Showing posts with label cyber safety. Show all posts
Showing posts with label cyber safety. Show all posts

Monday, November 29, 2021

New Cyber Security Requirements

As you surely have seen in the news or in your personal life recently, cyber attacks continue to develop and increase in frequency and complexity.  Many organizations - including major technology and social media companies - are taking additional steps to ensure that the accounts of their employees and customers remain well-protected.  Manhattan College has not been immune to these attacks and associated risks and we are now being required to implement stricter controls for our community members who access institutional data.  Given this new reality, two specific requirements that we must meet are as follows:

  • All Employees must complete a yearly Cyber Security training program (More information will be coming about this shortly. This must be completed by January 21, 2022)

  • All Employees must enroll their JasperNet account in Multi-Factor Authentication (MFA or 2SV) (Must be completed by January 18th, 2022 or you will be auto-enrolled)


Cyber Security Training

ITS is actively working with our insurance provider to develop a yearly Cyber Security training program that must be completed on a yearly basis starting in January 2022.  More information about the cyber security training program will be made available in the new year and must be completed by December 31st each year.  Content for the initial training program will be delivered by our insurance provider, however, we will assess the program throughout the year and provide the opportunity for campus experts to participate in determining and developing the curriculum for following years in alignment with the same requirements of the insurance provider.  ALL employees (including Faculty, Graduate Assistants, and Student Employees) will be required to complete this course yearly.


Multi-Factor Authentication

Multi-Factor Authentication (MFA) - sometimes referred to as Two-Step Verification (2SV) - will be required for all employees going forward and must be implemented no later than January 2022.  While Manhattan College has previously taken a very targeted and calculated approach to require MFA based on a “risk score” (i.e. users that access Banner or other escalated access), we must now require MFA for ALL employees (including Faculty, Graduate Assistants, and Student Employees).  To date, over 670 community members have already enrolled in MFA.  ITS will be contacting community members that still need to enroll in MFA in the coming days to provide instructions and support for enabling MFA by 1/18/2022.


MFA Support Sessions


ITS will be offering support sessions with members from the Technology Training team for those who will need to enable DUO Multi-Factor Authentication on their JasperNet accounts. Below please find more information about the drop-in training sessions. There is no signup required.

When:

  • January: 12th, 18th, and 19th (all Wednesday’s) from 11:00am-2:00pm


Where: MGL 305 (Computer Lab)

Please remember to bring your cell phone to complete the setup.

If you are unable to attend or have any questions please contact its@mahattan.edu and someone from the Training Team will reach out to schedule a separate time and answer any questions you may have.


Tuesday, February 23, 2021

What is Ransomware & How Can You Protect Yourself From It?

Ransomware is a class of malware that prevents you from accessing your systems or data and demands a sum of money to be paid in return for the decryption key. This has resulted in billions of dollars in losses with over 2 million incidents reported in 2019. These kinds of cyberattacks are getting more complex and are holding organizations hostage until they pay millions in ransom. Ransomware attacks have a new target every 14 seconds and have the ability to shutdown digital operations, steal information, and exploit businesses, essential services, and individuals. 


Below are precautions to protect you against the threat of ransomware:
  • Update software and operating systems. Outdated applications and operating systems are the target of most attacks.

  • Never click on links or open attachments in unsolicited emails.

  • Backup data on a regular basis. Keep it on a separate device and store it offline.

  • Restrict permissions to install and run software applications.

  • Enable strong spam filters to prevent phishing emails from reaching you and authenticate inbound email to prevent email spoofing.

  • Scan all incoming and outgoing emails to detect threats.

  • Configure firewalls to block access to known malicious IP addresses.

For more information on Ransomware and how to defend against it please check out these articles: 

Friday, October 23, 2020

5 Steps to Protecting Your Digital Home

Now that devices like digital door locks, refrigerators and smart assistants have become prevalent in American homes, hackers have a new way to target devices to hack. 

The National Cybersecurity Alliance has written the above poster to shed light on ways to combat this. Extra measures like those listed below are good ways to put an extra blocker on the two primary places of hacker access into our lives.

