---
title: "Cybersecurity News Update, Week 39 of 2022 | DuoCircle"
description: "This week’s cybersecurity bulletin covers headlines that gained attention from the cybersecurity community, extending from pig butchering crypto scams."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/weekly-cyber-news-updates-week-39-of-2022/"
---

Quick Answer

Week 39 of 2022 cybersecurity highlights: the FBI warned about pig butchering crypto romance scams after a victim lost $1 million; Fortinet patched CVE-2022-40684, an authentication bypass on FortiGate, FortiSwitch Manager, and FortiProxy admin interfaces affecting more than 100,000 internet-reachable firewalls; Trellix tracked a callback phishing campaign (BazarCall successor) impersonating Geek Squad, McAfee, PayPal, Norton, and Microsoft to drop ClickOnce malware; Binance Bridge lost 2 million BNB ($566 million) to a forged-proof exploit on the BSC Token Hub; the US Defense Industrial Base disclosed a 10-month breach using CovalentStealer, Impacket, and ProxyLogon-era Exchange exploits; and Netwalker affiliate Sebastien Vachon-Desjardins received 20 years and a $21.5 million forfeiture order.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fweekly-cyber-news-updates-week-39-of-2022%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cybersecurity%20News%20Update%2C%20Week%2039%20of%202022&url=undefined%2Fblog%2Fannouncements%2Fweekly-cyber-news-updates-week-39-of-2022%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fweekly-cyber-news-updates-week-39-of-2022%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fweekly-cyber-news-updates-week-39-of-2022%2F&title=Cybersecurity%20News%20Update%2C%20Week%2039%20of%202022 "Share on Reddit") [ ](mailto:?subject=Cybersecurity%20News%20Update%2C%20Week%2039%20of%202022&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fweekly-cyber-news-updates-week-39-of-2022%2F "Share via Email") 

![cybersecurity update](https://media.mailhop.org/duocircle/images/2022/10/check-dmarc-record.jpg) 

This week’s [cybersecurity](/) bulletin covers headlines that gained attention from the cybersecurity community, extending from pig butchering crypto scams, malware drops, Fortinet vulnerabilities, cryptocurrency theft, **data breaches**, and ransomware affiliate getting 20 years in prison. Let us see the top cybersecurity news this week.

## Pig Butchering Crypto Scams Targeting Investors

[Pig butchering scams](https://www.indiatimes.com/explainers/news/the-rise-of-pig-butchering-scams-584184.html) are on the rise, with threat actors using **social engineering tactics** to initiate romantic relationships or building up trust to pressure the victim to invest in bogus crypto schemes. The FBI (Federal Bureau of Investigation) has [warned](https://www.ic3.gov/Media/Y2022/PSA221003) about these “Pig Butchering” cryptocurrency scams.

The threat actors use social media to scout profiles, initiate contact, and engage in long-term communication for friendship or romantic partnerships. After gaining the victim’s trust, the threat actors bring out **fake investment schemes** with the promise of significant rewards.

Once the victim engages in the phony scheme, the fraudsters reel them in further to squeeze out as much crypto as possible, asking them to pay income taxes, processing charges, or international transaction fees for withdrawals. Many victims were also duped into making **wire transfers** to accounts overseas or purchasing credit cards.

Pig Butchering scams are the latest in this week’s cybersecurity news, with Forbes sharing the story of a 52-year-old man losing [$1 million](https://www.forbes.com/sites/cyrusfarivar/2022/09/09/pig-butchering-crypto-super-scam/?sh=2d6000d8ec8e) in one such scam. It would be best to look out for **unsolicited messages** or even from those claiming to be long-lost friends or acquaintances.

[![threat actors](https://media.mailhop.org/duocircle/images/2022/10/email-sending-services-8811.jpg)](https://media.mailhop.org/duocircle/images/2022/10/email-sending-services-8811.jpg)

## Fortinet Admins Beware: Critical Auth Bypass Bug Needs Fixing

Fortinet suffered the [CVE-2022-40684](https://www.fortinet.com/blog/psirt-blogs/update-regarding-cve-2022-40684), a security flaw that allowed threat actors to **bypass authentication** on admin panels and take control of devices. After discovering the security flaw, Fortinet has advised admins to update FortiGate firewalls, FortiSwitch Manager, and FortiProxy web proxies.

