December 23, 2022

LastPass data breach

Post updated on 1/13/2023 What happened? Is there anything I need to do? What data was accessed? Are my passwords now compromised? Who is at greatest risk? Does this mean LastPass shouldn’t be trusted? How can I manage this type of risk? What other risks should I consider? References What happened?  LastPass notified customers in…


October 31, 2022

OpenSSL: Critical Patch on Nov 1st

lock

Audience for this post: System administrators, IT staff, and staff members responsible for maintaining IT systems Latest update Summary Best Practices References We will continue to update this post with news and links to resources to help you prioritize your remediation efforts as more information becomes available. 11/01/2022 update: OpenSSL has published a blog post…


October 28, 2022

Students: Beware of debt relief scams

Hand stealing money through a computer

We posted about this a few weeks ago, but in this busy month, it’s worth repeating: The U.S. Department of Education and the Federal Trade Commission are working together to raise awareness about potential scams and misinformation that may be aimed at those seeking student loan debt relief. Beware of scammers who may contact you…


October 18, 2022

Message to the UW community

It’s the beginning of a new academic year and it’s Cybersecurity Awareness Month. So how can you be safer and more secure online? Get tips, tools, and resources from the annual message to the UW community. Go to message More News & Alerts


October 7, 2022

Students: Beware job & loan scams

Scams are nothing new, but we are seeing a surge in scams targeting UW students and costs for victims are rising. Our Scams web page covers some of the more commonly used tactics, but there are two kinds that we want to highlight in today’s post: Employment Scams Student Aid Scams Employment scams use elaborate…


July 1, 2022

PowerShell guidance from the NSA

The National Security Agency (NSA), along with authorities from New Zealand and the United Kingdom, have released a joint Cybersecurity Information Sheet (CIS) on security practices for using Microsoft PowerShell. The information sheet provides recommendations for proper configuration and monitoring with the use of capabilities and features such as PowerShell remoting and remoting over SSH,…