  • Secure Wi-Fi 

  • Dual-Authentication Logins (Like Duo!)

  • Constantly checking for software updates from our hardware and software makers is also crucial since the updates are usually made in direct response to potential vulnerabilities. 

  • Limiting the information being posted on social media regarding your location will impede a hacker’s ability to pinpoint your home to begin hacking

Fore more information and tips on protecting your devices and yourself please check out this digital poster. 

Special thanks to Lisa Juncaj for passing this poster along! 

Sunday, November 10, 2019

How Can Higher Ed Better Prepare Cybersecurity Students for a Hot Job Market?

The 2018 (ISC)2 Cybersecurity Workforce Study estimates a global shortage of cybersecurity professionals of around three million workers. This shortage of skilled job seekers is having a real-world impact on companies and the people responsible for cybersecurity at those companies. The study also points out that Gen X and Baby Boomer workers make up about half of the current cybersecurity workforce, leaving many entry-level opportunities for new college graduates and pathways for growth as these more experienced workers approach retirement age.

The need for trained cybersecurity professionals is not going to go away. The US Bureau of Labor Statistics projects a 28% growth in US employment for cybersecurity consultants between 2016 and 2026. How can we help our students go beyond the theoretical concepts taught in computer science or cybersecurity classes and make themselves more attractive to future employers? We need to take the lead to encourage students to take the initiative to learn more about current issues in cybersecurity and take advantage of the many cybersecurity resources available.
Here are some ways you can help your students and contribute to narrowing the cybersecurity skills gap:
  • Hold informational sessions on cybersecurity. Help spread the word on your campus about the cybersecurity skills gap and job opportunities. You could ask your CISO or information security team to conduct a cybersecurity seminar or invite local experts to share their knowledge and expertise with your students. The Enterprise Security Team at The Ohio State University has already implemented this idea, and they sponsor an annual and free on-campus Cybersecurity Days to expand knowledge of security and data protection for their entire college community.
  • Sponsor or encourage membership in student associations. There are two student cybersecurity organizations for your students to explore—NationalCybersecurity Student Association and Women in CyberSecurity (WiCyS. The National Cybersecurity Student Association has a number of resources on their website, and you can sign up for their newsletter or follow their Snapchat account to view a day in the life of a cyber student or industry professional. The WiCyS is dedicated to bringing together women in cybersecurity from academia, research, and industry to share knowledge, experience, networking, and mentoring. You can also explore setting up a local WiCyS student chapter on your campus.
  • Offer campus internships. In addition to knowledge of advanced cybersecurity concepts, the most important qualification for cybersecurity employment is relevant work experience. You can help your students by hiring them as interns in your institution's information security department. This offers students real-world experience while providing supplemental staffing for your department. For suggested qualifications and responsibilities, use the Information Security Intern Job Description Template on the EDUCAUSE website as a starting point.
  • Identify scholarship opportunities. The CyberCorps: Scholarship for Services, funded by the NSF, provides up to $22,500 per year for undergraduates and $34,000 per year for graduate students. In return, students commit to work in a for a federal, state, or local agency for a period matching the length of their scholarship. The Cyber Security Degree website provides a comprehensive list of additional cybersecurity scholarships and other career resources.
  • Encourage students to deepen their knowledge. The NICCS Education Training Catalog is a central location where cybersecurity professionals across the nation can find more than 3,000 cybersecurity-related courses. Anyone can use the interactive map and filters to search for courses offered in their local area to add to their skill set, increase their level of expertise, or earn a certification. You could also direct your students to take advantage of the free online courses offered through edXUS Department of Homeland Security, Cybrar, or SANS Cyber Aces Online.
  • Attend cyber competitions. Institutions with an information assurance or computer security curriculum can give their students an additional way to hone their skills and have fun by participating in regional events hosted by the National Collegiate Cyber Defense Competition(NCCDC). The top regional teams can then go on to the National Championship, which was won by University of Virginia in 2018. Another cybersecurity competition for high school and college students is the National Cyber League (NCL), is a defensive and offensive puzzle-based, capture-the-flag style competition. All participants play the games simultaneously and are tested with real cybersecurity challenges they will likely face in the workforce.
  • Participate in cybersecurity conferences. Students may be interested the educational and networking opportunities from attending the annual conferences for the National Cybersecurity Student Association or Women in CyberSecurity. For additional conferences in your area, InfoSec publishes a comprehensive list with hundreds of cybersecurity events in the United States, Europe, and Asia.

