<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyber attack Archives - Mear Technology</title>
	<atom:link href="https://www.meartechnology.co.uk/category/security/cyber-attack/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.meartechnology.co.uk/category/security/cyber-attack/</link>
	<description>Providing IT support and solution to small and medium businesses. Servicing Edinburgh, Livingston, Fife and surrounding areas.  Responsive, Flexible, Professional and friendly local support.</description>
	<lastBuildDate>Wed, 29 Nov 2023 16:27:07 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://www.meartechnology.co.uk/wp-content/uploads/2021/04/cropped-Logo-512x512-1-32x32.png</url>
	<title>Cyber attack Archives - Mear Technology</title>
	<link>https://www.meartechnology.co.uk/category/security/cyber-attack/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Featured Article : 3000% Increase in Deepfake Frauds</title>
		<link>https://www.meartechnology.co.uk/2023/11/29/featured-article-3000-increase-in-deepfake-frauds/</link>
		
		<dc:creator><![CDATA[Paul Stradling]]></dc:creator>
		<pubDate>Wed, 29 Nov 2023 16:27:01 +0000</pubDate>
				<category><![CDATA[Cyber attack]]></category>
		<category><![CDATA[Funnies]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Manufacturers]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Data Security]]></category>
		<category><![CDATA[Deepfake]]></category>
		<category><![CDATA[social media]]></category>
		<guid isPermaLink="false">https://www.meartechnology.co.uk/?p=15173</guid>

					<description><![CDATA[<p>A new report from ID Verification Company Onfido shows that the availability of cheap generative AI tools has led to Deepfake fraud attempts increasing by 3,000 per cent (specifically, a factor of 31) in 2023. Free And Cheap AI Tools&#160; Although deepfakes have now been around for several years, as the report points out, deepfake&#8230; <br /> <a class="read-more" href="https://www.meartechnology.co.uk/2023/11/29/featured-article-3000-increase-in-deepfake-frauds/">Read more</a></p>
<p>The post <a href="https://www.meartechnology.co.uk/2023/11/29/featured-article-3000-increase-in-deepfake-frauds/">Featured Article : 3000% Increase in Deepfake Frauds</a> appeared first on <a href="https://www.meartechnology.co.uk">Mear Technology</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A new report from ID Verification Company Onfido shows that the availability of cheap generative AI tools has led to Deepfake fraud attempts increasing by 3,000 per cent (specifically, a factor of 31) in 2023.</p>



<p class="wp-block-paragraph"><strong>Free And Cheap AI Tools&nbsp;</strong></p>



<p class="wp-block-paragraph">Although deepfakes have now been around for several years, as the report points out, deepfake fraud has become significantly easier and more accessible due to the widespread availability of free and cheap generative AI tools. In simple terms, these tools have democratised the ability to create hyper-realistic fake images and videos, which were once only possible for those with advanced technical skills and access to expensive software.&nbsp;</p>



<p class="wp-block-paragraph">Prior to the public availability of AI tools, for example, creating a convincing fake video or image required a deep understanding of computer graphics and access to high-end, often costly, software (a barrier to entry for would-be deep-fakers). &nbsp;</p>



<p class="wp-block-paragraph"><strong>Document and Biometric Fraud – The New Frontier&nbsp;</strong></p>



<p class="wp-block-paragraph">The Onfido data reveals a worrying trend in that while physical counterfeits are still prevalent, there’s a notable shift towards digital manipulation of documents and biometrics, facilitated by the availability and sophistication of AI tools. Fraudsters are not only altering documents digitally but also exploiting biometric verification systems through deepfakes and other AI-assisted methods. The Onfido report highlights a dramatic rise in the&nbsp;rate of biometric fraud, which doubled from 2022 to 2023.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Deepfakes – A Growing Threat&nbsp;</strong></p>



<p class="wp-block-paragraph">As reinforced by the findings of the report, deepfakes pose an emerging and significant threat, particularly in biometric verification. The accessibility of generative AI and face-swap apps has made the creation of deepfakes easier and highly scalable, which is evidenced by a 31X increase in deepfake attempts in 2023 compared to the previous year!&nbsp;</p>



<p class="wp-block-paragraph"><strong>Minimum Effort (And Cost) For Maximum Return</strong>&nbsp;</p>



<p class="wp-block-paragraph">As the Onfido report points out, simple ‘face swapping’ apps (i.e. apps which leverage advanced AI algorithms to seamlessly superimpose one person’s face onto another in photos or videos) offer ease of use and effectiveness in creating convincing fake identities. They are part of an influx of readily available online AI assisted tools that are providing fraudsters with a new avenue into biometric fraud.&nbsp;For example, the Onfido data shows that Biometric fraud attempts are clearly higher this year than in previous years with fraudsters favouring tools like the face-swapping apps to target selfie biometric checks and create fake identities. &nbsp;</p>



<p class="wp-block-paragraph">The kind of fakes these cheap, easy apps create have been dubbed “cheapfakes” and this conforms with something that’s long been known about online fraudsters and cyber criminals – they seek methods that require minimum effort, minimum expense and minimum personal risk, yet deliver maximum effect.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Sector-Specific Impact of Deepfakes&nbsp;</strong></p>



<p class="wp-block-paragraph">The Identity Fraud Report shows that (perhaps obviously) the gambling and financial sectors in particular are facing the brunt of these sophisticated fraud attempts. The lure of cash rewards and high-value transactions in these sectors makes them attractive targets for deepfake-driven frauds. In the gambling industry, for example, fraudsters may be particularly attracted to the sign-up and referral bonuses. In the financial industry, where frauds tend to be based around money laundering and loan theft, Onfido reports that digital attacks are easy to scale, especially when incorporating AI tools.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Implications For UK Businesses In The Age of (AI) Deepfake-Driven Fraud&nbsp;</strong></p>



<p class="wp-block-paragraph">The surge in deepfake-driven fraud highlighted by the somewhat startling statistics in Onfido’s 2024 Identity Fraud Report, suggest that UK businesses navigating this new landscape may require a multifaceted approach. This could be achieved by&nbsp;balancing the implementation of cutting-edge technologies with heightened awareness and strategic planning. In more detail, this could involve:&nbsp;</p>



<p class="wp-block-paragraph">– UK businesses prioritising the reinforcement of their identity verification processes. The traditional methods may no longer suffice against the sophistication of deepfakes. Therefore, Adopting AI-powered solutions that are specifically designed to detect and counter deepfake attempts could be the way forward.&nbsp;This could work as long as such systems can keep up with the advancements in fraudulent techniques (more advanced techniques may emerge as more AI sophisticated AI tools emerge).&nbsp;</p>



<p class="wp-block-paragraph">– The training of staff, i.e. educating them about the nature of deepfakes and how they can be used to perpetrate fraud. This could empower employees to better recognise potential threats and respond appropriately, particularly in sectors like customer service and security, where human judgment plays a key role.&nbsp;</p>



<p class="wp-block-paragraph">– Maintaining customer trust. UK businesses must navigate the fine line between implementing robust security measures and ensuring a frictionless customer experience. Transparent communication about the security measures in place and how they protect customer data can help in maintaining and even enhancing customer trust.&nbsp;</p>



<p class="wp-block-paragraph">– As the use of deepfakes in fraud rises, regulatory bodies may introduce new compliance requirements and UK businesses will need to ensure that they stay abreast of these changes both to protect customers and remain compliant with legal standards. This in turn could require more rigorous data protection protocols or mandatory reporting of deepfake-related breaches.&nbsp;</p>



<p class="wp-block-paragraph">– Collaboration with industry peers and participation in broader discussions about combating deepfake fraud may also be a way to gain valuable insights. Sharing knowledge and strategies, for example, could help in developing industry-wide best practices. Also, partnerships with technology providers specialising in AI and fraud detection could offer access to the latest tools and expertise.&nbsp;</p>



<p class="wp-block-paragraph">– Since deepfake fraud may be an ongoing threat, long-term strategic planning may be essential. This perspective could be integrated into long-term business strategies, thereby (hopefully) making sure that resources are available and allocated not just for immediate solutions but also for future-proofing against evolving digital threats.&nbsp;</p>



<p class="wp-block-paragraph"><strong>What Else Can Businesses Do To Combat Threats Like AI-Generated Deepfakes?&nbsp;</strong></p>



<p class="wp-block-paragraph">Other ways that businesses can contribute to the necessary comprehensive approach to tackling the AI-generated deepfake threat may also include:&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">– Implementing biometric verification technologies that require live interactions (so-called ‘liveness solutions’), such as head movements, which are difficult for deepfakes to replicate.&nbsp;</p>



<p class="wp-block-paragraph">– The use of SDKs (platform-specific building tools for developers) over APIs. For example,&nbsp;SDKs provide better protection against fraudulent submissions as they incorporate live capture and device integrity checks.&nbsp;</p>



<p class="wp-block-paragraph"><strong>The Dual Nature Of Generative AI&nbsp;</strong></p>



<p class="wp-block-paragraph">Although, as you’d expect an ‘Identity Fraud Report’ to do, the Onfido report focuses solely on the threats posed by AI, it’s important to remember that AI tools can be used by all businesses to add value, save time, improve productivity, get more creative, and to defend against the AI threats. AI-driven verification tools, for example, are becoming more adept at detecting and preventing fraud, underscoring the technology’s dual nature as both a tool for fraudsters and a shield for businesses.&nbsp;</p>



<p class="wp-block-paragraph"><strong>What Does This Mean For Your Business?&nbsp;</strong></p>



