Article Archive #2
Service navigation

Importance of Security
Information security is about addressing and reducing IT RISK. It’s easy to overlook risk as a topic when all you hear is talk about passwords, firewalls, encryption, policies, or two-factor authentication. In this section, you’ll read about how the university is at risk and what you can do to reduce the risk in your group, department, and college.
-
Think Before You Share: What the Claude Search Exposure Teaches Us About AI Privacy
Recent reporting found that some Claude chats and Artifacts shared by public links appeared in Google search results. Reported examples included internal documents, health-related information, contact details, and API keys. This does not appear to mean that all private Claude chats were exposed, but it is an important reminder that a shared AI link may be far more…
-
Two-Factor Authentication (2FA) Prompt Bombing
Two-factor authentication (also known as, “Multi-factor Authentication (MFA)”) provides an extra layer of security for your accounts, but it’s important to think before you click. Cybercriminals can use an attack method called 2FA prompt bombing to bypass 2FA protections and overwhelm you with prompts via the Push feature of Duo. For example, cybercriminals may try to log…
-
When ‘Too Good to Be True’ Comes from Someone You Know
For years, cybercriminals have used social media to post fake sales listings for popular items such as furniture or electronics. As these scams have gained in popularity, most of us have learned to use caution when buying items online from strangers. Now, cybercriminals are impersonating people you trust to lure you into their fake listing…

Scam Types
Scams used to be easier to detect without worry. A Nigerian prince asks for a few hundred dollars to give you access to his fortune. But those days are gone, and scammers are in a constant arms race with cybersecurity for your sensitive information. Learn about the different types of scams and how to deal with them.
-
ClickFix: Don’t Be Tricked by a Fake “Fix”
Cybercriminals are using a tactic called ClickFix to trick people into compromising their own devices. These scams use fake error messages, security warnings, or fake CAPTCHA verification prompts that tell users to take steps to “fix” a problem. One common trick is instructing users to press Windows + R to open the Run box, then press Ctrl + V to paste…
-
Triggers Hackers Use to Trick You: Urgency, Authority, and Curiosity
Hackers don’t rely on technology alone—they rely on human psychology. Most attacks rely on three simple triggers to get people to act quickly without thinking. The first trigger is a sense of urgency, with messages like “act now or lose access” or “your account will be locked,” creating pressure that pushes users to respond immediately…
-
Understanding QR Code Phishing
In the dynamic world of cybersecurity, threat actors continue to innovate using methods like QR code phishing. This technique, which seemed emergent just a few years ago, has now become more refined and widespread. QR code phishing, also known as “Quishing,” remains a threat as these codes are now ubiquitously used for convenience in many…
-
Typosquatting: When a Tiny Typo Leads to Big Trouble
Have you ever mistyped a website address? Maybe you accidentally hit “goggle.com” instead of “google.com”? Well, that seemingly innocent slip-up can lead you down a treacherous path—one paved with cyber traps. What Is Typosquatting? Typosquatting is like a cunning chameleon. It preys on our human tendency to fumble our keystrokes. Here’s how it works: Why…

Benefits & Tips for You
In this section, you can learn about all the different tools available to you at UT, such as secure file sharing and monitoring your systems. We will also share best practices for staying secure at school and at home.
-
Physical Security Tips While Traveling
Traveling is an exciting experience, but it also comes with risks to your physical security. Whether you’re exploring a new city or attending a business conference, safeguarding your belongings and personal safety is essential. Here are some practical tips to enhance your physical security while traveling. 1. Secure Your Luggage Always use TSA-approved locks for…
-
Can You Identify a Phishing Website?
A phishing website is a malicious site designed to steal sensitive information such as login credentials, credit card numbers, and other personal data. These websites often mimic legitimate sites to trick users into interacting with the website. Recognizing the signs of a phishing website and knowing how to protect yourself can help prevent identity theft…
-
Spring Cleaning Your Digital Life
Spring is often a time when people begin thinking about cleaning up their personal living space and getting rid of old belongings. It is also a good time to tighten your data security. Here are some places you might find some cyber dust bunnies! These are only a few examples of where you may practice…

Protecting University Data
Discover essential articles on cybersecurity practices specifically tailored for the University of Tennessee. Learn effective strategies to safeguard sensitive information, defend against threats, and maintain data integrity. Equip yourself with knowledge to protect your university’s digital ecosystem.
-
I’ve been hacked!
Determining whether or not your computer or mobile device has been hacked can be difficult. Nonetheless, there are a few common issues that will indicate your computer has been hacked. If your browser’s homepage has unexpectedly changed or is taking you to websites you have never visited, this could be an indication. Also, if your…
-
Phishing Ourselves
In September of 2021, the UTK Administration asked that OIT develop and carry out a phishing campaign. The phishing will continue until the clicks improve, and they ARE improving! A couple of Frequently Asked Questions (FAQs) about the phishing campaign: OIT conducted a baseline phishing exercise in September 2021 used to compare all following campaigns.…

Explore
Write
Chat
Call