Sunday, October 27, 2019

Top Tips to Securely Using Social Media


Manhattan College IT Services is sharing cyber safety tips in support of raising awareness during National Cyber Security Awareness Month, October 2019.

Overview 

Social media sites, such as Snapchat, Facebook, Twitter, Instagram, and LinkedIn, are amazing resources, allowing you to meet, interact, and share with people around the world. However, with all this power comes risks--not just for you, but your family, friends, and employer. In this post, we cover the key steps to making the most of social media securely and safely. 

Posting 

Be careful and think before posting. Anything you post will most likely become public at some point, impacting your reputation and future, including where you can go to school or the jobs you can get. If you don’t want your family or boss to see it, you probably shouldn’t post it. Also, be aware of what others are posting about you. You may have to ask others to remove what they share about you. 

Privacy 

Almost all social media sites have strong privacy options. Enable them when possible. For example, does the site really need to be able to track your location? In addition, privacy options can be confusing and change often. Make it a habit to check and confirm they are working as you expect them to. 

Passphrase 

Secure your social media account with a long, unique passphrase. A passphrase is a password made up of multiple words, making it easy for you to type and remember, but hard for cyber attackers to guess. 

Lock Down Your Account 

Even better, enable two-factor authentication on all of your accounts. This adds a one-time code with your password when you need to log in to your account. This is actually very simple and is one of the most powerful ways to secure your account. 

Scams 

Just like in email, bad guys will attempt to trick or fool you using social media messages. For example, they may try to trick you out of your password or credit card. Be careful what you click on: If a friend sends you what appears to be an odd message or one that does not sound like them, it could be a cyber attacker pretending to be your friend. 

Terms of Services

Know the site’s terms of service. Anything you post or upload might become the property of the site.

Work

If you want to post anything about work, check with your supervisor first to make sure it is okay to publicly share.
Follow these tips to enjoy a much safer online experience. To learn more on how to use social media sites safely, or report unauthorized activity, check your social media site’s security page.


Be Secure Online! Refer to Manhattan College's Cyber Safety site for additional resources.

Refer to Manhattan College's Email Signature Knowledge Base 
Article for instructions on how to create your own email signature. 
Using a Manhattan College email signature is important because it is the perfect opportunity to brand every message you send. By creating a cohesive email signature for each employee on your team, you create brand recognition in every person to whom your employees sends emails. 

Reach out to IT Services with any questions:



Partially reposted from www.sans.org/security-awareness


Sunday, October 13, 2019

Step Up to Stronger Passwords

Weak and reused passwords continue to be a common entry point for account or identity takeover and network intrusions. Simple steps and tools exist to help your end users achieve unique, strong passwords for their dozens of accounts. Help your community members improve their individual and collective security by sharing the following tips.

A password is often all that stands between you and sensitive data. It’s also often all that stands between a cybercriminal and your account. Below are tips to help you create stronger passwords, manage them more easily, and take one further step to protect against account theft.
  • Always: Use a unique password for each account so one compromised password does not put all of your accounts at risk of takeover.
  • Good: A good password is 10 or more characters in length, with a combination of uppercase and lowercase letters, plus numbers and/or symbols — such as pAMPh$3let. Complex passwords can be challenging to remember for even one site, let alone using multiple passwords for multiple sites; strong passwords are also difficult to type on a smartphone keyboard (for an easy password management option, see “best” below).
  • Better: A passphrase uses a combination of words to achieve a length of 20 or more characters. That additional length makes its exponentially harder for hackers to crack, yet a passphrase is easier for you to remember and more natural to type. To create a passphrase, generate four or more random words from a dictionary, mix in uppercase letters, and add a number or symbol to make it even stronger — such as rubbishconsiderGREENSwim$3. You’ll still find it challenging to remember multiple passphrases, though, so read on.
  • Best: The strongest passwords are created by password managers — software that generates and keeps track of complex and unique passwords for all of your accounts. All you need to remember is one complex password or passphrase to access your password manager. With a password manager, you can look up passwords when you need them, copy and paste from the vault, or use functionality within the software to log you in automatically. Best practice is to add two-step verification to your password manager account. Keep reading!
  • Step it up! When you use two-step verification** (a.k.a., two-factor authentication or login approval), a stolen password doesn’t result in a stolen account. Anytime your account is logged into from a new device, you receive an authorization check on your smartphone or other registered device. Without that second piece, a password thief can’t get into your account. It’s the single best way to protect your account from cybercriminals.
**Please note: this option is not available for Manhattan College accounts but should be considered for external (personal) accounts.




