SURIT PTY LTD

SURIT PTY LTD Cyber security focused IT service provider

If you deleted a OneDrive file recently and went looking for it in your Recycle Bin… surprise, it's not there.Starting i...
08/07/2026

If you deleted a OneDrive file recently and went looking for it in your Recycle Bin… surprise, it's not there.
Starting in May 2026, files deleted from OneDrive or SharePoint in the cloud no longer appear in your local Recycle Bin or Trash.
They are removed directly from your device and can only be recovered from the OneDrive or SharePoint web‑based recycle bin.
1.
Go to onedrive.com or your SharePoint site
2.
Click "Recycle bin" in the left menu
3.
Right-click the file and select "Restore"
You typically have 30 days before files move to the second‑stage recycle bin (which most people don’t know about), and up to 93 more days there, depending on your organisation’s settings.
After about 123 days, they’re gone for good.

06/07/2026
MFA fatigue is one of the most common attacks on small businesses today, and most owners don't know it by name.The attac...
03/07/2026

MFA fatigue is one of the most common attacks on small businesses today, and most owners don't know it by name.
The attacker already has the password (bought from a leak or stolen from another site). They log in. The MFA push hits your employee's phone. They tap "Deny." The attacker tries again 10 seconds later. Then again at 2am. Then during lunch. Eventually someone taps "Approve" just to make it stop. The attacker is in.
Uber got hit this way in 2022. Cisco too. It still works on small businesses every week because passwords keep leaking and the push prompt looks identical to a real login.
Three things close the gap, and none of them are expensive. Switch your team from "tap to approve" to number matching, which both Microsoft Authenticator and Duo support out of the box and takes about 10 minutes to enable in your tenant. Then turn on geo-blocking or impossible-travel rules in your identity platform so logins from countries you don't operate in get blocked before the push ever fires. Last, give your team one rule: if you get an MFA prompt you didn't ask for, deny it AND report it. The report is what catches the attacker mid-attempt.
The attacker doesn't need a fancy hack. They just need someone tired enough to tap "Approve."

Saving passwords in Chrome is one of the riskiest habits you could have today.Chrome stores them in a way that's easy to...
01/07/2026

Saving passwords in Chrome is one of the riskiest habits you could have today.
Chrome stores them in a way that's easy to steal. Anyone who gets onto your computer can pull every saved login in seconds. Malware called infostealers (names like Redline, Lumma, and Vidar) does exactly that. Once it's on a machine, it copies every saved password and sells them online within hours.
The fix takes about 10 minutes. Sign up for a real password manager. Keeper Security, Bitwarden, and Dashlane all work, some even have a free tier that are actually good. Use the built-in import tool to bring in your saved Chrome passwords. Then go into
Chrome's settings (Settings > Autofill > Password Manager), delete every saved password, and turn off "Offer to save passwords."
A real password manager costs around a couple of dollars a month per user. Chrome's free one could cost you your business.

AI Acceptable Use PolicyYour team is using AI right now, whether you have a policy on it or not.ChatGPT, Gemini, Copilot...
29/06/2026

AI Acceptable Use Policy
Your team is using AI right now, whether you have a policy on it or not.
ChatGPT, Gemini, Copilot, Claude, and a dozen niche business tools are in the workflow of someone in your business this week. These tools learn from what you type, sometimes retain it for training, and live outside whatever data security setup you've built for the rest of the business.
Without a written policy, you have no way to know what client data is being pasted into prompts, which business decisions are being made with AI assistance, or how your insurance views any of it if something goes wrong.
An AI Acceptable Use Policy doesn't have to be 30 pages. A one-page version covers the essentials: which tools are approved, what data is forbidden as input, what disclosure rules apply to AI-generated work, and who reviews AI output before it goes to a client.
If you want a full AI Acceptable Use Policy template to implement in your business, comment below with "AI Policy" and we'll send it to you.

