---
title: "Cyber Security News Update, Week 47 of 2020 | DuoCircle"
description: "Passwords protect our cellphones and applications but what happens underneath this so-called anti-phishing protection is beyond the comprehension of internet."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/email-hosting/cyber-security-news-update-week-47-of-2020/"
---

Quick Answer

Week 47 of 2020 covered six items. Researchers found a Facebook flaw that data-scraping groups abused to expose phone numbers tied to user accounts, prompting Facebook to lock down the affected endpoint. An Australian man pleaded guilty to running a DDoS-for-hire stresser service used in tens of thousands of attacks against schools, businesses, and government sites. A threat actor was observed selling network access and database dumps tied to Pakistan International Airlines on an underground forum. The Ransomexx crew added a Linux variant to its toolkit, expanding from Windows to encrypt servers running enterprise Linux distributions. A flaw in Intel's Support Assistant allowed local privilege escalation to SYSTEM through weak directory permissions. The FTC announced a proposed settlement with Zoom over its security and encryption claims, requiring annual independent assessments and a beefed-up information security program.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Femail-hosting%2Fcyber-security-news-update-week-47-of-2020%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2047%20of%202020&url=undefined%2Fblog%2Femail-hosting%2Fcyber-security-news-update-week-47-of-2020%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Femail-hosting%2Fcyber-security-news-update-week-47-of-2020%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Femail-hosting%2Fcyber-security-news-update-week-47-of-2020%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2047%20of%202020 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2047%20of%202020&body=Check out this article: undefined%2Fblog%2Femail-hosting%2Fcyber-security-news-update-week-47-of-2020%2F "Share via Email") 

![Cyber Security](https://media.mailhop.org/duocircle/images/2020/11/smtp-service-5747.jpg) 

Passwords protect our cellphones and applications but what happens underneath this so-called [anti-phishing protection](/email/phishing-protection) is beyond the comprehension of internet users. The following headlines will astound you if you believe cyber adversaries will target anyone but you

## Data-Scraping Groups Exploit Facebook Vulnerability

_The security issues with Facebook never seem to end_, do they? Several [data-scraping groups](https://www.zdnet.com/article/facebook-link-preview-feature-used-as-a-proxy-in-website-scraping-scheme/?&web%5Fview=true) have manipulated Facebook’s link preview feature in the latest incident by pretending to be their content crawler.

These data scraping groups compromised Facebook developer accounts and requested Facebook or Facebook Messenger API servers for link previews of pages they wanted to scrap. Oblivious of this **cyber scam**, Facebook would procure the data, assemble it in a link preview, and forward the same to the adversaries who would then misuse the data. _This security glitch went unnoticed until the security firm DataDome discovered it_.

The most shocking element is still the figures, the data-scraping groups could retrieve link previews for as many as **10,000 URLs** by compromising just one Facebook developer account. One can only imagine the intensity of the damage! However, _Facebook has taken the required measures and improved rate limiting on the Messenger preview API_.

[![DDoS attacks](https://media.mailhop.org/duocircle/images/2020/11/sendgrid-alternative-8652.jpg)](https://media.mailhop.org/duocircle/images/2020/11/sendgrid-alternative-8652.jpg)

## Melbourne DDoS Attacker Pleads Guilty

We hire SEO experts to enhance our site’s online presence, but what if that person turns out to be a hacker? Melbourne’s [Brett Bruce White](https://www.theaustralian.com.au/breaking-news/brett-bruce-white-pleads-guilty-to-hacking-multiple-business-websites/news-story/6fd86950d97e9ca60a5df651b6331138?&web%5Fview=true) is one such cyber attacker who showered the websites of health and fitness professional Phillip Learney, businessman Terence Newton, and payment services provider Openpay with [DDoS attacks](https://www.cloudflare.com/learning/ddos/what-is-a-ddos-attack/) between April and May in 2018\. White is now being tried at the Melbourne County Court after the police found a Macbook laptop with evidence at his residence.

