Skip to content Skip to main navigation Report an accessibility issue
Information Security

Article Archive #2


Service navigation


Security Learning Icon One

Importance of Security

Information security is about addressing and reducing IT RISK. It’s easy to overlook risk as a topic when all you hear is talk about passwords, firewalls, encryption, policies, or two-factor authentication. In this section, you’ll read about how the university is at risk and what you can do to reduce the risk in your group, department, and college.

  • It’s the Simple Things

    The vast majority of cyberattacks, 98%, start with phishing attacks that contain NO zero-days and NO malware. They simply trick us into clicking on a link or opening an attachment, thereby turning over our passwords to the bad guys. Zero-days are bugs in software that the software company does not know exist. That’s why they’re…

    Read article…

  • Don’t Become a victim!

    Here are a few facts that illustrate the dramatic increase in cybercrime; 2,244 cyberattacks happen daily, according to the University of Maryland! Cyberattacks have increased 37% month-to-month due to the COVID-19 pandemic! An estimated $108M in losses are due to scams in a recent 6-month period. Cybercrime is big business—and happens more often than you…

    Read article…

  • No! Really! You are a target!

    Cybercriminals are very effective at getting what they want. They have learned that the easiest way around the university’s defenses isn’t hacking and cracking; it’s tricking you into letting them in. They will use everything in their toolbox to implement their attacks. Social engineering is the art of manipulating, influencing, or deceiving you into taking some…

    Read article…


Scam Types

Scams used to be easier to detect without worry. A Nigerian prince asks for a few hundred dollars to give you access to his fortune. But those days are gone, and scammers are in a constant arms race with cybersecurity for your sensitive information. Learn about the different types of scams and how to deal with them.

  • Safeguarding Against QR Code Fishing

    In the ever-evolving landscape of cybersecurity threats, one emerging tactic is the use of QR codes in phishing emails. This deceptive technique poses a significant risk to both end users and IT professionals. Understanding QR Code Fishing: QR code phishing involves embedding malicious URLs or content within a seemingly innocuous QR code within emails, on…

    Read article…

  • Safeguarding Against QR Code Fishing

    In the ever-evolving landscape of cybersecurity threats, one emerging tactic is the use of QR codes in phishing emails. This deceptive technique poses a significant risk to both end users and IT professionals. UNDERSTANDING QR CODE FISHING: QR code phishing involves embedding malicious URLs or content within a seemingly innocuous QR code. These codes can…

    Read article…

  • .zip Domains 

    Recently, .zip top-level domains have become available for public purchase. A top-level domain is the final section of a domain name. So, in utk[dot]edu, “.edu” is the top-level domain. Unsurprisingly, cybercriminals have begun purchasing and using .zip domains for their own malicious purposes.  In the coming months, we expect to see an influx of cybercriminals…

    Read article…

  • Phishing with Images

    Cybercriminals use images in phishing emails to impersonate real organizations. By using images like official logos (i.e., UT, UPS, FedEx, etc.) and promotional materials, cybercriminals hope to trick you into thinking the email is legitimate.  In one recent incident, cybercriminals spoofed Delta Airlines to try to steal sensitive information. The body of the email consists…

    Read article…


Benefits & Tips for You

In this section, you can learn about all the different tools available to you at UT, such as secure file sharing and monitoring your systems. We will also share best practices for staying secure at school and at home.

  • The Need to Replace SMS-Based MFA

    In December 2024, the FBI and CISA advised Americans against using SMS codes for multi-factor/two-factor (MFA/2FA) authentication. CISA’s Mobile Communications Best Practice Guidance bluntly recommended: “Do not use SMS as a second factor for authentication. SMS messages are not encrypted–a threat actor with access to a telecommunication provider’s network who intercepts these messages can read…

    Read article…

  • Safeguarding Your Remote Work

    Remote work in higher education is now the norm. To keep your online work safe using university-provided tools like OneDrive and Microsoft Teams, follow these straightforward steps: Working remotely in higher education is convenient and secure when you use the university-provided tools while taking these precautionary steps.

    Read article…

  • Privacy Concerns with Onboard AI: Microsoft Copilot

    Continuing with privacy concerns with onboard AI, Microsoft Copilot, which uses the hardware on any system with Windows 11 Copilot+ to run the native AI of Copilot, has been seen as a potential issue for user privacy. We’ve highlighted a few privacy concerns associated with Microsoft Copilot: You can opt out of data collection for…

    Read article…


Protecting University Data

Discover essential articles on cybersecurity practices specifically tailored for the University of Tennessee. Learn effective strategies to safeguard sensitive information, defend against threats, and maintain data integrity. Equip yourself with knowledge to protect your university’s digital ecosystem.

  • MFA + Strong Passwords: Your Best Defense Against Account Attacks

    Multi-factor authentication (MFA) adds an extra layer of protection to your accounts by requiring more than just a password to sign in. Even if a password is stolen through phishing, malware, or a data breach, MFA can still prevent an attacker from accessing your account. This additional safeguard is especially important because passwords can be…

    Read article…

  • Digital Privacy—What is a Data Broker?

    In today’s digital age, personal information has become a valuable commodity. Data brokers have emerged as key players in this data-driven economy. Data brokers operate behind the scenes, gathering vast amounts of personal information from various sources. They compile detailed profiles on individuals and sell this data to businesses, marketers, and even government agencies. Understanding…

    Read article…

  • Getting Into the Mindset of a Hacker

    Have you ever wondered how a hacker looks at systems and finds unexpected ways around controls meant to keep them out? Is this a special mindset or a thought process that is learned? The mindset of a hacker can vary widely, but generally, it involves a few key traits and perspectives: While the term “hacker”…

    Read article…