---
title: "WPS Office Exploit, Notion Exits Russia, Uber’s $325M Fine, Cybersecurity News [August 26, 2024] | DuoCircle"
description: "WPS Office Exploit, Notion Exits Russia, Uber’s $325M Fine, Cybersecurity News [August 26."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-36-of-2024/"
---

Quick Answer

Cybersecurity news for the week of August 26, 2024\. The South Korea-linked APT-C-60 group exploited CVE-2024-7262 in WPS Office to deploy the SpyGlace backdoor against East Asian targets, abusing how the software handles custom protocol handlers; Kingsoft's initial patch was incomplete. Notion announced it would terminate Russia-based accounts on September 9, 2024, in response to US sanctions on software providers. Uber was fined $325 million by Dutch regulators for illegal driver-data transfers from Europe to the US. Microsoft also documented Tickler malware targeting US government systems, and the FBI reported RansomHub had hit 210 victims.

WPS Office Exploit, Notion Exits Russia, Uber’s $325M Fine, Cybersecurity News \[August 26, 2024\]

Your browser does not support the audio element.

[ Download episode](https://media.mailhop.org/duocircle/images/2024/09/WPS-Office-Exploit-Notion-Exits-Russia-Ubers-325M-Fine-–-Cybersecurity-News-August-26-2024.mp3) 

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-36-of-2024%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=WPS%20Office%20Exploit%2C%20Notion%20Exits%20Russia%2C%20Uber%E2%80%99s%20%24325M%20Fine%2C%20Cybersecurity%20News%20%5BAugust%2026%2C%202024%5D&url=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-36-of-2024%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-36-of-2024%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-36-of-2024%2F&title=WPS%20Office%20Exploit%2C%20Notion%20Exits%20Russia%2C%20Uber%E2%80%99s%20%24325M%20Fine%2C%20Cybersecurity%20News%20%5BAugust%2026%2C%202024%5D "Share on Reddit") [ ](mailto:?subject=WPS%20Office%20Exploit%2C%20Notion%20Exits%20Russia%2C%20Uber%E2%80%99s%20%24325M%20Fine%2C%20Cybersecurity%20News%20%5BAugust%2026%2C%202024%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-36-of-2024%2F "Share via Email") 

![Cybersecurity News](https://media.mailhop.org/duocircle/images/2024/09/spf-validator.jpg) 

We’re back with the latest [cybersecurity](/) scoop of the week that will keep you privy to the latest attacks and help you stay safe. This week, we’ll take a look at how hackers are leveraging the WPS office to spread malware, the withdrawal of Notion from Russia, how [Uber was fined $325 million](https://www.bleepingcomputer.com/news/legal/uber-fined-325-million-for-moving-driver-data-from-europe-to-us/) for illegal data transfers, the Tickler malware attacking US government systems, and the **FBI’s report** on RansomHub ransomware’s 210 victims and the tactics used. Let’s take a look!

## South Korean Hackers Leveraged WPS Office Vulnerability to Spread Malware

[APT-C-60](https://thehackernews.com/2024/08/apt-c-60-group-exploit-wps-office-flaw.html) hackers have been leveraging zero-day code execution flaws in **WPS Office for Windows systems** and installing the SpyGlace backdoor.

The [threat actor](/email-security/threat-actors-attack-thousands-of-computers-following-the-ion-incident/) group is a South Korea-aligned cyberespionage group and is [targeting East Asians](https://www.voanews.com/a/usa%5Frace-america%5Fhate-crimes-targeting-asian-americans-spiked-150-major-us-cities/6202736.html). The flaw that they are using is the **CVE-2024-7262**, which has been popular in attacks since February this year. The patch was patched by Kingsoft back in March, the Chinese enterprise behind WPS Office. However, they did this silently, without informing its customers, and researchers at ESET were able to investigate the vulnerability and the exploitation. ESET shared that the vulnerability lies where the software handles custom protocol handles. _There’s improper validation of the URLs used within documents that allows threat actors to craft and use malicious links, leading to code execution_. APT-C-60 has been misusing this and [embedding malicious](https://abcnews.go.com/Technology/hackers-embed-malicious-links-websites-stars-biel/story?id=8477614) hyperlinks in decoy images that trigger exploits whenever a victim clicks on said images. An encoded command is triggered that loads malicious DLLs with the threat actor’s code and installs SpyGlace, their custom backdoor.

ESET also [shared](https://www.welivesecurity.com/en/eset-research/analysis-of-two-arbitrary-code-execution-vulnerabilities-affecting-wps-office/) how Kingsoft’s attempt at fixing the flaw failed and they released an incomplete patch. Threat actors can still exploit the vulnerability via **local systems or network sharing**.

## Notion Withdraws From Russia, Plans to Shut down Accounts by September

Notion released an [announcement sharing](https://www.notion.so/help/restrictions-for-customers-based-in-russia) that they are exiting Russia and will terminate all accounts linked to **Russian users**.

