<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MFA Archives - Quayside Technical Services</title>
	<atom:link href="https://www.qts-ltd.com/tag/mfa/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.qts-ltd.com/tag/mfa/</link>
	<description>Delivering effective IT &#38; telecoms services &#38; support across Devon &#38; The South West.</description>
	<lastBuildDate>Sat, 06 Sep 2025 14:06:22 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.0.12</generator>

<image>
	<url>https://www.qts-ltd.com/wp-content/uploads/2019/07/cropped-quayside-favicon-32x32.png</url>
	<title>MFA Archives - Quayside Technical Services</title>
	<link>https://www.qts-ltd.com/tag/mfa/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>When the Boss Is Away… Don’t Let the Security Slip</title>
		<link>https://www.qts-ltd.com/when-the-boss-is-away-dont-let-the-security-slip/</link>
					<comments>https://www.qts-ltd.com/when-the-boss-is-away-dont-let-the-security-slip/#respond</comments>
		
		<dc:creator><![CDATA[staff]]></dc:creator>
		<pubDate>Wed, 06 Aug 2025 09:10:37 +0000</pubDate>
				<category><![CDATA[Uncategorised]]></category>
		<category><![CDATA[Cyber Essentials]]></category>
		<category><![CDATA[cyber-security]]></category>
		<category><![CDATA[Cybsafe]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Information Commissioner’s Office]]></category>
		<category><![CDATA[MFA]]></category>
		<category><![CDATA[multi factor authentication]]></category>
		<category><![CDATA[National Cyber Security Centre]]></category>
		<category><![CDATA[NCSC]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[Richard Home]]></category>
		<guid isPermaLink="false">https://www.qts-ltd.com/?p=129255</guid>

					<description><![CDATA[<p>With managers away, risks like poor passwords, unlocked screens and slow reporting can quietly escalate. This article explains why it happens and how to stop it. Why summer leave demands heightened password hygiene In 2025, just over four in ten UK businesses (43%) reported experiencing a cyber security breach or attack during the previous 12 [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/when-the-boss-is-away-dont-let-the-security-slip/">When the Boss Is Away… Don’t Let the Security Slip</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>With managers away, risks like poor passwords, unlocked screens and slow reporting can quietly escalate. This article explains why it happens and how to stop it.</p>
<h5><strong>Why summer leave demands heightened password hygiene</strong></h5>
<p>In 2025, just over four in ten UK businesses (43%) reported experiencing a cyber security breach or attack during the previous 12 months, with that figure rising to 67% in medium sized firms and 74% in large ones. Phishing remained the dominant method of attack, affecting 85% of organisations that identified breaches.</p>
<p>Seasonal reductions in staff numbers, remote working and less oversight can allow small mistakes, such as reusing passwords, to have much bigger consequences. According to the Royal Institution of Chartered Surveyors, 27% of UK businesses were hit by a cyber attack in the past year, up from 16% the year before. These figures highlight the growing risk, particularly during periods with less supervision.</p>
<h5><strong>Use modern password standards and move beyond forced expiry</strong></h5>
<p>UK cyber guidance now discourages regular forced password changes unless there has been a suspected breach. This is because, when users are prompted to change credentials frequently, they often create weaker, predictable passwords, for example by simply adding a number or punctuation mark.</p>
<p>Instead, the National Cyber Security Centre (NCSC) recommends the use of longer passphrases made up of three random words, separated by full stops. These are both stronger and easier to remember than traditional passwords. The NCSC also advises organisations to adopt password managers and, where possible, passkeys. These tools can generate and store unique credentials securely, reducing the risk of password reuse or staff writing details down.</p>
<h5><strong>MFA</strong></h5>
<p>Multi factor authentication (MFA) remains one of the most effective ways to protect business critical systems. Yet despite its benefits, only around 40% of UK businesses have implemented MFA across all user accounts. Email accounts are especially vulnerable, as they can often be used to reset access to other platforms. Ensuring these are protected with MFA is considered a baseline measure by most UK security professionals.</p>
<h5><strong>Lock screens and devices immediately when unattended</strong></h5>
