---
title: "Microsoft Update Dilemma, Cyberattack Disrupts LKQ, Krispy Kreme Breach, Cybersecurity News [December 16, 2024] | DuoCircle"
description: "Microsoft Update Dilemma, Cyberattack Disrupts LKQ, Krispy Kreme Breach, Cybersecurity News [December 16."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-52-of-2024/"
---

Quick Answer

Cybersecurity news for the week of December 16, 2024\. Microsoft's December Patch Tuesday addressed 71 vulnerabilities including a new zero-day, but warned that PCs without TPM 2.0 hardware would lose access to future Windows 11 security fixes if upgraded, leaving roughly 400 million users in limbo. Cybercrime trends covered crypto-romance scams and the digital-arrest scam. A cyberattack on auto parts firm LKQ disrupted its Canadian unit. Krispy Kreme disclosed a breach impacting online ordering. Guidance focused on patching decisions and user awareness.

Microsoft Update Dilemma, Cyberattack Disrupts LKQ, Krispy Kreme Breach, Cybersecurity News \[December 16, 2024\]

Your browser does not support the audio element.

[ Download episode](https://media.mailhop.org/duocircle/images/2024/12/Microsoft-Update-Dilemma-Cyberattack-Disrupts-LKQ-Krispy-Kreme-Breach-–-Cybersecurity-News-December-16-2024.mp3) 

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-52-of-2024%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Microsoft%20Update%20Dilemma%2C%20Cyberattack%20Disrupts%20LKQ%2C%20Krispy%20Kreme%20Breach%2C%20Cybersecurity%20News%20%5BDecember%2016%2C%202024%5D&url=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-52-of-2024%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-52-of-2024%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-52-of-2024%2F&title=Microsoft%20Update%20Dilemma%2C%20Cyberattack%20Disrupts%20LKQ%2C%20Krispy%20Kreme%20Breach%2C%20Cybersecurity%20News%20%5BDecember%2016%2C%202024%5D "Share on Reddit") [ ](mailto:?subject=Microsoft%20Update%20Dilemma%2C%20Cyberattack%20Disrupts%20LKQ%2C%20Krispy%20Kreme%20Breach%2C%20Cybersecurity%20News%20%5BDecember%2016%2C%202024%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-52-of-2024%2F "Share via Email") 

![cybersecurity news](https://media.mailhop.org/duocircle/images/2024/12/sender-policy-framework-7.jpg) 

Cybercriminals are intelligent and innovative, proactively searching for notorious ideas to launch their cyberattacks. This week’s news article discusses two innovative methods that [threat actors](/email-security/what-threat-actor-can-do-with-your-emails-without-password/) consider, the [crypto-romance scammers](https://www.infosecurity-magazine.com/news/crypto-scams-reach-new-heights-fbi/) and the digital arrest scam. Nowadays cyber attackers are willing to target almost anything, we will learn about the two attacks that targeted on an online doughnut chain and an **auto parts company**. _Hence, efforts are being made on grounds of user awareness and system updates that should help prevent such attacks_. But downloading and installing updates can also be confusing so we have also discussed whether to download the latest [Microsoft system update](/dmarc/microsofts-latest-updates-help-domain-owners-fight-modern-phishing-with-dmarc/) or not. Read on to learn more. 

## Microsoft Updates Confusion, To Download Or Not To Download?

_Microsoft released its December Patch_ _last Tuesday, containing a list of 71 vulnerabilities, including a new zero-day version_. So, can users safely download it? Yes, [Windows 11 users can download these updates](https://www.forbes.com/sites/zakdoffman/2024/12/14/microsoft-warns-400-million-windows-users-do-not-update-your-pc/), but what about users working on earlier Windows versions? Microsoft states that all users can download these updates but warns them that they could lose access to future security fixes if they update their PCs. So, it has become a million-dollar question for **nearly 400 million users**. 

What is the confusion about? Migrating to Windows 11 from earlier versions requires users to ensure that their PCs meet the **TPM 2.0 Hardware Hurdle**. So, PCs without the minimum system requirement cannot upgrade to Windows 11\. However, with Windows 10 approaching the end of its lifespan, Microsoft has changed its stance and issued instructions for installing Windows 11 on incompatible PCs, including the rider that they will lose Windows 11 support. Should users download the latest [December patch](https://news.sophos.com/en-us/2024/12/11/december-patch-tuesday-arrives-bearing-71-gifts/) or not is an unanswered question. 

The solution is to install the TPM 2.0 hardware and then **upgrade to Windows 11**.

