Become Cybersafe – 14th March

Table of Contents

[fusion_builder_container type=”flex” hundred_percent=”no” equal_height_columns=”no” hide_on_mobile=”small-visibility,medium-visibility,large-visibility” background_position=”center center” background_repeat=”no-repeat” fade=”no” background_parallax=”none” parallax_speed=”0.3″ video_aspect_ratio=”16:9″ video_loop=”yes” video_mute=”yes” border_style=”solid” margin_top=”1px” flex_align_items=”center” flex_justify_content=”flex-start”][fusion_builder_row][fusion_builder_column type=”1_1″ type=”1_1″ layout=”1_1″ background_position=”left top” border_style=”solid” border_position=”all” spacing=”yes” background_repeat=”no-repeat” margin_top=”0px” margin_bottom=”0px” animation_speed=”0.3″ animation_direction=”left” hide_on_mobile=”small-visibility,medium-visibility,large-visibility” center_content=”no” last=”true” hover_type=”none” first=”true” background_blend_mode=”overlay” min_height=”” link=””][fusion_text]

Welcome to the latest edition of the Cybersafe Cyber Threats Update, on the 14th March. This is a weekly series in which we bring attention to the latest cyber attacks, scams, frauds, and malware including Ransomware, to ensure you stay safe online. Being aware of these cyber threats helps UK companies to gain cyber essentials certifications and keeps employees on alert for potential danger.

Here are the most prominent cyber threats to businesses which you should be aware of:

Microsoft says Russian hackers accessed source code in cyber attack

Microsoft has reported a security breach by Russian hacking group Midnight Blizzard, also known as NOBELIUM. The breach involved unauthorised access to internal systems and source code repositories using stolen authentication secrets.

This incident follows a previous breach in January, where the group accessed corporate email servers through a password spray attack. The compromised test account lacked multi-factor authentication, allowing access to Microsoft’s systems.

In a stark warning to business owners, Midnight Blizzard exploited this access to steal data from corporate mailboxes, including those of Microsoft’s leadership, cybersecurity, and legal departments.

Microsoft suspects the hackers breached email accounts to gather information about their activities. Recently, the group utilised stolen data to access additional systems and source code repositories. Microsoft is reaching out to affected customers whose secrets were exposed and has heightened security measures to defend against further attacks. All business owners are encouraged to emphasise the importance of constant password changes to employees and to be extra vigilant with cyber security frameworks. Neuways have excelled at helping CEO’s and CFO’s to make their business become Cybersafe by helping them to implement these processes.

Midnight Blizzard has increased password spray attacks, underscoring the value of multi-factor authentication. The group’s actions highlight the ongoing threat posed by state-sponsored hackers like Midnight Blizzard, previously implicated in the SolarWinds supply chain attack. For more information on ensuring your business is Cybersafe, you can read our latest article.

Three-quarters of Cyber Incident victims are small businesses


A recent Sophos report revealed that small businesses bore the brunt of cyber incidents in 2023 making up over three-quarters of those affected. Ransomware, particularly from the LockBit group, dominated these attacks. LockBit accounted for 27.59% of minor business ransomware incidents handled by Sophos, surpassing other groups such as Akira and BlackCat.

The report highlights evolving ransomware tactics, including remote encryption and targeting macOS and Linux systems. Additionally, over 90% of cyber attacks reported involved data or credential theft. Nearly half of malware targeting small and medium businesses focused on data theft, with password stealers like RedLine and Raccoon Stealer being prevalent.

Stolen credentials hold significant value for cybercriminals, enabling various malicious activities such as social engineering attacks and accessing third-party services. Malware-as-a-service (MaaS) operators increasingly use SEO poisoning and web advertising to infect victims. At the same time, BEC attacks have become more sophisticated, involving conversations before sending malicious links or attachments.

The report underscores the need for heightened cybersecurity measures among small businesses as cyber threats evolve and diversify, posing significant risks to their operations and data security.

USB’s now proving to be popular method of cyber attack by nation-state threat actors


Nation-state cyber threat groups are once again turning to USBs to compromise highly guarded government organisations and critical infrastructure facilities.

These attacks exploit vulnerabilities in organisational security, often relying on unsuspecting employees. For instance, a power company employee unwittingly introduced malware into the corporate network by plugging in a seemingly harmless USB received in an Amazon package. USBs serve as a bridge between segregated networks, allowing malware to bypass traditional security measures.