<p>An unattended device with an open screen is one of the easiest targets for opportunistic attacks or accidental misuse. Whether it is a visitor in the office, a contractor passing by or a well meaning colleague, leaving access open can result in emails being forwarded, data copied or malware being introduced via USB.</p>
<p>The Information Commissioner’s Office (ICO) advises that screens should lock automatically after two or three minutes of inactivity. Staff should also be trained to manually lock their devices every time they step away from their desks. This is especially important during summer when office routines may be more relaxed and the mix of people in the workplace can change.</p>
<p>Recent incidents show that even organisations with secure buildings can fall victim to social engineering or internal threats if unattended devices are left exposed. Automatic screen locking, combined with a strong culture of responsibility, helps reduce the risk significantly.</p>
<h5><strong>Ensure quick incident reporting when supervision is reduced</strong></h5>
<p>When teams are leaner, delays in reporting suspicious activity can allow small issues to spiral. For example, even a single phishing email that goes unreported could result in credential theft, malware infection or wider compromise of the organisation’s systems.</p>
<p>The ICO reminds organisations of their legal obligation to report serious personal data breaches within 72 hours. However, underreporting remains an issue. For example, a 2023 Cybsafe survey found that many employees still hesitate to report security issues, fearing they will be blamed or seen as incompetent. Some of them attempt to fix problems themselves, often making the situation worse.</p>
<h5><strong>Clear policies</strong></h5>
<p>Clear policies and non udgemental internal reporting procedures can also help. Businesses should reinforce the message that early reporting is vital, regardless of the perceived severity of the issue. When fewer people are available to detect problems, every employee becomes part of the security perimeter.</p>
<h5><strong>Vigilance essential</strong></h5>
<p>Major cyber attacks on well known UK retailers in early 2025 highlighted how attackers often exploit gaps in supervision. In one widely reported case, criminals impersonated staff during a helpdesk call to reset login credentials at a large national department store chain. Using publicly available information and a convincing pretext, they persuaded internal support teams to grant access to privileged systems. The attackers then used this access to infiltrate the company’s ordering and stock systems, causing widespread disruption to online deliveries, store stock management and customer services across the UK.</p>
<p>The NCSC has since updated its guidance to stress the importance of identity verification, particularly during periods when usual contacts may be away. Organisations should ensure that all staff know who to contact in case of a suspected breach and that backup procedures are in place when key individuals are on leave.</p>
<p>Proofpoint’s 2024 threat report showed a rise in phishing campaigns timed around bank holidays and summer breaks, many of which referenced internal systems or posed as absent executives. These tailored scams are more convincing and more dangerous when teams are under pressure or lacking oversight.</p>
<h5><strong>Promote a culture of year round accountable vigilance</strong></h5>
<p>It’s worth noting here that security does not begin and end with IT departments. In reality, everyone in the organisation has a role to play, particularly when fewer colleagues are present to notice if something goes wrong.</p>
<p>As Richard Horne, CEO of the NCSC, recently warned<em> “businesses ignore advice at their peril,”</em> thereby highlighting that even basic security measures can reduce insurance claims by over 90%. However, the latest government figures show that fewer than one in ten UK organisations are currently certified under Cyber Essentials, the UK’s official baseline standard.</p>
<p>The ICO and NCSC both emphasise that technical tools must be matched by behaviour and awareness. That includes locking screens, using secure credentials, escalating concerns early and understanding that cyber security is not someone else’s job.</p>
<h5><strong>What does this mean for your business?</strong></h5>
<p>A key takeaway here is that there’s no seasonal exemption from cyber threats. In fact, if anything, the summer period heightens the risk, as gaps in supervision and more flexible routines make it easier for poor habits to slip through unnoticed. For UK businesses, this is not just a matter of good practice but of operational resilience. Attacks timed during holiday cover or lean staffing can have a disproportionate impact, especially when response times are slower and reporting structures unclear.</p>