<p class="wp-block-paragraph">Tempering the reading of the startling stats in the report with the knowledge that Onfido is selling its own deepfake (liveness) detection solution and SDKs, it still paints a rather worrying picture for businesses. That said, The Onfido 2024 Identity Fraud Report’s findings, highlighting a 3000 per cent increase in deepfake fraud attempts due to readily available generative AI tools, signal a pivotal shift in the landscape of online fraud. This shift could pose new challenges for UK businesses but also open avenues for innovative solutions.&nbsp;</p>



<p class="wp-block-paragraph">For businesses, the immediate response may involve upgrading identity verification processes with AI-powered solutions tailored to detect and counter deepfakes. However, it’s not just about deploying advanced technology. It’s also about ensuring these systems evolve with the fraudsters’ tactics. Equally crucial is the role of employee training in recognising and responding to these sophisticated fraud attempts.&nbsp;</p>



<p class="wp-block-paragraph">As regulatory landscapes adjust to these emerging threats, staying informed and compliant is also likely to become essential. The goal is not only to counter current threats but to build resilience and innovation for future challenges.</p>
<p>The post <a href="https://www.meartechnology.co.uk/2023/11/29/featured-article-3000-increase-in-deepfake-frauds/">Featured Article : 3000% Increase in Deepfake Frauds</a> appeared first on <a href="https://www.meartechnology.co.uk">Mear Technology</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Trend Micro Takes Down Notorious Phishing Operation by Working with INTERPOL</title>
		<link>https://www.meartechnology.co.uk/2023/09/12/trend-micro-takes-down-notorious-phishing-operation-by-working-with-interpol/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Tue, 12 Sep 2023 09:29:30 +0000</pubDate>
				<category><![CDATA[Cyber attack]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[Trend Micro]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Virus and antivirus]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[interpol]]></category>
		<category><![CDATA[trendmicro]]></category>
		<guid isPermaLink="false">https://www.meartechnology.co.uk/?p=14959</guid>

					<description><![CDATA[<p>Trend Micro have a long-standing history of working with Law enforcement around the world to help take down organised criminals. This is just one example of many where they have been successful in closing down and disrupting organised crime. Well done and thank you Trend Micro and Interpol. What is the significance of this takedown?&#8230; <br /> <a class="read-more" href="https://www.meartechnology.co.uk/2023/09/12/trend-micro-takes-down-notorious-phishing-operation-by-working-with-interpol/">Read more</a></p>
<p>The post <a href="https://www.meartechnology.co.uk/2023/09/12/trend-micro-takes-down-notorious-phishing-operation-by-working-with-interpol/">Trend Micro Takes Down Notorious Phishing Operation by Working with INTERPOL</a> appeared first on <a href="https://www.meartechnology.co.uk">Mear Technology</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Trend Micro have a long-standing history of working with Law enforcement around the world to help take down organised criminals. This is just one example of many where they have been successful in closing down and disrupting organised crime.  Well done and thank you Trend Micro and Interpol.</p>



<h2 class="wp-block-heading" id="h-what-is-the-significance-of-this-takedown">What is the significance of this takedown? </h2>



<p class="wp-block-paragraph">16Shop specialises in the sales of phishing kits that other cybercriminals can purchase to mount phishing attacks on a large scale, ultimately facilitating the theft of credentials and payment details from users of popular services such as Apple, PayPal, American Express, Amazon, and Cash App, among others.</p>



<p class="wp-block-paragraph">It is estimated that around 70,000 users across 43 countries have been compromised thanks to 16Shop. So it is good news globally that this has been a successful campaign. </p>



<div class="wp-block-media-text is-stacked-on-mobile has-white-color has-black-background-color has-text-color has-background"><figure class="wp-block-media-text__media"><a href="https://newsroom.trendmicro.com/2023-08-14-Trend-Micro-Teams-Up-with-INTERPOL-to-Take-Down-Notorious-Phishing-Operation#assets_all" target="_blank" rel="noreferrer noopener"><img fetchpriority="high" decoding="async" width="663" height="260" src="https://www.meartechnology.co.uk/wp-content/uploads/2023/09/Learn-more-about-16Shop-Takedown.png" alt="" class="wp-image-14962 size-full no-lazyload" srcset="https://www.meartechnology.co.uk/wp-content/uploads/2023/09/Learn-more-about-16Shop-Takedown.png 663w, https://www.meartechnology.co.uk/wp-content/uploads/2023/09/Learn-more-about-16Shop-Takedown-300x118.png 300w" sizes="(max-width: 663px) 100vw, 663px" /></a></figure><div class="wp-block-media-text__content">
<p class="has-text-align-center has-white-color has-black-background-color has-text-color has-background wp-block-paragraph">To find out more about how Trend helped <a href="https://newsroom.trendmicro.com/2023-08-14-Trend-Micro-Teams-Up-with-INTERPOL-to-Take-Down-Notorious-Phishing-Operation#assets_all">click here</a></p>
</div></div>



<h2 class="wp-block-heading" id="h-in-the-news">In the News</h2>



<p class="wp-block-paragraph"><a href="https://newsroom.trendmicro.com/2023-08-14-Trend-Micro-Teams-Up-with-INTERPOL-to-Take-Down-Notorious-Phishing-Operation#assets_all">https://newsroom.trendmicro.com/2023-08-14-Trend-Micro-Teams-Up-with-INTERPOL-to-Take-Down-Notorious-Phishing-Operation#assets_all</a></p>



<p class="wp-block-paragraph"><a href="https://www.interpol.int/en/News-and-Events/News/2023/Notorious-phishing-platform-shut-down-arrests-in-international-police-operation">https://www.interpol.int/en/News-and-Events/News/2023/Notorious-phishing-platform-shut-down-arrests-in-international-police-operation</a></p>



<p class="wp-block-paragraph"><a href="https://thehackernews.com/2023/08/interpol-busts-phishing-as-service.html">https://thehackernews.com/2023/08/interpol-busts-phishing-as-service.html</a></p>
<p>The post <a href="https://www.meartechnology.co.uk/2023/09/12/trend-micro-takes-down-notorious-phishing-operation-by-working-with-interpol/">Trend Micro Takes Down Notorious Phishing Operation by Working with INTERPOL</a> appeared first on <a href="https://www.meartechnology.co.uk">Mear Technology</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Tech Insight : What Are &#8216;Zero-Day&#8217; Attacks?</title>
		<link>https://www.meartechnology.co.uk/2023/07/21/tech-insight-what-are-zero-day-attacks/</link>
		
		<dc:creator><![CDATA[Paul Stradling]]></dc:creator>
		<pubDate>Fri, 21 Jul 2023 09:16:58 +0000</pubDate>
				<category><![CDATA[Cyber attack]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Office 365]]></category>
		<category><![CDATA[Operating System]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[Virus and antivirus]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[zero-day attacks]]></category>
		<guid isPermaLink="false">https://www.meartechnology.co.uk/?p=14048</guid>

					<description><![CDATA[<p>In this tech insight, we look at what ‘zero-day’ attacks are, then look at some recent high-profile examples and ultimately at what businesses can do to protect themselves from zero-day attacks.&#160; Sophisticated Attacks That Highlight Vulnerabilities&#160; In the ever-evolving landscape of digital threats and cyber warfare, one term often sends chills down the spines of&#8230; <br /> <a class="read-more" href="https://www.meartechnology.co.uk/2023/07/21/tech-insight-what-are-zero-day-attacks/">Read more</a></p>
<p>The post <a href="https://www.meartechnology.co.uk/2023/07/21/tech-insight-what-are-zero-day-attacks/">Tech Insight : What Are &#8216;Zero-Day&#8217; Attacks?</a> appeared first on <a href="https://www.meartechnology.co.uk">Mear Technology</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">In this tech insight, we look at what ‘zero-day’ attacks are, then look at some recent high-profile examples and ultimately at what businesses can do to protect themselves from zero-day attacks.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Sophisticated Attacks That Highlight Vulnerabilities&nbsp;</strong></p>



<p class="wp-block-paragraph">In the ever-evolving landscape of digital threats and cyber warfare, one term often sends chills down the spines of cybersecurity professionals:&nbsp;<strong>Zero-Day Attack</strong>s. These sophisticated and stealthy cyber-attacks represent a significant challenge in today’s interconnected business world. They symbolise not just the advancement of cybercriminals’ tactics but also highlight the vulnerabilities that exist within our most trusted digital infrastructures.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Exploiting Zero-Day Vulnerabilities&nbsp;</strong></p>



<p class="wp-block-paragraph">Zero-day attacks are attacks by threat actors that exploit zero-day vulnerabilities. These are undisclosed software vulnerabilities (unknown to vendor or victims) that hackers can exploit to adversely affect computer programs, data, additional computers, or a network.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Vulnerabilities targeted in zero-day attacks can be found in operating systems, web browsers, Office applications, open-source components, hardware and firmware, and the Internet of Things (IoT).&nbsp;</p>



<p class="wp-block-paragraph"><strong>Why “Zero-Day”?&nbsp;</strong></p>



<p class="wp-block-paragraph">The term “zero-day” comes from the fact that software developers and those in charge of digital security have zero days to fix the vulnerability because it is simply not known to them until the first attack. This means that attackers can exploit the vulnerabilities before developers become aware and are able to issue any patches or remediations.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph"><strong>How Big Is The Problem?&nbsp;</strong></p>