## Cyberattack On Auto Parts Firm LKQ Disrupts The Canadian Business Unit

LKQ Corporation, a major US auto parts supplier, informed the SEC of a [cyberattack that caused massive disruptions](https://www.securityweek.com/major-auto-parts-firm-lkq-hit-by-cyberattack/) to its Canadian business unit. LKQ has over 45,000 employees working at more than 1600 locations across two dozen nations. The [company has revealed](https://www.sec.gov/Archives/edgar/data/1065696/000106569624000134/lkq-20241213.htm) in its 8-K filing with the SEC that cybercriminals had unauthorizedly accessed one of its business units in Canada on November 13, 2024\. This attack disrupted its business activities for a few weeks before the company contained the threat. No one has taken responsibility for the attack, but still, many consider it a ransomware attack. However, the company is working at **near-full operation today**.

_That brings us to the dangers that ransomware attacks can cause to companies globally_. Therefore, organizations must equip themselves to thwart any such attack. **Store data on independent**, stand-alone servers to enhance [ransomware protection](/resources/locky-ransomware). Secondly, creating awareness among its employees is another way of countering ransomware because they learn how to handle suspicious files, emails, and document attachments.

[![cyberattack](https://media.mailhop.org/duocircle/images/2024/12/email-sending-services-4935.jpg)](https://media.mailhop.org/duocircle/images/2024/12/email-sending-services-4935.jpg)

## Krispy Kreme Doughnuts Cybersecurity Breach

Ordering delicious doughnuts online is fun, but users must be aware of cyberattacks that can disrupt online systems. Recently, the doughnut chain Krispy Kreme was hit by a [cyberattack](https://www.bbc.com/news/articles/c4gl9np1g2go) that affected the online ordering of doughnuts. Krispy Kreme reported this cyberattack in its **latest regulatory filing** with the SEC. While online activity was disrupted, the cyberattack did not have a material impact on its brick-and-mortar stores.

No cybercriminal group has claimed responsibility for the attack. However, **Krispy Kreme** has told BBC that it has taken steps to investigate and contain the incident by bringing in [cybersecurity](/) experts. The team is working hard to restore online ordering. _Meanwhile, the company has stated in its SEC filing that it has cybersecurity insurance, which allows it to offset the loss_.

This attack proves that cybercriminals have no favorites when launching cyberattacks. 

## Nigeria Arrests Nearly 800 Honey-Trap Crypto-Romance Scammers

[Cybercriminals](https://thehackernews.com/2024/11/cybercriminals-use-excel-exploit-to.html) keep innovating novel ways to target victims. Luring prospective victims with offers of romance is nothing new, but the technique has evolved considerably, with malicious actors demanding victims to hand over cash for phony cryptocurrency transactions. The **Nigerian anti-graft agency** has tightened its screws on such scams by arresting nearly [800 suspected fraudsters](https://www.reuters.com/world/africa/almost-800-arrested-over-nigerian-crypto-romance-scam-2024-12-16/) in a raid on a premise believed to be a cybercrime hub. 

_Educating people is the only way to counter these threats_. Therefore, one should know how these attacks operate. These criminals contact their targets through [social media](/email-security/simple-social-media-security-practices-your-business-should-adopt/) and platforms like **Instagram and WhatsApp**. After gaining their confidence, they seduce them online and offer lucrative investment opportunities. This leads them to pressure victims to transfer money for cake cryptocurrency schemes. 

How do you identify a [cryptocurrency scam](https://news.sophos.com/en-us/2024/02/02/cryptocurrency-scams-metastasize-into-new-forms/)? People should realize that any scheme that offers unrealistic returns in a **short period and sounds too good** to be true is a red flag. They should avoid responding to such messages and be on their guard. 

## Digital Arrest Scam Is The Latest Cyberthreat In Town Today

Digital payments are the order of the day. India is leading the global arena in digital payments with innovative techniques like [Unified Payments Interface(UPI)](https://www.investopedia.com/terms/u/unified-payment-interface-upi.asp), which have made digital transactions most convenient. Users can make s**ecure digital payments** using their mobile phones. However, these innovative techniques have their flipside, as well. 

[![Beware of digital arrest scam](https://media.mailhop.org/duocircle/images/2024/12/sendgrid-alternative-1.jpg)](https://media.mailhop.org/duocircle/images/2024/12/sendgrid-alternative-1.jpg)

The Digital Arrest Scam is one such type of online fraud where [malicious actors](https://www.securitymagazine.com/articles/100953-new-research-malicious-actors-are-imitating-tech-companies) impersonate income tax and other law-enforcement officials to target gullible victims. How does the scam work? Cybercriminals contact victims through phone or video calls and falsely implicate them in legal cases such as tax evasion and money laundering. _They create a sense of fear and urgency in the victims to threaten them with immediate arrest unless they pay a ransom or share confidential information_. Sometimes, they create false scenarios like a fake police station and engage in video calls with their victims to make their victims believe that they are dealing with **genuine law enforcement agencies**.