Although White’s defense lawyer Zarah Garde, Wilson brought in the sad tale of White’s personal life and innate skill at computers, we know that nothing justifies disregard of cybersecurity laws!

## Cunning Hacker Sells Access To Pakistan Airlines’ Network And Database

For all those times when we said that [cyberattacks in 2020](https://www.infosecurity-magazine.com/news/hacker-sells-access-to-pakistani/?&web%5Fview=true) are not just about the hack, they also involve **data theft**, here is the example of the Pakistan International Airlines’ network. _A cyber adversary is offering the Pakistan International Airlines’ network and database for sale on the dark web_. The security researchers at security firm KELA discovered the Airlines’ domain admin access being **sold for $4,000** on two Russian and one English illegal forums.

Researchers at KELA have been monitoring the threat actors since July, and the adversaries have put up a total of 38 accesses for sale at a price not **less than $118,700**. On 9th November, KELA notified of a domain access sale of the airlines. The attackers are also selling all databases on the airlines’ network, containing as many as 500k records. Incidents like this make us regret even making travel plans, the affected people have their names, phone numbers, and passports exposed to malicious actors. Adopting [phishing prevention](/email/phishing-protection) measures at a personal level is highly recommended for all those who’ve traveled with Pakistan International Airlines.

## Ransomexx Now A Threat For Linux Users

_Ransomware RansomEXX began with a low infection rate but is now a serious threat_ factor for [Windows and Linux](https://web.archive.org/web/20220627145928/https://cyware.com/news/major-windows-ransomware-strain-ported-to-linux-54b2966a) users. It mainly targets victims on paydays and goes by the name of **decryptor64 for Linux**. There are quite a few similarities between the Linux and Windows versions of RansomEXX, such as the same source code, ransom notes, etc.

To protect yourself from phishing, experts advise to have [anti-ransomware services](/advanced-threat-defense) in place and keep regular **data backups**. Nothing is better than prevention; hence, Linux and Windows users alike must adopt necessary [anti-phishing solutions](/email/phishing-protection) to stay safe from RansomEXX. Also consider the option to [hire seo experts](https://www.seotagg.com/uk-london-seo-consultant-expert/) for more website visibilty in Google.

[![privilege-escalation attacks](https://media.mailhop.org/duocircle/images/2020/11/smtp-email-8965.jpg)](https://media.mailhop.org/duocircle/images/2020/11/smtp-email-8965.jpg)

## Simple Errors Lead To Major Vulnerabilities At Intel Support Assistant

_Security firm CyberArk recently discovered two vulnerabilities with Intel Support Assistant_ that could cause [privilege-escalation](https://www.darkreading.com/application-security/flaws-in-privileged-management-apps-expose-machines-to-attack/d/d-id/1339419?&web%5Fview=true) attacks. One of the vulnerabilities involved Intel Support Assistant interacting without cybersecurity with nonprivileged data and directories, _making it easy for adversaries to modify a nonprivileged file and execute code as the privileged program_. Abusing some features of the Intel Support Assistant is enough to escalate into a system account. The second vulnerability was a bit more complicated and gave adversaries the power to delete an arbitrary file.

Although _Intel has launched a patch fixing the vulnerability_, insufficient preventive measures such as not securing the system utilities’ directories can lead to the most damaging cyber attacks. Hence, developers must ensure the safety against modification of directories and files used by privileged programs, and coders must take measures for [protection against phishing](/) as well.

## FTC Discusses Zoom’s Poor Privacy Policy In A Proposed Settlement

Ever since the Coronavirus pandemic spread, we have been continuously hearing about Zoom and its many security issues. Sadly, it isn’t over yet: the Federal Trade Commission (FTC) proposed a settlement of allegations against the video conferencing [application Zoom](https://www.securityweek.com/ftc-says-zoom-misled-users-its-security-meetings?&web%5Fview=true) on 9th November. The Federal regulators have accused Zoom of having misled its users about their **phishing attack prevention** measures and meeting security levels at least since 2016.

