Skip to content Skip to main navigation Report an accessibility issue
Information Security

Article Archive #2


Service navigation


Security Learning Icon One

Importance of Security

Information security is about addressing and reducing IT RISK. It’s easy to overlook risk as a topic when all you hear is talk about passwords, firewalls, encryption, policies, or two-factor authentication. In this section, you’ll read about how the university is at risk and what you can do to reduce the risk in your group, department, and college.

  • Agentic AI Browsers and Associated Risks

    Unlike traditional browsers, which rely on user clicks and keystrokes, Agentic AI browsers integrate autonomous agents into the browsing experience. These tools interpret natural language commands and are capable of executing multi-step tasks across websites. Popular AI Browser examples include: These browsers aim to boost productivity by automating tasks like booking appointments, comparing products, or…

    Read article…

  • Don’t Delete That Suspicious Email

    Phishing emails are among the most common threats facing universities today. These messages appear legitimate, enticing you to click on malicious links, download harmful attachments, or give away sensitive information. At UT, we rely on your help to identify and stop these threats. That’s why reporting suspicious emails is essential—not just deleting them. What Happens…

    Read article…

  • Understanding Passwordless Authentication

    Passwordless authentication is a modern security practice that eliminates the need for traditional passwords to verify a user’s identity. Instead, it relies on alternative methods such as biometrics, physical security keys, or cryptographic keys stored on a device to grant access. This approach reduces security risks such as reused passwords, stolen credentials, and weak authentication…

    Read article…


Scam Types

Scams used to be easier to detect without worry. A Nigerian prince asks for a few hundred dollars to give you access to his fortune. But those days are gone, and scammers are in a constant arms race with cybersecurity for your sensitive information. Learn about the different types of scams and how to deal with them.

  • When Bad News Travels, Attackers Are Listening 

    Malicious actors monitor news outlets and social media for signs of confirmed or suspected security events that they can exploit to their advantage. A campus outage that generates public discussion is, to them, an opportunity with a shelf life. The psychology is simple: during a disruption, people expect to hear from IT, so a call…

    Read article…

  • ClickFix: Don’t Be Tricked by a Fake “Fix”

    Cybercriminals are using a tactic called ClickFix to trick people into compromising their own devices. These scams use fake error messages, security warnings, or fake CAPTCHA verification prompts that tell users to take steps to “fix” a problem. One common trick is instructing users to press Windows + R to open the Run box, then press Ctrl + V to paste…

    Read article…

  • Triggers Hackers Use to Trick You: Urgency, Authority, and Curiosity

    Hackers don’t rely on technology alone—they rely on human psychology. Most attacks rely on three simple triggers to get people to act quickly without thinking. The first trigger is a sense of urgency, with messages like “act now or lose access” or “your account will be locked,” creating pressure that pushes users to respond immediately…

    Read article…

  • Understanding QR Code Phishing

    In the dynamic world of cybersecurity, threat actors continue to innovate using methods like QR code phishing. This technique, which seemed emergent just a few years ago, has now become more refined and widespread. QR code phishing, also known as “Quishing,” remains a threat as these codes are now ubiquitously used for convenience in many…

    Read article…


Benefits & Tips for You

In this section, you can learn about all the different tools available to you at UT, such as secure file sharing and monitoring your systems. We will also share best practices for staying secure at school and at home.

  • The Need to Replace SMS-Based MFA

    In December 2024, the FBI and CISA advised Americans against using SMS codes for multi-factor/two-factor (MFA/2FA) authentication. CISA’s Mobile Communications Best Practice Guidance bluntly recommended: “Do not use SMS as a second factor for authentication. SMS messages are not encrypted–a threat actor with access to a telecommunication provider’s network who intercepts these messages can read…

    Read article…

  • Safeguarding Your Remote Work

    Remote work in higher education is now the norm. To keep your online work safe using university-provided tools like OneDrive and Microsoft Teams, follow these straightforward steps: Working remotely in higher education is convenient and secure when you use the university-provided tools while taking these precautionary steps.

    Read article…

  • Privacy Concerns with Onboard AI: Microsoft Copilot

    Continuing with privacy concerns with onboard AI, Microsoft Copilot, which uses the hardware on any system with Windows 11 Copilot+ to run the native AI of Copilot, has been seen as a potential issue for user privacy. We’ve highlighted a few privacy concerns associated with Microsoft Copilot: You can opt out of data collection for…

    Read article…


Protecting University Data

Discover essential articles on cybersecurity practices specifically tailored for the University of Tennessee. Learn effective strategies to safeguard sensitive information, defend against threats, and maintain data integrity. Equip yourself with knowledge to protect your university’s digital ecosystem.

  • Protecting Your Virtual Machines

    Many of us use virtual machines (VMs) on our computers these days for various reasons – to run an older operating system, test new software safely, or access work resources remotely. While VMs provide great flexibility, they also introduce potential security risks if not configured properly. Just like with regular software on your main operating…

    Read article…

  • The Importance of Installing Approved Software

    As we navigate the ever-evolving landscape of cybersecurity, it’s crucial for each member of our university to play an active role in maintaining a secure computing environment. Today, we’ll shed light on the significance of only installing approved software on university-owned machines and the impact it has on our collective digital safety. 1. Protecting Sensitive…

    Read article…

  • Enhancing Cybersecurity: A Guide to Browser Extensions

    Browser extensions are a great way to enhance your browsing experience but can pose a significant security risk. Cybercriminals frequently use browser extensions to gain access to your personal information, such as login credentials, browsing history, and other sensitive data. In fact, according to a report by Kaspersky, more than 1.3 million users were affected by…

    Read article…