The best way to **prevent becoming a victim** of the [Digital Arrest Scam](https://www.cnbctv18.com/technology/digital-arrest-financial-fraud-scam-how-to-stay-safe-tips-npci-19523958.htm) is to ignore calls and messages from unknown numbers, especially those claiming to be from government agencies like the police. The police never call their suspects over the phone. They have the power to visit your homes and question you if necessary. If you suspect a scam or have become a victim, you can report it to law-enforcing agencies to take further action.

## Topics

cyber securityNewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-52-of-2024%2F) [ ](https://twitter.com/intent/tweet?text=Microsoft%20Update%20Dilemma%2C%20Cyberattack%20Disrupts%20LKQ%2C%20Krispy%20Kreme%20Breach%2C%20Cybersecurity%20News%20%5BDecember%2016%2C%202024%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-52-of-2024%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-52-of-2024%2F) Copy 

Related Articles

- [ ![cybersecurity news](https://media.mailhop.org/duocircle/images/2025/01/spf-permerror.jpg)  Microsoft Cybersecurity Transparency, Chrome Update Required, Google Calendar Phishing, Cybersecurity News \[December 23, 2024\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2025/)
- [ ![cybersecurity news](https://media.mailhop.org/duocircle/images/2026/01/email-smtp-service-7865.jpg)  Trust Wallet Hack, Browser Extension Espionage, Unleash Protocol Loss, Cybersecurity News \[December 29, 2025\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2026/)
- [ ![cybersecurity news](https://media.mailhop.org/duocircle/images/2025/03/phishing-protection-5643.jpg)  Bybit’s $1.5B Loss, FatalRAT Hits APAC, GitVenom Targets Wallets,, Cybersecurity News \[February 24, 2025\] News ](/blog/announcements/cyber-security-news-update-week-10-of-2025/)
- [ ![cybersecurity news](https://media.mailhop.org/duocircle/images/2026/03/email-smtp-service-6670.jpg)  LastPass Users Phished, Amazon Down US, UK Cybersecurity Boost, Cybersecurity News \[March 02, 2026\] News ](/blog/announcements/cyber-security-news-update-week-10-of-2026/)

## Related Articles

[  News 6m  Microsoft Cybersecurity Transparency, Chrome Update Required, Google Calendar Phishing, Cybersecurity News \[December 23, 2024\]  Jan 2, 2025 ](/blog/announcements/cyber-security-news-update-week-1-of-2025/)[  News 6m  Trust Wallet Hack, Browser Extension Espionage, Unleash Protocol Loss, Cybersecurity News \[December 29, 2025\]  Jan 5, 2026 ](/blog/announcements/cyber-security-news-update-week-1-of-2026/)[  News 7m  Bybit’s $1.5B Loss, FatalRAT Hits APAC, GitVenom Targets Wallets,, Cybersecurity News \[February 24, 2025\]  Mar 3, 2025 ](/blog/announcements/cyber-security-news-update-week-10-of-2025/)[  News 6m  LastPass Users Phished, Amazon Down US, UK Cybersecurity Boost, Cybersecurity News \[March 02, 2026\]  Mar 9, 2026 ](/blog/announcements/cyber-security-news-update-week-10-of-2026/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Microsoft Update Dilemma, Cyberattack Disrupts LKQ, Krispy Kreme Breach, Cybersecurity News [December 16, 2024]","description":"Microsoft Update Dilemma, Cyberattack Disrupts LKQ, Krispy Kreme Breach, Cybersecurity News [December 16.","url":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-52-of-2024/","datePublished":"2024-12-23T15:44:39.000Z","dateModified":"2025-04-16T15:22:19.000Z","dateCreated":"2024-12-23T15:44:39.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-52-of-2024/"},"articleSection":"announcements","keywords":"cyber security, News, Security, Updates","wordCount":1056,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/12/sender-policy-framework-7.jpg","caption":"cybersecurity news","width":900,"height":506},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Microsoft Update Dilemma, Cyberattack Disrupts LKQ, Krispy Kreme Breach, Cybersecurity News [December 16, 2024]","item":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-52-of-2024/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Microsoft Update Dilemma, Cyberattack Disrupts LKQ, Krispy Kreme Breach, Cybersecurity News [December 16, 2024]","item":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-52-of-2024/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Microsoft Update Dilemma, Cyberattack Disrupts LKQ, Krispy Kreme Breach, Cybersecurity News [December 16, 2024]","description":"Microsoft Update Dilemma, Cyberattack Disrupts LKQ, Krispy Kreme Breach, Cybersecurity News [December 16.","url":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-52-of-2024/","datePublished":"2024-12-23T15:44:39.000Z","dateModified":"2025-04-16T15:22:19.000Z","dateCreated":"2024-12-23T15:44:39.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-52-of-2024/"},"articleSection":"announcements","keywords":"cyber security, News, Security, Updates","wordCount":1056,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/12/sender-policy-framework-7.jpg","caption":"cybersecurity news","width":900,"height":506},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
