News

October 11, 2018

October 4, 2018

The goal of National Cyber Security Awareness Month (NCSAM) – celebrated every October – is to ensure that all Americans have the resources they need to stay safer and more secure online. Check out these offerings to find an event near you, or a webinar of interest.


***highlighted event***

Oct 16, 11AM-1PM
UCOP Cyber Security Awareness Month Forum
UCOP, 1111 Franklin St., Oakland, CA, Lobby 1 Conference Room

September 25, 2018

To our campus community,

We are implementing some necessary updates to our Wi-Fi network that will require some action on your part. On Oct. 2, 2018 at 7 a.m., the Airbears2 and eduroam wireless networks will be updated with a new certificate. After this update is complete, devices attempting to connect to either wireless network will be presented with a message similar to one of the three examples shown below (message will vary based on the device and operating system you are using):

Example 1: MacOS X 10.13 (MacBook Air)

September 19, 2018

This is a reminder that throughout the UC system, we have a shared responsibility of information security. This can mean everything from daily practices around secure passphrases, encrypting laptops, and setting up CalNet 2-Step, all the way to making sure servers have the latest patches and are behind bSecure firewalls. 

New Policy

August 23, 2018

Summary

A critical remote code execution vulnerability has been discovered in Apache Struts, a popular open source framework for developing web applications in the Java programming language. [1] In the past, Apache Struts RCE vulnerabilities have been weaponized in less than 24 hours -- one of which resulted in the Equifax breach that totaled over $600 million in cost. [2]

August 17, 2018

Summary

A vulnerability has been discovered in Oracle Database that could allow for complete compromise of the database, as well as shell access to the underlying server. [1] . The vulnerability resides in the Java Virtual Machine component of the Oracle Database Server and does not require user interaction. The vulnerability allows low-privileged attackers that have Create Session privilege with network access via Oracle Net to compromise the Java VM component.

August 10, 2018

Students at school

The new school year is an exciting time for students, faculty, and staff. It's also an exciting time for hackers, identity thieves, and other unscrupulous types who take advantage of people during this busy time of year. 

August 8, 2018

If you an IT Security professional and want to join a talented and dynamic team, check out our available job openings at: https://security.berkeley.edu/about/job-postings

If you an IT Security professional and want to join a talented and dynamic team, check out our available job openings at: https://security.berkeley.edu/about/job-postings

July 12, 2018

NSF’s new Research Terms and Conditions (effective March 1, 2018) require recipients of NSF funding to protect Personally Identifiable Information within the scope of an NSF award.  Article 35 states:  

July 9, 2018

The Campus Policy for Minimum Security Standards for Electronic Information (MSSEI) [1] requires departments to register computer systems and applications containing restricted data.  Restricted Data is defined as "any confidential or personal information that is protected by law or policy, and that requires the highest level of access control and security protections whether in storage or in transit" [2]  and further refined based on adverse business impact into "High" or Protection Level 2 and "Moderate" or Protection Level 1. [3]

June 12, 2018

In the last few months our office has received an increasing number of laptop theft reports. These incidents occurred both on and off campus, and in varying circumstances, however in all the recent cases the laptops involved were not configured for Full Disk Encryption (FDE). In a few of these cases, the laptops were used to access sensitive data as part of campus business processes, and the Security team is concerned about possible data exposure due to lost and stolen devices with access to campus protected data. 

April 26, 2018

NOTE: These vulnerabilities are already being exploited in the wild. If you have an affected Drupal site, update IMMEDIATELY!

Summary

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. [1]

March 28, 2018

NOTE: Drupal core developers have stated that exploits for this vulnerability will likely be developed within days. Drupal site owners must take action immediately or risk complete compromise of their sites. 

Summary

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. [1]

Impact

This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being completely compromised. [1]

March 14, 2018

The IST-Telecommunications networking group will begin piloting the new bSecure Campus VPN service in the coming weeks. Eventually, this service will become the replacement for the existing Cisco AnyConnect based Campus Remote Access VPN service.

March 2, 2018

Summary

Multiple vulnerabilities have been discovered in PHP, the most severe of which could allow an attacker to execute arbitrary code.  PHP is a programming language originally designed for use in web-based applications with HTML content.  PHP supports a wide variety of platforms and is used by numerous web-based software applications.  [1]

February 22, 2018

Summary

Multiple critical vulnerabilities have been discovered in Drupal core. [1]

Impact

Attackers may be able to view restricted content or add content of their own. Additionally, a JavaScript function in Drupal core may allow attackers to perform cross-site scripting attacks. 

January 31, 2018

The bSecure team would like to provide an update on our planned migration to the new firewall services in the Data Center.

Data Center Firewall Administrator Training

As previously announced, we will be holding two on-campus training sessions for Data Center Firewall Administrators.  Both sessions are identical, so you only need to attend one.  The Dates for these one day sessions will be:

January 19, 2018

 Phishing Leads the IRS List of Tax ScamsThe Internal Revenue Service has reported a big spike in phishing and malware incidents during the 2016 and 2017 tax seasons.

January 12, 2018

The bSecure project team would like to provide the Campus IT community, and especially administrators of existing firewall services, with an update on the planned migration to the new service, and information on what to expect next.