    How to pick a proper password.

    Partially reposted from http://er.educause.edu/blogs/2016/11/may-2017-step-up-to-stronger-passwords

    Sunday, October 6, 2019

    Stop That Phish

    Overview




    phishing computer screen

    Email and messaging services (such as Skype, Twitter, or Snapchat) are one of the primary ways we communicate. We not only use these technologies every day for work, but also to stay in touch with friends and family. Since so many people around the world depend on these technologies, they have become one of the primary attack methods used by cyber attackers. This attack method is called phishing. Learn what phishing is and how you can spot and stop these attacks, regardless if you are at work or at home.

    What Is Phishing

    Phishing is a type of attack that uses email or a messaging service to fool you into taking an action you should not take, such as clicking on a malicious link, sharing your password, or opening an infected email attachment. Attackers work hard to make these messages convincing and tap your emotional triggers, such as urgency or curiosity. They can make them look like they came from someone or something you know, such as a friend or a trusted company you frequently use. They could even add logos of your bank or forge the email address so the message appears more legitimate. Attackers then send these messages to millions of people. They do not know who will take the bait, all they know is the more they send, the more people will fall victim.

    Protecting Yourself

    In almost all cases, opening and reading an email or message is fine. For a phishing attack to work, the bad guys need to trick you into doing something. Fortunately, there are clues that a message is an attack. Here are the most common ones:
    • A tremendous sense of urgency that demands “immediate action” before something bad happens, like threatening to close an account or send you to jail. The attacker wants to rush you into making a mistake.
       
    • Pressuring you to bypass or ignore your policies or procedures at work.
       
    • A strong sense of curiosity or something that is too good to be true. (No, you did not win the lottery.)
       
    • A generic salutation like “Dear Customer.” Most companies or friends contacting you know your name.
       
    • Requesting highly sensitive information, such as your credit card number, password, or any other information that a legitimate sender should already know.
       
    • The message says it comes from an official organization, but has poor grammar or spelling or uses a personal email address like @gmail.com.
       
    • The message comes from an official email (such as your boss) but has a Reply-To address going to someone’s personal email account.
       
    • You receive a message from someone you know, but the tone or wording just does not sound like him or her. If you are suspicious, call the sender to verify they sent it. It is easy for a cyber attacker to create a message that appears to be from a friend or coworker.
    Ultimately, common sense is your best defense. If an email or message seems odd, suspicious, or too good to be true, it may be a phishing attack. 
    Be Secure Online! Refer to Manhattan College's Cyber Safety site for additional resources.

    Refer to Manhattan College's Email Signature Knowledge Base 
    Article for instructions on how to create your own email signature.

    Using a Manhattan College email signature is important because it is the perfect opportunity to brand every message you send. By creating a cohesive email signature for each employee on your team, you create brand recognition in every person to whom your employees sends emails. 

    Reach out to IT Services with any questions:


    Wednesday, September 11, 2019

    Information Security To Go!

    Protect your data and devices when you travel.

