---
title: "TryCloudflare Malware Spread, FBI Scam Alert, Azure Outage Triggered-Cybersecurity News [July 29, 2024] | DuoCircle"
description: "TryCloudflare Malware Spread, FBI Scam Alert, Azure Outage Triggered-Cybersecurity News [July 29."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-32-of-2024/"
---

Quick Answer

Cybersecurity news for the week of July 29, 2024\. Threat actors abused TryCloudflare's free tunnel service to deliver Remcos, VenomRAT, GuLoader, and Xworm via temporary subdomains hosting LNK phishing payloads. The FBI warned about scammers impersonating crypto exchange staff via phone and SMS to steal credentials and funds. Microsoft suffered a 9-hour Azure and M365 outage triggered by a DDoS attack that misfired against its own DDoS protection. Google Chrome added app-bound encryption on Windows to protect cookies and stored credentials from infostealers. A flaw in WhatsApp for Windows was disclosed that lets PYZ, PYZW, and EVTX scripts run without warning.

TryCloudflare Malware Spread, FBI Scam Alert, Azure Outage Triggered-Cybersecurity News \[July 29, 2024\]

Your browser does not support the audio element.

[ Download episode](https://media.mailhop.org/duocircle/images/2024/08/TryCloudflare-Malware-Spread-FBI-Scam-Alert-Azure-Outage-Triggered-Cybersecurity-News-July-29-2024.mp3) 

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-32-of-2024%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=TryCloudflare%20Malware%20Spread%2C%20FBI%20Scam%20Alert%2C%20Azure%20Outage%20Triggered-Cybersecurity%20News%20%5BJuly%2029%2C%202024%5D&url=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-32-of-2024%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-32-of-2024%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-32-of-2024%2F&title=TryCloudflare%20Malware%20Spread%2C%20FBI%20Scam%20Alert%2C%20Azure%20Outage%20Triggered-Cybersecurity%20News%20%5BJuly%2029%2C%202024%5D "Share on Reddit") [ ](mailto:?subject=TryCloudflare%20Malware%20Spread%2C%20FBI%20Scam%20Alert%2C%20Azure%20Outage%20Triggered-Cybersecurity%20News%20%5BJuly%2029%2C%202024%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-32-of-2024%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2024/08/spf-record-tester.jpg) 

This week’s latest scoop in [cybersecurity](/) will take you to the TryCloudflare exploitation for deploying RATs, the new FBI warning about scammers impersonating crypto exchanges, the MS Azure outage details, [new features on Google Chrome](https://www.infosecurity-magazine.com/news/chrome-feature-alerts-malicious/) against infostealers, and the security gap in Whatsapp for Windows that allows threat actors to run [malicious scripts](https://thehackernews.com/2024/07/onedrive-phishing-scam-tricks-users.html) without alerts. **Stay tuned** to learn more about these and how to stay safe!

## Hackers Exploit Free TryCloudflare Service to Spread Remote Access Malware

Researchers at Proofpoint [reported that](https://www.proofpoint.com/us/blog/threat-insight/threat-actor-abuses-cloudflare-tunnels-deliver-rats) threat actors have been abusing Cloudflare to spread malware and drop RATs (Remote Access Trojans). 

The activity has been going on since February, and the threat actors leverage the [TryCloudflare](https://www.bleepingcomputer.com/news/security/hackers-abuse-free-trycloudflare-to-deliver-remote-access-malware/) free service to distribute RATs like Remcos, VenomRAT, GuLoader, and Xworm. The service allows access to local services by proxying traffic via an encrypted tunnel so there’s no exposure of the **IP addresses**. It allows users to create temporary tunnels and test them without the need for an account as well. _Each tunnel basically generates a temporary, random subdomain that users can use to route traffic, and threat actors have been abusing this feature_. They have been targeting the manufacturing, technology, law, and finance sectors by hosting LNK files on such domains and luring victims via [phishing emails](/content/phishing-prevention/phishing-email) that lead to the payload. The file executes BAT or CMD scripts when opened and deploys PowerShell, through which the final RAT payload is distributed on the victim systems.

Since the domains are temporary, it is not much use blocking them. The service is **free and reliable** to use and Cloudflare is taking steps to disable and take down any [malicious tunnels](https://www.securityweek.com/cloudflare-tunnels-abused-for-malware-delivery/) they come across.

[![phishing emails](https://media.mailhop.org/duocircle/images/2024/08/smtp-email-5832.jpg)](https://media.mailhop.org/duocircle/images/2024/08/smtp-email-5832.jpg)

## FBI Issues Warning About Scammers Impersonating Crypto Exchange Staff

The FBI issued a warning this week about scammers who are now [impersonating crypto exchange](https://www.malwarebytes.com/blog/news/2024/08/scammers-are-impersonating-cryptocurrency-exchanges-fbi-warns) employees to steal finances. 

_They detailed how these scammers are contacting victims via phone calls and messages and create a sense of urgency, citing a security issue or a hack into the victim’s account to establish contact_. After this, they employ [social engineering](/phishing-protection/social-engineering-is-a-growing-threat/) tactics to gain the trust of the victims and steal their login credentials and **sensitive information**. The scammers use this to gain access to the victim’s accounts and steal all the funds. The FBI [shared how](https://www.ic3.gov/Media/Y2024/PSA240801) you can exercise caution and verify all identities before you divulge any sensitive information to scammers. _It’s best that you contact the crypto exchange independently instead of responding to their messages or calls to find out the truth_. You can easily stay safe from such scammers by avoiding clicking on any links that they send you, as they are likely to be fraudulent and malicious. 

