Skip to content Skip to main navigation Report an accessibility issue
Information Security

Article Archive #2


Service navigation


Security Learning Icon One

Importance of Security

Information security is about addressing and reducing IT RISK. It’s easy to overlook risk as a topic when all you hear is talk about passwords, firewalls, encryption, policies, or two-factor authentication. In this section, you’ll read about how the university is at risk and what you can do to reduce the risk in your group, department, and college.

  • Think Before You Share: What the Claude Search Exposure Teaches Us About AI Privacy

    Recent reporting found that some Claude chats and Artifacts shared by public links appeared in Google search results. Reported examples included internal documents, health-related information, contact details, and API keys. This does not appear to mean that all private Claude chats were exposed, but it is an important reminder that a shared AI link may be far more…

    Read article…

  • Two-Factor Authentication (2FA) Prompt Bombing

    Two-factor authentication (also known as, “Multi-factor Authentication (MFA)”) provides an extra layer of security for your accounts, but it’s important to think before you click. Cybercriminals can use an attack method called 2FA prompt bombing to bypass 2FA protections and overwhelm you with prompts via the Push feature of Duo. For example, cybercriminals may try to log…

    Read article…

  • When ‘Too Good to Be True’ Comes from Someone You Know

    For years, cybercriminals have used social media to post fake sales listings for popular items such as furniture or electronics. As these scams have gained in popularity, most of us have learned to use caution when buying items online from strangers. Now, cybercriminals are impersonating people you trust to lure you into their fake listing…

    Read article…


Scam Types

Scams used to be easier to detect without worry. A Nigerian prince asks for a few hundred dollars to give you access to his fortune. But those days are gone, and scammers are in a constant arms race with cybersecurity for your sensitive information. Learn about the different types of scams and how to deal with them.

  • Malvertising

    What is “Malvertising”? Malvertising is the use of online advertising to spread malware. Malvertising involves injecting malicious or malware-laden advertisements into legitimate online advertising networks and web pages. With the increase in online shopping and news browsing, Malvertising is a way of spreading malware that can easily go undetected until it is too late. How…

    Read article…

  • News Related Scams

    Last week, news stories announced that Queen Elizabeth II, known for having the longest reign of any British monarch, passed away at 96. When an influential figure such as the queen passes away, people worldwide will be interested in reading more about their life and death. Cybercriminals take advantage of high-profile news stories to catch…

    Read article…

  • Zelle Fraud Alert

    Zelle is a popular mobile payment application that allows users to send payments to one another. Like most financial institutions, Zelle alerts users of possible fraud to stop suspicious account activity from happening. However, not all fraud alerts are legitimate, and cybercriminals can impersonate Zelle and send fake fraud alerts to scam you. In a…

    Read article…

  • How Do Cybercriminals Make an Email Sound so Authentic?

    Email or phone call scams are not new; cybercriminals have been attempting to fool people for years. Older scams like “You Won the Lottery” or the infamous “Nigerian Prince” are created as generic messages sent out to millions of people. The non-specific nature of these messages makes them easier to spot. More recently, personalized scams…

    Read article…


Benefits & Tips for You

In this section, you can learn about all the different tools available to you at UT, such as secure file sharing and monitoring your systems. We will also share best practices for staying secure at school and at home.

  • Safeguarding Your Data in the Cloud: A Guide to Cloud Security

    In today’s digital age, cloud computing has become an integral part of how we store, access, and share data. Whether you’re an end user or an IT professional, understanding cloud security is crucial for safeguarding sensitive information. Let’s explore some essential tips to help you navigate the world of cloud security. Remember, cloud security is…

    Read article…

  • Safeguarding Your Online Presence: A Guide to Secure Social Media Use

    In today’s interconnected world, social media has become integral to our daily lives. It’s a great way to stay in touch with friends, share experiences, and network professionally. However, it’s crucial to remember that the information we share online can have significant implications for our privacy and security.  Here are some tips on how to…

    Read article…

  • Compromised Workstations & Laptops

    An early nineteenth-century Prussian General stated, “No plan survives contact with the enemy.” President Eisenhower said, “…plans are useless, but planning is indispensable.” Ransomware, the type of attack where the bad guys take your data and render it useless, is recent. The methods to prevent it or lessen its impact are not. It’s your IT Professionals’ age-old, sage advice: “Patch it, back it up, and above all, don’t click…

    Read article…


Protecting University Data

Discover essential articles on cybersecurity practices specifically tailored for the University of Tennessee. Learn effective strategies to safeguard sensitive information, defend against threats, and maintain data integrity. Equip yourself with knowledge to protect your university’s digital ecosystem.

  • Look, No Hands—Let OIT Continuously Monitor Your Systems

    One of the responsibilities of every user of UT’s IT resources is to continuously monitor their UT Owned workstations, laptops, and servers. What does that even mean? HOW? WHO? Who does ANYTHING continuously? These two words, continuous monitoring,” would imply that you (or somebody) should be looking at a computer(s) 24 hours a day, 365 days per year. Thankfully, this…

    Read article…

  • Plans and Programs and Controls, Oh My!

    Information security conversations often include words like “IT security plans,” “systems,” and “program plans.” What do these terms mean in the context of cyber security, and why should we care? Three reasons WHY we are talking about cyber security: Human Resource (HR) or Fiscal (FI) policies provide a governance structure for conducting university business, the…

    Read article…

  • File Sharing Options for Sensitive Information

    We regularly receive questions about sharing or storing sensitive information.  While we have several recommendations, first, let’s talk about why you should be concerned about how you share or store sensitive information. ALL users are responsible for ensuring that their use of sensitive information services complies with laws, regulations, and policies where applicable; it is EVERYONE’s responsibility.…

    Read article…