Are you confident that your WordPress website is secure?

Yesterday, on the 9th of December 2021, 1.6 Million WordPress Sites were Hit With 13.7 Million Attacks In 36 Hours From 16,000 IPs. It’s safe to say this is a major concern to businesses everywhere. WordPress security is key to ensuring your website continues to deliver content for your customers and leads and business continues to operate.

 

How this can affect your business?

For most companies, websites are the main source of information about your business, therefore your WordPress being hacked means your site isn’t available for your customers and prospects, which could have a huge impact on your business and revenue. It can then lead to loss of reputation and loss of custom.

If user details are stored on the site, they may become compromised too. Loss of personally identifiable information or if your site is used to redirect and trick customers into paying  fraudulent accounts, may cause legal issues as well.

 

So what can you do?

Wordfence Premium users are protected against any exploit attempts targeting all of these vulnerabilities. Wordfence free users are protected against attacks but there is a one month delay in the updates which means this latest attack will not be protected until January 6 2021.

As a minimum we would recommend that you download and install Wordfence within WordPress. Once it has run ensure you apply the fixes to better protect your website.

Website hosting also has a significant role to play in keeping your website secure.  When choosing a hosting provider ask some questions about how they approach security.  Many hosting providers just buy space which means they have no control over the physical server let alone the firewalls that protect that server from the Internet.  Absolutely PC uses dedicated servers in secure data centres and employs the latest security techniques to ensure the infrastructure is as safe as possible.  More information about secure hosting can be found on our hosting page 

 

Let us help you

If security of your website is of concern then book a free 15 minute consultation so we can make sure your website and WordPress is secure. On the Wordfence website you can see more details about this attack here

 

When Cybercriminals Turn On Each Other, Your Firm Still Loses

When cybercriminals start threatening each other, it can look like good news, even an opportunity. But for a regulated firm, trusting one attacker to rescue you from another is a governance risk, not a lifeline. Here is why the only reliable route through a cyber incident runs through proper protection and trusted support, and how to make sure your firm is ready before the pressure hits.

The Fake CAPTCHA Trap: “Prove You’re Human” With Fresh Suspicion

CAPTCHAs are so familiar that we barely register them, and that trust is exactly what criminals are now exploiting. A new breed of fake verification page asks you to “prove you’re human” by sending a text, quietly racking up premium-rate charges that only surface later. For regulated firms, the stakes reach further than the bill. Here’s how the trap works, and how to protect your team.

Why a Routine Update Has Become a Board-Level Risk

For regulated firms, a routine software update should never become a compliance incident. Yet a highly convincing fake Windows 11 update is now fooling even experienced professionals, and a single click can expose client data. This post explains how the scam works, why it slips past security tools, and the governance-led steps every professional firm should take to stay protected and audit-ready.

Fake Microsoft Azure Alerts, Why Regulated Firms Must Not Let Their Guard Down

A sophisticated new phishing campaign is exploiting Microsoft Azure Monitor to deliver scam alerts that look entirely legitimate. For regulated firms, where client trust and data governance are non-negotiable, this evolving threat demands a more rigorous approach to email verification and incident response.

Is Your Data Security Keeping Pace With Your Business?

Most professional service firms believe their data security is under control — but confidence and compliance readiness are not the same thing. As cloud platforms, legacy systems and AI tools increase complexity beneath the surface, the gap between perceived security and actual governance grows. This post examines the questions every regulated firm should be asking about where data lives, who has access, and whether the answers would satisfy an auditor.

Why AI is the wrong tool for Passwords

Are the passwords protecting your business as strong as you think they are? AI may seem like a smart shortcut, but when it comes to security, it could be creating hidden weaknesses you can’t afford to ignore.

Beware the Next Generation of Phishing Attacks

Phishing scams are no longer crude or easy to spot. New, smarter attacks are changing the rules — and businesses need to rethink how they stay protected.

Your Browser Knows More Than You Think

Your browser doesn’t just see the websites you visit. It sees patterns, habits, and clues about your business. Most people never check what’s being shared behind the scenes. That’s a risk worth paying attention to.

Old Passwords Are Still Unlocking Systems

Old passwords your team hasn’t used in years could still unlock your systems — and attackers know it. A recent cyber incident revealed how forgotten credentials put professional service firms at serious risk, and why enforcing MFA has never been more important.

Protecting Your Business from Today’s Smarter Digital Fraud

Digital fraud is evolving at a rapid pace, and modern scams are becoming harder to spot than ever. In this article, we explore practical, everyday habits your team can adopt to stay safer online — and how a few simple tools can make a big difference.

Eternal Blue – Behind the Hack [Video Guide]

What would you do if a hacker had access to all of your sensitive documents and data through a machine that they had exploited, with access to control your webcam as well as monitor the screen and keyboard? It’s not something out of action movie, what we’re describing...

Protecting Your Business from Today’s Smarter Digital Fraud

Digital fraud is evolving at a rapid pace, and modern scams are becoming harder to spot than ever. In this article, we explore practical, everyday habits your team can adopt to stay safer online — and how a few simple tools can make a big difference.

Can your business cope with winter disruption?

Thanks to the unseasonably mild weather we’ve enjoyed this autumn, it’s easy to forget that winter, and all the potential havoc it can wreak, is soon to follow. It’s hard not to feel that our weather has become more unpredictable and freak storms just aren’t, well,...

Is Your Data Security Keeping Pace With Your Business?

Most professional service firms believe their data security is under control — but confidence and compliance readiness are not the same thing. As cloud platforms, legacy systems and AI tools increase complexity beneath the surface, the gap between perceived security and actual governance grows. This post examines the questions every regulated firm should be asking about where data lives, who has access, and whether the answers would satisfy an auditor.

4000 small businesses a day: the vicious spread of WannaCry

In May this year the online world witnessed the Wannacry ransomware attack, a cryptoworm which spread like wildfire, demanding payments in the cryptocurrency Bitcoin in over 230,000 computers using the Windows operating system. The National Health Service, the UK's...

Phishing Email: Is that email from Microsoft or a phishing attempt?

Update on how realistic phishing attacks are becoming. Could you tell the difference between a real email and a phishing one?

Ransomware – Behind the Hack [Video Guide]

How would your business react if you were locked out of every single file stored on any PC or cloud platform in your network, with the only way to free your data being to pay vast sums of money to a hacker? Well, ransomware does just that. Despite how crippling this...

Have you made these IT upgrades?

Technology is constantly changing and adapting; as such, it is important to always stay on top of upgrades to ensure you are running at optimum efficiency. At Absolutely PC, IT upgrades are a necessary and consistent part of our monthly and annual maintenance...

IT Security: Folina Vulnerability Fixed

IT security update: Folina vulnerability has been fixed by Microsoft. How to ensure your system is protected and reverse the temporary fix we suggested.

LastPass Security Breach

LastPass is a password management utility and application allowing companies and people to store their passwords. After a recent breach there are some serious security issues that need attention. This article looks at what these issues are and how to re-secure your passwords.