IT Security is particularly important for businesses and as a leading IT Support company in Bristol we known how devastating a zero  day attack is.  The big news today is there is a zero day attack in progress right now that could compromise your computers.  By following this simple advise you can protect your system until Microsoft have created a fix.

What is a Zero Day Attack?

A zero day attack is an attack that attempts to exploit a software vulnerability that the software vendor may not yet be aware of.  Bottom line is that the hackers have found a way in.

These types of attacks are particularly serious as the vendor has to rush to create a fix (which is often flawed as testing is compromised by the lack of time) and push it out before too many systems are affected.

 

What is this attack?

This attack is utilising a flaw called Folina which has been identified in Microsoft Office and other underlying software dealing with templates.

 

When will it be fixed?

At the moment there is no information from Microsoft as to when it will be fixed.

 

What can I do to protect my systems?

Until Microsoft have created a fix we are recommending a workaround that will prevent the vulnerability being utilised by attackers.

1. Click Windows icon
2. Type Powershell
3. Right click the powershell icon and select “Run as administrator”
4. Copy and paste the following code into the blue powershell box

PS C:\WINDOWS\system32> reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\ScriptedDiagnostics /f /v EnableDiagnostics /d 0

5. Press Enter
6. You should receive a response to say “The operation completed successfully”

How can I get help

A good IT support company will be able to assist you with this task and we have engineers available if your business requires assistance.  For our contract support customers this fix has already been applied to your system and once a patch has been created by Microsoft we will test and deploy it as well as reverse the changes made above.

 

What next?

Unlike most IT support companies, we have a dedicated security department proactively looking for these sorts of issues.  If your business would like to talk about our secure support services then fill out our contact form, phone us or click on the appointment button below and lets start a conversation to see if we are able to help you and your business.

Our guarantee:

  • There are no hidden charges – this is a 100% free 15 minute consultation with no hidden charges.
  • We will never spam you or sell on your contact details.
  • We will treat your information with absolute confidentiality.

 

Now AI is Scanning for Weaknesses, Should Regulated Firms Rethink Cyber Security?

Cyber security is shifting. AI is beginning to hunt for weaknesses before attackers can exploit them, and Microsoft’s early work is genuinely impressive. But for regulated firms, the headline technology does not change the foundations that keep client data safe and audit-ready. Here is the measured, board-level view on where AI fits, and why the basics still matter most.

When Cybercriminals Turn On Each Other, Your Firm Still Loses

When cybercriminals start threatening each other, it can look like good news, even an opportunity. But for a regulated firm, trusting one attacker to rescue you from another is a governance risk, not a lifeline. Here is why the only reliable route through a cyber incident runs through proper protection and trusted support, and how to make sure your firm is ready before the pressure hits.

The Fake CAPTCHA Trap: “Prove You’re Human” With Fresh Suspicion

CAPTCHAs are so familiar that we barely register them, and that trust is exactly what criminals are now exploiting. A new breed of fake verification page asks you to “prove you’re human” by sending a text, quietly racking up premium-rate charges that only surface later. For regulated firms, the stakes reach further than the bill. Here’s how the trap works, and how to protect your team.

Why a Routine Update Has Become a Board-Level Risk

For regulated firms, a routine software update should never become a compliance incident. Yet a highly convincing fake Windows 11 update is now fooling even experienced professionals, and a single click can expose client data. This post explains how the scam works, why it slips past security tools, and the governance-led steps every professional firm should take to stay protected and audit-ready.

Windows 11 Is Finally Addressing What Has Been Frustrating Your Team

Constant new features are not what professional firms need from their operating system — they need reliability, consistency, and fewer distractions. Microsoft has recognised this, and the latest Windows 11 direction prioritises fixing real-world frustrations over adding experimental tools. From scaling back unnecessary AI, to smoother updates and a faster File Explorer, here is what is changing and why it matters for governance-focused businesses.

Fake Microsoft Azure Alerts, Why Regulated Firms Must Not Let Their Guard Down

A sophisticated new phishing campaign is exploiting Microsoft Azure Monitor to deliver scam alerts that look entirely legitimate. For regulated firms, where client trust and data governance are non-negotiable, this evolving threat demands a more rigorous approach to email verification and incident response.