<p>The broader lesson is that culture really matters. Password policies, screen locking procedures and incident response plans are only effective when staff at all levels understand them and use them without hesitation. For security teams and senior leaders, this means investing in clarity and communication as much as in software or hardware.</p>
<p>UK regulators are already making expectations clear. With the ICO strengthening its stance on breach reporting and the NCSC repeatedly highlighting the need for accountability beyond the IT department, there is growing pressure on organisations to prove that cyber responsibility is being taken seriously throughout the business. That includes facilities managers, HR teams and anyone with access to systems or data.</p>
<p>What this means for UK businesses is a need to treat holiday periods not as downtime, but as a potential test of their internal defences. For insurers, regulators and supply chain partners, lapses in protocol will look less like an accident and more like a failure to plan. For customers and clients, the reputational damage from a breach can be immediate and lasting.</p>
<p>Avoiding that outcome does not require complex changes. It comes down to reinforcing a few non negotiables. Strong, unique passwords. Locked screens. Prompt reporting. And a shared understanding that good security is not a favour to the IT team but a safeguard for the whole organisation.</p>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/when-the-boss-is-away-dont-let-the-security-slip/">When the Boss Is Away… Don’t Let the Security Slip</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.qts-ltd.com/when-the-boss-is-away-dont-let-the-security-slip/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>GoDaddy Complaint Over Years of Poor Cybersecurity</title>
		<link>https://www.qts-ltd.com/godaddy-complaint-over-years-of-poor-cybersecurity/</link>
					<comments>https://www.qts-ltd.com/godaddy-complaint-over-years-of-poor-cybersecurity/#respond</comments>
		
		<dc:creator><![CDATA[staff]]></dc:creator>
		<pubDate>Wed, 22 Jan 2025 10:30:01 +0000</pubDate>
				<category><![CDATA[Tech News]]></category>
		<category><![CDATA[complaint]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[GoDaddy]]></category>
		<category><![CDATA[International Trade Commission]]></category>
		<category><![CDATA[ITC]]></category>
		<category><![CDATA[Managed WordPress]]></category>
		<category><![CDATA[MFA]]></category>
		<category><![CDATA[multi factor authentication]]></category>
		<category><![CDATA[search engine optimisation]]></category>
		<category><![CDATA[security incidents]]></category>
		<category><![CDATA[Security Information and Event Management]]></category>
		<category><![CDATA[SEO]]></category>
		<category><![CDATA[SIEM]]></category>
		<category><![CDATA[US]]></category>
		<guid isPermaLink="false">https://www.qts-ltd.com/?p=128968</guid>

					<description><![CDATA[<p>The US International Trade Commission has issued a scathing complaint against web hosting giant GoDaddy, accusing the company of failing to implement basic cybersecurity tools and practices since 2018. What is the ITC, and what is the complaint? The International Trade Commission (ITC) is a US federal agency responsible for enforcing trade laws, addressing unfair [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/godaddy-complaint-over-years-of-poor-cybersecurity/">GoDaddy Complaint Over Years of Poor Cybersecurity</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The US International Trade Commission has issued a scathing complaint against web hosting giant GoDaddy, accusing the company of failing to implement basic cybersecurity tools and practices since 2018.</p>
<h5><strong>What is the ITC, and what is the complaint?</strong></h5>
<p>The International Trade Commission (ITC) is a US federal agency responsible for enforcing trade laws, addressing unfair trade practices, and protecting industries from harm. Although its remit typically covers trade related matters, it has increasingly expanded its oversight to include consumer protection, particularly in cases where corporate failings have broader implications for commerce and public interest.</p>
<p>In a recent formal complaint, the ITC alleged that GoDaddy violated Section 5 of the Federal Trade Commission Act, which prohibits unfair or deceptive business practices. Despite marketing itself as a secure and reliable hosting provider, GoDaddy, according to the ITC, failed to live up to its claims, thereby leaving millions of customer websites vulnerable, resulting in multiple security breaches and significant data compromises.</p>
