---
title: "Cyber Security News Update, Week 7 of 2021 | DuoCircle"
description: "Effective use of cybersecurity tools and regular security patches helps minimize cyber threats to an extent; however."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/email-hosting/cyber-security-news-update-week-7-of-2021/"
---

Quick Answer

Week 7, 2021 cyber news: an unnamed organization paid \~6.5M ransom only to be re-extorted within two weeks via the same unfixed vulnerability; Red Rabbit leaks 2.5 million Bharti Airtel J&K subscribers despite Airtel denials; Kaspersky releases a free RakhniDecryptor for Fonix ransomware (5,000-6,000 systems infected since 2020); Forward Air reports $7.5M loss from a December 2020 Hades ransomware attack; DARPAs FETT bug bounty surfaces 10 SSITH hardware flaws (7 critical, 3 high); Vdoo discloses six flaws in Realtek RTL8195A WiFi modules including buffer-overflow CVE-2020-9395 and CVE-2020-25854 (patched in Ameba Arduino 2.0.8); HelpSystems acquires Digital Defense.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Femail-hosting%2Fcyber-security-news-update-week-7-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%207%20of%202021&url=undefined%2Fblog%2Femail-hosting%2Fcyber-security-news-update-week-7-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Femail-hosting%2Fcyber-security-news-update-week-7-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Femail-hosting%2Fcyber-security-news-update-week-7-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%207%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%207%20of%202021&body=Check out this article: undefined%2Fblog%2Femail-hosting%2Fcyber-security-news-update-week-7-of-2021%2F "Share via Email") 

![Cyber Security](https://media.mailhop.org/duocircle/images/2021/02/spf-validator-7423.jpg) 

_Effective use of cybersecurity tools and regular security patches helps minimize cyber threats to an extent_; however, no strategy is one-hundred percent foolproof, as suggested by the following headlines on recent cybersecurity issues. Read on to know how malicious actors pick their victims and how you can learn from others’ mistakes to make sure the confidentiality, integrity, and availability of your digital assets remain intact!

## Cybersecurity Tip: Fix Vulnerability First, Pay Ransom Later

An unnamed organization recently underwent a **ransomware attack** and _paid nearly £6.5million to get the data decrypted_. However, they skipped the [ransomware protection](/advanced-threat-defense) measures because of which the same attackers came back less than two weeks later, exploited the same vulnerability, and extracted a [second ransom](https://www.zdnet.com/article/ransomware-this-is-the-first-thing-you-should-think-about-if-you-fall-victim-to-an-attack/?&web%5Fview=true) from them. Such incidents are not uncommon in the cyberworld; **decrypting data** is usually the first thing on a victim organization’s mind, but being cautious is equally essential, as evident from this incidence.

While the cybersecurity goal is to avoid attacks, an enterprise must always question the circumstances and **security vulnerabilities** leading to the attack in the advent of a security incident. In the absence of such introspective security measures, cyberattacks keep happening again and again. Hence, _businesses must keep their software up-to-date, use strong passwords, maintain backups and enable MFA for enhanced security_.

## Indian Airtel Users Beware Of Red Rabbit

A hacker group named Red Rabbit attacked the Bharti Airtel servers in December 2020; now, _they have leaked the data of over 25 lakh Airtel subscribers on the dark web_. While the [telecom operator](https://ciso.economictimes.indiatimes.com/news/data-of-25-lakh-airtel-customers-in-j-k-allegedly-leaked-telco-claims-no-breach-in-server/80661483) has denied any breach, evidence provided by security researcher Rajshekhar Rajaharia suggests otherwise.

While the leaked data belongs to Airtel users from the Jammu and Kashmir circle, _hackers claim that they have access to records of all Indians using Airtel_. Airtel continues to deny the cybersecurity breach, but users are advised to **stay vigilant** and refrain from sharing sensitive information on telephonic interactions.

