| [an error occurred while processing this directive] | |
03/06/07 : Secure IT! News: Web Appls, BlackBerries & More12/15/06 : December edition of Secure IT! News now available11/10/06 : National Student Video Contest09/25/06 : News, Classes and a Colloquium02/27/06 : Be Wary of Phishing Messages from the IRS and the Social Security Administration02/13/06 : Read the latest edition of Secure IT! News02/13/06 : Read the latest edition of Secure IT! News02/01/06 : Latest phishing scam - don't get hooked!02/01/06 : Computer worm poised to delete files on 2/301/18/06 : Windows computer users: Patch Now!10/03/05 : keep IT safe: Security Awareness Month06/03/05 : Debut of SecureIT! Online Newsletter02/11/05 : Canned Spam01/20/05 : Are you being spied on? The latest Spyware threat.07/08/04 : Something phishy going on? How not to get hooked!01/27/04 : Year of the WormSecure IT! News: Web Appls, BlackBerries & More Posted on
March 6, 2007 02:06 PM
The latest edition of the Secure IT! newsletter is now online:
December edition of Secure IT! News now available Posted on
December 15, 2006 02:30 PM
Check out the latest edition of the Secure IT! newsletter to learn:
National Student Video Contest Posted on
November 10, 2006 02:56 PM
Students are encouraged to enter the Computer Security Awareness Video Contest, which seeks creative, topical and effective videos, of two minutes or less, focusing attention on computing security problems and how best to handle them. The EDUCAUSE/Internet2 Computer and Network Security Task Force in partnership with the Research Channel are conducting the national contest in search of short computer security awareness videos developed by college students for college students. Contest winners will receive cash prizes, their videos will be featured on the Security Task Force Web site, and the videos may be used in campus security awareness campaigns. Six cash prizes will be awarded in the contest, sponsored by the National Cyber Security Alliance, three for each of two categories: training videos and 30-second Public Service Announcements. Gold: $1000 – Silver: $800 – Bronze: $500 The contest deadline is March 15, 2007. For more information and to submit your video, visit: www.educause.edu/SecurityVideoContest2007 News, Classes and a Colloquium Posted on
September 25, 2006 03:59 PM
Start a new school year with more computing security smarts. Take a free class and read the fall edition of Secure IT!, now online and featuring:
Visit www.brown.edu/cis/itsecurity/news/ for all the details. And as part of National Cyber Security Awareness month, we will present a special half-day event on October 25. "Cyber Security Awareness Colloquium: Privacy, Piracy And Protection" will include three afternoon sessions, each focusing on a different topic: identity theft, social networking web sites, and balancing global security and individual privacy. Register now for one or more of the sessions, which are open to the entire Brown community. Please go to our Keep IT Safe & Secure web site for more details on this special event, which includes a free raffle and refreshments. Be Wary of Phishing Messages from the IRS and the Social Security Administration Posted on
February 27, 2006 03:21 PM
It's tax season! However, it's also phishing season - and will be for the foreseeable future! There are various messages circulating at Brown that look very official and appear to come from the IRS or the Social Security Administration. These messages claim they need you to click on a link to verify your personally identifiable information in order to process your tax return - or they claim you will get an additional amount (due to an error) if you sign in and approve the adjustment for some additional dollars. Do not take the bait! These messages are clever and while they look official, NEVER EVER provide personal information via email (or by phone) unless you instigate the communication yourself. Do not click on links. Do not open attachments. We are also still seeing many phishing messages that look like they come from Paypal or various banks. If you have questions, please contact ITSecurity@Brown.edu - before you make a mistake that could take months or even years to correct! Stay safe. Visit the Anti-Phishing Working Group web site for more phishing news. Brought to you by ITSecurity. Read the latest edition of Secure IT! News Posted on
February 13, 2006 09:14 AM
The latest edition of the Secure IT! newsletter is now online, featuring: :: Botnet 101: Don't Get Own3d! Presented by the Office of IT Security. Read the latest edition of Secure IT! News Posted on
February 13, 2006 09:14 AM
The latest edition of the Secure IT! newsletter is now online, featuring: :: Botnet 101: Don't Get Own3d! Presented by the Office of IT Security. Latest phishing scam - don't get hooked! Posted on
February 1, 2006 01:25 PM
A new phishing scam has been sited in the Brown computing community and some individuals have already reported that they suspect they've become victims of identity theft. The perpetrators send official-looking emails using names such as Federal Credit Union, Amazon, VISA or PayPal. The messages contain warnings that your account has been locked down due to suspicious use, requiring that you provide certain details to reactivate the account. One scam going around Brown now claims that someone has charged 30 days of pornography-related services to your account - and this certainly gets people concerned enough to react. Never reply to such a message! If you do suspect foul play, contact your service directly (by phone or an email initiated by you). To compound the threat of robbing you of important confidential information, many of these emails contain viruses as well. Unfortunately institutions of higher education are especially targeted. This recent onslaught is due in part to vulnerable computers that have become infected with a virus/worm, and as a result, are spewing out these email messages. These have the potential for infecting others as well as gathering confidential information. Brown's email spam filters have been updated to handle these, but we expect new variants to come out quickly and encourage everyone to remain vigilant. To protect your identity as well as your computer, take the following actions:
For more tips and links to other sources, see the article Your Identity - Don't Get Caught Without it!, and visit the Anti-Phishing Working Group's website. Computer worm poised to delete files on 2/3 Posted on
February 1, 2006 01:23 PM