Above all, **never share any login information** via unsolicited calls or text messages, and do not open [attachments provided in emails](https://www.csoonline.com/article/575213/attacks-increasingly-use-malicious-html-email-attachments.html). Scammers are not just impersonating crypto exchanges and there’s also a rise in of threat actors posing as law firms offering crypto recovery services. Be wary of them as well.

## Microsoft Reveals Azure Outage Triggered by DDoS Attack

Microsoft suffered a 9-hour outage on Tuesday when multiple MS 365 and Azure services were down around the world. 

The outage impacted many Microsoft platforms and Azure app services. Microsoft [shared](https://azure.status.microsoft/en-us/status/history/#incident-history-collapse-KTY1-HW8) a mitigation statement in which they outlined that the disruption of services was caused by a [DDoS (Distributed Denial of Service) attack](https://therecord.media/ddos-attack-thwarted-on-banking). They did not share any news about the type of attack or the threat actor behind it but did share that it **activated Microsoft’s DDoS protection** mechanisms that amplified the attack instead of mitigating it due to an error in implementation. _They have made network configuration changes and also performed failovers to other network paths so users can enjoy all services without any disruption_. 

Redmond will share a PIR (Preliminary Post-Incident Review) within three days and a **final report within 15 days** that will share all the details about the outage. 

[![DDoS attack](https://media.mailhop.org/duocircle/images/2024/08/sender-policy-framework.jpg)](https://media.mailhop.org/duocircle/images/2024/08/sender-policy-framework.jpg)

## Google Chrome Introduces App-Bound Encryption to Combat Infostealer Malware

This week, Google [added](https://security.googleblog.com/2024/07/improving-security-of-chrome-cookies-on.html) an [app-bound encryption](https://www.bleepingcomputer.com/news/security/google-chrome-adds-app-bound-encryption-to-block-infostealer-malware/) to its **web browser** that will offer better cookie and infostealer protection on Windows systems. 

Chrome is adopting better techniques provided by operating systems to protect the sensitive data of the users, such as cookies and passwords, using Keychain services on Mac, [DPAPI (Data Protection Application Programming Interface)](https://en.wikipedia.org/wiki/Data%5FProtection%5FAPI) on Windows, and kwallet on Linux. The new Chrome will feature an app-bound encryption that will improve **DPAPI and encrypt all data** tied to an application identity instead of letting the application with the user login to access said data. The service will confirm an application’s identity and encode it into the encrypted data so only the application can decrypt it, and not any third-party applications, adding a layer of protection. This will stop threat actors as they would need to gain system privileges or deploy malware, triggering anti-virus programs. With the new feature, all passwords, payment data, and authentication tokens will be safe from infostealer attacks. 

This is the second update that improves Chrome because last week, **Google announced new Chrome** warnings that would issue alerts about potentially malicious downloads. 

## WhatsApp for Windows Allows Python and PHP Scripts to Run Without Alerts

A security issue was discovered in the WhatsApp web interface for Windows that [threat actors](/email-security/threat-actors-are-using-google-ads-to-launch-sophisticated-phishing-campaigns/) could use to send **Python and PHP** attachments, which are executed without any warning. 

_A similar issue was also discovered and then fixed on Telegram back in April. It only works on systems that already have Python installed, so the target audience is software developers, students, power users, and researchers_. When you receive a potentially dangerous file, WhatsApp provides two choices: open it or save it as a file. But if you try to open EXE, COM, DLL, HTA, VBS, SCR, BAT, and **Perl files**, the execution is blocked, and you can only save these files to the disk; however, if you try to execute PYZ, PYZW, and EVTX files, it does not block the launch and they are executed. 

Saumyajeet Das [found](https://www.bleepingcomputer.com/news/security/whatsapp-for-windows-lets-python-php-scripts-execute-with-no-warning/) the issue and reported it to Meta, but the organization has not taken any steps to mitigate it.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-32-of-2024%2F) [ ](https://twitter.com/intent/tweet?text=TryCloudflare%20Malware%20Spread%2C%20FBI%20Scam%20Alert%2C%20Azure%20Outage%20Triggered-Cybersecurity%20News%20%5BJuly%2029%2C%202024%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-32-of-2024%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-32-of-2024%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"TryCloudflare Malware Spread, FBI Scam Alert, Azure Outage Triggered-Cybersecurity News [July 29, 2024]","description":"TryCloudflare Malware Spread, FBI Scam Alert, Azure Outage Triggered-Cybersecurity News [July 29.","url":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-32-of-2024/","datePublished":"2024-08-05T22:04:26.000Z","dateModified":"2025-08-21T19:50:49.000Z","dateCreated":"2024-08-05T22:04:26.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-32-of-2024/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1025,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/08/spf-record-tester.jpg","caption":"cybersecurity","width":900,"height":506},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"TryCloudflare Malware Spread, FBI Scam Alert, Azure Outage Triggered-Cybersecurity News [July 29, 2024]","item":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-32-of-2024/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"TryCloudflare Malware Spread, FBI Scam Alert, Azure Outage Triggered-Cybersecurity News [July 29, 2024]","item":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-32-of-2024/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"TryCloudflare Malware Spread, FBI Scam Alert, Azure Outage Triggered-Cybersecurity News [July 29, 2024]","description":"TryCloudflare Malware Spread, FBI Scam Alert, Azure Outage Triggered-Cybersecurity News [July 29.","url":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-32-of-2024/","datePublished":"2024-08-05T22:04:26.000Z","dateModified":"2025-08-21T19:50:49.000Z","dateCreated":"2024-08-05T22:04:26.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-32-of-2024/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1025,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/08/spf-record-tester.jpg","caption":"cybersecurity","width":900,"height":506},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