<h5><strong>The allegations in more detail</strong></h5>
<p>The ITC’s complaint paints a troubling picture of the lack of GoDaddy’s cybersecurity practices. It accuses the company of failing to implement even the most rudimentary safeguards to protect its hosting environment. Among the lapses cited by the ITC are the absence of essential measures such as multi factor authentication (MFA), proper asset inventory, and robust threat monitoring.</p>
<p>Specifically, the ITC’s complaint,published online, identified the following failings:</p>
<ul>
<li><strong>No centralised asset management</strong>. As of 2020, GoDaddy had visibility over only 15,000 devices out of the approximately 450,000 in its environment.</li>
<li><strong>Irregular patch management</strong>. Despite a policy requiring critical updates to be applied within 30 days, GoDaddy relied on scattered teams to handle patches with no central oversight, leading to unpatched vulnerabilities across thousands of servers.</li>
<li><strong>Inadequate logging and monitoring</strong>. Security related events were inconsistently logged, making it difficult to investigate breaches or suspicious activity.</li>
<li><strong>Weak authentication practices</strong>. The company relied on username/password combinations without requiring MFA for privileged accounts until 2020, thereby exposing sensitive systems to unauthorised access.</li>
<li><strong>Network mismanagement</strong>. A lack of segmentation between shared hosting and other services enabled threat actors to move laterally within GoDaddy’s infrastructure.</li>
<li><strong>API insecurity</strong>. GoDaddy’s APIs, critical for managing customer data, used outdated protocols, such as plaintext credentials, leaving them highly susceptible to interception and exploitation.</li>
</ul>
<h5><strong>A history of breaches and consequences</strong></h5>
<p>The ITC report also details several high profile security incidents that occurred under GoDaddy’s watch, starting back in 2019. The ITC alleges that these breaches highlight the tangible risks posed by the company’s inadequate security measures.</p>
<h5><strong>The 2019-2020 breaches</strong></h5>
<p>A breach in October 2019 saw attackers exploit vulnerabilities in GoDaddy’s infrastructure to move laterally into its shared hosting environment. Threat actors replaced critical server files with malicious versions, ultimately compromising customer and employee login credentials. Shockingly, these intrusions went undetected for six months until another, unrelated event in March 2020 prompted an external security audit.</p>
<p>During this time, attackers reportedly stole credentials for over 28,000 customer accounts and 199 employees, gaining administrative access to key systems. The breach also involved the theft of approximately 1,000 payment card details.</p>
<h5><strong>2021 WordPress API breach</strong></h5>
<p>In November 2021, GoDaddy discovered another breach targeting its Managed WordPress hosting service. This time, attackers exploited an exposed API, obtaining data for 1.2 million customers, including email addresses, private encryption keys, and login credentials for WordPress and database management tools. Evidence suggests the attackers used this access to plant malware and commit search engine optimisation (SEO) fraud, misleading visitors and search engines alike.</p>
<h5><strong>2022 malware resurgence</strong></h5>
<p>The most recent breach, in December 2022, saw the same threat actors return to exploit remnants of the 2019-2020 compromise. This time, attackers deployed malware that redirected visitors to customers’ websites to malicious destinations, such as phishing pages or explicit content. Despite the repeated nature of these attacks, the ITC alleges that GoDaddy failed to proactively detect the intrusion, learning of it only through customer complaints.</p>
<h5><strong>Impact on customers and the broader ecosystem</strong></h5>
<p>The consequences of GoDaddy’s alleged failings have been farvreaching. Small businesses that rely on its hosting services have endured significant disruptions, including compromised websites, stolen customer data, and tarnished reputations. Some customers have faced financial fraud or identity theft, while others have spent substantial time and resources remediating the damage caused by breaches.</p>
<p>The ITC’s complaint makes the point that these harms were entirely avoidable had GoDaddy employed widely available, low cost security measures. Also, it accuses the company of misleading customers by marketing its services as secure while failing to back these claims with appropriate protections.</p>