_Zoom has allegedly held cryptographic keys allowing it to access content from user meetings and secure meetings with poor privacy encryption._ The FTC holds Zoom guilty of mishandling the security of users via inferior and dubious **security practices**. The settlement would require Zoom to strengthen its cybersecurity measures and review all software updates for security flaws.

And that’s the week that was.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Femail-hosting%2Fcyber-security-news-update-week-47-of-2020%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2047%20of%202020&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Femail-hosting%2Fcyber-security-news-update-week-47-of-2020%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Femail-hosting%2Fcyber-security-news-update-week-47-of-2020%2F) Copy 

Related Articles

- [ ![setting up a self-hosted mail server](https://media.mailhop.org/duocircle/images/2026/03/spf-flatterning-5911.jpg)  10 Steps To Set Up A Self-Hosted Mail Server Without Hitting Spam Blog ](/blog/email-hosting/10-steps-set-up-self-hosted-mail-server-avoid-spam/)
- [ ![Moving Mail to the Cloud](https://media.mailhop.org/duocircle/images/2016/04/spf-record-checker-4741.jpg)  The 9 Ways You Benefit from Moving Mail to the Cloud Blog ](/blog/email-hosting/9-ways-benefit-moving-mail-cloud/)
- [  Amazon Order Confirmation Trojan Blog ](/blog/email-hosting/amazon-order-confirmation-trojan/)
- [ ![Zero-day Vulnerability](https://media.mailhop.org/duocircle/images/2021/12/smtp-relay-7593.jpg)  Apache Log4j Zero-day Vulnerability: How to Detect it & Precautions You Need to Take Blog ](/blog/email-hosting/apache-log4j-zero-day-vulnerability-how-to-detect-it-precautions-you-need-to-take/)

## Related Articles

[  Email Hosting 18m  10 Steps To Set Up A Self-Hosted Mail Server Without Hitting Spam  Mar 10, 2026 ](/blog/email-hosting/10-steps-set-up-self-hosted-mail-server-avoid-spam/)[  Email Hosting 5m  The 9 Ways You Benefit from Moving Mail to the Cloud  Apr 13, 2016 ](/blog/email-hosting/9-ways-benefit-moving-mail-cloud/)[  Email Hosting 1m  Amazon Order Confirmation Trojan  Feb 16, 2019 ](/blog/email-hosting/amazon-order-confirmation-trojan/)[  Email Hosting 6m  Apache Log4j Zero-day Vulnerability: How to Detect it & Precautions You Need to Take  Dec 24, 2021 ](/blog/email-hosting/apache-log4j-zero-day-vulnerability-how-to-detect-it-precautions-you-need-to-take/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 47 of 2020","description":"Passwords protect our cellphones and applications but what happens underneath this so-called anti-phishing protection is beyond the comprehension of internet.","url":"https://www.duocircle.com/blog/email-hosting/cyber-security-news-update-week-47-of-2020/","datePublished":"2020-11-21T23:37:44.000Z","dateModified":"2025-05-26T11:33:47.000Z","dateCreated":"2020-11-21T23:37:44.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/email-hosting/cyber-security-news-update-week-47-of-2020/"},"articleSection":"email-hosting","keywords":"","wordCount":931,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2020/11/smtp-service-5747.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"Email Hosting"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 47 of 2020","item":"https://www.duocircle.com/blog/email-hosting/cyber-security-news-update-week-47-of-2020/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"Email Hosting","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 47 of 2020","item":"https://www.duocircle.com/blog/email-hosting/cyber-security-news-update-week-47-of-2020/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 47 of 2020","description":"Passwords protect our cellphones and applications but what happens underneath this so-called anti-phishing protection is beyond the comprehension of internet.","url":"https://www.duocircle.com/blog/email-hosting/cyber-security-news-update-week-47-of-2020/","datePublished":"2020-11-21T23:37:44.000Z","dateModified":"2025-05-26T11:33:47.000Z","dateCreated":"2020-11-21T23:37:44.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/email-hosting/cyber-security-news-update-week-47-of-2020/"},"articleSection":"email-hosting","keywords":"","wordCount":931,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2020/11/smtp-service-5747.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