The Fortinet vulnerability is critical, [allowing](https://twitter.com/Gi7w0rm/status/1578299492822003712) unauthenticated threat actors to perform admin operations by accessing the admin interface using crafted HTTP or HTTPS (Hypertext Transfer Protocol Secure) requests. With over **100,000 FortiGate firewalls** reachable via the web, it is a significant flaw that needs immediate attention. The Fortinet vulnerability affects various products, versions 7.0.0 to 7.0.6 and from 7.2.0 to 7.2.1 of FortiOS, versions 7.0.0 to 7.0.6 and 7.2.0 of FortiProxy, and versions 7.0.0 and 7.2.0 of FortiSwitch Manager.

Fortinet released security patches and urged customers to update all devices. However, suppose organizations are unable to download security patches. In that case, they can block these [threat actors](/email-security/threat-actors-abuse-linkedins-smart-links-in-evasive-email-phishing-attacks/) by limiting the IP (Internet Protocol) addresses that reach the admin interface by **utilizing a local-in-policy**.

## Malware Drops via Evolving Callback Phishing Attacks

Threat actors are evolving and developing [social engineering](https://www.techtarget.com/searchsecurity/definition/social-engineering) techniques, using fake subscriptions to bait individuals and posing as customer support to provide infection or hack guidance. The phishing campaign infects systems with **malware loaders** that drop remote access trojans, [ransomware](/email-security/ransomware-report-2022-the-top-5-ransomware-and-malware-groups-making-strides-this-year/), and key loggers.

Callback [phishing attacks](/content/phishing-prevention/phishing-attacks) are rising, baiting individuals with **high-priced subscriptions** to confuse recipients and providing numbers and emails that victims can contact to cancel the subscriptions. However, the support on the other side dupes victims and installs malware on their devices. This callback phishing campaign was [discovered](https://www.trellix.com/en-us/about/newsroom/stories/research/evolution-of-bazarcall-social-engineering-tactics.html) by Trellix and targeted the _US, Canada, UK, India, China, and Japan_.

The callback phishing campaign started in 2021 as BazarCall, sending subscription invoices for streaming services or medical, urging individuals to contact a phone number to cancel purchases. The recent attack baits individuals similarly with an invoice for _Geek Squad, McAfee, PayPal, Norton, or Microsoft._

When the individual contacts the number, the threat actor declares no matching entries were found, convincing individuals that a **malware infection** is present on their system and forwarding them to a technical specialist, another threat actor then “aids” the victim and downloads malware disguised **as an anti-virus**.

The callback phishing campaign dropped malware that pushed **ClickOnce executables** when launched and installed remote access tools, allowing threat actors to perform operations on the system, install fake lock screens, and lock the victim out of the system. It would be best to watch the [callback phishing](https://www.bleepingcomputer.com/news/security/callback-phishing-attacks-evolve-their-social-engineering-tactics/) campaign and **cross-check all information** on authentic websites.

## Binance Bridge loses $566 million to Hacker

Binance Bridge lost 2 million BNB (Binance Coins), with a value of $566 million, to threat actors. The threat actor stole the sum, with their wallet receiving two transactions, with 1 million BNB each.

The CEO of Binance, Changpeng Zhao, [tweeted](https://twitter.com/cz%5Fbinance/status/1578171072067031042) about the incident after its discovery, pointing out that cross-chain bridge exploits of the BSC Token Hub resulted in extra Binance coins, explaining how individual’s funds are safe, and validators had suspended the **BSC (Binance Smart Chain)** temporarily. Most of the stolen cryptocurrency remains on the BSC and is inaccessible to the threat actor.

However, the threat actor took about **$70-$80 million off-chain**. Binance has been working with partners, pursuing the stolen crypto, and has already frozen an additional $7 million in off-chain funds. The attack on the BSC stirred the crypto community again, and Binance resumed all operations at 2:30 AM EST.

Following the attack, Binance apologized to its community for the incident, thanked partners and validators for aiding in securing a significant amount from the stolen $566 million, and will release a detailed report of the incident later. Binance has clarified that the exploit was the **forgery of low-level proofs** into a single shared library.

[![data breach](https://media.mailhop.org/duocircle/images/2022/10/email-smtp-service-7611.jpg)](https://media.mailhop.org/duocircle/images/2022/10/email-smtp-service-7611.jpg)

## Data breach at the US Defense Industrial Base

The US Government suffered a data breach from state-backed hackers and stole data from the [DIB (Defense Industrial Base).](https://en.wikipedia.org/wiki/Defense%5Findustrial%5Fbase) The threat actors used custom Covalent Stealer malware with the Impacket framework to carry out the data breach that lasted ten months.