<h5><strong>GoDaddy’s response and the way forward</strong></h5>
<p>In response to the ITC’s allegations, GoDaddy has neither admitted nor denied the charges but has agreed to implement a comprehensive security overhaul. This includes creating a centralised inventory of its hardware and software, adopting Security Information and Event Management (SIEM) tools for real time threat detection, and enforcing MFA across all privileged accounts.</p>
<p>A spokesperson for the company stated: <em>“We are committed to safeguarding our customers’ data and continually improving our security posture. Many of the measures outlined in the settlement are already underway.”</em></p>
<h5><strong>The settlement</strong></h5>
<p>Despite the gravity of the accusations and the scale of harm outlined in the ITC’s complaint, the settlement agreement struck with GoDaddy has left some questioning its adequacy. Under the terms of the proposed deal, GoDaddy must implement sweeping improvements to its cybersecurity practices. This includes undergoing regular, independent third party assessments of its security programme and adhering to a ban on making deceptive claims about its data protection efforts in the future.</p>
<p>Notably, the ITC has not imposed any fines but has warned that future violations could result in penalties of up to $51,744 per breach.</p>
<h5><strong>What’s next?</strong></h5>
<p>The ITC has opened the settlement for public comment, and its finalisation will mark a critical juncture for GoDaddy. The case serves as a cautionary tale for other companies, demonstrating the risks of neglecting cybersecurity in an increasingly hostile digital landscape.</p>
<h5><strong>What if you’re a business customer of GoDaddy’s?</strong></h5>
<p>For businesses that rely on GoDaddy’s hosting services, the revelations in the ITC’s complaint may understandably be a little unsettling. Many may now be questioning whether their websites or customer data were compromised in the breaches. Those who suspect they have been affected can review communications from GoDaddy, as the company has stated that it notified impacted customers following major incidents. Another option for businesses may be to engage independent security experts to audit their sites and data for any lingering vulnerabilities. Moving forward, customers will need to think carefully about whether GoDaddy’s promised security enhancements can restore their confidence or if alternative hosting providers may better meet their needs.</p>
<h5><strong>What does this mean for your business?</strong></h5>
<p>As one of the largest web hosting providers, GoDaddy holds a significant position of responsibility, safeguarding not only its customers but also the broader ecosystem of internet users who interact with its hosted websites. The ITC’s findings, therefore, paint a very concerning picture of allegedly some very basic and systemic failures in cybersecurity practices over several years, leading to serious breaches that have impacted countless businesses and their customers.</p>
<p>For GoDaddy, the settlement offers a chance to repair its reputation and demonstrate a renewed commitment to cybersecurity. Although the lack of financial penalties has been surprising to some, it appears to be more of a case of getting some swift remedial action rather than prolonged litigation. However, it is understandable that some stakeholders may view the resolution as lenient, given the scale of the alleged failings and the potential harm caused. The onus is clearly now on GoDaddy to follow through on its promises and implement the sweeping changes outlined in the settlement.</p>
<p>For businesses affected by the breaches, the road to recovery may be a long and complex one. While GoDaddy’s notification efforts and security improvements may offer some reassurance, the damage to customer trust and the potential for lingering vulnerabilities remain pressing concerns. Businesses should, perhaps, weigh the risks and benefits of continuing their reliance on GoDaddy and consider proactive steps to safeguard their operations, regardless of the hosting provider they choose.</p>
<p>This case serves as a wake up call for the entire tech industry, underscoring the need for vigilance in an era of evolving cyber threats. Basic security hygiene, while often viewed as a standard requirement, is essential to maintaining trust and preventing harm on a global scale. For organisations of GoDaddy’s stature, the stakes are even higher, as lapses in security can reverberate far beyond their own systems.</p>
