IT SPECIALISTS

Insights

Blogs, resources and industry news

This Incident Response Guide is a practical resource that helps your business prepare for, manage, and recover from cyber incidents quickly and confidently.

Download

This Cybersecurity Practice eBook, offers comprehensive guidance on building and maintaining a strong cyber resilience strategy for businesses.

Download

Unlock the Power of Your IT Ecosystem with this Application Landscape Guide.

Download

This handy operating guide gives you all the tools you need to run your business' own 8-Week Wellbeing Challenge.

Download

In today's fast-paced world, meetings are evolving. Our latest eBook, dives into how technology and innovative practices are transforming the way we collaborate.

Download

This comprehensive guide is designed to empower businesses to harness the potential of Copilot through strategic adoption.

Download

Dive deep into the world of Artificial Intelligence, exploring its impact and the future ahead.

Download

This summary contains information for staff on how to stay aware of current cyber security risks and the role they play in keeping data safe.

Download

If you believe that you could conduct your meetings in a more efficient, productive way then our Better Meetings Guide will help.

Download

27/2/2025

Researchers have disclosed AirSnitch, a new Wi-Fi attack that can bypass the protection people expect from WPA2/WPA3 and client isolation. It does not crack Wi-Fi encryption directly; instead, it abuses weaknesses in how Wi-Fi networks handle clients at lower network layers, which can let an attacker on the same network carry out machine-in-the-middle attacks, intercept traffic, and potentially tamper with unencrypted data. The risk applies across home, office, and enterprise environments, especially where defenders assume client isolation is enough on its own.

Read More

25/2/2026

Researchers found multiple Claude Code flaws that could let attackers run commands on a developer’s machine or steal Anthropic API keys simply by getting them to open a malicious repository. The issues involved unsafe handling of project hooks, MCP server settings, and environment variables, and Anthropic has already released fixes across affected versions. The broader takeaway is that with AI coding tools, even opening an untrusted project can now create real security risk.

Read More

9/2/2026

Microsoft is investigating an Exchange Online issue that is wrongly marking some legitimate emails as phishing and sending them to quarantine. The problem started on 5 February 2026 and was linked to a new URL detection rule that incorrectly classified some safe links as malicious. Microsoft has been working to release affected emails and unblock legitimate URLs.

Read More

27/1/2025

Microsoft has updated the Exchange Online SMTP AUTH Basic Authentication deprecation timeline. After delays to support customers still transitioning, Microsoft now plans to fully retire Basic Auth for Client Submission in stages, and organisations still relying on it need to move to Modern Authentication or alternative options to avoid mail flow disruption. The post is mainly a reminder for admins to confirm where SMTP AUTH Basic Auth is still in use and complete remediation before the new cutoff dates.

Read More

15/1/2026

Researchers disclosed WhisperPair, a critical flaw in Google’s Fast Pair protocol that can let attackers silently take over vulnerable Bluetooth audio devices. In some cases they can pair without the user knowing, track the device’s location, or even eavesdrop through its microphone. The issue affects many Fast Pair-enabled earbuds, headphones, and speakers across multiple brands, and the main fix is to apply any available firmware updates from the manufacturer.

Read More

23/12/2025

Microsoft is turning on stronger Teams messaging protections by default from 12 January 2026 for tenants still using the default settings and who have not already customised them. The change enables three protections: blocking potentially dangerous file types, warning on suspicious URLs, and letting users report false positives. Existing customised settings will stay as they are. Microsoft is also advising admins to review their Teams messaging safety settings, update internal documentation, and brief helpdesk staff before the rollout.

Read More

11/12/2025

The UK ICO fined LastPass £1.2 million over its 2022 breach, which affected data linked to 1.6 million UK users. The regulator said weak internal security controls allowed attackers to access customer information and encrypted password vault backups, highlighting the need for stronger internal protections even for security-focused providers.

Read More

25/11/2025

The threat actor known as ToddyCat has been observed adopting new methods to obtain access to corporate email data belonging to target companies, including using a custom tool dubbed TCSectorCopy. "This attack allows them to obtain tokens for the OAuth 2.0 authorization protocol using the user's browser, which can be used outside the perimeter of the compromised infrastructure to access corporate mail," Kaspersky said in a technical breakdown.

Read More

19/11/2025

Microsoft is trying to transform Windows into a “canvas for AI,” with new AI agents integrated into the Windows 11 taskbar. These new taskbar capabilities are designed to make AI agents feel like an assistant in Windows that can go off and control your PC and do tasks for you at the click of a button. It’s part of a broader overhaul of Windows to turn the operating system into an “agentic OS.”

Read More