Infortech - Managed I. T. and Cyber Security Services Company

Infortech - Managed I. T. and Cyber Security Services Company - Managed IT Services
- CoManaged IT Services
- Managed Cloud Services
- Managed Security Services

Since 1999 we have been enabling MANUFACTURING Businesses in the Bay Area to take advantage of better, disruptive technologies to improve their operations by bringing efficiencies, and lowering their cost. We offer end-to-end managed services keep the businesses running reliably and securely. Our Services include...
- ExpertCare Managed IT Services
- CoManaged IT Services
- Managed Cloud & Datacen

ter Services
- Managed Security Services
- Managed VOIP Telecom Solutions
- Global Networks and Unified Communications

Did your Outlook stop working yesterday? You were definitely not alone.A major Microsoft email outage hit on Monday morn...
09/01/2026

Did your Outlook stop working yesterday? You were definitely not alone.

A major Microsoft email outage hit on Monday morning, August 31st, and affected businesses across the globe for most of the day. Email delivery failures, login errors, and disruptions to OneDrive and SharePoint all came along with it. Nearly 6,000 users reported problems, and as of this morning Microsoft is still working through the recovery.

Outages like this are a good reminder that even the tools we rely on most can go down without warning — and there is nothing you can do locally to fix a platform-level problem.

What you can do is have a plan ready before it happens:

Know what alternative communication channel your team will use when email is unavailable. Make sure customers can still reach you through a phone number or contact form if Outlook is down. Know where to check Microsoft's official service status so you are not wasting time troubleshooting something outside your control.

It does not take much preparation to handle an outage smoothly. It just has to happen before the outage, not during it.

Full details in this week's blog — link in the comments. Share this with a business owner who was impacted yesterday.

Heads up for anyone running a WordPress website that uses the miniOrange Single Sign On plugin.Hackers are actively expl...
08/26/2026

Heads up for anyone running a WordPress website that uses the miniOrange Single Sign On plugin.

Hackers are actively exploiting two security vulnerabilities in that plugin right now that let them log into a WordPress site as an administrator without any username or password. And many of the site owners at risk have no idea because the company behind the plugin never publicly warned paid customers that they needed to update.

If your site uses any version of miniOrange SAML SSO, you need to manually check whether your version is up to date. WordPress may not be showing you a notification about this one.

Here is what to do:

Log into your WordPress admin dashboard and check which version of the miniOrange plugin is installed. Then log into your miniOrange vendor account and update to the latest patched release. After updating, check your list of WordPress admin users for anything unfamiliar.

If you are not sure whether your site uses this plugin, get your web developer or IT provider to check today.

Full details including the specific patched version numbers for each edition are in this week's blog — link in the comments. Share this with anyone who manages a WordPress site.

Urgent alert for anyone using a Mac — especially in a business environment.A critical security vulnerability in macOS is...
08/18/2026

Urgent alert for anyone using a Mac — especially in a business environment.

A critical security vulnerability in macOS is being actively exploited right now that allows attackers to take full control of a Mac with Screen Sharing enabled — without needing a password.

In confirmed attacks, hackers have been installing cryptocurrency mining software that runs silently in the background, draining the Mac's processing power and electricity while the attacker profits.

Apple has already released a fix. Here is what to do right now:

Click the Apple menu, then System Settings, then General, then Software Update, and install any available update immediately.

If you cannot update right now, go to General, then Sharing, and turn Screen Sharing off until you can.

If you have a Mac with Screen Sharing turned on that you do not actively use — turn it off regardless.

This one is actively being exploited today. Do not wait.

Full details in this week's blog — link in the comments. Share this with anyone who uses a Mac for work.

Here is something worth thinking about this week.A strong password and a two-factor code confirm that someone knows the ...
08/12/2026

Here is something worth thinking about this week.

A strong password and a two-factor code confirm that someone knows the right information. They do not confirm who is actually at the keyboard or what device they are using.

AI is now making it faster and cheaper than ever to steal that information. Phishing attacks are more personalized. Credential theft is more automated. Two-factor codes sent by text message can be intercepted. And stolen passwords from old data breaches get reused constantly.

The security concept gaining traction in response is called device trust. The idea is simple: even if an attacker has the right username, password, and two-factor code, if the login is coming from a device the organization has never seen before, access should not be automatically granted.

For businesses with employees working remotely or using personal devices for work, this is more relevant than ever.

Here is where to start:

Review which devices are accessing your business systems. Move away from text message two-factor codes toward an authenticator app. And if your business has never run a Dark Web Scan, now is a good time to find out whether your employee credentials are already out there.

Full details in this week's blog — link in the comments. Share this with a business owner who relies on passwords and two-factor authentication and thinks that covers it.

Quick question — have you ever seen "Managed by your organization" at the bottom of your Chrome settings on a personal c...
08/04/2026

Quick question — have you ever seen "Managed by your organization" at the bottom of your Chrome settings on a personal computer?

If so, and if nobody actually manages your device, something may not be right.

Malware has been quietly exploiting a Chrome feature designed for businesses to force-install extensions on personal computers that users cannot remove. These extensions hijack your new tab page and redirect your searches through sites you never intended to visit.

Google is building a fix — but it is not available yet.