    Almost 88 million Americans traveled abroad in 2017, and whether for business or personal use, our technology devices seem indispensable during our travels. Unfortunately, traveling with devices also means that you must take care to protect those devices—and the data contained on them—while you are away from home. That preparation begins before you leave, and you may need to restore settings when you return.
    Many people love the adventure that traveling provides: meeting new people, seeing new places, and having new experiences are part of the allure. Technology makes it easier than ever to satisfy our wanderlust. We can use our connected devices to discover the exotic locales we wish to visit, book tickets on planes and trains, practice driving virtually, and seamlessly navigate once we get to our final destination. For all this ease that technology brings, we should prepare our technology for travel as carefully as we plan our travel itineraries.

    Travel tips
    • Back-up your data! Backing up your data ensures that you won't lose information if your device is lost or stolen. Consider encrypting your data as well, but check with your IT support staff first about how best to implement encryption.
    • Protect your devices with a strong password or lengthy passcode. Sometimes devices get lost or stolen, even when we are being careful. By protecting your device with a passcode or lengthy password, you make it harder for your device to be used and data to be accessed by others.
    • Make sure your devices and applications are up to date. Keep your applications and devices up to date and patched. This helps protect your device and data from security vulnerabilities and threats.
    • Just say no to unsecured public Wi-Fi. Having a wireless connection is almost a necessity for the modern traveler. However, using an unsecured public Wi-Fi hotspot can allow others to view the contents of your electronic activity. Never access your sensitive financial accounts from an unsecured network. If you must access sensitive data from an unsecured network, be sure that you use a VPN service.
    • Double check your MFA settings. Many of us rely on multifactor authentication (MFA) to secure both personal and work-related accounts. Be sure that you know how (or if) that will work in the countries that you are visiting. For instance, if your MFA relies on SMS, be sure that you will be able to receive that message in the destination that you are visiting. If the option is available to you, consider using a physical token option to ensure you'll be able to login to your accounts.
    • Update your physical location with your password vault. Many people use password vaults to manage all of their account passwords. Don't be surprised if your password vault requires additional verification steps when logging into it from a location that is not in your home country. (After all, we count on these vaults to be secure!) Check the vendor documentation or your account settings to make sure that there are no country restrictions or settings that you need to change before your trip. Also double-check that you're able to access your recovery/secondary email address just in case there is an issue.
    • Consider leaving your daily devices at home. If you are traveling to a location where you are concerned about your individual privacy rights, consider leaving your primary mobile device at home and purchasing a replacement device to take with you instead. Put only the apps, services, and data that you need for that trip on the device. Some businesses and colleges and universities offer programs where a traveler can check out a "clean laptop" when traveling for business purposes. Using these types of devices help limit any exposure of your personal data. Check your data plan as well. A "burner phone" or car GPS may be cheaper.
    • Be smart about posting on social media. It is always fun to post vacation pictures in the moment, but online postings on social networks (e.g., Twitter, Facebook, Instagram, Snapchat, etc.) can let other people know that you are not at home and that your home may be empty. Posting vacation pictures on social media once you are safely home helps protect your physical belongings.
    • Use hotel safes to protect your technology. Here's another place where there is an overlap between online safety and physical safety. Just like you would put your passport, jewelry, and money in a hotel safe, consider using that safe to hold your electronic devices when you are not carrying them with you. Not only are the devices themselves expensive to replace, your personal data contained in the device can be irreplaceable (especially if you skipped the first tip on this list).
    • Remember your adapters! Make sure you have power adapters that will work with three-prong plugs and that they fit the country's outlets. Some travel adapters only accept two-prong plugs. (If you're attending a conference, you may be able to borrow a charging cable temporarily.) Outlets also vary, even, for example, between the UK and Ireland. Your technology gadgets are not very helpful when they run out of charge or cannot be powered on. Charge and take a portable battery pack.
    • Mind your voltage! Like plug types, different parts of the world use different voltages. Make sure that your technology devices can run on the voltage used at your destination. Getting shocked with 220V is not the same as 110V.
    As surely as you can reduce wrinkles in your clothing with careful packing, so too can you avoid the most common technology travel woes by preparing before you leave home.
    Refer to Manhattan College's Cyber Safety Site site for additional resources.
    Refer to Manhattan College's Email Signature Knowledge Base Article for instructions on how to create your own email signature.

