Article Archive #2
Service navigation

Importance of Security
Information security is about addressing and reducing IT RISK. It’s easy to overlook risk as a topic when all you hear is talk about passwords, firewalls, encryption, policies, or two-factor authentication. In this section, you’ll read about how the university is at risk and what you can do to reduce the risk in your group, department, and college.
-
Think Before You Share: What the Claude Search Exposure Teaches Us About AI Privacy
Recent reporting found that some Claude chats and Artifacts shared by public links appeared in Google search results. Reported examples included internal documents, health-related information, contact details, and API keys. This does not appear to mean that all private Claude chats were exposed, but it is an important reminder that a shared AI link may be far more…
-
Two-Factor Authentication (2FA) Prompt Bombing
Two-factor authentication (also known as, “Multi-factor Authentication (MFA)”) provides an extra layer of security for your accounts, but it’s important to think before you click. Cybercriminals can use an attack method called 2FA prompt bombing to bypass 2FA protections and overwhelm you with prompts via the Push feature of Duo. For example, cybercriminals may try to log…
-
When ‘Too Good to Be True’ Comes from Someone You Know
For years, cybercriminals have used social media to post fake sales listings for popular items such as furniture or electronics. As these scams have gained in popularity, most of us have learned to use caution when buying items online from strangers. Now, cybercriminals are impersonating people you trust to lure you into their fake listing…

Scam Types
Scams used to be easier to detect without worry. A Nigerian prince asks for a few hundred dollars to give you access to his fortune. But those days are gone, and scammers are in a constant arms race with cybersecurity for your sensitive information. Learn about the different types of scams and how to deal with them.
-
Watch Out for High Profile Scams
The US-based Silicon Valley Bank (SVB) recently shut down due to failure to meet its financial obligations. This collapse has caused public panic, and unfortunately, like all major news events, cybercriminals take advantage of high-profile news stories to catch your attention and manipulate your emotions. Cybercriminals will use every tool in their arsenal to prey on…
-
Keep IT Private and Separate
“YOU” exist in digital form all over the Internet. It is thus important to ensure that the “digital YOU” matches what you intend to share. It is also critical to guard your privacy — not only to avoid embarrassment but also to protect your identity and finances! The following are specific steps you can take…
-
IT or Cybercriminal?
Coinbase, a cryptocurrency platform, is the latest victim of a social engineering attack. Social engineering occurs when cybercriminals manipulate you to try to steal your sensitive information. In this Coinbase attack, a cybercriminal sent smishing (SMS phishing) messages to their employees containing a link directing them to log in to their company accounts. Shortly after…
-
There was PHISHING. Then, there was SMISHING!
A single sign-on (SSO) service allows you to log in to multiple accounts using one login credential, such as your NETID and the Central Authentication Service (CAS). Unfortunately, you aren’t the only one who benefits from this service. Cybercriminals are taking advantage of SSO services in a recent smishing (SMS phishing) scam. A SMISHING scam…

Benefits & Tips for You
In this section, you can learn about all the different tools available to you at UT, such as secure file sharing and monitoring your systems. We will also share best practices for staying secure at school and at home.
-
The Need to Replace SMS-Based MFA
In December 2024, the FBI and CISA advised Americans against using SMS codes for multi-factor/two-factor (MFA/2FA) authentication. CISA’s Mobile Communications Best Practice Guidance bluntly recommended: “Do not use SMS as a second factor for authentication. SMS messages are not encrypted–a threat actor with access to a telecommunication provider’s network who intercepts these messages can read…
-
Safeguarding Your Remote Work
Remote work in higher education is now the norm. To keep your online work safe using university-provided tools like OneDrive and Microsoft Teams, follow these straightforward steps: Working remotely in higher education is convenient and secure when you use the university-provided tools while taking these precautionary steps.
-
Privacy Concerns with Onboard AI: Microsoft Copilot
Continuing with privacy concerns with onboard AI, Microsoft Copilot, which uses the hardware on any system with Windows 11 Copilot+ to run the native AI of Copilot, has been seen as a potential issue for user privacy. We’ve highlighted a few privacy concerns associated with Microsoft Copilot: You can opt out of data collection for…

Protecting University Data
Discover essential articles on cybersecurity practices specifically tailored for the University of Tennessee. Learn effective strategies to safeguard sensitive information, defend against threats, and maintain data integrity. Equip yourself with knowledge to protect your university’s digital ecosystem.
-
Tips for Securing Windows
Many people use Microsoft Windows as their primary operating system for work, school, personal computing, and even gaming. The most recent Windows Operating System is Windows 11, but there are still many people on Windows 10. Fortunately making your operating system more secure is very similar in both versions. Tips to help secure your Windows…
-
Secure File Transfer
Vault (UT Secure Courier) is a secure file transfer application that allows users to easily share large files, including executables, quickly and securely. Files are uploaded and downloaded via SSL-encrypted HTTP and stored in an encrypted data store. Using Vault is as easy as sending an email with an attachment, and it can be used…
-
Protecting University-Owned Devices from Infostealers
In recent months, a surge in infostealer malware has been making headlines, posing a significant threat to individuals and organizations alike. Infostealers are a type of malware designed to infiltrate systems and steal sensitive information such as passwords, cookies, and search histories. This stolen data can then be sold on the dark web or used…

Explore
Write
Chat
Call