[![ransomware protection solution](https://media.mailhop.org/duocircle/images/2021/02/spf-record-generator-8095.jpg)](https://media.mailhop.org/duocircle/images/2021/02/spf-record-generator-8095.jpg)

## A Ray of Hope: Kaspersky Launches Free Decryptor For Fonix Ransomware

It’s not just adversaries who succeed in their digital advents; the latest Kaspersky release provides an unmatched [ransomware protection solution](/advanced-threat-defense) that brings cyber warriors at par with cyber attackers. The new Kaspersky release is mainly for the dangerous **Fonix ransomware strain**. _Fonix has affected over 5000-6000 systems since its launch in 2020_. Now, Kaspersky has created a **free decryptor** capable of recovering all files encrypted by Fonix.

Following the decryptor launch, the Fonix admins have announced a [shut down](https://www.bleepingcomputer.com/news/security/new-fonix-ransomware-decryptor-can-recover-victims-files-for-free/?&web%5Fview=true) of their ransomware operation and _released a decryption key to decrypt all infected systems for free_. It was later confirmed that their key was useful in decrypting a victim’s files. However, _let’s stick to what security firm Kaspersky calls the RakhniDecryptor_. Using the decryptor is made easy with the comprehensive instructions and should be accessible to all users.

## Forward Air Loses $7.5 Million To Ransomware

_Forward Air, the trucking and freight transportation logistics company was attacked by the Hades ransomware on 15th December 2020_. Consequently, the company incurred a financial **loss of $7.5 million** as part of the temporary business shut down. Forward Air’s instance is just one example justifying why security researchers always advise to invest in [email security services](/) and [prevent phishing](/email/phishing-protection) attacks instead of trying and dealing with them.

While we don’t know whether Forward Air paid a ransom or availed a cyber insurance policy, a Coveware report states the [recent trend](https://www.zdnet.com/article/trucking-company-forward-air-said-its-ransomware-incident-cost-it-7-5-million/?&web%5Fview=true) where _organizations prefer to start from scratch and rebuild their systems instead of paying a ransom to the adversaries_.

## DARPA’s Bug Bounty Program Sets Example For All

The **bug bounty program** set up by the US Defense Advanced Research Projects Agency (DARPA) to evaluate the hardware architectures of its System Security Integration Through Hardware and Firmware (SSITH) program has resulted in **10 significant vulnerabilities**. While seven of these are marked as critical, three vulnerabilities have been marked as high.

However, _DARPA’s efficient cybersecurity tools have already fixed four of these security flaws_, and they hope to resolve the others soon. The bug bounty program, Finding Exploits to Thwart Tampering (FETT) was helpful both for securing the hardware architecture in the SSITH program and [motivating](https://portswigger.net/daily-swig/darpa-bug-bounty-helps-strengthen-military-research-agencys-security-defenses?&web%5Fview=true) the researchers to work harder on advancing their technology.

## Six Vulnerabilities In Realtek Devices, Now Patched

_Researchers from Israeli security firm Vdoo have found six vulnerabilities in the Realtek RTL8195A Wi-Fi module_, which, if exploited, could give adversaries root access to a device’s wireless communications. While the flaws were found in RTL8195A alone, [researchers believe](https://thehackernews.com/2021/02/critical-bugs-found-in-popular-realtek.html?&web%5Fview=true) that they exist in other modules like RTL8710AF, RTL8711AM, and RTL8711AF.

The **buffer overflow vulnerability** (CVE-2020-9395) allows attackers near an RTL8195 module to take charge of the module even without the password. Two other flaws can be used to launch **DoS attacks**, and the remaining three bugs, including CVE-2020-25854, let adversaries execute arbitrary code on the Wi-Fi client devices. However, Realtek has responded to the cybersecurity issues and released patches for all six flaws in its Ameba Arduino 2.0.8.

[![security infrastructure](https://media.mailhop.org/duocircle/images/2021/02/spf-permerror-8538.jpg)](https://media.mailhop.org/duocircle/images/2021/02/spf-permerror-8538.jpg)

## HelpSystems Acquires Digital Defense

In what seems like a beneficial digital merger, _HelpSystems has acquired the cloud security company Digital Defense_. All HelpSystems clients who wanted to strengthen their [security infrastructure](https://www.infosecurity-magazine.com/news/helpsystems-cybersecurity/?&web%5Fview=true) can now access Digital Defense’s comprehensive security assessment toolkit. The latest acquisition comes after HelpSystems acquired Titus, Vera, and Boldon James last year and FileCatalyst this year.