Notion’s decision came after the US government-imposed restrictions on software service providers, so Notion will stop all activity and **end-user access** to its platform on 9 September 2024\. The application has been a great productivity tool for document creation and task management, with tons of **collaboration tools and databases** that are used by millions globally. They will delete all Russian-based accounts and have given time till 8 September to extract all data, after which it will no longer be possible. _If the admins have imposed exporting restrictions, you may not be able to download any internal data_. However, if there are massive files, you will not be able to download them directly from the platform, and Notion will send a download link to your email.

All the impacted users were already sent closure notices of their accounts. You can find all help [in this guide](https://www.notion.so/help/export-your-content) that shows how you can export the data in **PDF, HTML, or CSV files**.

[![ GDPR (General Data Protection Regulation)](https://media.mailhop.org/duocircle/images/2024/09/spf-permerror-3759.jpg)](https://media.mailhop.org/duocircle/images/2024/09/spf-permerror-3759.jpg)

## Uber Faces $325 Million Fine for Illegally Transferring Driver Data From Europe to the US

In other news, the Autoriteit Persoonsgegevens (**Dutch Data Protection Authority**) [fined](https://autoriteitpersoonsgegevens.nl/system/files?file=2024-08/Besluit%20boete%20Uber%20doorgifte%20naar%20VS.pdf) Uber over [GDPR (General Data Protection Regulation)](https://www.investopedia.com/terms/g/general-data-protection-regulation-gdpr.asp) €290 million ($325 million).

This is the third fine by the authority on Uber, following €6 million and €10 million fines from November 2018 and January 2024, respectively. Autoriteit Persoonsgegevens has been investigating the organization’s data practices for quite a while and noticed complaints from French drivers. According to the Schrems II ruling, the [EU-US privacy](https://www.darkreading.com/cloud-security/eu-us-privacy-shield-what-now-what-next-) shield was invalidated because the [data protection](https://www.techtarget.com/searchdatabackup/definition/data-protection) standards in the US are not enough. Uber did not follow the ruling and continued to transfer personal data to the US without implementing proper safeguards. _In response, Uber argued that no data transfers occurred as all data was uploaded directly to **US-based servers** via the application, but these arguments were rejected._

Uber has filed for an appeal against the decisions, which might take as long as four years, so the fine is **suspended for this duration**.

## Tickler Malware Targets US Government and Defense Organizations for Unauthorized Access

The APT33 Iranian threat actors (also called [Peach Sandstorm](https://www.infosecurity-magazine.com/news/iran-peach-sandstorm-hackers/)) have been installing backdoors onto **US and UAE government**, defense, oil, gas, and other sectors using the [new Tickler malware](https://www.securityweek.com/iranian-hackers-use-new-tickler-malware-to-collect-intel-from-us-uae/).

Microsoft’s security researchers have been observing the attack tactics where these threat actors use the infrastructure of MS Azure for C2 (Command and Control) via [fraud subscriptions](https://www.usatoday.com/story/news/nation/2024/08/27/minnesota-magazine-scam-2-sentenced-in-300-million-64-person-case/74971581007/). _APT33 carried out many organizations of said sectors between April and May this year and gained access to accounts by leveraging commonly used passwords_. They used the same tactic to deploy FalseFont backdoor [malware](/resources/malware-and-its-defense-mechanism) on **defense contractor devices** back in November 2023, but now they seem to have switched to Tickler.

[Microsoft](https://www.microsoft.com/en-us/security/blog/2024/08/28/peach-sandstorm-deploys-new-custom-tickler-malware-in-long-running-intelligence-gathering-operations/) also shared that APT33 has been targeting accounts of defense, pharma, and satellite organizations using [password spray attacks](https://www.darkreading.com/remote-workforce/cisco-warns-of-massive-surge-in-password-spraying-attacks-on-vpns), and they will mandate MFA for all Azure sign-ins from 15 October 2024 to protect all users.

**[![ password spray attacks](https://media.mailhop.org/duocircle/images/2024/09/spf-record-generator.jpg)](https://media.mailhop.org/duocircle/images/2024/09/spf-record-generator.jpg)**

## FBI Reports RansomHub Ransomware Attacked 210 Victims Since February

Affiliates of the [RansonHub](https://cybernews.com/security/ransomware-newcomer-ransomhub-claiming-one-victim-per-day/) ransomware have attacked nearly 210 organizations since February, most of which are **critical infrastructure enterprises** in the US.

RansomHub is a new Raas (Ransomware as a Service) operation that steals files for demanding ransoms, and if they are not paid, the data is sold to the highest bidders. _This is slightly different as they do not always encrypt the data like other ransomware do and just steal it_. FBI released a joint advisory with CISA, [HHS (Department of Health and Human Services)](https://en.wikipedia.org/wiki/United%5FStates%5FDepartment%5Fof%5FHealth%5Fand%5FHuman%5FServices), and MS-ISAC (Multi-State Information Sharing and Analysis Center) and also highlighted that many of these are also [double-extortion attacks](https://www.securitymagazine.com/articles/99969-ransomware-double-extortion-attacks-increased-72). Since February, RansomHub has targeted 210 organizations in water, IT, government, facilities, healthcare, public health, food and agriculture, **financial services**, critical manufacturing, communications, and transportation sectors. To stay safe against the threat, it’s best to implement the recommendations [shared](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-242a) in the advisory.