<p>The ITC’s intervention, therefore, not only holds GoDaddy to account in some way but also sends a clear message to the industry: that data protection and cybersecurity are not optional. As businesses and consumers alike navigate the fallout, the hope is that this episode will lead to meaningful changes, not just for GoDaddy but for the industry as a whole, ensuring a more secure digital landscape for everyone.</p>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/godaddy-complaint-over-years-of-poor-cybersecurity/">GoDaddy Complaint Over Years of Poor Cybersecurity</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.qts-ltd.com/godaddy-complaint-over-years-of-poor-cybersecurity/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Update Your Software and Drivers</title>
		<link>https://www.qts-ltd.com/update-your-software-and-drivers/</link>
					<comments>https://www.qts-ltd.com/update-your-software-and-drivers/#respond</comments>
		
		<dc:creator><![CDATA[staff]]></dc:creator>
		<pubDate>Thu, 27 Jun 2024 09:20:14 +0000</pubDate>
				<category><![CDATA[Tech Tip]]></category>
		<category><![CDATA[Here's how]]></category>
		<category><![CDATA[location]]></category>
		<category><![CDATA[MFA]]></category>
		<category><![CDATA[Microsoft 365]]></category>
		<category><![CDATA[multi factor authentication]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[settings]]></category>
		<guid isPermaLink="false">https://www.qts-ltd.com/?p=128442</guid>

					<description><![CDATA[<p>Managing privacy settings in your Microsoft 365 account can help protect your personal and business information. Properly configured privacy settings help ensure that your data is only accessible to those who are authorised and that your activities remain private. Here&#8217;s how to access and manage your privacy settings to enhance security and privacy: Access Your [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/update-your-software-and-drivers/">Update Your Software and Drivers</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div>
<p>Managing privacy settings in your Microsoft 365 account can help protect your personal and business information. Properly configured privacy settings help ensure that your data is only accessible to those who are authorised and that your activities remain private. Here&#8217;s how to access and manage your privacy settings to enhance security and privacy:</p>
</div>
<div>
<h5><b>Access Your Privacy Settings</b></h5>
</div>
<div>
<ul>
<li>Sign in to your Microsoft 365 account.</li>
<li>Click on your profile picture in the top right corner and select My Account.</li>
</ul>
</div>
<div>
<h5><b>Review and Adjust Privacy Settings</b></h5>
</div>
<div>
<ul>
<li>In the left hand menu, select Privacy.</li>
<li>Here you can manage various aspects of your privacy settings, including ad preferences, location services, activity history: browsing and search, and more.</li>
</ul>
</div>
<div>
<h5><b>Configure Security Settings</b></h5>
</div>
<div>
<ul>
<li>In the left hand menu, select Security.</li>
<li>Here you can review your sign in activity and security settings, enable Multi Factor Authentication (MFA) for an additional layer of security, and regularly update your password and ensure it is strong and unique.</li>
</ul>
</div>
<div>
<p>By taking steps to manage your privacy settings, you can enhance the security of your Microsoft 365 account, ensuring your personal and business information remains protected and private.</p>
</div>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/update-your-software-and-drivers/">Update Your Software and Drivers</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.qts-ltd.com/update-your-software-and-drivers/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>‘Networkless’ Attacks?</title>
		<link>https://www.qts-ltd.com/networkless-attacks/</link>
					<comments>https://www.qts-ltd.com/networkless-attacks/#respond</comments>
		
		<dc:creator><![CDATA[staff]]></dc:creator>
		<pubDate>Fri, 26 Apr 2024 09:10:57 +0000</pubDate>
				<category><![CDATA[Tech Insight]]></category>
		<category><![CDATA[Adversary in The Middle phishing]]></category>
		<category><![CDATA[AiTM]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[CrowdStrike]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[EDR]]></category>
		<category><![CDATA[endpoint detection and response]]></category>
		<category><![CDATA[MFA]]></category>
		<category><![CDATA[multi factor authentication]]></category>
		<category><![CDATA[Oktajacking]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[SAMLjacking]]></category>
		<category><![CDATA[Single Sign On]]></category>
		<category><![CDATA[SSO]]></category>
		<guid isPermaLink="false">https://www.qts-ltd.com/?p=128109</guid>