Here is what to do right now:

Open Chrome and type chrome://extensions into the address bar. Look for anything you do not recognize or anything whose toggle is grayed out and cannot be turned off. Then go to Settings and check whether your default search engine has been changed.

If something looks wrong on a device you use for work, reach out to your IT provider before using that browser to log into any business accounts.

Full details in this week's blog — link in the comments. Share this with someone who uses Chrome.

There is a new type of malware attack that antivirus software may not catch — and it is active right now.A campaign call...
07/29/2026

There is a new type of malware attack that antivirus software may not catch — and it is active right now.

A campaign called SourTrade is using fake versions of popular financial websites like TradingView to deliver malware. But here is the part that makes it different from anything most people have seen before.

The malware is not downloaded to your computer as a file. Your own browser assembles it invisibly from pieces while the page loads, then hands it to you as what looks like a normal download. Security tools that scan files crossing the network have nothing to catch because no finished malicious file ever travels over the internet.

Once installed, it steals passwords, records keystrokes, intercepts web traffic, and harvests cryptocurrency wallet data.

Here is what to do:

Never click a sponsored ad or search result to download financial or investment software. Go directly to the official website instead. Before running any downloaded installer, check who signed it. Use a password manager instead of saving passwords in your browser.

An antivirus tool not flagging a download does not mean it is safe. That is the whole point of this attack.

Full details in this week's blog — link in the comments. Share this with someone who uses investment or trading platforms online.

Quick heads up for anyone using 7-Zip to open compressed files at work or at home.A serious security vulnerability was j...
07/21/2026

Quick heads up for anyone using 7-Zip to open compressed files at work or at home.

A serious security vulnerability was just disclosed that could let an attacker run malicious code on your computer just by getting you to open a specially crafted file. The flaw has been in 7-Zip's code since at least 2021.

The fix is already available. 7-Zip version 26.02 patches this completely.

The problem is that 7-Zip does not update itself automatically. You have to do it manually.

Here is what to do:
Open 7-Zip File Manager, click Help, then About, and check your version number. If it is anything older than 26.02, go to 7-zip.org and update it today.

That is it. Five minutes and you are protected.

Full details in this week's blog — link in the comments. Share this with someone who uses 7-Zip.

A newly published cybersecurity research report reveals that attackers can hide malicious instructions inside an ordinar...
07/14/2026

A newly published cybersecurity research report reveals that attackers can hide malicious instructions inside an ordinary image file — and AI tools will follow those instructions without any human ever knowing.

The attack is called Ghostcommit. The AI reads the image, finds hidden instructions, opens your credential file, and quietly encodes your passwords into code that looks completely normal.

No alarm. No warning. No red flag.

And the review tools that were supposed to catch it? They never even opened the image file.

Here is what every business using AI tools should be thinking about right now:
Your AI tools should not have access to sensitive credentials or systems they do not need. Review what permissions your AI tools have been granted. And never rely entirely on automated review — human oversight still matters.

AI tools are powerful. But they can be manipulated by the content they are shown.

Full details in this week's blog — link in the comments. Share this with someone who uses AI tools in their business workflow.

Did you know anyone can now build a working software app in minutes using AI — no coding experience required?It sounds a...
07/08/2026

Did you know anyone can now build a working software app in minutes using AI — no coding experience required?

It sounds amazing. And it is. But it is also creating a real security problem for businesses.

When software gets built that fast, the security checks that used to happen along the way get skipped. The code looks fine. It works fine. But hidden vulnerabilities can sit inside it for months before anyone notices.

And it is not just the apps your team downloads. Employees are now building their own internal tools with AI. A quick form, a workflow script, a data tracker. Convenient, yes. Reviewed for security, often not.

Here is what every business should be doing:
Review any new tool or software before it connects to your systems or data. Make sure employees are not deploying AI-built tools without IT approval. Keep a current list of everything running in your business environment.

Speed is great. Security review is still non-negotiable.

Full details in this week's blog — link in the comments. Share this with a business owner who uses AI tools in their workflow.

🚨 Do you use browser extensions? Ad blockers, VPNs, translators, video downloaders?Microsoft just removed 119 of them fr...
06/30/2026

🚨 Do you use browser extensions? Ad blockers, VPNs, translators, video downloaders?

Microsoft just removed 119 of them from the Edge store — after discovering they'd been secretly stealing passwords for years.

The scary part? They looked completely legitimate. They worked normally. They had good reviews. The malware was hidden inside the extensions' own image files — invisible to security tools and invisible to users.

What were they doing? Stealing Google passwords, two-factor login codes, and browser cookies that can be used to take over accounts — all without anyone noticing.

Here's what to do right now:
✅ Type edge://extensions into your Edge browser and review what's installed
✅ Remove anything you don't recognize or no longer use
✅ If Edge already removed something automatically — change your passwords now
✅ Switch from SMS two-factor codes to an authenticator app

Fewer extensions, safer browser. It's that simple.

Full details in this week's blog — link in the comments. Share this with someone who uses browser extensions. 👇

Address

Santa Clara, CA
95054

Opening Hours

Monday 8am - 5pm
Tuesday 8am - 5pm
Wednesday 8am - 5pm
Thursday 8am - 5pm
Friday 8am - 5pm

Telephone

+18007418530

Alerts

Be the first to know and let us send you an email when Infortech - Managed I. T. and Cyber Security Services Company posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share