Less Than 1% of AI-Found Vulnerabilities Have Been PatchedWhen Anthropic tested its newest unreleased AI model on the wo...
25/06/2026

Less Than 1% of AI-Found Vulnerabilities Have Been Patched

When Anthropic tested its newest unreleased AI model on the world's most critical software earlier this year...
It found thousands of zero-day vulnerabilities (a "zero-day" is a flaw the software vendor doesn't know about yet, which gives hackers a head start before any patch is available) in every major operating system and every major web browser.
Over 99% of those flaws are still unpatched, mostly because AI now finds bugs almost instantly while humans still patch on calendar speed.
While the industry catches up, you can stay safer with a few simple habits.
Turn on automatic updates for every browser, OS, and major app on your company devices, and confirm your antivirus is actually running on every machine, not just installed.
It also helps to review critical patches monthly rather than quarterly, so nothing important sits exposed for weeks.
The good news is that the same AI capability finding these flaws is now being used to fix them at scale, through industry coalitions like Anthropic's Project Glasswing.
Smaller businesses should inherit the benefit for free as the technology rolls out over the next year or two.

🪟 Microsoft Adds "Agent Mode" to Word, Excel, and PowerPointMicrosoft's Copilot Agent Mode went generally available acro...
24/06/2026

🪟 Microsoft Adds "Agent Mode" to Word, Excel, and PowerPoint
Microsoft's Copilot Agent Mode went generally available across Word, Excel, and PowerPoint. It can now take multi-step actions directly inside your documents, spreadsheets, and decks, so you can ask for an entire formatted report or a rebuilt presentation with a single prompt instead of 20 clicks.

Copilot's newest features are now generally available as the default experience across all Microsoft 365 subscriptions.

If a website ever tells you to press Windows Key + R, close the tab.That single instruction is the giveaway for a fast-g...
22/06/2026

If a website ever tells you to press Windows Key + R, close the tab.
That single instruction is the giveaway for a fast-growing scam called ClickFix, which
has been behind a wave of infostealer infections all year.
An infostealer is malware that scrapes every saved password, browser cookie, session
token, and stored credit card...
You click a Google result that takes you to a hacked website.
A fake CAPTCHA pops up and tells you to press Windows Key + R, then Ctrl + V, then
Enter to verify you're human.
The second you hit Enter, you've installed malware on your own machine.
This attack slips past most security tools because you run the command yourself.
No file was downloaded, so antivirus has nothing to scan.
The browser shows no warning.
From the operating system's perspective, you typed a command into a Windows
utility, the same as any admin doing real work.
A few things you can do this week:
Tell your team that if any website prompts the user to press Win+R or paste
something into the Run box, they should close the tab and report it.
Restrict PowerShell for non-IT staff using AppLocker or Windows Defender
Application Control. Most office employees have no work reason to run PowerShell
scripts.
Make sure your endpoint protection is doing behavioral monitoring and not just
signature scanning. Microsoft Defender for Endpoint and most modern EDR tools
have detection rules specifically for this attack chain.
There's no shame in falling for a fake CAPTCHA. They're designed to look real. But once your team knows the keystroke trick, this scam stops working on them.

Google might have a secret weapon for the Pixel 11: a notification system called Pixel Glow that uses lights on the back...
21/06/2026

Google might have a secret weapon for the Pixel 11: a notification system called Pixel Glow that uses lights on the back of the phone. It is a stylish way to stay informed without picking up your device. Would this feature make you switch phones?

The Google Pixel 11 series might feature RGB lights on the back to alert you of notifications.

A new AI named Claude Mythos has begun autonomously finding zero-day security flaws across major systems. The speed of d...
19/06/2026

A new AI named Claude Mythos has begun autonomously finding zero-day security flaws across major systems. The speed of digital threats is officially moving faster than human patch cycles. Is your business security ready for the era of autonomous attacks?

AI vulnerability discovery is outrunning patch cycles. A cybersecurity coalition explains what Mythos means for defenders and what to do.

Address

Unit 13, 11 Pinnacle Place
Somersby, NSW
2250

Opening Hours

Monday 8:30am - 6pm
Tuesday 8:30am - 6pm
Wednesday 8:30am - 6pm
Thursday 8:30am - 6pm
Friday 8:30am - 6pm

Telephone

+61283228118

Alerts

Be the first to know and let us send you an email when SURIT PTY LTD posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to SURIT PTY LTD:

Shortcuts

Share