					<description><![CDATA[<p>In this article, we look at why and how networkless attacks, which target cloud apps and identities, have created new opportunities for attackers and new risks for businesses, as well as what your business can do to mitigate these risks. The Move To SaaS and Cloud  In the rapidly evolving digital landscape, one of the [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/networkless-attacks/">‘Networkless’ Attacks?</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>In this article, we look at why and how networkless attacks, which target cloud apps and identities, have created new opportunities for attackers and new risks for businesses, as well as what your business can do to mitigate these risks.</p>
<h5><strong>The Move To SaaS and Cloud </strong></h5>
<p>In the rapidly evolving digital landscape, one of the key drivers enabling attackers to compromise an organistaion without needing to touch the endpoint or conventional networked systems and services is the increased reliance on cloud based services and software as a service (SaaS) applications, to drive efficiency and innovation. This shift, while beneficial, has also created new cybersecurity challenges for businesses, primarily due to the decentralisation of ‘digital identities’ and the interconnected nature of cloud services.</p>
<h5><strong>The SaaS Revolution and Its Impact on Security </strong></h5>
<p>The proliferation of SaaS applications is a direct result of the digital transformation that has reshaped the business world. For example, companies can now be using hundreds, if not thousands of cloud applications to perform daily operations, from customer relationship management to financial operations. This shift is driven by the convenience and scalability of SaaS solutions, however it comes with inherent security risks.</p>
<p>The new risk that businesses are facing is that each application potentially serves as an entry point for malicious actors, and the interconnectivity between these apps can allow a breach in one service to cascade through to others.</p>
<h5><strong>Why Digital Identities Are The New Security Battleground </strong></h5>
<p>As the traditional network perimeter dissolves, digital identities become the new security frontier. Put simply, a digital identity can be a user account created for services that someone in the business has signed up for using a username or email and password. More broadly, it can also mean other personal data used to identify and authenticate users online.</p>
<p>These digital identities, which provide access to a myriad of cloud applications, are now central targets for attackers. Securing them has become increasingly complex due to the sheer number of them that businesses may be using and their dispersion across various cloud platforms, each with its own security environment. This decentralisation not only makes consistent security policies harder to enforce but also increases the complexity of monitoring these identities for potential breaches.</p>
<h5><strong>How Attackers Are Exploiting Vulnerabilities in Cloud Identities </strong></h5>
<p>Attackers have adapted to this new environment by developing sophisticated techniques to exploit vulnerabilities in cloud identities without ever touching the physical endpoints or traditional networked systems.</p>
<p>Examples of techniques include AiTM (Adversary in The Middle) phishing, SAMLjacking, and Oktajacking, all of which exploit weaknesses in the authentication processes and session management of cloud services.</p>
<p>AiTM phishing involves intercepting and manipulating real time data during a session to steal credentials or manipulate transactions. SAMLjacking and Oktajacking focus on manipulating Single Sign On (SSO) processes to gain unauthorised access.</p>
<p>Security stats now reveal increasingly that attackers are deliberately targeting cloud services as a way into organisations. For example, malware used to be one of the main threats, but CrowdStrike figures show that three out of four attacks last year were malware free, and that the targeting of cloud services has increased 110 per cent. This helps to illustrate why cloud identities are the new digital perimeter and that cloud apps and identities now give attackers the same result as old style attacks without them having to try and breach a network perimeter via the endpoint.</p>
<h5><strong>The Security Gap in Identity Management </strong></h5>
<p>Despite advances in cybersecurity, it’s clear to see why many businesses are now vulnerable to identity based attacks. Traditional security measures like endpoint detection and response (EDR) systems and firewalls, for example, are less effective in a cloud centric world where applications are accessed primarily through web browsers. This gap is exacerbated by the reactive nature of many security strategies, which focus on mitigating threats after they have been detected rather than preventing them proactively.</p>
