Tuesday, October 1, 2013

Happy National Computer Security Awareness Month!

NCSAM It's finally here! National Computer Security Awareness Month starts today and the entire KUMC campus is celebrating throughout the month of October with both online and face-to-face opportunities to learn more about how to keep you, your family, and your data safe and secure. Each day on this blog, we'll focus on a different risk or threat such as phishing, iPad and mobile device security, social media privacy, or keeping track of all those passwords.  It will be a learning experience, but it will be a fun one....we promise!

During the week of October 28th, we hope you'll bring your lunch and join us for all four of the following Lunch 'n Learn sessions from 12 to 1 p.m. 
(You can sign up now using the links below):

Monday, October 28th:  Got (Too Many) Passwords?
Description:  Passwords, passwords, passwords for your bank site, your personal and work email, Facebook, and on and on. How do you keep track of all of them? Bring your lunch and learn about a FREE and secure way to manage your passwords, including how to make sure they're always available when you need them.

Tuesday, October 29th:  Defend Yourself: Top 10 FREE Security Tools
Description:  A new computer taken out of the box and connected to the Internet is easily taken over by a hacker within minutes. If you've got a computer, you need to arm yourself with the right tools to fight this constant battle. Bring your lunch and learn about the FREE security tools that are a must-have for any PC owner.

Thursday, October 31st:  R U My Friend? Privacy and Social Media
Description: Social media sites like Facebook and Instragram are great for keeping track of friends and sharing your everyday life with those you love. But there's also a dark side to sharing your information on these types of sites. Bring your lunch and find out how companies and criminals use the information and photos that you share on these sites and what YOU can do to protect yourself on social media.

Friday, November 1st:   Mobile Revolution: Mobile Device and Cloud Security
Description: Smartphones, iPads, tablets and other mobile devices are literally changing the way we work and play. But do you know how to protect your shiny new device from hackers? And just what does it mean to store your data "in the cloud"? Bring your lunch and your questions as we discuss security issues related to mobile devices and storing data in the cloud.


 
The more you participate, the more chances you have to win one of the great prizes* to be raffled off on November 1st!  And, even if you can' t make one of the sessions, you can still enter the raffle by participating in the online treasure hunt starting October 28th.
 *Prizes to be announced later this month.

We hope you'll join us in the celebration!

UPDATE 10/24/13:  Prizes for this year have been announced and they look great.  Click here to find out details on what prizes are available and how you can enter to win. 

UPDATE 10/28/13: The online security scavenger hunt is now open.  Even if you can't find time to attend the Lunch 'n Learn sessions, completing the hunt will give you an entry into the prize drawing on Friday.  Good luck!

Monday, September 23, 2013

NCSAM is coming in October!



Next month, KUMC will be participating in the nationwide celebration of the 10th anniversary of National Cyber Security Awareness Month.   Check back here often for information on some great learning opportunities on campus, contests and even prizes!

What is National Cyber Security Awareness Month?

We lead Internet-connected, digital lives. From our desks and homes to on the go, we work, learn and play online. Even when we are not directly connected to the Internet, our critical infrastructure—the vast, worldwide connection of computers, data, and websites supporting our everyday lives through financial transactions, transportation systems, healthcare records, emergency response systems, personal communications, and more—impacts everyone.

National Cyber Security Awareness Month (NCSAM) – celebrated every October - was created as a collaborative effort between government and industry to ensure that we all have the resources we need to stay safer and more secure online.

This year's theme is "Our Shared Responsibility" because no individual, business, or government entity is solely responsible for securing the Internet. Everyone has a role in securing their part of cyberspace, including the devices and networks they use. Individual actions have a collective impact and when we use the Internet safely, we make it more secure for everyone. If each of us does our part—implementing stronger security practices, raising community awareness, educating young people, training employees—together we will be a digital society safer and more resistant from attacks and more resilient if one occurs.

If you are concerned about making the Internet safer and more secure for everyone, we invite you to join us next month as we celebrate.  Everyone can do something—even if you have less than one hour to devote to this effort!

Want to read President Obama's Presidential Proclamation on NCSAM?  Go here.

Monday, December 3, 2012

12 Scams of Christmas



Are you the 1 person out of 4 that will be shopping from a mobile device this year?  McAfee has just released a list of the 12 most popular scams that online shoppers should watch out for this Christmas season.  It's great list!