<p class="wp-block-paragraph">Although zero-day vulnerabilities fell by almost a third in 2022, it was still the second highest year on record (Mandiant research) with 55 zero-day vulnerabilities exploited and products from the three largest vendors (Microsoft, Google, and Apple) were the most commonly exploited (for the third year in a row).&nbsp;</p>



<p class="wp-block-paragraph"><strong>What Can Happen?&nbsp;</strong></p>



<p class="wp-block-paragraph">Zero-day attacks commonly result in unauthorised data access, data theft, or service disruptions. These, in turn, can result in reputational damage, lost customers, fines (e.g. legal action by those affected an/or ICO fines), plus possibly the loss of the business itself if the attack is serious enough. Secondary attacks on the business and those affected by data theft could also come from the first attack,.e.g. malware, ransomware, phishing, social engineering attacks, and more.&nbsp;</p>



<p class="wp-block-paragraph">Cybersecurity experts, therefore, continually work to discover these types of vulnerabilities before hackers do, to try and prevent potential attacks.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Vulnerabilities, Exploits, Then Attacks&nbsp;</strong></p>



<p class="wp-block-paragraph">After threat actors have discovered a zero-day vulnerability, the next stage is ‘zero-day exploits’ – the blueprints that outline how these hidden flaws can be taken advantage of, often traded on the dark web. The zero-day attack itself is, therefore, the act of exploiting the flaw/vulnerability, using the guidance of the exploit, before a patch can be rolled out, leaving a digital system scrambling in the wake of the unforeseen breach.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Who?&nbsp;</strong></p>



<p class="wp-block-paragraph">These under-the-radar strikes are often orchestrated by advanced cyber criminals, state-sponsored hacking groups, or unscrupulous entities with nefarious motives. The objectives are as varied as the threat actors themselves. For some, it’s about monetary gains whereas for others, it’s a tool for intellectual property theft, infiltrating state secrets, or merely sowing seeds of chaos. Corporate espionage and political machinations are just the tip of the iceberg when it comes to reasons behind these attacks.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Recent High-Profile Examples&nbsp;</strong></p>



<p class="wp-block-paragraph">Some recent, high-profile examples of Zero-Day attacks include:&nbsp;</p>



<p class="wp-block-paragraph">– In 2023, a critical vulnerability was uncovered in the secure managed file transfer (MFT) service provided by MOVEit, a transfer platform widely used by large companies in a variety of sectors including healthcare, government, finance, and aviation. The Russian-based Clop Ransomware group exploited the vulnerability and were able to steal data from eight UK organisations including BBC, British Airways, Aer Lingus, and Boots.&nbsp;</p>



<p class="wp-block-paragraph">– In 2022 the CVE-2022-30190, a.k.a.&nbsp;Follina vulnerability in Microsoft Diagnostics Tool (MDST), was exploited and victims were persuaded to open Word documents which enabled attackers to execute arbitrary code. The government of the Philippines, business service providers in South Asia, and organisations in Belarus and Russia were all subject to the same zero-day attack.&nbsp;</p>



<p class="wp-block-paragraph">– The notorious Microsoft Exchange Server hack in early 2021, widely believed to have been sponsored by a nation-state, exploited several previously unknown vulnerabilities in Microsoft’s email server software. The damage was widespread and profound, with tens of thousands of organisations worldwide left grappling with the aftermath before a security patch could be rolled out.&nbsp;</p>



<p class="wp-block-paragraph">– Google’s Chrome suffered a series of zero-day threats in 2021,&nbsp;causing Chrome to issue updates. The vulnerability was a bug in the V8 JavaScript engine used in the web browser.&nbsp;</p>



<p class="wp-block-paragraph">– A zero-day attack on video conferencing platform Zoom in 2020 where hackers accessed a user’s PC remotely if they were running an older version of Windows. The hackers targeted the administrator, allowing them to completely take over their machine and access all files.&nbsp;</p>



<p class="wp-block-paragraph">– In 2020, the Apple iOS was attacked twice with zero-day vulnerabilities and one zero-day bug allowed attackers to compromise iPhones remotely.&nbsp;</p>



<p class="wp-block-paragraph"><strong>How Businesses Can Protect Themselves&nbsp;</strong></p>



<p class="wp-block-paragraph">So, how can businesses protect themselves against the threat of zero-day attacks? Given their nature, these attacks pose a formidable challenge, but protective measures that can be taken include:&nbsp;</p>



<p class="wp-block-paragraph">– Regularly updating software updates and staying up to date with patching.&nbsp;</p>



<p class="wp-block-paragraph">– Employing advanced threat detection tools that utilise behaviour-based detection techniques to pinpoint anomalies and unusual activity in network traffic (often the first sign of a zero-day attack).&nbsp;</p>



<p class="wp-block-paragraph">– Conducting regular penetration tests and vulnerability assessments. These proactive practices can unearth previously unknown vulnerabilities within systems, allowing businesses to patch them before they are exploited. Following the principle of least privilege – limiting user access rights to the bare minimum needed for their work – can also help reduce the extent of potential damage should an attack occur.&nbsp;</p>



<p class="wp-block-paragraph">– Beyond technological defences, investing in comprehensive cybersecurity awareness training for employees is crucial. An informed team acts as the human firewall against cyber threats, understanding the risks, recognising signs of possible attacks, and knowing how to respond swiftly and effectively.&nbsp;</p>



<p class="wp-block-paragraph"><strong>What Does This Mean For Your Business?&nbsp;</strong></p>



<p class="wp-block-paragraph">In the face of the ominous threat of zero-day attacks, businesses must adopt a proactive and comprehensive approach to digital security. A robust defence strategy isn’t a luxury but an absolute necessity in today’s digital age. It involves a constant balancing act of risk management, regular system updates, advanced threat detection, routine penetration testing, and vulnerability assessments, regular system audits, and maintaining a culture of security vigilance throughout the organisation.&nbsp;</p>



<p class="wp-block-paragraph">A multi-layered security approach and a zero-trust model could, therefore, provide a solid foundation for defence although, because some vulnerabilities may still not be known until it’s too late, zero-day attacks remain an ever-present threat.&nbsp;</p>



<p class="wp-block-paragraph">The potential devastation of zero-day attacks and their aftermath is unquestionable, but it is not an insurmountable challenge. By being as vigilant and proactive in defence measures as is realistically possible, businesses can steer through the murky waters of the cyber threat landscape, securing their digital assets, and upholding the trust of their customers and partners. The world of cybersecurity may be akin to a never-ending arms race, but with the right preparation and resilience, staying one step ahead must be an achievable goal.</p>
<p>The post <a href="https://www.meartechnology.co.uk/2023/07/21/tech-insight-what-are-zero-day-attacks/">Tech Insight : What Are &#8216;Zero-Day&#8217; Attacks?</a> appeared first on <a href="https://www.meartechnology.co.uk">Mear Technology</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How scammers are using AI</title>
		<link>https://www.meartechnology.co.uk/2023/06/06/how-scammers-are-using-ai/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Tue, 06 Jun 2023 22:04:10 +0000</pubDate>
				<category><![CDATA[Cyber attack]]></category>
		<category><![CDATA[Cyber Essentials]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[cyber security]]></category>
		<guid isPermaLink="false">https://www.meartechnology.co.uk/?p=13415</guid>

					<description><![CDATA[<p>Unmasking the Dangers: How Scammers Exploit Voice Cloning Technology There has been lots of information in the news about AI Microsoft has announced that soon AI will be integrated into their Office Suite by way of copilot. While the benefits of AI are helping deliver faster solutions to issues those who make their living from&#8230; <br /> <a class="read-more" href="https://www.meartechnology.co.uk/2023/06/06/how-scammers-are-using-ai/">Read more</a></p>
<p>The post <a href="https://www.meartechnology.co.uk/2023/06/06/how-scammers-are-using-ai/">How scammers are using AI</a> appeared first on <a href="https://www.meartechnology.co.uk">Mear Technology</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Unmasking the Dangers: How Scammers Exploit Voice Cloning Technology</p>



<p class="wp-block-paragraph">There has been lots of information in the news about AI Microsoft has announced that soon AI will be integrated into their Office Suite by way of copilot.  While the benefits of AI are helping deliver faster solutions to issues those who make their living from exploiting others have also been gaining from these advanced. </p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<div class='embed-container'><iframe title="Introducing Microsoft 365 Copilot | Your Copilot for Work" width="1920" height="1080" src="https://www.youtube.com/embed/S7xTBa93TX8?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></div>
</div></figure>



<p class="wp-block-paragraph">Voice cloning, once limited to science fiction, has become a reality with the advent of deepfake technology. While voice cloning has legitimate applications, it has also become a powerful tool for scammers and cybercriminals to deceive and manipulate unsuspecting victims. In this blog post, we will explore the insidious ways in which scammers exploit voice cloning technology, highlighting the need for awareness and vigilance in an increasingly digital world.</p>



<ol class="wp-block-list">
<li><strong>Understanding Voice Cloning: </strong>Voice cloning technology utilizes deep learning algorithms to replicate and synthesize a person&#8217;s voice. By analyzing a target&#8217;s vocal patterns, intonation, and speech patterns, scammers can create a convincing replica that mimics the original speaker. This technology has numerous positive applications, such as improving text-to-speech systems or aiding those with speech impairments. However, scammers have found ways to exploit it for malicious purposes.</li>



<li><strong>Impersonation and Social Engineering: </strong>Scammers can use voice cloning to impersonate someone familiar to the victim, such as a family member, friend, or colleague. By mimicking the voice of a trusted individual, scammers aim to deceive victims into believing they are communicating with the real person. This tactic is particularly effective in social engineering schemes, where scammers manipulate victims into disclosing sensitive information, transferring funds, or granting unauthorized access to accounts.</li>