<h5><strong>What Does This Mean for Your Business? </strong></h5>
<p>For UK businesses, their move to the cloud and the usage of a wide range and complicated combination of SaaS apps, digital identities, and the interconnection and decentralisation of these have meant that they are now vulnerable to networkless attack techniques, perhaps without realising it until now. The shift to cloud computing has not only expanded the attack surface but also highlighted the inadequacies of traditional security models in protecting digital identities. This means that UK businesses must now take a much closer look at the security of these identities as part of their overall cybersecurity strategy.</p>
<p>To mitigate the risks associated with networkless attacks, businesses should perhaps consider adopting a zero trust security model, which assumes that threats could be internal or external and verifies each identity and device continuously, regardless of their location. Additionally, enhancing visibility across all cloud services and implementing advanced security measures like multi factor authentication (MFA), behavioral analytics, and more sophisticated identity and access management (IAM) solutions could help.</p>
<p>In short, as these networkless attacks continue to evolve, UK businesses must be proactive with security, stay vigilant and adapt their security strategies. By understanding the vulnerabilities associated with digital identities and cloud services, and implementing security measures accordingly, businesses can safeguard their assets in the cloud era.</p>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/networkless-attacks/">‘Networkless’ Attacks?</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.qts-ltd.com/networkless-attacks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>iPhone Users Targeted With Password Reset Scam</title>
		<link>https://www.qts-ltd.com/iphone-users-targeted-with-password-reset-scam/</link>
					<comments>https://www.qts-ltd.com/iphone-users-targeted-with-password-reset-scam/#respond</comments>
		
		<dc:creator><![CDATA[staff]]></dc:creator>
		<pubDate>Fri, 05 Apr 2024 09:40:04 +0000</pubDate>
				<category><![CDATA[An Apple Byte]]></category>
		<category><![CDATA[Uncategorised]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[Apple Recovery Key]]></category>
		<category><![CDATA[Apple Support]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[MFA]]></category>
		<category><![CDATA[notifications]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scam]]></category>
		<guid isPermaLink="false">https://www.qts-ltd.com/?p=128092</guid>

					<description><![CDATA[<p>It’s been reported that some iPhone users have recently been targeted with an MFA bombing or multi factor fatigue phishing attack, in a password reset scam. The attack, which uses a bug in Apple’s password reset feature, bombards the user’s phone with password reset requests and ‘Allow’ or ‘Disallow’ options. If the user eventually clicks [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/iphone-users-targeted-with-password-reset-scam/">iPhone Users Targeted With Password Reset Scam</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>It’s been reported that some iPhone users have recently been targeted with an MFA bombing or multi factor fatigue phishing attack, in a password reset scam.</p>
<p>The attack, which uses a bug in Apple’s password reset feature, bombards the user’s phone with password reset requests and ‘Allow’ or ‘Disallow’ options. If the user eventually clicks on ‘Allow’ in an attempt to stop the many prompts, they receive a call from scammers pretending to be Apple Support, asking the user to verify a one time code in an attempt to gain access to the account and/or to sensitive user information.</p>
<p>So far, it’s understood that these attacks have been highly targeted at certain individuals and users should note that Apple Support will never call a user unless that user has specifically asked them to. It’s also been reported that turning on Apple Recovery Key for the account is a way to stop the multiple notifications generated by the scammers.</p>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/iphone-users-targeted-with-password-reset-scam/">iPhone Users Targeted With Password Reset Scam</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.qts-ltd.com/iphone-users-targeted-with-password-reset-scam/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