The DIB entries contain product and service information for the deployment of military operations. Multiple threat actors were persistent in the data breach effort, utilizing [CovalentStealer](https://www.bleepingcomputer.com/news/security/hackers-stole-data-from-us-defense-org-using-impacket-covalentstealer/), Impacket collection of Python classes, remote access trojans, **VPNs (Virtual Private Networks)**, and China Chopper web shells.

The threat actors exploited ProxyLogon vulnerabilities that were zero days at the time of the attack on the Microsoft Exchange Server used by the DIB. After initial access, the threat actors started mailbox searches, compromising admin accounts to access services for **sending and receiving web service** communication from clients.

Following the attack, CISA (Cybersecurity and Infrastructure Security Agency) has provided a detailed [report on the Covalent Stealer malware](https://www.cisa.gov/uscert/ncas/analysis-reports/ar22-277a) and its resource library for encryption, decryption, and secure communications. Furthermore, CISA has also shared the [details of the HyperBro RAT](https://www.cisa.gov/uscert/ncas/analysis-reports/ar22-277b) (Remote Access Trojan) that can download or upload files from compromised systems, l**og keystrokes**, and bypass user account control.

## 20 Years in Prison for Ransomware Affiliate

Ransomware affiliate Sebastien Vachon-Desjardins has been sentenced to [20 years](https://www.documentcloud.org/documents/23118450-judgment-as-to-sebastien-vachon-desjardins) and demanded $21.5 million for his cyberattacks, with 27.65 Bitcoin held by law enforcement credited towards the same.

The Canadian cybercriminal pleaded guilty in a Florida court and was sentenced considering the following charges, “Conspiracy to commit _computer fraud, wire fraud, intentional damage_ to protected computers, and transmitting a demand about **damaging protected systems**.

[Netwalker](https://www.upguard.com/blog/what-is-netwalker-ransomware#:~:text=Netwalker%20ransomware%20is%20a%20Window's,decryption%20of%20the%20compromised%20data.) was a [Raas (Ransomware as a service)](https://www.crowdstrike.com/cybersecurity-101/ransomware/ransomware-as-a-service-raas/) model launched in 2019 that hired affiliates to deploy the ransomware in exchange for a share. Sebastien is believed to have conducted attacks worldwide, targeting US organizations and 17 Canadian ones, stealing corporate data and **encrypting their devices**, and demanding ransoms.

The Canadian threat actor was bought in on 27 January 2021 when law enforcement seized almost $800,000 and 719 Bitcoin from his address and was sentenced to 6 years and 8 months. With his current sentence of 20 years with an additional three years of supervised release, cybercriminals worldwide will realize that their attacks come with **significant repercussions** and the law always catches up

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fweekly-cyber-news-updates-week-39-of-2022%2F) [ ](https://twitter.com/intent/tweet?text=Cybersecurity%20News%20Update%2C%20Week%2039%20of%202022&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fweekly-cyber-news-updates-week-39-of-2022%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fweekly-cyber-news-updates-week-39-of-2022%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cybersecurity News Update, Week 39 of 2022","description":"This week’s cybersecurity bulletin covers headlines that gained attention from the cybersecurity community, extending from pig butchering crypto scams.","url":"https://www.duocircle.com/blog/announcements/weekly-cyber-news-updates-week-39-of-2022/","datePublished":"2022-10-14T19:48:18.000Z","dateModified":"2025-04-21T14:17:50.000Z","dateCreated":"2022-10-14T19:48:18.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/weekly-cyber-news-updates-week-39-of-2022/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1253,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/10/check-dmarc-record.jpg","caption":"cybersecurity update","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cybersecurity News Update, Week 39 of 2022","item":"https://www.duocircle.com/blog/announcements/weekly-cyber-news-updates-week-39-of-2022/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cybersecurity News Update, Week 39 of 2022","item":"https://www.duocircle.com/blog/announcements/weekly-cyber-news-updates-week-39-of-2022/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cybersecurity News Update, Week 39 of 2022","description":"This week’s cybersecurity bulletin covers headlines that gained attention from the cybersecurity community, extending from pig butchering crypto scams.","url":"https://www.duocircle.com/blog/announcements/weekly-cyber-news-updates-week-39-of-2022/","datePublished":"2022-10-14T19:48:18.000Z","dateModified":"2025-04-21T14:17:50.000Z","dateCreated":"2022-10-14T19:48:18.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/weekly-cyber-news-updates-week-39-of-2022/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1253,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/10/check-dmarc-record.jpg","caption":"cybersecurity update","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
