Welcome to CyberIntelMag’s weekly review, which covers the most important events in the world of cybersecurity over the past week.

Positive developments

This week’s good news includes Apple fixing a zero-day vulnerability, Oracle joining a multi-cloud security initiative, Biden signing a law on cybersecurity in schools, more than 30 countries joining forces to combat ransomware, and much more.

Apple fixed CVE-2021-30883 in IOMobileFrameBuffer, which allowed an app to execute commands with kernel privileges on vulnerable devices. After updating, this bug no longer poses a threat.

Google has created a cybersecurity team to help governments, critical infrastructure, companies, and small businesses with security and digital transformation issues. Services include strategic consulting, trust and compliance, security engineering, and threat analysis and incident response.

Oracle has become a new member of the Cloud Security Notification Framework (CSNF), a project aimed at reducing dependence on the notification systems of individual cloud providers. This will help both companies and cloud services improve their security.

The K-12 Cybersecurity Act, signed by the Biden administration, requires CISA to assess threats to US schools and provide recommendations and tools for staff on cyber hygiene. The goal is to protect critical information in educational institutions across the country.

During a two-day virtual summit on combating ransomware, representatives from more than 30 countries discussed the global risks associated with ransomware. Participants emphasized the responsibility of countries to improve network resilience, prevent attacks, and respond effectively.

Negative events

There were a number of incidents this week: Amnesty International uncovered a link between a cybersecurity company and spyware, a prestigious school in Hollywood was hacked, Iranian hackers attacked US defense companies, Olympus was attacked again, Acer’s support systems were hacked, and Accenture acknowledged a data breach.

Amnesty International found evidence of espionage against an activist in Togo and signs of spyware spreading in several Asian countries. An Android app developed by Indian company Innefu Labs was actively used to deliver the malware.

Two vulnerabilities (CVE-2021-21940 and CVE-2021-21941) have been discovered in Anker Eufy Homebase that could lead to code execution or buffer overflow. An attacker could send a specially crafted packet to exploit the bugs.

The prestigious Harvard-Westlake school in Hollywood was hacked. The academic data of about 150 graduates was stolen. The reason was the compromise of a senior administrator’s account.

Microsoft has discovered that Iranian hackers are conducting password spray attacks against defense companies that supply radars, satellite systems, drones, and emergency communications systems to the US, EU, and Israel.

A cyber incident occurred at Meliá (Spain): part of the internal network and web servers, including the booking system and public websites, were taken offline.

Olympus was again attacked on its EMEA infrastructure. This is the second incident in 2021. The company said that no data had been compromised.

Acer’s after-sales support systems in India were hacked, with attackers stealing more than 60 GB of files and databases, including customer, business, and financial information, as well as distributor login details.

Accenture acknowledged unauthorized access to its systems and those of its service providers, resulting in the theft of company and customer data. Some of the information became public due to the actions of hackers.