CyberAware UK Weekly Recap: Microsoft's Big Patch, Licence Data Sale and What To Do Today

Every Sunday we take stock of what actually happened in security this week, in plain English, so you know what deserves your attention and what doesn't.

The numbers

DarkWatch logged 480,887 captures over the last seven days. Those fed into 9,358 entities and 1,629 alerts, with one active target being tracked. Captures are pieces of suspicious activity picked up by monitoring. Alerts are the ones that mattered enough to flag.

A ransomware leak site was also detected live and responding. If a company you use is breached, the risk to you is usually your account details. Change that password and turn on two-step verification.

Microsoft's big patch

Microsoft fixed nearly a thousand security holes in this month's release. That sounds alarming, but these bundles land every month. The ones that matter most are flaws already being used by criminals, and the fix is the same: let your updates install. Most home machines do it overnight.

Licence records for sale

The FBI is investigating a service that was selling more than 153 million driver's licence records. This is a US case, but the lesson travels. Your licence details are valuable to a fraudster trying to open accounts in your name. Keep the number safe and never hand it over to someone who contacted you out of the blue.

Two arrests in Australia

Two alleged members of a group known as TeamPCP were arrested. Nothing for you to do, but a reminder that reporting scams to Action Fraud or your bank feeds the bigger picture.

Business flaws added to the exploited list

CISA added five actively exploited flaws covering Artifactory, ScreenConnect and RouterOS. These are business tools, so if you run a small business and use any of them, apply the updates this week.

One thing to do today

Check your phone and laptop for waiting updates, and make sure two-step verification is switched on for your email and your bank. That single habit covers most of what we discussed this week.