<li><strong>Phishing and Vishing Attacks: </strong>Voice cloning adds a chilling level of authenticity to phishing and vishing attacks. Phishing scams involve sending fraudulent emails, while vishing (voice phishing) attacks use phone calls to trick victims. Scammers can use cloned voices to make phone calls or leave voice messages that seem legitimate, urging victims to provide personal information or perform certain actions. The familiar voice combined with urgency can lead unsuspecting individuals to fall prey to these fraudulent schemes.</li>



<li><strong>Malicious Content Generation: </strong>Voice cloning enables scammers to generate convincing audio content, such as fake news, forged voice messages, or doctored recordings. By mimicking the voices of prominent figures, scammers can spread misinformation, incite panic, or even damage reputations. The widespread availability of social media platforms and messaging apps amplifies the potential harm of such manipulated content, as it can easily be shared and disseminated to a large audience.</li>



<li><strong>Combining Voice Cloning with Other Technologies:</strong> Voice cloning can be further enhanced by combining it with other technologies like artificial intelligence (AI) chatbots or video deepfakes. By synchronizing a cloned voice with an AI-powered chatbot or overlaying it on a video, scammers can create highly realistic and persuasive interactions. This multi-modal deception can intensify the impact on victims, making it even more challenging to discern between genuine and manipulated content.</li>
</ol>



<p class="wp-block-paragraph">As voice cloning technology continues to advance, scammers are increasingly harnessing its power to exploit unsuspecting individuals. It is crucial for individuals and organizations to be aware of these risks and take precautions to protect themselves. Educating oneself about voice cloning, being vigilant while interacting with others, and implementing robust security measures are key to mitigating the dangers posed by scammers who abuse this technology. By staying informed and exercising caution, we can safeguard ourselves and prevent falling victim to the insidious tactics of voice cloning scammers in this digital age.</p>



<p class="wp-block-paragraph">One of the youtube channels we follow has a nice youtube short basically saying the same thing</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<div class='embed-container'><iframe title="A.I. voice cloning is scary!" width="1920" height="1080" src="https://www.youtube.com/embed/BqRLYI84WYU?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></div>
</div></figure>



<h2 class="wp-block-heading" id="h-how-to-protect-yourself-from-voice-cloning-scams-and-what-are-the-risks">How to protect yourself from voice cloning scams and what are the risks</h2>



<p class="wp-block-paragraph">The risks of voice cloning scams are serious. You may lose money, compromise your identity, expose your sensitive data or damage your relationships. You may also feel violated, betrayed and confused by hearing a familiar voice that is not real.</p>



<p class="wp-block-paragraph">Here are some tips:</p>



<ul class="wp-block-list">
<li>Be sceptical of any unexpected or urgent calls from people you know asking for money or personal information. Verify their identity by asking questions that only they would know, or by calling them back on their known number.</li>



<li>Do not rely on caller ID alone to identify the caller. Caller ID can be easily manipulated by scammers using spoofing techniques.</li>



<li>Do not send money or share personal information through unusual methods, such as gift cards, cryptocurrency or wire transfers. These methods are often untraceable and irreversible.</li>



<li>Do not follow any instructions that ask you to keep the call secret or not to tell anyone about it. This is a common tactic used by scammers to prevent you from seeking help or advice.</li>



<li>Report any suspicious calls to your local authorities, your bank or your phone company. You may also want to warn your contacts about the possibility of voice cloning scams and ask them to be careful.</li>
</ul>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://www.meartechnology.co.uk/2023/06/06/how-scammers-are-using-ai/">How scammers are using AI</a> appeared first on <a href="https://www.meartechnology.co.uk">Mear Technology</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>New Reports Reveal Two Key Cyber Security Insights</title>
		<link>https://www.meartechnology.co.uk/2023/06/02/new-reports-reveal-two-key-cyber-security-insights/</link>
		
		<dc:creator><![CDATA[Paul Stradling]]></dc:creator>
		<pubDate>Fri, 02 Jun 2023 10:00:31 +0000</pubDate>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Cyber attack]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Office 365]]></category>
		<category><![CDATA[Operating System]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[spear phishing]]></category>
		<guid isPermaLink="false">https://www.meartechnology.co.uk/?p=13408</guid>

					<description><![CDATA[<p>With phishing attacks being favoured for their effectiveness by attackers and most ransomware attacks now targeting backup storage, we look at what businesses can do to protect themselves.&#160;&#160; Spear Phishing Accounted For Two-Thirds Of All Attacks Last Year&#160; A recent report from security provider Barracuda has revealed that although spear phishing attacks make up just&#8230; <br /> <a class="read-more" href="https://www.meartechnology.co.uk/2023/06/02/new-reports-reveal-two-key-cyber-security-insights/">Read more</a></p>
<p>The post <a href="https://www.meartechnology.co.uk/2023/06/02/new-reports-reveal-two-key-cyber-security-insights/">New Reports Reveal Two Key Cyber Security Insights</a> appeared first on <a href="https://www.meartechnology.co.uk">Mear Technology</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">With phishing attacks being favoured for their effectiveness by attackers and most ransomware attacks now targeting backup storage, we look at what businesses can do to protect themselves.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph"><strong>Spear Phishing Accounted For Two-Thirds Of All Attacks Last Year&nbsp;</strong></p>



<p class="wp-block-paragraph">A recent report from security provider Barracuda has revealed that although spear phishing attacks make up just 0.1 per cent of all email-based attacks in 2023, they were responsible for two-thirds of all breaches. The report showed that a massive 50 per cent of the 1,350 organisations surveyed had fallen victim to a spear-phishing attack in 2022, a quarter had had at least one email account compromised via an account takeover. The report also showed that of those who fell victim to a successful spear phishing attack, 55 per cent had machines infected with malware or viruses, and 49 per cent and 48 per cent respectively had sensitive data or login details stolen.&nbsp;</p>



<p class="wp-block-paragraph"><strong>What Is Spear Phishing?&nbsp;</strong></p>



<p class="wp-block-paragraph">Spear phishing is a targeted form of phishing that aims to deceive individuals or organisations by sending bogus, fraudulent emails or messages. While traditional phishing attempts are more generic and widespread, spear phishing campaigns are highly tailored and personalised to trick specific targets, such as employees of a particular company or members of an organisation.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Targets Are Researched&nbsp;</strong></p>



<p class="wp-block-paragraph">The attackers behind spear phishing typically research their targets extensively to gather information that will make their messages appear legitimate and increase the chances of success. They may gather details from social media profiles, online directories, or leaked data from previous breaches. This information is then used to create highly convincing email messages that appear to be from a trusted source, such as a colleague, a client, or a supervisor.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Personalised Content To Make Them More Convincing&nbsp;</strong></p>



<p class="wp-block-paragraph">Spear phishing emails often contain personalised content, such as the recipient’s name, job title, or other relevant details, which makes them appear more authentic. They may also exploit psychological manipulation techniques to evoke a sense of urgency, curiosity, or fear to compel the target to click on a malicious link or download a malicious attachment. Once the recipient interacts with the malicious content, the attacker may gain unauthorised access to sensitive information, such as login credentials, financial data, or proprietary information.&nbsp;</p>



<p class="wp-block-paragraph"><strong>The Consequences&nbsp;</strong></p>



<p class="wp-block-paragraph">Spear phishing attacks can have severe consequences for individuals and organisations, including data breaches, financial loss, reputational damage, and further exploitation of compromised accounts.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph"><strong>How To Protect Your Business From Spear Phishing&nbsp;</strong><br>&nbsp;<br>To protect against spear phishing, it is important to exercise caution when opening emails, verify the legitimacy of unexpected or suspicious requests, and regularly educate and train employees on identifying and reporting phishing attempts. Also, account takeover protection solutions with artificial intelligence capabilities can be effective.&nbsp;</p>



<p class="wp-block-paragraph">It is difficult, however, to stop attackers from gathering the information about a business and specific personnel within that business to help them target their attacks. For example, some information may have been gathered from information stolen in previous cyberattacks or data breaches and may have been gathered from social media. Businesses should, where possible, be careful about how much information is shared online about the business and staff members, e.g., ‘meet the team’ or ‘about us’ pages, as this could also be used by attackers.&nbsp;</p>



<p class="wp-block-paragraph"><strong>A Launching Point For More Advanced Attacks&nbsp;</strong></p>



<p class="wp-block-paragraph">Spear Phishing is widely recognised as one of the most successful and commonly used techniques in cybercriminal campaigns and is favoured by attackers because it capitalises on human vulnerabilities/human error, exploits the trust placed in familiar or authoritative sources, and can be easier than trying hack complicated and well-defended systems – cyber criminals always look for the maximum payoff from minimum effort and risk.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">By carefully crafting personalised messages, attackers can significantly increase the chances of success in compromising targets compared to generic phishing attempts. The level of sophistication and customisation in spear phishing attacks makes them harder to detect and raises the probability of successful infiltration.&nbsp;</p>



<p class="wp-block-paragraph">Moreover, spear phishing serves as a launching point for more advanced attacks, such as targeted malware infections, social engineering exploits, or business email compromise (BEC) schemes. Once an attacker gains a foothold through spear phishing, they can proceed with their malicious activities, including data exfiltration, network infiltration, or financial fraud.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Reasons For The New Figures&nbsp;</strong></p>



