Thursday, November 1, 2012

Important iPhone/iPad IOS 6.0.1 Update

Apple released a software update today for iPhone/iPads running IOS version 6. This is a recommended and critical update for anyone planning on using ActiveSync for Calendar scheduling when KUMC migrates to the new Exchange email system on November 9th.  This update addresses a known issue in the initial release that caused calendar entries to disappear.

The IOS 6.0.1 update is available on iTunes as well as wirelessly.

For more details on IOS 6.0.1, see Apple’s Knowledge Base at http://support.apple.com/kb/DL1606

Tuesday, September 4, 2012

Check Your PC For A MAJOR Java 1.7 Vulnerability

A new zero-day vulnerability in Java has been discovered and exploits are being found in the wild.  The flaw affects all versions of Oracle's Java 7 (version 1.7) on all supported platforms. No patch is available at this time.  Java 6 and earlier are currently unaffected.

In order for this vulnerability to be exploited, you have to visit a web page or follow a link to an infected site.  If you get hit with this, the software can do anything with your computer that you can.  Rapid7, a security research company, has released an online tool to test if your machine is exploitable through Java.  To test your machine with this tool, go to  http://www.isjavaexploitable.com/.

A copy of this message will be posted to TechWeb (www.bu.edu/tech) for reference.  Check there for further updates and information regarding this issue.

Recommendations:

·      If you are not using any programs that require Java, remove it from your system altogether.  Java is one of the most heavily exploited platforms in the world today due to its almost ubiquitous presence.
·      If you have to have Java for a specific program, but don’t need it for the web pages you visit, disable Java for universal use on your browsers. (Links for how to do this are below.)  It is safest to allow use of Java browser plug-ins on a case-by-case basis when prompted for permission by trusted programs.
·      If you can't do that, at least confine your browsing to regular commercial sites which, while not immune from being infected, are typically more carefully maintained and monitored and represent a lower risk.  This is not a reliable security approach, but it is better than nothing.

How to disable Java:

                (For Firefox on Mac OS X, it is like Windows XP (Tools > Add-ons))
...in Chrome:  While in Chrome, enter this URL:  chrome://plugins/  then click "Disable" under Java.


For more information:

Thursday, July 26, 2012

Do You Trust Your Hotel's Security?

You might want to think twice the next time you decide to leave your laptop, iPhone or other valuable in your hotel room on that next vacation or business trip.

As this story by Extreme Tech shows the card-protected locks that are commonly  used on hotel room doors aren't secure.  In fact, it can be easy for someone with $50 off off-the-shelf equipment from Radio Shack to get access and there wouldn't be a trace that they had been in your room.

Wednesday, June 6, 2012

LinkedIn.Com User? Change Your Password NOW

If you use LinkedIn.com to keep track of professional connections, please continue reading.  If not, please disregard.
 
Earlier today, it was confirmed that 6.5 million LinkedIn passwords were compromised and posted to a Russian hacker site.  As of yet, LinkedIn has not yet notified its users; however, if you have an account on LinkedIn.com, there is a high probability that your LinkedIn password has been compromised and you should change it immediately.
 
As a reminder, you should never use your KUMC password or a derivative of it on any external website.  Additionally, if you use the same password on LinkedIn and other websites, I recommend that you change your password on those other sites as well.
 
 
If you are a member of the KUMC community and have a question regarding this situation, please contact Information Security at (913) 588-3333 or email kumc-security@kumc.edu

Tuesday, February 21, 2012

Students Steal Laptops for Class Credit?

This recent story by Charlie Osborne at ZDNet highlights a research project where students at the University of Twente were told to steal 30 laptops from faculty and staff on campus. The "thefts" were part of a PhD thesis titled "Alignment of Organizational Security Policies, Theory and Practice" that explored the ways in which human behavior and habits can thwart good security practices.

During the project, the laptops had been "loaned" to random individuals by the researcher, Trajce Dimkov, and the recipients were asked to safeguard the laptops by either chaining them to their desk, locking them up, or securing them witha password. Students then used various creative methods of "stealing" the laptops. In over half the attempts that were made, students were successful in stealing the laptops.

What's the lesson? 
  •  Pay attention to where your computers are and whether or not they are secure from theft. 
  • Unlocked offices are great targets for theft.
  • Don't get too comfortable in your habits or think "it will never happen to me."

Tuesday, February 14, 2012

Mozilla Fixes Critical Bug in Firefox 10

Just one week after Firefox version 10 was released, Mozilla has pushed out a fix for a critical flaw that could be exploited to crash the browser.  Students and home users are encouraged to download and apply the fix immediately.  The security patch will be pushed automatically to all University and UKP-owned workstations.

For more information, read the Mozille Security Advisory.

Thursday, February 9, 2012

How Do I Secure My Mobile Apps?


iPad, Xoom, Evo, GalaxyTab....whatever your mobile device is, you've probably thought about or even downloaded apps onto it.  Everybody wants to play Angry Birds, right? 

But you need to be aware of the risks that come with downloading apps as well.  In this SANS Securing The Human newsletter, you'll learn what the risks are and great tips on how to make sure your apps are useful and not harmful.