  1. Social media scams: Cybercriminals know social media networks are a good place to catch you off guard because we’re all “friends,” right? Scammers use channels, like Facebook and Twitter, just like email and websites to scam consumers during the holidays. Be careful when clicking or liking posts, while taking advantage of raffle contests, and fan page deals that you get from your “friends” that advertise the hottest Holiday gifts, installing apps to receive discounts, and your friends’ accounts being hacked and sending out fake alerts. Twitter ads and special discounts utilize blind, shortened links, many of which could easily be malicious.
  2. Malicious Mobile Apps: As smartphone users we are app crazy, downloading over 25 billion apps for Android devices alone! But as the popularity of applications has grown, so have the chances that you could download a malicious application designed to steal your information or even send out premium-rate text messages without your knowledge.
  3. Travel Scams: Before you book your flight or hotel to head home to see your loved ones for the holidays, keep in mind that the scammers are looking to hook you with too-good-to-be-true deals. Phony travel webpages, sometimes using your preferred company, with beautiful pictures and rock-bottom prices are used to get you to hand over your financial details.
  4. Holiday Spam/Phishing: Soon many of these spam emails will take on holiday themes. Cheap Rolex watches and pharmaceuticals may be advertised as the “perfect gift” for that special someone.
  5. iPhone 5, iPad Mini and other hot holiday gift scams: The kind of excitement and buzz surrounding Apple’s new iPhone 5 or iPad Mini is just what cybercrooks dream of when they plot their scams. They will mention must-have holiday gifts in dangerous links, phony contests (example: “Free iPad”) and phishing emails as a way to grab computer users’ attention to get you to reveal personal information or click on a dangerous link that could download malware onto your machine.
  6. Skype Message Scare: People around the world will use Skype to connect with loved ones this holiday season, but they should be aware of a new Skype message scam that attempts to infect their machine, and even hold their files for ransom.
  7. Bogus gift cards: Cybercriminals can't help but want to get in on the action by offering bogus gift cards online. Be wary of buying gift cards from third parties; just imagine how embarrassing it would be to find out that the gift card you gave your mother-in-law was fraudulent!
  8. Holiday SMiShing: “SMiSishing” is phishing via text message. Just like with email phishing, the scammer tries to lure you into revealing information or performing an action you normally wouldn’t do by pretending to be a legitimate organization.
  9. Phony E-tailers: Phony e-commerce sites, that appear real, try to lure you into typing in your credit card number and other personal details, often by promoting great deals. But, after obtaining your money and information, you never receive the merchandise, and your personal information is put at risk.
  10. Fake charities: This is one of the biggest scams of every holiday season. As we open up our hearts and wallets, the bad guys hope to get in on the giving by sending spam emails advertising fake charities.
  11. Dangerous e-cards: E-Cards are a popular way to send a quick “thank you” or holiday greeting, but some are malicious and may contain spyware or viruses that download onto your computer once you click on the link to view the greeting.
  12. Phony classifieds: Online classified sites may be a great place to look for holiday gifts and part-time jobs, but beware of phony offers that ask for too much personal information or ask you to wire funds via Western Union, since these are most likely scams.
Want more information?  Check out the results of the 2012 Holiday Shopping Study.

Friday, November 2, 2012

25 Most Popular Passwords of 2012


You need a password to access just about anything on a computer today: your bank account, your email, your resources here at KUMC.  So it's important that we choose long and strong passwords to protect our information.  If we don't, the odds that someone can guess our password and get access increase exponentially.

SplashData has just released the results of their annual study on the 25 Most Popular Passwords and, while there are several familiar passwords on the list from last year - "password", "123456", and "12345678" - there are some surprising new additions as well.  Take a look and, hopefully, you don't see your password on the list  (And, if you do, it's time to change it to something more complex!)

Here's the full list, along with how the popularity of the phrase has increased or decreased in the past year:

1. password (Unchanged)
2, 123456 (Unchanged)
3. 12345678 (Unchanged)
4. abc123 (Up 1)
5. qwerty (Down 1)
6. monkey (Unchanged)
7. letmein (Up 1)
8. dragon (Up 2)
9. 111111 (Up 3)
10. baseball (Up 1)
11. iloveyou (Up 2)
12. trustno1 (Down 3)
13. 1234567 (Down 6)
14. sunshine (Up 1)
15. master (Down 1)
16. 123123 (Up 4)
17. welcome (New)
18. shadow (Up 1)
19. ashley (Down 3)
20. football (Up 5)
21. jesus (New)
22. michael (Up 2)
23. ninja     (New)
24. mustang (New)
25. password1 (New)

Thursday, November 1, 2012

Important iPhone/iPad IOS 6.0.1 Update

Apple released a software update today for iPhone/iPads running IOS version 6. This is a recommended and critical update for anyone planning on using ActiveSync for Calendar scheduling when KUMC migrates to the new Exchange email system on November 9th.  This update addresses a known issue in the initial release that caused calendar entries to disappear.

The IOS 6.0.1 update is available on iTunes as well as wirelessly.

For more details on IOS 6.0.1, see Apple’s Knowledge Base at http://support.apple.com/kb/DL1606

Tuesday, September 4, 2012

Check Your PC For A MAJOR Java 1.7 Vulnerability

A new zero-day vulnerability in Java has been discovered and exploits are being found in the wild.  The flaw affects all versions of Oracle's Java 7 (version 1.7) on all supported platforms. No patch is available at this time.  Java 6 and earlier are currently unaffected.

In order for this vulnerability to be exploited, you have to visit a web page or follow a link to an infected site.  If you get hit with this, the software can do anything with your computer that you can.  Rapid7, a security research company, has released an online tool to test if your machine is exploitable through Java.  To test your machine with this tool, go to  http://www.isjavaexploitable.com/.

A copy of this message will be posted to TechWeb (www.bu.edu/tech) for reference.  Check there for further updates and information regarding this issue.

Recommendations:

·      If you are not using any programs that require Java, remove it from your system altogether.  Java is one of the most heavily exploited platforms in the world today due to its almost ubiquitous presence.
·      If you have to have Java for a specific program, but don’t need it for the web pages you visit, disable Java for universal use on your browsers. (Links for how to do this are below.)  It is safest to allow use of Java browser plug-ins on a case-by-case basis when prompted for permission by trusted programs.
·      If you can't do that, at least confine your browsing to regular commercial sites which, while not immune from being infected, are typically more carefully maintained and monitored and represent a lower risk.  This is not a reliable security approach, but it is better than nothing.

How to disable Java:

                (For Firefox on Mac OS X, it is like Windows XP (Tools > Add-ons))
...in Chrome:  While in Chrome, enter this URL:  chrome://plugins/  then click "Disable" under Java.


For more information: