IT Security is particularly important for businesses and as a leading IT Support company in Bristol we known how devastating a zero  day attack is.  The big news today is there is a zero day attack in progress right now that could compromise your computers.  By following this simple advise you can protect your system until Microsoft have created a fix.

What is a Zero Day Attack?

A zero day attack is an attack that attempts to exploit a software vulnerability that the software vendor may not yet be aware of.  Bottom line is that the hackers have found a way in.

These types of attacks are particularly serious as the vendor has to rush to create a fix (which is often flawed as testing is compromised by the lack of time) and push it out before too many systems are affected.

 

What is this attack?

This attack is utilising a flaw called Folina which has been identified in Microsoft Office and other underlying software dealing with templates.

 

When will it be fixed?

At the moment there is no information from Microsoft as to when it will be fixed.

 

What can I do to protect my systems?

Until Microsoft have created a fix we are recommending a workaround that will prevent the vulnerability being utilised by attackers.

1. Click Windows icon
2. Type Powershell
3. Right click the powershell icon and select “Run as administrator”
4. Copy and paste the following code into the blue powershell box

PS C:\WINDOWS\system32> reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\ScriptedDiagnostics /f /v EnableDiagnostics /d 0

5. Press Enter
6. You should receive a response to say “The operation completed successfully”

How can I get help

A good IT support company will be able to assist you with this task and we have engineers available if your business requires assistance.  For our contract support customers this fix has already been applied to your system and once a patch has been created by Microsoft we will test and deploy it as well as reverse the changes made above.

 

What next?

Unlike most IT support companies, we have a dedicated security department proactively looking for these sorts of issues.  If your business would like to talk about our secure support services then fill out our contact form, phone us or click on the appointment button below and lets start a conversation to see if we are able to help you and your business.

Our guarantee:

  • There are no hidden charges – this is a 100% free 15 minute consultation with no hidden charges.
  • We will never spam you or sell on your contact details.
  • We will treat your information with absolute confidentiality.

 

When Cybercriminals Turn On Each Other, Your Firm Still Loses

When cybercriminals start threatening each other, it can look like good news, even an opportunity. But for a regulated firm, trusting one attacker to rescue you from another is a governance risk, not a lifeline. Here is why the only reliable route through a cyber incident runs through proper protection and trusted support, and how to make sure your firm is ready before the pressure hits.

The Fake CAPTCHA Trap: “Prove You’re Human” With Fresh Suspicion

CAPTCHAs are so familiar that we barely register them, and that trust is exactly what criminals are now exploiting. A new breed of fake verification page asks you to “prove you’re human” by sending a text, quietly racking up premium-rate charges that only surface later. For regulated firms, the stakes reach further than the bill. Here’s how the trap works, and how to protect your team.

Why a Routine Update Has Become a Board-Level Risk

For regulated firms, a routine software update should never become a compliance incident. Yet a highly convincing fake Windows 11 update is now fooling even experienced professionals, and a single click can expose client data. This post explains how the scam works, why it slips past security tools, and the governance-led steps every professional firm should take to stay protected and audit-ready.

Windows 11 Is Finally Addressing What Has Been Frustrating Your Team

Constant new features are not what professional firms need from their operating system — they need reliability, consistency, and fewer distractions. Microsoft has recognised this, and the latest Windows 11 direction prioritises fixing real-world frustrations over adding experimental tools. From scaling back unnecessary AI, to smoother updates and a faster File Explorer, here is what is changing and why it matters for governance-focused businesses.

Fake Microsoft Azure Alerts, Why Regulated Firms Must Not Let Their Guard Down

A sophisticated new phishing campaign is exploiting Microsoft Azure Monitor to deliver scam alerts that look entirely legitimate. For regulated firms, where client trust and data governance are non-negotiable, this evolving threat demands a more rigorous approach to email verification and incident response.

Windows 11 Shifts Its Focus to Efficiency, What This Means for Regulated Firms

For regulated firms, the biggest productivity gains rarely come from headline features. Microsoft’s latest Windows 11 updates prioritise something more valuable — smoother, faster systems that reduce friction and support the consistent performance your team depends on. Here is what is changing and why it matters for compliance-focused businesses.

