Rejuvenate IT Logo
  1. Home
  2. Rejuvenate IT News
  3. Security Alerts

Security Alerts

Breaches, ransomware and phishing campaigns as they happen, with the patches to apply and the checks worth making this week.

Someone searched for software, clicked the wrong result, and the business was ransomwared in 44 hours

No phishing email, no unpatched server. An IT administrator searched for a piece of software he already used, downloaded it from the top result, and the whole network was encrypted two days later.
Read more

The phishing email really did come from Facebook – how attackers went after business ad accounts

Attackers got Meta's own systems to send the phishing email for them, from a genuine Facebook address. If your business runs a Facebook page or pays for ads, this is the one to understand.
Read more

One advertising script turned thousands of websites against their own visitors

A tracking script used by thousands of sites was tampered with for a day. Every site carrying it served the attackers' code to visitors, and none of those site owners did anything wrong.
Read more

A contact form let attackers onto the server – then they rented it out

One web page that did not check what people typed into it. From there, attackers took the server, switched off its defences and put it to work making money for somebody else.
Read more

WordPress patched a flaw that let strangers take over a site with no login – check your version

Two flaws in WordPress itself, chained together, handed complete control of a site to anyone who asked. Patched on 17 July. Here is how to be sure yours is on a safe version.
Read more

Attackers phoned staff pretending to be IT support – and got straight into the company Microsoft accounts

Criminals rang staff claiming to be internal IT, sent them to a fake login page, and used the sign-in to reach Microsoft Entra and SharePoint. What to put in place this week.
Read more

Ransomware gangs are using a SonicWall remote-access flaw that was patched a month ago

CISA now records ransomware crews exploiting two SonicWall SMA1000 flaws. The fix has been out since mid-July, yet 380-odd appliances are still exposed. How to tell if one is yours.
Read more

Phishing now starts more than half of all attacks – and multi-factor was got round in two thirds

Cisco Talos published what it actually saw last quarter across the incidents it was called into. Two of the numbers should change how a small business spends its next hour on security.
Read more

Seven WordPress plugins were hijacked to create hidden admin accounts – how to check your site

Attackers poisoned a data feed used by seven popular Elementor plugins, creating hidden administrator accounts on sites that had done nothing wrong. Here is how to check yours.
Read more