to RTSPS streams.

Further, Nooie’s baby cameras also use Amazon Web Services (AWS) to store the video recordings on the cloud. While _each user would have unique access credentials, the adversaries could easily access these credentials and view their recordings_. Bitdefender first disclosed these vulnerabilities privately to the vendor in November 2020, but since it did not receive the expected response so far, the firm recently went public and shared all details of the vulnerabilities along with recommended [ransomware protection](/email-security/5-ways-you-protect-your-business-from-ransomware/) measures.

[![ransomware protection](https://media.mailhop.org/duocircle/images/2022/02/buy-smtp-7414.jpg)](https://media.mailhop.org/duocircle/images/2022/02/buy-smtp-7414.jpg)

## Beware of Fake Windows 11 Updates Installing RedLine

_Adversaries are spreading the RedLine info-stealer malware in the name of Windows 11 upgrade installers_. Their timing couldn’t have been better as Microsoft continues to roll out Windows 11 updates for users worldwide! However, following the adversaries and downloading the so-called Windows 11 installer might actually download the [RedLine stealer on our devices](https://www.bleepingcomputer.com/news/security/fake-windows-11-upgrade-installers-infect-you-with-redline-malware/) which are known for stealing credit card details, browser cookies, passwords, and other confidential information.

Cybersecurity researchers at HP traced this RedLine campaign recently where the adversaries used a seemingly authentic “windows-upgraded.com” domain to **distribute malware**. In a typical attack attempt, the victims receive a 1.5 MB ZIP upon clicking on ‘Download Now.’ This ZIP folder is titled “Windows11InstallationAssistant.zip.” At the time of research, the said domain was inactive, but _the adversaries could easily create hundreds of other fake domains using the same strategy_. It is recommended that users try and install Windows 11 only from the official Windows Upgrade website page. There are tons of malicious pages out there that only aim to infect your device and steal credentials.

## Poland to Launch New Cyber Defense Unit

_Poland is about to add a defense force to its military operations and recently appointed an army general to head a newly created Cyber Defense Force_. The Polish Defense Minister Mariusz Blaszczak announced that the cyber defense force would strive to protect Poland’s [Armed Forces from cyberattacks](https://www.securityweek.com/poland-launches-cybersecurity-military-unit). This move comes as a response to the **millions of cyberattacks** happening globally and making it to the headlines daily. Blaszczak noted that today, cyberattacks are used to launch massive political wars, and it is necessary to shield Poland’s Armed Forces against attacks from the beginning.

_Cybersecurity for the military is a matter of national security_, and Poland seems to be taking it very seriously. Brig. Gen. Karol Molenda was appointed as the head of the cyber defense unit, and Molenda is now working in close association with the National Center for Cyber Security.

## Google Helps Protect 150M Users with Added Security

_2-step verification, though with new possibilities of intrusion, has proven to be a robust security measure_. According to a Google press release, _2FA has reduced account hacks through passwords by 50%_. Therefore the company has taken the onus to auto-enroll **over 150 million** Gmail users in 2-step verification. The venture also required 2 million YouTube users to enable 2FA. In its statement, Google mentioned that it is happy with the results of this initiative and hopes to [secure more people against cyberattacks](https://www.zdnet.com/article/google-has-auto-enrolled-150-million-users-in-2-step-verification/).

Emphasizing the connection between users’ Gmail and all other online accounts (such as social media, banking, online shopping, or job portal accounts), Google has notified that it wants to secure users’ non-Google accounts by blocking phishing or malware loaded spam messages at the entry-level. The company plans to offer additional protection to a select **10,000 high-risk user**s, including celebrities, journalists, billionaires, etc., using security keys. Since _passwords are no longer enough to safeguard user accounts_, Google provides security checkup features to users, recommending the proper cybersecurity measures for their accounts.

[![cyberattacks](https://media.mailhop.org/duocircle/images/2022/02/smtp-7215.jpg)](https://media.mailhop.org/duocircle/images/2022/02/smtp-7215.jpg)

## New Ransomware Sugar is All Set to Operate as a RaaS

_The newly emerged ransomware family called Sugar is all set to function as Ransomware-as-a-Service (RaaS)_. The ransomware was first uncovered by cybersecurity experts at Walmart in November 2021.

Primarily targeting enterprise and individual networks, the [Sugar ransomware](https://web.archive.org/web/20240918025517/https://cyware.com/news/newly-found-sugar-ransomware-is-now-being-offered-as-raas-641cfa69) is known to infect users in the US, Canada, Thailand, Israel, and Lithuania. Sugar resembles REvil and Cl0p ransomware in some aspects, and its distribution as a RaaS shall increase its attack scope and make things easier for affiliates. As its reach increases, it is advised for all organizations to enhance their [ransomware protection](/email-security/5-ways-you-protect-your-business-from-ransomware/) measures.

## The US to Get New Cyber Safety Review Board

A new [Cyber Safety Review Board](https://www.itsecurityguru.org/2022/02/04/us-federal-government-creates-cybersecurity-incident-review-board/) is in the making, and the Department of Homeland Security recently announced its arrival. _The review board shall comprise cybersecurity experts from public and private organizations_ who will assess and review significant cybersecurity events. The creation of this board is a part of an executive order that was signed last year.

Reportedly, the Cyber Safety Review Board will conduct a thorough assessment of past cybersecurity events, pose questions and introduce upgraded [email security](/) measures for public and private sectors alike.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 7 of 2022","description":"Following are this week’s significant updates from the world of cybersecurity that would make you realize the importance of keeping yourself updated about the.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-7-of-2022/","datePublished":"2022-02-17T15:33:58.000Z","dateModified":"2025-05-02T12:50:21.000Z","dateCreated":"2022-02-17T15:33:58.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-7-of-2022/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1103,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/02/hosted-email-server.jpg","caption":"cybersecurity update","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 7 of 2022","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-7-of-2022/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 7 of 2022","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-7-of-2022/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 7 of 2022","description":"Following are this week’s significant updates from the world of cybersecurity that would make you realize the importance of keeping yourself updated about the.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-7-of-2022/","datePublished":"2022-02-17T15:33:58.000Z","dateModified":"2025-05-02T12:50:21.000Z","dateCreated":"2022-02-17T15:33:58.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-7-of-2022/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1103,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/02/hosted-email-server.jpg","caption":"cybersecurity update","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