Is Your Data Security Keeping Pace With Your Business?

Most professional service firms believe their data security is under control — but confidence and compliance readiness are not the same thing. As cloud platforms, legacy systems and AI tools increase complexity beneath the surface, the gap between perceived security and actual governance grows. This post examines the questions every regulated firm should be asking about where data lives, who has access, and whether the answers would satisfy an auditor.

Microsoft Teams Just Fixed One of Its Most Annoying Meeting Problems

It is the small software irritations that cause the biggest disruptions. Microsoft Teams has quietly addressed one of its most frustrating quirks, the ease with which you could accidentally quit a meeting mid-conversation. For professional firms where composure and continuity matter, this subtle update is more significant than it sounds.

Why AI is the wrong tool for Passwords

Are the passwords protecting your business as strong as you think they are? AI may seem like a smart shortcut, but when it comes to security, it could be creating hidden weaknesses you can’t afford to ignore.

Relying on Windows 10 Extended Support? For Regulated Firms, Time Is Running Out

Still relying on Windows 10 Extended Security Updates? That safety net has a fixed end date. For regulated firms, waiting too long introduces unnecessary compliance and cyber risk.

LastPass Security Breach

LastPass is a password management utility and application allowing companies and people to store their passwords. After a recent breach there are some serious security issues that need attention. This article looks at what these issues are and how to re-secure your passwords.

When Cybercriminals Turn On Each Other, Your Firm Still Loses

When cybercriminals start threatening each other, it can look like good news, even an opportunity. But for a regulated firm, trusting one attacker to rescue you from another is a governance risk, not a lifeline. Here is why the only reliable route through a cyber incident runs through proper protection and trusted support, and how to make sure your firm is ready before the pressure hits.

Can your business cope with winter disruption?

Thanks to the unseasonably mild weather we’ve enjoyed this autumn, it’s easy to forget that winter, and all the potential havoc it can wreak, is soon to follow. It’s hard not to feel that our weather has become more unpredictable and freak storms just aren’t, well,...

Is Your Data Security Keeping Pace With Your Business?

Most professional service firms believe their data security is under control — but confidence and compliance readiness are not the same thing. As cloud platforms, legacy systems and AI tools increase complexity beneath the surface, the gap between perceived security and actual governance grows. This post examines the questions every regulated firm should be asking about where data lives, who has access, and whether the answers would satisfy an auditor.

4000 small businesses a day: the vicious spread of WannaCry

In May this year the online world witnessed the Wannacry ransomware attack, a cryptoworm which spread like wildfire, demanding payments in the cryptocurrency Bitcoin in over 230,000 computers using the Windows operating system. The National Health Service, the UK's...

Fake Microsoft Azure Alerts, Why Regulated Firms Must Not Let Their Guard Down

A sophisticated new phishing campaign is exploiting Microsoft Azure Monitor to deliver scam alerts that look entirely legitimate. For regulated firms, where client trust and data governance are non-negotiable, this evolving threat demands a more rigorous approach to email verification and incident response.

IT Security: Folina Vulnerability Fixed

IT security update: Folina vulnerability has been fixed by Microsoft. How to ensure your system is protected and reverse the temporary fix we suggested.

Protecting Your Business from Today’s Smarter Digital Fraud

Digital fraud is evolving at a rapid pace, and modern scams are becoming harder to spot than ever. In this article, we explore practical, everyday habits your team can adopt to stay safer online — and how a few simple tools can make a big difference.

Using AI Browsers at Work? You Need to Know This.

AI‑powered browsers can boost productivity, but they also introduce new security and data risks. Learn what businesses need to consider before adopting them.

New Password Management Tool Available from Absolutely PC

With cyber attacks on the rise and remote working becoming commonplace, now, more than ever - businesses need to keep on top of the security of their passwords or be at risk of suffering a costly data breach. A study by Verizon Data Breach Investigations found that...