Skip to content Skip to main navigation Report an accessibility issue
Information Security

Article Archive #2


Service navigation


Security Learning Icon One

Importance of Security

Information security is about addressing and reducing IT RISK. It’s easy to overlook risk as a topic when all you hear is talk about passwords, firewalls, encryption, policies, or two-factor authentication. In this section, you’ll read about how the university is at risk and what you can do to reduce the risk in your group, department, and college.

  • Think Before You Share: What the Claude Search Exposure Teaches Us About AI Privacy

    Recent reporting found that some Claude chats and Artifacts shared by public links appeared in Google search results. Reported examples included internal documents, health-related information, contact details, and API keys. This does not appear to mean that all private Claude chats were exposed, but it is an important reminder that a shared AI link may be far more…

    Read article…

  • Two-Factor Authentication (2FA) Prompt Bombing

    Two-factor authentication (also known as, “Multi-factor Authentication (MFA)”) provides an extra layer of security for your accounts, but it’s important to think before you click. Cybercriminals can use an attack method called 2FA prompt bombing to bypass 2FA protections and overwhelm you with prompts via the Push feature of Duo. For example, cybercriminals may try to log…

    Read article…

  • When ‘Too Good to Be True’ Comes from Someone You Know

    For years, cybercriminals have used social media to post fake sales listings for popular items such as furniture or electronics. As these scams have gained in popularity, most of us have learned to use caution when buying items online from strangers. Now, cybercriminals are impersonating people you trust to lure you into their fake listing…

    Read article…


Scam Types

Scams used to be easier to detect without worry. A Nigerian prince asks for a few hundred dollars to give you access to his fortune. But those days are gone, and scammers are in a constant arms race with cybersecurity for your sensitive information. Learn about the different types of scams and how to deal with them.

  • ClickFix: Don’t Be Tricked by a Fake “Fix”

    Cybercriminals are using a tactic called ClickFix to trick people into compromising their own devices. These scams use fake error messages, security warnings, or fake CAPTCHA verification prompts that tell users to take steps to “fix” a problem. One common trick is instructing users to press Windows + R to open the Run box, then press Ctrl + V to paste…

    Read article…

  • Triggers Hackers Use to Trick You: Urgency, Authority, and Curiosity

    Hackers don’t rely on technology alone—they rely on human psychology. Most attacks rely on three simple triggers to get people to act quickly without thinking. The first trigger is a sense of urgency, with messages like “act now or lose access” or “your account will be locked,” creating pressure that pushes users to respond immediately…

    Read article…

  • Understanding QR Code Phishing

    In the dynamic world of cybersecurity, threat actors continue to innovate using methods like QR code phishing. This technique, which seemed emergent just a few years ago, has now become more refined and widespread. QR code phishing, also known as “Quishing,” remains a threat as these codes are now ubiquitously used for convenience in many…

    Read article…

  • Typosquatting: When a Tiny Typo Leads to Big Trouble

    Have you ever mistyped a website address? Maybe you accidentally hit “goggle.com” instead of “google.com”? Well, that seemingly innocent slip-up can lead you down a treacherous path—one paved with cyber traps. What Is Typosquatting? Typosquatting is like a cunning chameleon. It preys on our human tendency to fumble our keystrokes. Here’s how it works: Why…

    Read article…


Benefits & Tips for You

In this section, you can learn about all the different tools available to you at UT, such as secure file sharing and monitoring your systems. We will also share best practices for staying secure at school and at home.

  • Secure Data Management: A Keystone of Cybersecurity

    In today’s interconnected world, managing data securely is not just a responsibility of the IT department; it’s a mission for every individual in an organization. Whether you’re at the helm of decision-making or ensuring day-to-day operations, your approach to handling data can make or break our collective cybersecurity efforts. Why Is Secure Data Management Important?…

    Read article…

  • Understanding Zero-Day Vulnerabilities

    In the ever-evolving landscape of cybersecurity, staying informed about emerging threats is crucial. One such threat that deserves your attention is the zero-day vulnerability. Let’s break it down in simple terms and explore how it impacts you. What Is a Zero-Day Vulnerability? A zero-day vulnerability is like a hidden trapdoor in your favorite app or operating…

    Read article…

  • Enhancing Cybersecurity: A Guide to Browser Extensions

    Browser extensions are a great way to enhance your browsing experience but can pose a significant security risk. Cybercriminals frequently use browser extensions to gain access to your personal information, such as login credentials, browsing history, and other sensitive data. In fact, according to a report by Kaspersky, more than 1.3 million users were affected by…

    Read article…


Protecting University Data

Discover essential articles on cybersecurity practices specifically tailored for the University of Tennessee. Learn effective strategies to safeguard sensitive information, defend against threats, and maintain data integrity. Equip yourself with knowledge to protect your university’s digital ecosystem.

  • Incident what?

    Information Security type individuals, as well as auditors, frequently talk about “Incident Response.” The term gets mentioned so much that it may be assumed that everyone knows what the term means.  Incident response is an organized approach to addressing and managing the aftermath of a security breach or cyberattack. The goal of an Incident Response…

    Read article…

  • Compromised Workstations/Laptops

    Is your workstation or laptop running “slow”? Does it take FOREVER for an application to start? Do you come in after being away from your desk to often find that your computer has restarted, displaying some sort of cryptic message about a problem? Your machine may be compromised or infected. Security incidents come in all…

    Read article…

  • Data Loss Prevention (DLP)

    One of the biggest risks that we face is the loss of our data. Whether it is cyber-breach, a stolen mobile device, or a stack of spreadsheets accidentally thrown away in an unsecured receptacle, the result is the same: our information falls into the hands of folks who are not authorized to view it. We can mitigate or…

    Read article…