USB-based attacks extend beyond individual organisations, as demonstrated by incidents where malware transmitted via USBs spread across multiple countries. Infections like Camaro Dragon and Raspberry Robin have facilitated ransomware attacks globally, underscoring the widespread impact of USB vulnerabilities.

Organisations can mitigate USB-related threats by implementing cyber security measures such as separating personal and work devices, enforcing strict removable device policies, and conducting regular security scans.

Additionally, critical infrastructure industries may need to implement more stringent measures like sanitation stations and physical barriers to prevent unauthorised USB usage.

Despite the challenges posed by USB-based attacks, organisations can enhance their security posture by adopting layered defence strategies and remaining vigilant against emerging cyber threats in the evolving cybersecurity landscape.

—————————————————————————————————————————–

Contact Neuways for Cyber Security For Businesses

If you need any assistance with cyber security to become Cybersafe, then please contact Neuways and we will help you where we can. Just get in touch with our team today. We’re based in Derby but we work with clients all over the UK and can travel for your needs.

[/fusion_text][/fusion_builder_column][/fusion_builder_row][/fusion_builder_container]

Want to keep up with our blog?

Get our most valuable tips right inside your inbox every Friday!

Latest IT News & Insights
VPN
SonicWall VPNs under attack: What businesses need to know  
Cybercriminals are always adapting, and the latest surge in activity from the Akira ransomware group...
Read More
Ransomware on the rise
Ransomware on the rise: Meet Akira & Lynx 
Ransomware continues to be one of the most disruptive cyber threats facing businesses today. As defences...
Read More
What is Ransomware
Ransomware: What is it and how to stay protected 
You’ve probably seen the term “ransomware” pop up in the news more often over the past few years, and...
Read More
ring-doorbell
What to know about the supposed Ring doorbell security breach in May 2025
In July 2025, Ring users across social media platforms raised alarm bells after spotting what appeared...
Read More
Heading-12
Windows 10 support ends in 2025: What your business needs to know
Microsoft has officially announced that support for Windows 10 will end on 14th October 2025. If your...
Read More
browser
The hidden danger of browser extensions: Are your staff putting your business at risk?
Browser extensions represent a serious business risk Browser extensions are often seen as harmless add-ons,...
Read More
Legacy systems
Legacy systems: The silent security liability
When thinking about cyber security, it’s easy to focus on the latest threats: phishing, ransomware, or...
Read More
Captchas
CAPTCHAs: A security tool that can be used against you
We’re all used to CAPTCHAs, those little tests that make you pick out traffic lights or type in squiggly...
Read More
Neuways logo

Frequently Asked Questions

As a leading IT and technology provider, we offer three core services, all of which have additional add-ons. We offer Managed IT Support, Business Central implementation and consultation, as well as Managed Cyber Security. Call us on 01283 753333 if you are interested in any of our services.

Contact us

Support: 01283 753300

Business Development: 01283 753333

Purchasing: 01283 753322

Admin and Accounts: 01283 753311

Email: hello@neuways.com

Managed IT support is a comprehensive solution where an expert IT provider, like Neuways, handles your technology infrastructure. This includes proactive monitoring, maintenance, cyber security, and support.

Yes we do. Your business needs Cyber Security due to the increasing number of cyber threats that are affecting businesses in all industries. If your business has data and technology systems implemented, you will need Managed Cyber Security.

We can help you conduct Cyber Audits to assess whether your business would gain Cyber Essentials and Cyber Essentials Plus Certification. Our dedicated departments work with your team to assess how much work is required before you gain Cyber Essentials Plus certification. We will then provide advice and consultation on what aspects you need to change within your business before providing a quote on how we can assist your company become Cybersafe.

Yes we can. We have our own dedicated Microsoft Dynamics 365 Business Central teams who work to ensure that we can implement the right systems and solutions into your website that are absolute right for you. Our experienced business consultants have worked all over the world for organisations operating on a global scale. 

Exclaimer Pro is a dynamic email signature that helps clients to switch and change around email signatures so that clients are able to advertise different offers and brands to a variety of email recipients. Administrators can also manage user emails internally, meaning the user does not have to touch their own email signature.

We offer Managed Security Training to help employees spot email phishing attacks, spear phishing attacks and vishing attacks. We also help train clients on how to use the various pieces of software we provide to clients, like Exclaimer Pro, Business Central and Cybersafe software.

We are a Managed IT Support provider based in Derby, East Midlands. However, we cover so many areas including the whole of the UK, Europe, and America. We are always willing to travel and send our expert technicians to ensure you have the best experience. 

Got a question?

Reach out
& Connect

Name