Arch Technologies

Arch Technologies We are an IT services company serving the St. Louis area specializing in Technology Solutions and Consulting for Small and Medium Sized businesses.

09/04/2026

If someone takes over your page, they can scam your customers using your name.

They can post scams to your followers, message your customers pretending to be you, or just lock you out and hold the account hostage. And a lot of businesses still run these accounts on a single shared password with no 2FA, sometimes one an ex-employee still knows.

The first thing to do is turn on two-factor authentication for every business account. After that, stop sharing one login. On Facebook and Instagram, Business Manager lets you give each person their own access, so you can add or remove people without changing a password. While you're in there, check who has access and remove anyone who's left.

And your business page is usually tied to someone's personal admin account. If that personal account gets hacked, your business page goes with it, so lock it down too.

09/03/2026

If your guests, your staff's personal phones, and your business computers all connect to the same wifi, they can all reach each other.

Everything on one network can talk to everything else on it. So a guest's malwareinfected laptop, or a cheap smart camera with a known flaw, sits on the same network as the computer running your accounts. If an attacker gets into the weak device, your business machines are right there next to it.

The fix is to split your network:
➡️ Put guests on a separate "Guest" wifi. Most business routers can do this in a couple of clicks, and it keeps visitors off your main network.
➡️ Put smart devices (cameras, TVs, thermostats, smart plugs) on their own network too. They're often the weakest, least-updated things you own.
➡️ Keep your actual work computers and servers on their own network, away from both.

Your IT provider can set this up, and on a lot of routers it's a built-in feature you're not using yet. Ask them which network your smart devices are on right now.

Everyone's downloading AI tools at the moment, and scammers have caught on.Say someone on your team wants to try a new A...
09/02/2026

Everyone's downloading AI tools at the moment, and scammers have caught on.

Say someone on your team wants to try a new AI app. They search for it, click the top result, and end up on a page that looks like the real company's site. They download the app. It's fake, and it steals every password saved on their computer.

The fake sites are hard to spot because they copy the real ones closely, and the link is often an ad shown above the real website in the results. Security firms have reported a lot more of this over the past year.

Only download software by going to the company's real website yourself, not by clicking an ad or a search result. If a page asks you to install something and you're not sure it's real, don't. And it helps to agree as a team on which AI tools you use, so people aren't installing unknown ones to try them out.

You can get hacked just by visiting a web page. No clicking required.In June 2026, Google put out an emergency Chrome up...
09/01/2026

You can get hacked just by visiting a web page. No clicking required.

In June 2026, Google put out an emergency Chrome update to fix a flaw (CVE-202611645) attackers were already exploiting. The flaw's in Chrome itself, so just visiting a malicious web page is enough to get hit. This is one of several Chrome flaws attackers have exploited in 2026.

Updating takes 30 seconds. Click the three dots in the top right of Chrome, go to Help, then About Google Chrome. Chrome will update automatically once you open that page, then click Relaunch to finish.

Do the same in Microsoft Edge, which runs on the same engine and needs the same fix. And if your IT provider manages your updates, ask them to confirm this one's done.

Browser updates only take effect after you restart, and a lot of us leave Chrome open for weeks. So restart it today.


Google released security updates for 74 Chrome vulnerabilities, including CVE-2026-11645, a high-severity V8 out-of-bounds memory access flaw.

08/26/2026

Attackers don't always need your password. A lot of the time they just go to the login page, click "forgot password," and reset it themselves.

That reset usually runs through your recovery email, your phone number, or those security questions like your mother's maiden name or the street you grew up on. A lot of that is easy to dig up on social media or in old data breaches.

If someone can answer your security questions or get into your recovery email, your strong password and MFA don't matter.

Try this:
➡️ Make sure the recovery email and phone number on your important accounts are current and protected with their own strong login and MFA. Your email matters most here, because whoever controls it can reset your other accounts.

➡️ When a site lets you, skip the security questions, or treat them like extra passwords. Make up an answer that isn't real and save it in your password manager.

➡️ Check the recovery details on your main business accounts now and then, especially after someone leaves, so an old personal phone number isn't still sitting there.

The reset process is one of the most overlooked ways in. Ten minutes on your key accounts closes it off.

Starting in August 2026, the EU has new rules about labeling AI-generated content, and they could apply to your business...
08/25/2026

Starting in August 2026, the EU has new rules about labeling AI-generated content, and they could apply to your business even if you're not based in Europe.

If you use AI to create content the public sees, things like images, videos, or text, and you have customers in the EU, you may need to make clear when something was made or heavily changed by AI, depending on the specific role you play and the type of content involved.

It's worth checking whether it applies to you rather than assuming it does or doesn't. Look at where you're already using AI in your marketing or customer-facing material and start labeling anything that needs it. If you're not sure whether the rules apply to you, that's a quick conversation with whoever handles your legal side.

Better to sort this out now than scramble when a customer or regulator asks.


This code of practice supports compliance with the AI Act transparency obligations related to marking and labelling of AI-generated content.

08/24/2026

Found a USB stick in the parking lot? Don't plug it in to see what's on it.

The second you plug in a dodgy USB drive, it can load malware, or even act like a keyboard and type out commands on its own, faster than you could.

The best practice?
➡️ If you didn't buy it, don't trust it. A USB drive you found goes in the bin, not into
your laptop.

➡️ Ask your IT provider to block USB drives on the computers that don't need them, or to only allow ones you've approved.

➡️ Share files through the cloud instead of passing memory sticks around, so nobody's in the habit of plugging in whatever's lying about.

And if you do keep sensitive files on USB drives, use encrypted ones, so a drive going missing doesn't turn into a data breach.

08/23/2026

Everyone's careful with their laptop, but the phone in your pocket has the same company email and files on it, plus all your saved logins. It just doesn't get the same attention.

Here's what to check:
➡️ A screen lock on every phone that has work stuff on it, with a real PIN, fingerprint, or face unlock. A lost phone with no lock is wide open.

➡️ Automatic updates left on. Phone makers are constantly fixing security holes, and an old un-updated phone is full of ones attackers already know about.

➡️ Apps only from the official App Store or Google Play. The ones you install from a random link or website are a common way to pick up malware.

➡️ A way to wipe a phone if it goes missing. Microsoft 365 and Google Workspace can both erase the company data off a lost phone, as long as it's set up beforehand.

If your team uses personal phones for work, you can keep the company side separate from their personal stuff. Your IT provider can set up a space that holds just the work email and files, which you can lock or wipe on its own without touching anything personal.

08/22/2026

You know how the old advice was that you could spot a scam by the bad spelling and clunky grammar? You can't anymore.

Google has sued a cybercrime group it says used its Gemini AI to mass-produce scam texts and fake websites, alleging the group generated large volumes of fraudulent pages over several months, pretending to be banks, government offices, and well-known stores.

The AI lets a tiny crew pump out polished fakes faster than any team of people could. These fakes look clean and copy real companies right down to the logo. What still works is looking at what the message wants you to do. Anything rushing you to click a link, log in, or move money should make you stop, no matter how legit it looks.

Don't tap the link. Go straight to the company's app or website yourself and check there.

Address

St. Louis, MO

Opening Hours

Monday 9am - 5pm
Tuesday 9am - 5pm
Wednesday 9am - 5pm
Thursday 9am - 5pm
Friday 9am - 5pm

Alerts

Be the first to know and let us send you an email when Arch Technologies posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share