Windows 11 Shifts Its Focus to Efficiency, What This Means for Regulated Firms

For regulated firms, the biggest productivity gains rarely come from headline features. Microsoft’s latest Windows 11 updates prioritise something more valuable — smoother, faster systems that reduce friction and support the consistent performance your team depends on. Here is what is changing and why it matters for compliance-focused businesses.

Is Your Data Security Keeping Pace With Your Business?

Most professional service firms believe their data security is under control — but confidence and compliance readiness are not the same thing. As cloud platforms, legacy systems and AI tools increase complexity beneath the surface, the gap between perceived security and actual governance grows. This post examines the questions every regulated firm should be asking about where data lives, who has access, and whether the answers would satisfy an auditor.

Microsoft Teams Just Fixed One of Its Most Annoying Meeting Problems

It is the small software irritations that cause the biggest disruptions. Microsoft Teams has quietly addressed one of its most frustrating quirks, the ease with which you could accidentally quit a meeting mid-conversation. For professional firms where composure and continuity matter, this subtle update is more significant than it sounds.

Why AI is the wrong tool for Passwords

Are the passwords protecting your business as strong as you think they are? AI may seem like a smart shortcut, but when it comes to security, it could be creating hidden weaknesses you can’t afford to ignore.

Protecting Your Business from Today’s Smarter Digital Fraud

Digital fraud is evolving at a rapid pace, and modern scams are becoming harder to spot than ever. In this article, we explore practical, everyday habits your team can adopt to stay safer online — and how a few simple tools can make a big difference.

How to Protect your Business from Cybersecurity Threats

With UK small businesses targeted with 65,000 attempted cyber attacks per day, having robust measures to deal with cyber security threats is more important than ever. The recent attack on SolarWinds proves that no business is safe from hackers and that businesses both...

The Fake CAPTCHA Trap: “Prove You’re Human” With Fresh Suspicion

CAPTCHAs are so familiar that we barely register them, and that trust is exactly what criminals are now exploiting. A new breed of fake verification page asks you to “prove you’re human” by sending a text, quietly racking up premium-rate charges that only surface later. For regulated firms, the stakes reach further than the bill. Here’s how the trap works, and how to protect your team.

WordPress Security – Attacks leave 1.6 million sites damaged

Are you confident that your WordPress website is secure? Yesterday, on the 9th of December 2021, 1.6 Million WordPress Sites were Hit With 13.7 Million Attacks In 36 Hours From 16,000 IPs. It’s safe to say this is a major concern to businesses everywhere. WordPress...

Cyber Security Infographic

Cyber attacks are no longer something that only happens to large corporations. Small and medium-sized businesses in Bristol and across the UK are increasingly being targeted, and the consequences - data loss, financial damage, reputational harm, and regulatory...

Old Passwords Are Still Unlocking Systems

Old passwords your team hasn’t used in years could still unlock your systems — and attackers know it. A recent cyber incident revealed how forgotten credentials put professional service firms at serious risk, and why enforcing MFA has never been more important.

Beware the Next Generation of Phishing Attacks

Phishing scams are no longer crude or easy to spot. New, smarter attacks are changing the rules — and businesses need to rethink how they stay protected.

Your Browser Knows More Than You Think

Your browser doesn’t just see the websites you visit. It sees patterns, habits, and clues about your business. Most people never check what’s being shared behind the scenes. That’s a risk worth paying attention to.

8.4 Billion Passwords Leaked In “RockYou2021” Hack – How To Protect Your Business

The largest password collection of all time was recently leaked onto a hacker forum, with an eye-watering 8,459,060,239 (8.4 billion) unique entries stored in a 100GB TXT file putting potentially billions of logins at risk.  Dubbed as ‘RockYou2021’ after the RockYou...

Is Your Data Security Keeping Pace With Your Business?

Most professional service firms believe their data security is under control — but confidence and compliance readiness are not the same thing. As cloud platforms, legacy systems and AI tools increase complexity beneath the surface, the gap between perceived security and actual governance grows. This post examines the questions every regulated firm should be asking about where data lives, who has access, and whether the answers would satisfy an auditor.