    From The Barefoot Nomad's How Not to Fry Your Smartphone Overseas: A Quick Guide
    Partially reposted from Educause September 2019: Information Security To Go!


















































































    Tuesday, August 20, 2019

    Understanding the Basics of Online Safety and Security

    Americans use 3,138,420 GB of internet data every minute of the day. It is safe to say that being online is now a way of life for many. Engaging in safe and secure online practices helps protect against the risks of living life on the internet.
    Shopping, surfing, banking, gaming, and connecting Internet of Things devices such as toasters and refrigerators are some of the many actions performed each minute in cyberspace. These common everyday activities carry the cyber threats of social engineering to gain unauthorized access to data, identity theft, bullying, location tracking, and phishing, to name just a few. How can we decrease our risk from these cyber threats without abandoning our online activities altogether? Here are some basic online tips everyone can follow to help stay secure while online.


    • Set up alerts. Consider setting up alerts on your financial accounts. Many credit card companies and banks allow you to set up alerts on your accounts via their websites. These alerts range from sending you an email or text each time a transaction happens on your account to alerts when transactions meet or exceed a designated spending limit that you set. These alerts keep you in control of your accounts' activities. These types of alerts are useful because they make you aware of what's going on with your account quicker than waiting for monthly statements. When you receive an alert about a transaction that you did not authorize, you can reach out to the credit card company or bank immediately. Log into your credit card company and banking websites to set up alerts on your accounts.
    • Keep devices and apps up to date. This familiar tip is useful even if you are just casually surfing the internet. Keeping your devices up to date (including apps and operating systems) ensures you have the latest security fixes.
    • Don't use public Wi-Fi. In addition to an updated device, the network the device is connected to is also important. Did you have to enter a password to connect to a Wi-Fi network? If you did, that network is more secure than an open one that any device within range can connect to. Whenever possible, use a secure network, especially when banking or shopping online.
    • Consider using a VPN. VPN stands for virtual private network, and its main purpose is to provide a tunnel for encrypted internet traffic. If you are connected to the internet without using a VPN, your traffic is passed through the internet service provider's servers. The location of your device is known, and if you must connect to a public Wi-Fi network, there is a risk of snooping by other devices on the same network. Connecting to a VPN redirects your internet traffic to a remote server, encrypting the traffic, reducing the snooping risk. There are many options for VPN software today for consumers and businesses. Do your research and decide which one makes sense for your online needs.
    • Create unique passwords. Here's another familiar tip. Using the same password for many sites is not a best practice. Suppose that one of your accounts suffered a data breach and your password was exposed. If you reused this password on other accounts, it's likely that someone would be able to access those accounts as well (especially if your user name is an email address). Consider using a password manager to manage all your passwords. Not only do these tools manage all your passwords, they can also create strong passwords and can even autofill your username and password as you go to websites on different browsers.
    • Be vigilant. Be aware, there are fake websites out there waiting to collect your valuable information. Make sure you are on a legitimate site by double-checking the URL website address to make sure it is spelled correctly. Also make sure you see a padlock and https:// in the URL.
    Remember that you are in control of your online activities. Following these security tips will give you peace of mind while online.

    Be Secure Online! Refer to Manhattan College's Cyber Safety site for additional resources.

    Refer to Manhattan College's Email Signature Knowledge Base Article for instructions on how to create your own email signature.