<p class="wp-block-paragraph">The reasons why spear phishing makes up only 0.1 per cent of all email-based attacks but are responsible for two-thirds of all breaches (i.e they have disproportionately higher success rate compared to other types of email-based attacks) are, therefore, that:&nbsp;</p>



<p class="wp-block-paragraph">– Spear-phishing attacks are highly targeted and tailored to specific individuals or organisations, and this customisation makes the attacks more convincing, increases the likelihood of victims falling for them and, therefore, increases their effectiveness.&nbsp;</p>



<p class="wp-block-paragraph">– These attacks take advantage of human psychology and behavioural traits, such as trust, curiosity, and urgency and, by leveraging these vulnerabilities, attackers can trick individuals into divulging sensitive information or performing actions that compromise security.&nbsp;</p>



<p class="wp-block-paragraph">– Spear Phishing bypasses technical security measures, e.g. firewalls, antivirus software, and spam filters, enabling attackers to circumvent traditional security controls and directly target individuals.&nbsp;</p>



<p class="wp-block-paragraph">– While spear-phishing attacks may target a specific individual initially, their success can lead to broader repercussions. For example, compromising one employee’s credentials through a spear-phishing attack could provide the attacker with access to sensitive systems or information, potentially leading to a significant breach affecting an entire organisation.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Most Ransomware Attacks Target Backups&nbsp;</strong>&nbsp;</p>



<p class="wp-block-paragraph">The 2023 Ransomware Trends Report from software company Veeam has revealed that 93 per cent of cyber-attacks target backup storage to force the ransom payment because it removes the option of recovery. The report found that these attacks are successful in debilitating their victims’ ability to recover in three-quarters of events and that more than one-third (39 per cent) of backup repositories are completely lost in these backup-targeted attacks.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Ransomware?&nbsp;</strong></p>



<p class="wp-block-paragraph">As the name suggests, ransomware is a type of malicious software designed to encrypt files on a victim’s computer or network, rendering them inaccessible until a ransom is paid to the attacker (usually to a crypto account like bitcoin to avoid detection). It is a form of cyber extortion that aims to extort money from individuals, businesses, or organisations by holding their valuable data hostage.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Paying The Ransom?&nbsp;</strong></p>



<p class="wp-block-paragraph">It is widely known that paying the ransom often doesn’t work and even if the ransom is paid, data can still be destroyed and/or, the attackers don’t provide the decryption key and simply make off with the money.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">That said, according to the Veeam report, for the second year in a row, most of the organisations surveyed (80 per cent) said they had paid the ransom to end an attack and recover data, despite 41 per cent of organisations actually having a “Do-Not-Pay” policy on ransomware. Still, while 59 per cent paid the ransom and were able to recover data, 21 per cent paid the ransom yet still didn’t get their data back from the cyber criminals. Additionally, only 16 per cent of organisations avoided paying ransom because they were able to recover from backups. Sadly, the global statistic of organisations able to recover data themselves without paying ransom is down from 19 per cent in last year’s survey.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Protecting Your Business Against Ransomware Attacks</strong>&nbsp;</p>



<p class="wp-block-paragraph">Typically, preventing ransomware attacks involves a combination of proactive measures such as regularly updating software and systems, implementing robust security practices, training employees on recognising and avoiding suspicious emails or websites, maintaining secure backups of important data, and deploying reliable antivirus and anti-malware solutions.&nbsp;</p>



<p class="wp-block-paragraph">Veeam notes in its comments about the report’s findings that while best practices like securing backup credentials, automating cyber detection scans of backups, and auto verifying that backups are restorable can help protect against attacks,&nbsp;<em>“the key tactic is to ensure that the backup repositories cannot be deleted or corrupted. To do so, organisations must focus on immutability.”&nbsp;&nbsp;</em></p>



<p class="wp-block-paragraph"><strong>Immutability&nbsp;</strong></p>



<p class="wp-block-paragraph">Veeam reports that those who have fallen victim to ransomware have learned lessons and 82 per cent use immutable clouds, i.e. a cloud computing environment where the data stored within the cloud infrastructure is maintained in an immutable or unchangeable state. Also,&nbsp;64 per cent now use immutable disks, and only 2 per cent of organisations don’t have immutability in at least one tier of their backup solution.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Being Careful About Re-Infection During Recovery&nbsp;</strong></p>



<p class="wp-block-paragraph">In Veeam’s study, respondents were asked how they ensure that data is ‘clean’ during restoration. 44 per cent of respondents said they complete some form of “isolated-staging” to re-scan data from backup repositories prior to reintroduction into the production environment. Whilst this is positive news, the flip side of this statistic is that more than half (56 per cent) organisations risk re-infecting the production environment by not having a means to ensure clean data during recovery. The point is, therefore, that it’s important to thoroughly scan data during the recovery process.&nbsp;</p>



<p class="wp-block-paragraph"><strong>What Does This Mean For Your Business?&nbsp;</strong></p>



<p class="wp-block-paragraph">The obvious effectiveness of spear phishing attacks and the fact that most ransomware attacks are now targeting backups presents significant challenges for businesses, requiring proactive measures to protect themselves.&nbsp;</p>



<p class="wp-block-paragraph">As highlighted by Barracuda’ report, spear phishing attacks have proven to be highly successful, accounting for two-thirds of all breaches despite constituting a small percentage of email-based attacks. The targeted and personalised nature of spear phishing makes it difficult to detect, as attackers extensively research their targets to create convincing messages. To protect against spear phishing, businesses should, therefore, exercise caution when opening emails, verify the legitimacy of requests, and provide regular training to employees on identifying and reporting phishing attempts. Account takeover protection solutions with artificial intelligence capabilities can also be effective.&nbsp;</p>



<p class="wp-block-paragraph">As highlighted by Veeam’s report, ransomware attacks, on the other hand, have increasingly targeted backup storage, rendering organisations unable to recover their data even if they pay the ransom. While some organisations have paid the ransom and recovered their data, many have not been as fortunate. For businesses, the key to protecting against ransomware attacks lies in proactive measures such as regularly updating software, implementing robust security practices, training employees, maintaining secure backups, and deploying reliable antivirus and anti-malware solutions. Additionally, businesses should focus on immutability, ensuring that backup repositories cannot be deleted or corrupted.&nbsp;</p>



<p class="wp-block-paragraph">To combat the risks associated with spear phishing and ransomware attacks, businesses should favour a multi-layered approach to security. This includes investing in employee education and training, implementing strong technical security measures, and regularly evaluating and updating security protocols. Businesses can also help protect themselves by staying informed about emerging threats and best practices in cybersecurity to enable them to adapt their defences accordingly.&nbsp;</p>
<p>The post <a href="https://www.meartechnology.co.uk/2023/06/02/new-reports-reveal-two-key-cyber-security-insights/">New Reports Reveal Two Key Cyber Security Insights</a> appeared first on <a href="https://www.meartechnology.co.uk">Mear Technology</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Why adding &#8220;Meet the Team&#8221; to your website could put you at risk.</title>
		<link>https://www.meartechnology.co.uk/2023/04/19/why-adding-meet-the-team-to-your-website-could-put-you-at-risk/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Wed, 19 Apr 2023 22:25:20 +0000</pubDate>
				<category><![CDATA[Cyber attack]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://www.meartechnology.co.uk/?p=13218</guid>

					<description><![CDATA[<p>In today&#8217;s digital age, the security risks businesses face are ever-evolving. One of the most commonly overlooked areas of risk is the listing of employees on the company website. While it may seem innocuous to include staff bios and contact information on your website, it can expose your organization to social engineering attacks, which can&#8230; <br /> <a class="read-more" href="https://www.meartechnology.co.uk/2023/04/19/why-adding-meet-the-team-to-your-website-could-put-you-at-risk/">Read more</a></p>
<p>The post <a href="https://www.meartechnology.co.uk/2023/04/19/why-adding-meet-the-team-to-your-website-could-put-you-at-risk/">Why adding &#8220;Meet the Team&#8221; to your website could put you at risk.</a> appeared first on <a href="https://www.meartechnology.co.uk">Mear Technology</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">In today&#8217;s digital age, the security risks businesses face are ever-evolving. One of the most commonly overlooked areas of risk is the listing of employees on the company website. While it may seem innocuous to include staff bios and contact information on your website, it can expose your organization to social engineering attacks, which can be extremely damaging. In this article, we&#8217;ll discuss the risks of listing employees on your website and how to mitigate them.</p>



<h2 class="wp-block-heading" id="h-social-engineering-and-targeted-attacks">Social Engineering and Targeted Attacks</h2>



<p class="wp-block-paragraph">Social engineering is a form of attack where an attacker uses psychological manipulation to trick people into divulging confidential information or performing specific actions. One of the most common forms of social engineering is phishing, where an attacker impersonates a trustworthy entity to deceive a victim into giving up sensitive information or clicking on a malicious link. Phishing attacks can be highly targeted, with attackers using publicly available information to craft emails that appear to come from a known source.</p>



<p class="wp-block-paragraph">Listing employees on your website provides attackers with a wealth of information that they can use to launch targeted attacks. By researching your employees, an attacker can gather information such as their job titles, email addresses, phone numbers, and even personal details such as their hobbies and interests. With this information, an attacker can craft highly convincing phishing emails that are specifically tailored to individual employees, increasing the chances of success.</p>



<p class="wp-block-paragraph">Additionally, by listing employee job titles and contact information, attackers can identify potential targets for more sophisticated attacks such as spear-phishing, where attackers use social engineering to target specific individuals within an organization, often with the goal of gaining access to sensitive systems or data.</p>



