The Cybersecurity Operations Center and Information Technology’s Office 365 email team have been tracking an increase in spam email messages promoting adult websites. Some of these messages include links to tech support scam webpages.
Cybersecurity News
The Office of Cybersecurity manages the university’s risk-reduction efforts through data protection, ongoing diagnostics, cybersecurity awareness training and policies and procedures to safeguard intellectual property and sensitive information.
Stay cyber safe—and go on a (virtual) scavenger hunt!
What should you do if you get an MFA-Duo push notification that you didn’t request? How can you find out if your email or phone number was compromised in a data breach? And what the heck is “vishing?” Go on our scavenger hunt for Cybersecurity Awareness Month and find out!
Cybersecurity Announcement: WordPress Releases Patch for High Severity SQL Injection Vulnerability
WordPress has released version 6.0.2. This security and maintenance release contains patches for 3 vulnerabilities, including a high severity SQL Injection vulnerability in the Links functionality (CVSS Score of 8.0), as well as two Medium Severity Cross-Site Scripting vulnerabilities.
Cybersecurity Announcement: Atlassian Bitbucket Server and Data Center Critical Vulnerability (CVE-2022-36804)
Atlassian has published a security advisory warning Bitbucket Server and Data Center users of a critical security flaw that allows remote attackers with access to public repositories or read access to private Bitbucket repositories to execute arbitrary code.
8/29 phishing alert! Subject: “School Job Offer”
Watch out for an active phishing campaign on campus in which the attacker offers a a part-time, work-from-home job.
Cybersecurity Announcement: Microsoft Windows Support Diagnostic Tool and Point-to-Point Protocol Remote Code Execution Vulnerability (CVE-2022-34713) and (CVE-2022-30133)
Microsoft released announcements for known vulnerabilities addressed in their Tuesday Patch release. Two are considered Remote Code Execution vulnerabilities, meaning an attacker can exploit the system vulnerabilities remotely.
Cybersecurity Announcement: Django SQL injection vulnerability
Django, an open-source Python-based web framework, has detected a SQL injection vulnerability (CVE-2022-34265) in some recent versions.
Cybersecurity Announcement: Linux Local Privilege Escalation Vulnerability (CVE-2021-4034 PwnKit)
Qualys researchers discovered a Local Privilege Escalation vulnerability (CVE-2021-4034) in polkit’s pkexec, a program that is installed by default on every major Linux distribution.
Cybersecurity Announcement: Critical Illumina vulnerabilities (multiple CVEs)
Four critical vulnerabilities were discovered in Illumina Local Run Manager (LRM), software used by sequencing instruments to aid in genetic analysis.
Attend the Cybersecurity Forward virtual webinar series
Every Wed at noon, Jun 22-Jul 27: Come and learn information technology essentials, explore pertinent tools and case studies, and discover ways to hone your leadership skills. Receive Continuing Professional Education credits (CPEs) for each session you attend!