    Monday, July 22, 2019

    Keeping Tabs on Mobile Devices



    photo of mobile device sitting on stone wall
    As we roll out campaigns and educate our community on cybersecurity, we need to help make sure everyone understands and keeps in mind physical security risks. Because of the portability of devices, users have laptops, smartphones, and tablets with them when they are on the go, whether it is a trip to the coffee shop or a trip across the country. Make sure to secure your mobile devices to protect the device and the data it contains. Here are resources to help remind our community not to skip out on physical security!
    With an increasing amount of sensitive data being stored on personal devices, the value and mobility of smartphones, tablets, and laptops make them appealing and easy targets. These simple tips will help you be prepared in case your mobile device is stolen or misplaced.
    • Secure those devices and backup data! Make sure that you can remotely lock or wipe each mobile device. That also means backing up data on each device in case you need to use the remote wipe function. Backups are advantageous on multiple levels. Not only will you be able to restore the information, but you'll be able to identify and report exactly what information is at risk. (See Good Security Habits for more information).
    • Never leave your devices unattended in a public place or office. If you must leave your device in your car, place it in the truck, out of sight, before you get to your destination, and be aware that the summer heat of a parked car could damage your device.
    • Password-protect your devices. Give yourself more time to protect your data and remotely wipe your device if it is lost or stolen by enabling passwords, PINs, fingerprint scans, or other forms of authentication. (See Choosing and Protecting Passwords.) Do not choose options that allow your computer to remember your passwords.
    • Put that shredder to work! Make sure to shred documents with any personal, medical, financial, or other sensitive data before throwing them away.
    • Be smart about recycling or disposing of old computers and mobile devices. Properly destroy your computer's hard drive. Use the factory reset option on your mobile devices and erase or remove SIM and SD cards.
    • Verify app permissions. Don't forget to review an app’s specifications and privacy permissions before installing it!
    • Be cautious of public Wi-Fi hot spots. Avoid financial or other sensitive transactions while connected to public Wi-Fi hot spots.
    • Keep software up to date. If the vendor releases updates for the software operating your device, install them as soon as possible. Installing them will prevent attackers from being able to take advantage of known problems or vulnerabilities. 
    Keeping Tabs on Mobile Devices
    Partially reposted from Educause July 2019 Keeping Tabs on Mobile Devices

    Thursday, May 30, 2019

    Phishing Emails Pretend to be Office 365 'File Deletion' Alerts

    A new phishing campaign is underway that pretends to be from the "Office 365 Team" warning recipients that there has been unusual amount of file deletions occurring on their account.
    The phishing scam, pretends to be a warning from the Office 365 service that states a medium-severity alert has been triggered. It then goes on to say that there has been high amount of files deletions occurring in their Office 365 account and that they should review the alerts.
    For more details please review this Phishing Emails Pretend to be Office 365 'File Deletion' Alerts  blog post.


    Friday, May 24, 2019

    Scam Emails from "manhattan.edu@gmail.com" Accounts Today

    We have received several reports of scam emails being sent to the campus community today from accounts ending in "manhattan.edu@gmail.com".  These are scams and should be disregarded.  Luckily, in all the reported incidents, community members quickly recognized it as a scam.  We appreciate these being reported and the vigilance that the community has shown today.

    Example of how these emails look: john.doemanhattan.edu@gmail.com

    Please continue to report suspicious emails at its@manhattan.edu

    Don't click the link or any attachments.


    Wednesday, May 8, 2019

    Cryptocurrencies - Look Before You Leap!

    image of a gold bitcoin


    Cryptocurrency comes under many names. You have probably read about some of the most popular types of cryptocurrencies such as Bitcoin, Litecoin, and Ethereum. Cryptocurrencies are increasingly popular alternatives for online payments. Before converting real dollars, euros, pounds, or other traditional currencies into ₿ (the symbol for Bitcoin, the most popular cryptocurrency), you should understand what cryptocurrencies are, what the risks are in using cryptocurrencies, and how to protect your investment.
    What is cryptocurrency? A cryptocurrency is a digital currency, which is an alternative form of payment created using encryption algorithms. The use of encryption technologies means that cryptocurrencies function both as a currency and as a virtual accounting system. To use cryptocurrencies, you need a cryptocurrency wallet. These wallets can be software that is a cloud-based service or is stored on your computer or on your mobile device. The wallets are the tool through which you store your encryption keys that confirm your identity and link to your cryptocurrency.
    What are the risks to using cryptocurrency? Cryptocurrencies are still relatively new, and the market for these digital currencies is very volatile. Since cryptocurrencies don't need banks or any other third party to regulate them; they tend to be uninsured and are hard to convert into a form of tangible currency (such as US dollars or euros.) In addition, since cryptocurrencies are technology-based intangible assets, they can be hacked like any other intangible technology asset. Finally, since you store your cryptocurrencies in a digital wallet, if you lose your wallet (or access to it or to wallet backups), you have lost your entire cryptocurrency investment.
    Follow these tips to protect your cryptocurrencies:
    • Look before you leap! Before investing in a cryptocurrency, be sure you understand how it works, where it can be used, and how to exchange it. Read the webpages for the currency itself (such as Ethereum, Litecoin, Bitcoin) so that you fully understand how it works, and read independent articles on the cryptocurrencies you are considering as well.
    • Use a trustworthy wallet. It is going to take some research on your part to choose the right wallet for your needs. If you choose to manage your cryptocurrency wallet with a local application on your computer or mobile device, then you will need to protect this wallet at a level consistent with your investment. Just like you wouldn't carry a million dollars around in a paper bag, don't choose an unknown or lesser-known wallet to protect your cryptocurrency. You want to make sure that you use a trustworthy wallet.
    • Have a backup strategy. Think about what happens if your computer or mobile device (or wherever you store your wallet) is lost or stolen or if you don't otherwise have access to it. Without a backup strategy, you will have no way of getting your cryptocurrency back, and you could lose your investment.
    What is Cryptocurrency?