<h2 class="wp-block-heading">Mitigating the Risks</h2>



<p class="wp-block-paragraph">So, what can businesses do to mitigate the risks of listing employees on their websites? The following are some best practices that organizations can adopt to minimize the risks:</p>



<ol class="wp-block-list">
<li><strong>Limit the Information Available</strong>: Consider limiting the information displayed on your website to only essential details, such as an <strong>employee&#8217;s name</strong> and <strong>job title</strong>. Avoid including personal information such as hobbies or interests that could be used by attackers to craft targeted attacks.</li>



<li><strong>Implement Access Controls:</strong> Restrict access to sensitive information such as employee contact details, and limit access to only those who require it to perform their job functions. Additionally, implement two-factor authentication for employees accessing sensitive information.</li>



<li><strong>Educate Employees: </strong>Educate your employees about the risks of social engineering attacks and how to identify and report suspicious emails or phone calls. Conduct regular training sessions to reinforce this knowledge and ensure that employees remain vigilant.</li>



<li><strong>Monitor for Attacks:</strong> Implement monitoring and detection tools to identify suspicious activity on your network and systems. Monitor your email systems for phishing attempts, and implement a response plan to quickly contain and mitigate any incidents.</li>
</ol>



<h2 class="wp-block-heading">Even a photo can put you at risk</h2>



<p class="wp-block-paragraph">Profile pictures can provide valuable information about an individual, and when used in conjunction with other publicly available information, they can be used to find more information about staff on social sites. </p>



<p class="wp-block-paragraph">Attackers can use facial recognition software to identify individuals and cross-reference their profiles with other online sources to gather additional information such as job titles, phone numbers, and email addresses. This information can be used to craft highly targeted social engineering attacks, increasing the likelihood of success. Additionally, profile pictures can be used to impersonate an individual, creating a fake account and tricking others into believing that the attacker is a legitimate individual. </p>



<p class="wp-block-paragraph">This information can be used to gather further sensitive information or launch attacks on unsuspecting victims. Businesses should be aware of these risks and take steps to protect their employees&#8217; privacy, such as limiting the information available on social media profiles and providing education on the risks of sharing personal information online.</p>



<p class="wp-block-paragraph">Some examples of sites that can be used to search using an image</p>



<ol class="wp-block-list">
<li><strong>Google Images</strong> &#8211; You can use Google&#8217;s &#8220;Search by image&#8221; feature to search for similar images or to identify an image&#8217;s source.</li>



<li><strong>TinEye </strong>&#8211; TinEye is a reverse image search engine that allows you to search for images by uploading them or by entering a URL.</li>



<li><strong>Bing Image Match</strong> &#8211; Bing&#8217;s Image Match feature lets you search for similar images or to identify the source of an image.</li>



<li><strong>Social Catfish</strong> &#8211; Social Catfish is a people search engine that can search for people using a picture.</li>



<li><strong>Pictriev </strong>&#8211; Pictriev is a face recognition search engine that allows you to search for people using a picture.</li>
</ol>



<p class="wp-block-paragraph"></p>



<h2 class="wp-block-heading">Be creative</h2>



<p class="wp-block-paragraph">If you really want to present the friendly face of your team then be creative. Make it interesting to look at, don&#8217;t give details. Avoid using names be creative with descriptions if you need them don&#8217;t make it easy for hackers who don&#8217;t like each person to their LinkedIn page or Facebook or Twitter.  </p>



<p class="wp-block-paragraph">Our advice is you use pictures of your team to create engagement with visitors. Ditch the Meet the Team Page. Introduce your team into the fabric of the site or as buttons to book a meeting or get more information. </p>



<p class="wp-block-paragraph">Get photographs taken professionally. While smart phones can take brilliant pictures a photographer will simply do a superior job. </p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="525" src="https://www.meartechnology.co.uk/wp-content/uploads/2023/04/image-3-1024x525.png" alt="" class="wp-image-13223 no-lazyload" srcset="https://www.meartechnology.co.uk/wp-content/uploads/2023/04/image-3-1024x525.png 1024w, https://www.meartechnology.co.uk/wp-content/uploads/2023/04/image-3-300x154.png 300w, https://www.meartechnology.co.uk/wp-content/uploads/2023/04/image-3-768x394.png 768w, https://www.meartechnology.co.uk/wp-content/uploads/2023/04/image-3-1536x787.png 1536w, https://www.meartechnology.co.uk/wp-content/uploads/2023/04/image-3.png 1573w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph"> </p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">Listing employees on your website can expose your organization to social engineering attacks, which can be highly damaging. By limiting the information available, implementing access controls, educating employees, and monitoring for attacks, businesses can reduce the risks and protect themselves against these threats. It&#8217;s important to remember that social engineering attacks are constantly evolving, and businesses must remain vigilant to protect against them.</p>
<p>The post <a href="https://www.meartechnology.co.uk/2023/04/19/why-adding-meet-the-team-to-your-website-could-put-you-at-risk/">Why adding &#8220;Meet the Team&#8221; to your website could put you at risk.</a> appeared first on <a href="https://www.meartechnology.co.uk">Mear Technology</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>3CX DesktopApp Security Alert</title>
		<link>https://www.meartechnology.co.uk/2023/03/30/3cx-desktopapp-security-alert/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Thu, 30 Mar 2023 09:42:26 +0000</pubDate>
				<category><![CDATA[3CX]]></category>
		<category><![CDATA[Cyber attack]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[Virus and antivirus]]></category>
		<category><![CDATA[3cx]]></category>
		<category><![CDATA[3CX Desktop breach]]></category>
		<category><![CDATA[3CX Security issue]]></category>
		<guid isPermaLink="false">https://www.meartechnology.co.uk/?p=13167</guid>

					<description><![CDATA[<p>In the news What Mear Technology have done for our clients 30/03/23 am Identified all machines we manage with 3CX Desktop app 18.12.407 &#38; 18.12.416. 30/03/23 am Removed the affected version of 3CX desktop app on all clients and installed Web App (PWA) version. Sent a secure message directly to affect staff with instructions on&#8230; <br /> <a class="read-more" href="https://www.meartechnology.co.uk/2023/03/30/3cx-desktopapp-security-alert/">Read more</a></p>
<p>The post <a href="https://www.meartechnology.co.uk/2023/03/30/3cx-desktopapp-security-alert/">3CX DesktopApp Security Alert</a> appeared first on <a href="https://www.meartechnology.co.uk">Mear Technology</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading">In the news</h2>



<ul class="wp-block-list">
<li><strong>3CX:</strong> <strong> </strong><a href="https://www.3cx.com/blog/news/desktopapp-security-alert/">https://www.3cx.com/blog/news/desktopapp-security-alert</a></li>



<li><strong>Trend Micro: </strong><a href="https://www.trendmicro.com/en_us/research/23/c/information-on-attacks-involving-3cx-desktop-app.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/23/c/information-on-attacks-involving-3cx-desktop-app.html</a></li>



<li><strong>Crowd Strike:</strong> <a href="https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/">https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/</a></li>



<li><strong>3CX appoints 3rd party to investigate issue</strong> <a href="https://www.3cx.com/blog/news/desktopapp-security-alert-updates/" target="_blank" rel="noreferrer noopener">https://www.3cx.com/blog/news/desktopapp-security-alert-updates/</a> (30/03/23)</li>
</ul>



<h2 class="wp-block-heading">What Mear Technology have done for our clients</h2>



<p class="wp-block-paragraph"><strong>30/03/23 am</strong> Identified all machines we manage with 3CX Desktop app 18.12.407 &amp; 18.12.416.</p>



<p class="wp-block-paragraph"><strong>30/03/23 am</strong> Removed the affected version of 3CX desktop app on all clients and installed Web App (PWA) version. Sent a secure message directly to affect staff with instructions on what to do. Staff will need to Activate this install.</p>



<p class="wp-block-paragraph"><strong>30/03/23 pm</strong> forced a full scan of all machines that received </p>



<p class="wp-block-paragraph"><strong>30/03/23 pm</strong> patched all phone systems </p>



<h2 class="wp-block-heading">What else can we tell you?</h2>



<p class="wp-block-paragraph">All our customers using our Managed Antivirus will be glad to know that the infection was picked up by our Antivirus blocked and cleaned at the point of deployment. </p>



<h2 class="wp-block-heading" id="h-how-to-activate-install-3cx-web-app-pwa">How to activate/Install 3CX Web App (PWA)</h2>



<p class="wp-block-paragraph">To do this please log in to your webclient details can be found in your 3CX Welcome email</p>



<p class="wp-block-paragraph">Click Apps (bottom left corner) </p>



<figure class="wp-block-image size-full"><img decoding="async" width="63" height="90" src="https://www.meartechnology.co.uk/wp-content/uploads/2023/03/image.png" alt="" class="wp-image-13168 no-lazyload"/></figure>



<p class="wp-block-paragraph"><br>Click Web App (PWA)</p>



<figure class="wp-block-image size-full"><img decoding="async" width="552" height="286" src="https://www.meartechnology.co.uk/wp-content/uploads/2023/03/image-1.png" alt="" class="wp-image-13169 no-lazyload" srcset="https://www.meartechnology.co.uk/wp-content/uploads/2023/03/image-1.png 552w, https://www.meartechnology.co.uk/wp-content/uploads/2023/03/image-1-300x155.png 300w" sizes="(max-width: 552px) 100vw, 552px" /></figure>