The cloud native vulnerability scanning engine offered by Digital Defense allows organizations to identify security loopholes in their infrastructure and take necessary [email protection](/) and other security measures. HelpSystems is assertive that this latest acquisition shall enable them to serve their customers better.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Femail-hosting%2Fcyber-security-news-update-week-7-of-2021%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%207%20of%202021&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Femail-hosting%2Fcyber-security-news-update-week-7-of-2021%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Femail-hosting%2Fcyber-security-news-update-week-7-of-2021%2F) Copy 

Related Articles

- [ ![setting up a self-hosted mail server](https://media.mailhop.org/duocircle/images/2026/03/spf-flatterning-5911.jpg)  10 Steps To Set Up A Self-Hosted Mail Server Without Hitting Spam Blog ](/blog/email-hosting/10-steps-set-up-self-hosted-mail-server-avoid-spam/)
- [ ![Moving Mail to the Cloud](https://media.mailhop.org/duocircle/images/2016/04/spf-record-checker-4741.jpg)  The 9 Ways You Benefit from Moving Mail to the Cloud Blog ](/blog/email-hosting/9-ways-benefit-moving-mail-cloud/)
- [  Amazon Order Confirmation Trojan Blog ](/blog/email-hosting/amazon-order-confirmation-trojan/)
- [ ![Zero-day Vulnerability](https://media.mailhop.org/duocircle/images/2021/12/smtp-relay-7593.jpg)  Apache Log4j Zero-day Vulnerability: How to Detect it & Precautions You Need to Take Blog ](/blog/email-hosting/apache-log4j-zero-day-vulnerability-how-to-detect-it-precautions-you-need-to-take/)

## Related Articles

[  Email Hosting 18m  10 Steps To Set Up A Self-Hosted Mail Server Without Hitting Spam  Mar 10, 2026 ](/blog/email-hosting/10-steps-set-up-self-hosted-mail-server-avoid-spam/)[  Email Hosting 5m  The 9 Ways You Benefit from Moving Mail to the Cloud  Apr 13, 2016 ](/blog/email-hosting/9-ways-benefit-moving-mail-cloud/)[  Email Hosting 1m  Amazon Order Confirmation Trojan  Feb 16, 2019 ](/blog/email-hosting/amazon-order-confirmation-trojan/)[  Email Hosting 6m  Apache Log4j Zero-day Vulnerability: How to Detect it & Precautions You Need to Take  Dec 24, 2021 ](/blog/email-hosting/apache-log4j-zero-day-vulnerability-how-to-detect-it-precautions-you-need-to-take/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 7 of 2021","description":"Effective use of cybersecurity tools and regular security patches helps minimize cyber threats to an extent; however.","url":"https://www.duocircle.com/blog/email-hosting/cyber-security-news-update-week-7-of-2021/","datePublished":"2021-02-10T13:46:14.000Z","dateModified":"2025-05-02T13:31:08.000Z","dateCreated":"2021-02-10T13:46:14.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/email-hosting/cyber-security-news-update-week-7-of-2021/"},"articleSection":"email-hosting","keywords":"","wordCount":923,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/02/spf-validator-7423.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"Email Hosting"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 7 of 2021","item":"https://www.duocircle.com/blog/email-hosting/cyber-security-news-update-week-7-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"Email Hosting","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 7 of 2021","item":"https://www.duocircle.com/blog/email-hosting/cyber-security-news-update-week-7-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 7 of 2021","description":"Effective use of cybersecurity tools and regular security patches helps minimize cyber threats to an extent; however.","url":"https://www.duocircle.com/blog/email-hosting/cyber-security-news-update-week-7-of-2021/","datePublished":"2021-02-10T13:46:14.000Z","dateModified":"2025-05-02T13:31:08.000Z","dateCreated":"2021-02-10T13:46:14.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/email-hosting/cyber-security-news-update-week-7-of-2021/"},"articleSection":"email-hosting","keywords":"","wordCount":923,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/02/spf-validator-7423.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