      This Quadrangle article: Group of Students Create ‘MunchCoin,’ A Cryptocurrency For Local Eateries describes how several of our Manhattan College engineering and business students independently started their own cryptocurrency company in our neighborhood restaurants.  Note that among the students who created this cryptocurrency are several IT student workers and 1 full time ITS employee. 
      The story is impressive for several reasons, the students were able to : 

      • Put their engineering and data analysis skills into practice.  
      • Successfully navigate the cryptocurrency emerging technology. 



      Partially reposted from:  Educause's Campus Security Awareness Campaign  Cryptocurrencies - Look Before You Leap!

      Tuesday, April 9, 2019

      Whaling, SMiShing, and Vishing…Oh My!


      credit card with fish hook speared through it


      Cybercriminals use types of social engineering—manipulating people into doing what they want—as the most common way to steal information and money. Social engineering is at the heart of all types of phishing attacks—those conducted via email, SMS, and phone calls. Technology makes these sorts of attacks easy and very low risk for the attacker. Make sure you're on the lookout for these variants on the traditional, mass emailed phishing attack.
      • Spear phishing: This kind of attack involves often very well-crafted messages that come from what looks like a trusted VIP source, often in a hurry, targeting those who can conduct financial transactions on behalf of your organization (sometimes called "whaling").
      • SMiShing: Literally, phishing attacks via SMS, these scams attempt to trick users into supplying content or clicking on links in SMS messages on their mobile devices. Flaws in how caller ID and phone number verification work make this an increasingly popular attack that is hard to stop.
      • Vishing: Voice phishing, these are calls from attackers claiming to be government agencies such as the IRS, software vendors like Microsoft, or services offering to help with benefits or credit card rates. Attackers will often appear to be calling from a local number close to yours. As with SMiShing, flaws in how caller ID and phone number verification work make this a dangerous attack vector.
      No matter the medium, follow these techniques to help prevent getting tricked by these social engineering attacks:
      • Don't react to scare tactics: All of these attacks depend on scaring the recipient, such as with a lawsuit, that their computer is full of viruses, or that they might miss out on a chance at a great interest rate. Don't fall for it!
      • Verify contacts independently: Financial transactions should always follow a defined set of procedures, which includes a way to verify legitimacy outside email or an inbound phone call. Legitimate companies and service providers will give you a real business address and a way for you to contact them back, which you can independently verify on a company website, support line, etc. Don't trust people who contact you out of the blue claiming to represent your company.
      • Know the signs: Does the message/phone call start with a vague information, a generic company name like "card services," an urgent request, and/or an offer that seems impossibly good? Hang up or click that delete button!
      For further information on how a phishing attack affected this undergraduate students view this video:




      Information Security Awareness Training Video: "Phishing: E-Safe"


      View this video for strategies on how to address illegal robocalls:

      FCC Chairman provides some tips to help consumers confront illegal robocalls and maliciously spoofed calls.

      Partially reposted from: Educause Campus Security Awareness Campaign 2019: April 2019: Whaling, SMiShing, and Vishing…Oh My!