We are writing to let you know about a recent cyber security issue affecting the Bottisham Village College website, bottishamvc.org.  For a short period, the site displayed a fake reCAPTCHA message.  This issue stemmed from a new WordPress vulnerability and has now been resolved.  The website is now loading normally.

Most visitors to the website will not have been affected.  A device is only likely to be at risk if all three of the following things happened:

  • You visited bottishamvc.org between the early hours of Sunday 19 July and 1:30pm on Tuesday 21 July.
  • You clicked on the fake reCAPTCHA message.
  • You followed the instructions shown by that message, including opening PowerShell and running the code it provided.

If all three of these apply, we recommend taking precautionary action: run an anti-virus scan on the device, change any passwords you entered or used on that device during the period, and monitor the device for unusual behaviour. You may also wish to use a free account-monitoring service such as https://haveibeenpwned.com/.

We regularly monitor our public websites and work with our website provider to apply security updates and patches as part of our normal maintenance regime. This issue arose from a newly identified vulnerability, sometimes called a “zero-day”, where attackers may try to exploit a weakness before organisations and providers have had time to apply protective updates. We are reviewing the incident with our provider and strengthening our monitoring and alerting arrangements to reduce the chance of a similar issue occurring again.

SHARE
CONTACT DETAILS

+44 (0)1223 811250

enquiries@bottishamvc.org

Bottisham Village College, Lode Road, Bottisham, Cambridge, Cambridgeshire, CB25 9DL