<p class="wp-block-paragraph">Click install</p>



<figure class="wp-block-image size-full"><img decoding="async" width="999" height="408" src="https://www.meartechnology.co.uk/wp-content/uploads/2023/03/image-2.png" alt="" class="wp-image-13170 no-lazyload" srcset="https://www.meartechnology.co.uk/wp-content/uploads/2023/03/image-2.png 999w, https://www.meartechnology.co.uk/wp-content/uploads/2023/03/image-2-300x123.png 300w, https://www.meartechnology.co.uk/wp-content/uploads/2023/03/image-2-768x314.png 768w" sizes="(max-width: 999px) 100vw, 999px" /></figure>
<p>The post <a href="https://www.meartechnology.co.uk/2023/03/30/3cx-desktopapp-security-alert/">3CX DesktopApp Security Alert</a> appeared first on <a href="https://www.meartechnology.co.uk">Mear Technology</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Tech News : New Meta Verified Blue Badge Subscription Service</title>
		<link>https://www.meartechnology.co.uk/2023/03/03/tech-news-new-meta-verified-blue-badge-subscription-service/</link>
		
		<dc:creator><![CDATA[Paul Stradling]]></dc:creator>
		<pubDate>Fri, 03 Mar 2023 14:26:55 +0000</pubDate>
				<category><![CDATA[Cyber attack]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Operating System]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[Virus and antivirus]]></category>
		<category><![CDATA[Blue Badge]]></category>
		<category><![CDATA[blue tick]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Meta]]></category>
		<guid isPermaLink="false">https://www.meartechnology.co.uk/?p=13103</guid>

					<description><![CDATA[<p>Meta has announced it’s launching its own version of Twitter’s Blue Tick called ‘Meta Verified’ for Facebook and Instagram where users pay a monthly subscription to be verified on the platforms.&#160; Announcement&#160; On February 19, Meta’s CEO, Mark Zuckerberg, announced that Meta is starting the rollout of its new ‘Meta Verified’ subscription service for Facebook&#8230; <br /> <a class="read-more" href="https://www.meartechnology.co.uk/2023/03/03/tech-news-new-meta-verified-blue-badge-subscription-service/">Read more</a></p>
<p>The post <a href="https://www.meartechnology.co.uk/2023/03/03/tech-news-new-meta-verified-blue-badge-subscription-service/">Tech News : New Meta Verified Blue Badge Subscription Service</a> appeared first on <a href="https://www.meartechnology.co.uk">Mear Technology</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Meta has announced it’s launching its own version of Twitter’s Blue Tick called ‘Meta Verified’ for Facebook and Instagram where users pay a monthly subscription to be verified on the platforms.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Announcement&nbsp;</strong></p>



<p class="wp-block-paragraph">On February 19, Meta’s CEO, Mark Zuckerberg, announced that Meta is starting the rollout of its new ‘Meta Verified’ subscription service for Facebook and Instagram, staring in Australia and New Zealand. For a monthly subscription of $11.99 / month on web or $14.99 / month on iOS., Meta Verified lets users verify their account&nbsp;<em>“with a government ID”</em>&nbsp;in return for which they get a blue badge, i.e. extra impersonation-protection against accounts claiming to be them, plus direct access to customer support. &nbsp;<br>&nbsp;<br>Meta says that the new feature&nbsp;<em>“is about increasing authenticity and security across our services</em>”&nbsp;and Mark Zuckerberg says that a blue badge&nbsp;<em>“effectively find and remove any imposter accounts since we know which account is the real you.”&nbsp;</em></p>



<p class="wp-block-paragraph"><strong>Imposter Accounts Problem&nbsp;</strong></p>



<p class="wp-block-paragraph">Facebook and Twitter (two of the most widely used social media platforms) and other platforms have suffered from the issue of people setting up imposter accounts. Imposter accounts on social media platforms like Facebook or Twitter can pose several problems, including:&nbsp;</p>



<p class="wp-block-paragraph">– Misrepresentation. Imposter accounts often pretend to be someone else, such as a celebrity or a public figure, and use their name, image, or brand to mislead people. This misrepresentation can damage the reputation of the person or brand being impersonated.&nbsp;</p>



<p class="wp-block-paragraph">– Identity theft. Imposter accounts can also use stolen personal information to create fake accounts, which can lead to identity theft and other fraudulent activities.&nbsp;</p>



<p class="wp-block-paragraph">– The spreading of misinformation. Imposter accounts can also spread false information, rumours or propaganda, which can harm individuals or groups and influence public opinion.&nbsp;</p>



<p class="wp-block-paragraph">– Cyberbullying. Imposter accounts can also use fake identities to harass or bully people, which can cause emotional distress and harm mental health.&nbsp;</p>



<p class="wp-block-paragraph">– Security concerns. Imposter accounts can be used to gain access to personal information or to spread malware or viruses, which can compromise the security of social media users.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Like Twitter’s ‘Blue Tick’ Service&nbsp;</strong></p>



<p class="wp-block-paragraph">Meta’s Blue Badge service appears to be remarkably similar to Twitter’s Blue service.&nbsp;</p>



<p class="wp-block-paragraph">Twitter’s Blue service, often referred to as ‘Blue Tick’ was originally introduced back in 2021 following reports that perhaps as much as 19 per cent of Twitter accounts could be fake and untrustworthy. The problem persisted and became an issue last year when Elon Musk was buying Twitter when it was estimated that&nbsp;spam and fake accounts / bot accounts (not run by humans)&nbsp;made up 5 per cent of Twitter accounts.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">With Musk also needing a revenue stream in addition to advertising, a revamped, subscription Blue service was introduced in November 2022 with users able to&nbsp;verify (by use of a blue tick next to their name) that their account is genuine and&nbsp;get editing and customisation options that free accounts don’t have. Despite the service experiencing a backlash that alarmed some advertisers, and being temporarily halted, it was resumed it in December 2022.&nbsp;</p>



<p class="wp-block-paragraph">A recent tweet suggesting that Meta’s ‘Meta Verified’ subscription service (Blue Badge) is essentially a copy of Twitter’s idea was met with a reply from Elon Musk saying that Meta’s move was&nbsp;<em>“inevitable.”&nbsp;</em></p>



<p class="wp-block-paragraph"><strong>What Does This Mean For Your Business?&nbsp;</strong></p>



<p class="wp-block-paragraph">For Meta, in addition to being a competitive move, it’s also a way to increase revenue, tackle the problem of fake accounts and the spreading of disinformation and misinformation that Facebook, along with other platforms, has suffered from, while increasing trust in the platform. That said, the Meta Verified service is just in Australia and New Zealand at the moment, so it remains to be seen what kind of reaction there is to it, and how successful it looks likely to be if rolled out elsewhere.</p>



<p class="wp-block-paragraph">It may initially be more useful and more popular among some user groups than others, e.g. celebrities, political leaders, well known businesses, and content creators wanting to increase their presence on Facebook and Twitter. For those who subscribe to Meta Verified, it may be the case that access to customer support is a large part of the real value of the service, and not just the blue badge.&nbsp;</p>
<p>The post <a href="https://www.meartechnology.co.uk/2023/03/03/tech-news-new-meta-verified-blue-badge-subscription-service/">Tech News : New Meta Verified Blue Badge Subscription Service</a> appeared first on <a href="https://www.meartechnology.co.uk">Mear Technology</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cyber Essentials &#8211; Changes in April 2023</title>
		<link>https://www.meartechnology.co.uk/2023/02/18/cyber-essentials-changes-in-april-2023/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Sat, 18 Feb 2023 23:31:57 +0000</pubDate>
				<category><![CDATA[Cyber attack]]></category>
		<category><![CDATA[Cyber Essentials]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Cyber Essentials PLus]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[EC+]]></category>
		<guid isPermaLink="false">https://www.meartechnology.co.uk/?p=13052</guid>

					<description><![CDATA[<p>In April 2023, the UK government&#8217;s Cyber Essentials program will update its technical requirements to help small businesses protect against common cyber threats. The update is part of a regular review of the scheme&#8217;s technical controls and follows a major update last year. The 2023 update will be a lighter touch, providing a number of&#8230; <br /> <a class="read-more" href="https://www.meartechnology.co.uk/2023/02/18/cyber-essentials-changes-in-april-2023/">Read more</a></p>
<p>The post <a href="https://www.meartechnology.co.uk/2023/02/18/cyber-essentials-changes-in-april-2023/">Cyber Essentials &#8211; Changes in April 2023</a> appeared first on <a href="https://www.meartechnology.co.uk">Mear Technology</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">In April 2023, the UK government&#8217;s Cyber Essentials program will update its technical requirements to help small businesses protect against common cyber threats. The update is part of a regular review of the scheme&#8217;s technical controls and follows a major update last year. The 2023 update will be a lighter touch, providing a number of clarifications, alongside some important new guidance.</p>



<p class="wp-block-paragraph">The list of changes includes:</p>



<ul class="wp-block-list">
<li><strong>User devices</strong>: With the exception of network devices, all user devices declared within the scope of the certification only require the make and operating system to be listed. The requirement for listing the model of the device has been removed. This change will be reflected in the self-assessment question set, rather than the requirements document.</li>



<li><strong>Clarification on firmware</strong>: Router and firewall firmware are the only firmware that must be kept up to date and supported. This information has been clarified following feedback that it can be difficult to find.</li>



<li><strong>Third-party devices:</strong> More information and a new table clarify how third-party devices, such as a contractor or student devices, should be treated in your application.</li>



<li><strong>Device unlocking:</strong> A change has been made here to mitigate some issues around default settings in devices being unconfigurable. Where that is the case, it is now acceptable for applicants to use those default settings.</li>