A new worm has been reported that infects Windows PCs. Computers that have been compromised with the worm are programmed to delete files on February 3rd and the 3rd of each month thereafter. The actual impact of the spread of the worm is unclear at this time, but the impact on individual PCs could be quite high. DETAILS Name: How it spreads: What to look for: What happens if you are infected:
What you can do:
For more information: Windows computer users: Patch Now! Posted on
January 18, 2006 04:21 PM
If you missed the January 19th edition of Morning Mail on the WMF exploit and how to patch for it, we recommend that you review the article now for important information on a recent critical flaw in the Windows operating system. This flaw is particularly dangerous because unless your computer is patched, it could be compromised even without any action on your part. Once the malicious code resides on your computer, there's almost no limit on what can be done to it or how it could be used. See Windows computer users: Patch Now! for full details. keep IT safe: Security Awareness Month Posted on
October 3, 2005 11:14 AM
October is National Cyber Security Awareness month, which CIS is observing locally with the theme "keep IT safe & secure, because IT's not secure without U". During October we'll offer a variety of ways to learn how to "keep IT safe & secure", with a kick-off event on October 3 from 2:00 to 4:00 PM at the Science Library south patio. Everyone is invited to stop by and pick up tips on safe computing, learn about the laptop "lojack" software, CyberAngel, munch on fresh-popped popcorn and enter a raffle. The month-long observance includes hands-on security training, film screenings, a second cyber-on-the-green on October 19, and Brown Bag presentations on security hot spots: identity theft, copyright and file sharing, secure wireless computing, and managing malicious code (worms, viruses, phishing, etc.). The complete schedule of events is located at http://brown.edu/cis/keepitsafe. Debut of SecureIT! Online Newsletter Posted on
June 3, 2005 04:57 PM
Find out how to avoid some dangerous 'phishing' holes or go wireless at home and keep your network compromise-free in CIS's new publication, SecureIT!. The first edition is now online offering informative (and hopefully fun!) summertime reading:
All this and more in the first edition of the newsletter SecureIT!. Canned Spam Posted on
February 11, 2005 02:59 PM
CIS is changing the way that it manages spam. As of February 14th, 2005, spam sent to you will be quarantined and instead you will receive a daily digest that lists the messages held in quarantine for you. Previously, spam was 'tagged' by an anti-spam program but still delivered to your inbox. The new anti-spam system that CIS has purchased, called Proofpoint, not only tags spam, it also quarantines it so no longer clogs up your inbox. You are sent a spam quarantine digest each day that allows you to browse the list quickly to check if there are any email messages that were tagged as spam that shouldn't have been. Should this occur, you can release the email from the quarantine and it will be delivered to your inbox. However, CIS testing has shown that mis-tagging is rare, as is spam that eludes Proofpoint's defenses. More information about this service is available at: Spam Control Are you being spied on? The latest Spyware threat. Posted on
January 20, 2005 10:40 AM
Spyware is a growing cybersecurity threat at universities and colleges according to EDUCAUSE (non-profit association focused on IT in higher education, www.educause.edu). EDUCAUSE reports that "The most recent form of this data security problem is Marketscore. This type of spyware software directs all Web traffic through a marketing company's servers, allowing them to potentially view any information a user sends or receives through their Web browser." What can you do to protect yourself? 1. Get protection: Use an anti-spyware product 2. Boost your Spyware IQ 3. Look before your leap: Don't install spyware programs 4. Learn more about the latest threat, "Marketscore" Think your computer might already be infected? Common symptoms include an unusually slow or unstable performance, random pop-up ads or being redirected unexpectedly when Web-browsing. Contact the Help Desk (3-HELP) for assistance in removing the unwanted program. Something phishy going on? How not to get hooked! Posted on
July 8, 2004 09:48 AM
You can't have an e-mail account today and not be the victim of SPAM and various attempts at Internet fraud. One of the latest identity theft scams is called "Phishing" (pronounced like fishing). This scam simply looks like an official e-mail (or pop-up) from a trusted service provider (CITI, E-Bay, your bank, your retailer, a government agency, etc.). It looks official, but is actually an attempt to get you to click on a link that leads you to an official-looking form to provide personal information. Be very careful. Always contact your service providers to verify any online request you receive. Once the information is out, your personal data can be stored in thousands of locations and sold repeatedly. Phishing is a crime that can make you a victim over and over again. Identity theft is the fastest growing crime, and will not get better until technology improves, and we learn to implement it effectively. There are also few risks to the perpetrators, and in some states, this activity isn't even illegal. Most courts still see identify theft as a "victimless crime" although lives have been severely impacted by it. So, here are a few tips for e-mail users:
Year of the Worm Posted on
January 27, 2004 01:39 PM
IT Security Memo from Brown's Director of IT Security, Connie Sadler: The possible scenarios go on and on. The truth is: "hackers" and "spammers" are more organized than ever. They actually operate as development teams! We need to be very careful to confirm the authenticity of any sender of an attachment - even if we think we know the sender. If we weren't expecting anything, we shouldn't open the file until we check with the sender to see if the attachment is genuine. This may seem extreme, but it's really the only way to fully protect yourself. An attachment can also contain executable content while "appearing" to be a harmless text file. If in doubt about any e-mail you receive, contact your DCC, the sender of the message, or the Help Desk (3-HELP) before you take a chance. The "payloads" associated with these viruses and worms will only get worse. We fully expect that on a routine basis, your files could all be erased, or your keystrokes could be captured for months at a time, to be "played back" to someone else, who may or may not be known to you. Please be safe in 2004, which has been labeled by some experts as the "Year of the Worm". | |
| [an error occurred while processing this directive] | |