Most of these are straightforward, like [implementing MFA](https://medium.com/@biswas.rai101/step-by-step-guide-to-implementing-mfa-in-your-current-system-b1c19cf2b896) and strong passwords and using VPNs on critical system accounts. You should also **keep all software updated** and carry out [vulnerability assessments](https://www.fortinet.com/resources/cyberglossary/vulnerability-assessment) regularly.

## Topics

cyber securityNewsUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-36-of-2024%2F) [ ](https://twitter.com/intent/tweet?text=WPS%20Office%20Exploit%2C%20Notion%20Exits%20Russia%2C%20Uber%E2%80%99s%20%24325M%20Fine%2C%20Cybersecurity%20News%20%5BAugust%2026%2C%202024%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-36-of-2024%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-36-of-2024%2F) Copy 

Related Articles

- [ ![cybersecurity news](https://media.mailhop.org/duocircle/images/2025/01/spf-permerror.jpg)  Microsoft Cybersecurity Transparency, Chrome Update Required, Google Calendar Phishing, Cybersecurity News \[December 23, 2024\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2025/)
- [ ![cybersecurity news](https://media.mailhop.org/duocircle/images/2026/01/email-smtp-service-7865.jpg)  Trust Wallet Hack, Browser Extension Espionage, Unleash Protocol Loss, Cybersecurity News \[December 29, 2025\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2026/)
- [ ![cybersecurity news](https://media.mailhop.org/duocircle/images/2025/03/phishing-protection-5643.jpg)  Bybit’s $1.5B Loss, FatalRAT Hits APAC, GitVenom Targets Wallets,, Cybersecurity News \[February 24, 2025\] News ](/blog/announcements/cyber-security-news-update-week-10-of-2025/)
- [ ![cybersecurity news](https://media.mailhop.org/duocircle/images/2026/03/email-smtp-service-6670.jpg)  LastPass Users Phished, Amazon Down US, UK Cybersecurity Boost, Cybersecurity News \[March 02, 2026\] News ](/blog/announcements/cyber-security-news-update-week-10-of-2026/)

## Related Articles

[  News 6m  Microsoft Cybersecurity Transparency, Chrome Update Required, Google Calendar Phishing, Cybersecurity News \[December 23, 2024\]  Jan 2, 2025 ](/blog/announcements/cyber-security-news-update-week-1-of-2025/)[  News 6m  Trust Wallet Hack, Browser Extension Espionage, Unleash Protocol Loss, Cybersecurity News \[December 29, 2025\]  Jan 5, 2026 ](/blog/announcements/cyber-security-news-update-week-1-of-2026/)[  News 7m  Bybit’s $1.5B Loss, FatalRAT Hits APAC, GitVenom Targets Wallets,, Cybersecurity News \[February 24, 2025\]  Mar 3, 2025 ](/blog/announcements/cyber-security-news-update-week-10-of-2025/)[  News 6m  LastPass Users Phished, Amazon Down US, UK Cybersecurity Boost, Cybersecurity News \[March 02, 2026\]  Mar 9, 2026 ](/blog/announcements/cyber-security-news-update-week-10-of-2026/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"WPS Office Exploit, Notion Exits Russia, Uber’s $325M Fine, Cybersecurity News [August 26, 2024]","description":"WPS Office Exploit, Notion Exits Russia, Uber’s $325M Fine, Cybersecurity News [August 26.","url":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-36-of-2024/","datePublished":"2024-09-02T18:52:34.000Z","dateModified":"2025-08-21T18:53:55.000Z","dateCreated":"2024-09-02T18:52:34.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-36-of-2024/"},"articleSection":"announcements","keywords":"cyber security, News, Updates","wordCount":1011,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/09/spf-validator.jpg","caption":"Cybersecurity News","width":900,"height":506},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"WPS Office Exploit, Notion Exits Russia, Uber’s $325M Fine, Cybersecurity News [August 26, 2024]","item":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-36-of-2024/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"WPS Office Exploit, Notion Exits Russia, Uber’s $325M Fine, Cybersecurity News [August 26, 2024]","item":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-36-of-2024/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"WPS Office Exploit, Notion Exits Russia, Uber’s $325M Fine, Cybersecurity News [August 26, 2024]","description":"WPS Office Exploit, Notion Exits Russia, Uber’s $325M Fine, Cybersecurity News [August 26.","url":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-36-of-2024/","datePublished":"2024-09-02T18:52:34.000Z","dateModified":"2025-08-21T18:53:55.000Z","dateCreated":"2024-09-02T18:52:34.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-36-of-2024/"},"articleSection":"announcements","keywords":"cyber security, News, Updates","wordCount":1011,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/09/spf-validator.jpg","caption":"Cybersecurity News","width":900,"height":506},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