<li><strong>Malware protection</strong>: Anti-malware software will no longer need to be signature-based, and sandboxing is removed as an option. The requirements have also been clarified to indicate which mechanism is suitable for different types of devices.</li>



<li><strong>New guidance on zero trust</strong> architecture for achieving CE and a note on the importance of asset management.</li>



<li><strong>Style and language</strong>: Several language and format changes have been made to make the document easier to read.</li>



<li><strong>Structure updated</strong>: The technical controls have been reordered to align with the updated self-assessment question set.</li>



<li><strong>CE+ testing</strong>: The CE+ Illustrative Test Specification document has been updated to align with the requirements changes. The biggest change here is a refreshed set of Malware Protection tests, to simplify the process for both applicants and assessors.</li>
</ul>



<p class="wp-block-paragraph">These changes are based on feedback from assessors and applicants and have been made in consultation with technical experts from the National Cyber Security Centre (NCSC). Small businesses should note that the new requirements will take effect from 24 April 2023, and all applications started on or after this date will use the new requirements and question set. The Cyber Essentials delivery partner, IASME, will provide additional guidance and resources to help small businesses during the certification process.</p>



<h2 class="wp-block-heading" id="h-how-do-small-business-tackle-and-maintain-cyber-essentials">How do small business tackle and maintain Cyber Essentials</h2>



<p class="wp-block-paragraph">To help our customers achieve and maintain Cyber Essentials or Cyber Essentials Plus we have combined a  collection of solutions to help achieve and maintain Cyber Essentials. </p>



<p class="wp-block-paragraph">Our aim is to reduce disruption and costs to our customers helping them make required changes and put in tools to enforce any procedures put in place. </p>



<p class="wp-block-paragraph">To find out more book a meeting with our Director, let&#8217;s find out about your business and discuss how we can help get your business certified</p>


<div class="wp-block-image is-style-default">
<figure class="aligncenter size-full is-resized"><a href="https://outlook.office365.com/owa/calendar/BookwithMearTechnology@meartechnology.co.uk/bookings/" target="_blank" rel="noreferrer noopener"><img decoding="async" src="https://www.meartechnology.co.uk/wp-content/uploads/2023/02/2022-Stephen-wide-book-a-meeting.png" alt="" class="wp-image-13053 no-lazyload" width="720" height="189" srcset="https://www.meartechnology.co.uk/wp-content/uploads/2023/02/2022-Stephen-wide-book-a-meeting.png 720w, https://www.meartechnology.co.uk/wp-content/uploads/2023/02/2022-Stephen-wide-book-a-meeting-300x79.png 300w" sizes="(max-width: 720px) 100vw, 720px" /></a></figure>
</div>


<div class="wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex"></div>
<p>The post <a href="https://www.meartechnology.co.uk/2023/02/18/cyber-essentials-changes-in-april-2023/">Cyber Essentials &#8211; Changes in April 2023</a> appeared first on <a href="https://www.meartechnology.co.uk">Mear Technology</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Fewer Victims Pay Ransomware, Yet More Victims</title>
		<link>https://www.meartechnology.co.uk/2023/01/27/fewer-victims-pay-ransomware-yet-more-victims/</link>
		
		<dc:creator><![CDATA[Paul Stradling]]></dc:creator>
		<pubDate>Fri, 27 Jan 2023 10:58:03 +0000</pubDate>
				<category><![CDATA[Cyber attack]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Operating System]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[Virus and antivirus]]></category>
		<category><![CDATA[ransomware]]></category>
		<guid isPermaLink="false">https://www.meartechnology.co.uk/?p=12952</guid>

					<description><![CDATA[<p>Blockchain data platform Chainanalysis has reported that cybercriminals have seen a 40 per cent fall in their earnings as more people have refused to pay the ransom following ransomware attacks.&#160; More Strains With Shorter Lifespans&#160; However, the number of unique ransomware strains being used in attacks increased dramatically in 2022 (Fortinet). Also, Chainanalysis reports that&#8230; <br /> <a class="read-more" href="https://www.meartechnology.co.uk/2023/01/27/fewer-victims-pay-ransomware-yet-more-victims/">Read more</a></p>
<p>The post <a href="https://www.meartechnology.co.uk/2023/01/27/fewer-victims-pay-ransomware-yet-more-victims/">Fewer Victims Pay Ransomware, Yet More Victims</a> appeared first on <a href="https://www.meartechnology.co.uk">Mear Technology</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Blockchain data platform Chainanalysis has reported that cybercriminals have seen a 40 per cent fall in their earnings as more people have refused to pay the ransom following ransomware attacks.&nbsp;</p>



<p class="wp-block-paragraph"><strong>More Strains With Shorter Lifespans</strong>&nbsp;</p>



<p class="wp-block-paragraph">However, the number of unique ransomware strains being used in attacks increased dramatically in 2022 (Fortinet). Also, Chainanalysis reports that ransomware lifespans are dropping. For example, in 2022, the average ransomware strain remained active for just 70 days, down from 153 in 2021 and 265 in 2020.&nbsp;</p>



<p class="wp-block-paragraph"><strong>How Does Chainanalysis Know Criminals Get Paid?&nbsp;</strong></p>



<p class="wp-block-paragraph">Being a blockchain data platform (blockchain is the technology behind cryptocurrencies) Chainanalysis can track money flowing in and out of Bitcoin wallets. Ransomware crews use bitcoin wallets to collect ransoms and retain their anonymity. Also, evidence from cyber insurance firms who are usually the ones reimbursing victims for ransomware payments, show that these payments are down.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Why Are People Refusing To Pay Ransomware?&nbsp;</strong></p>



<p class="wp-block-paragraph">There are several reasons why more victims are refusing to pay the ransomware ransom, including:&nbsp;</p>



<p class="wp-block-paragraph">– Increased awareness. More people are becoming aware of the risks, so this has led to improved cyber-security at organisations, while increased awareness of the potential consequences of paying the ransom has led to many choosing not to do so.&nbsp;</p>



<p class="wp-block-paragraph">– Improved and more secure backups. With the increased use of more&nbsp;secure cloud-based backups and other disaster recovery solutions, more people are able to recover their data without paying the ransom. It’s worth noting that insurance companies are driving security by tightening underwriting standards, and by not renewing a policy unless the insured has comprehensive backup systems, uses EDR, and has multi-authentication.&nbsp;</p>



<p class="wp-block-paragraph">– Greater segmentation of data backups, resulting in&nbsp;less material business impact as a result of an attack, thereby reducing the economic justification to pay.&nbsp;</p>



<p class="wp-block-paragraph">– US sanctions against hacker groups, e.g. those Russia’s Federal Security Service, have made paying some groups legally risky.&nbsp;</p>



<p class="wp-block-paragraph">– Increased openness due to how common ransomware attacks have become. For example, a ransomware attack is now less of a PR disaster for companies, meaning that companies are less likely to keep quiet and pay the money to stay out of the news.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Why Are Ransomware Lifespans Dropping?&nbsp;</strong></p>



<p class="wp-block-paragraph">There are several reasons why ransomware lifespans are dropping (including those mentioned above), such as:&nbsp;</p>



<p class="wp-block-paragraph">– The increased use of anti-ransomware software. As more organisations and individuals use anti-ransomware software to protect their systems, the lifespan of ransomware attacks may be shorter, as the malware is detected and neutralised more quickly.&nbsp;</p>



<p class="wp-block-paragraph">– Improved incident response. As organisations and individuals become more familiar with the signs of a ransomware attack and have better incident response plans in place, they are able to quickly detect and respond to the attack, which can shorten the lifespan of the ransomware.&nbsp;</p>



<p class="wp-block-paragraph">– The development of decryption tools, some security researchers have been able to develop decryption tools that can help victims recover their data without paying the ransom. This can significantly shorten the lifespan of a ransomware attack.&nbsp;</p>



<p class="wp-block-paragraph">– More effective law enforcement action. Law enforcement agencies have been successful in shutting down some larger ransomware operations and gangs. This can also shorten the lifespan of a ransomware attack.&nbsp;</p>



<p class="wp-block-paragraph">– Cyber insurance and the involvement of specialised teams. More companies are now using cyber insurance and have specialised teams to deal with ransomware attacks, this also can shorten the lifespan of a ransomware attack.&nbsp;</p>



<p class="wp-block-paragraph"><strong>What Does This Mean For Your Business?&nbsp;</strong></p>



<p class="wp-block-paragraph">Criminal earnings from ransomware are down for the reasons mentioned above, and although larger ransomware gangs have been disrupted, there are now many smaller groups operating. It’s also worth noting that new strains of ransomware are being developed all the time, so the threat continues to be present (and is growing as previously stated). With this in mind, businesses should continue to focus on not falling victim to ransomware attacks in the first place. Measures businesses can take include having recurring meetings with all relevant teams/persons (security, networking, IT, server administration, PR, finance) and the company leadership to develop a clear picture of the strengths and weaknesses/vulnerabilities and establish how the business can remain secure and understand who’s responsible for all aspects of security.&nbsp;Also, seeking professional advice about cyber security and implementing best practices, e.g. with data backups and other security measures, can help keep the business safe from new as well as existing ransomware strains.&nbsp;</p>
<p>The post <a href="https://www.meartechnology.co.uk/2023/01/27/fewer-victims-pay-ransomware-yet-more-victims/">Fewer Victims Pay Ransomware, Yet More Victims</a> appeared first on <a href="https://www.meartechnology.co.uk">Mear Technology</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
