News

May 14, 2019

Summary

A zero-day elevation of privilege vulnerability exists in the way Microsoft Windows Error Reporting (WER) handles files. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.

While details about the use of the exploit are not available, it has reportedly been used in limited attacks against specific targets. Successful exploitation has been observed in the wild. [2][3]

Summary

*** Vulnerable RDP servers should be patched IMMEDIATELY even where there is a potential business impact (unscheduled maintenance). Notify security@berkeley.edu if you anticipate any delays in patching. ***

May 7, 2019

Overview

Every Windows product has a lifecycle and that lifecycle ends when it's no longer supported. On Jan. 14, 2020 Microsoft will discontinue support for its Windows 7 Operating System. After this date, if your PC is running Windows 7, it will no longer receive security updates or fixes, software updates, and/or technical support. Without security patches, these systems will be easy targets for hackers, malware, and viruses.

April 17, 2019

Summary

Multiple, critical security vulnerabilities have been discovered in Atlassian Confluence Server and Confluence Data Center.   
Information Security & Policy recommends emergency, out-of-band patching of all vulnerable Confluence servers. These flaws are actively being exploited in the wild. 

Impact

Attackers can exploit path traversal and other bugs to remotely execute code on vulnerable systems. [1] [2]

April 15, 2019

Registration for the 2019 Information Security Symposium is now open. The Symposium will be held June 18-19 in Davis, CA.  The theme is Connect, Share, Fortify, and the attractions include:

April 9, 2019

Summary

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account.

Exploitation of this vulnerability requires that a user uploads a specially crafted SharePoint application package to an affected version of SharePoint.

April 4, 2019

Summary

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected. 

Acknowledgments: The issue was discovered by Charles Fol.

March 14, 2019

A couple of recent phishing scams, referred to as a “Business Email Compromise (BEC),” have been targeting universities to steal funds through the purchasing process.

The first phishing scam targets suppliers that do business with campus by using Berkeley emails as the hook. These attacks involve purchase orders and requests for quotes that appear to come from the University, but are in fact fraudulent. 

Be Alert:

Summary

Serious security vulnerabilities have been discovered in the Ruby on Rails web application framework including a remote file content disclosure flaw and a Denial of Service (DoS) vulnerability. Please read the References links below to learn if your Rails application is affected.

Impact

March 8, 2019

 Starting March 11th services that use Active Directory Federation Services (ADFS) will require CalNet 2-Step Authentication. 

ADFS 2step login screenshot

Examples of software include CalShare and Microsoft 365.

February 21, 2019

Summary

A highly critical bug has been discovered in Drupal that can be used for remote code execution [1].  Drupal is a Content Management System (CMS) commonly used to host websites. In the past this sort of exploit has been used to deliver remote access tools, ransomware, and cryptominers to web servers [2]. Based on similar exploits against various CMS software in the past, we can expect that attackers will begin exploiting this software quickly.

February 20, 2019

Reserve your seat at DataEDGE 2019, the UC Berkeley School of Information's annual data science conference scheduled for April 23, 2019.

We are excited to announce that the Information Security and Policy Office is launching a Security Internship Program for staff. This is a unique opportunity for employees to work alongside the Security Operations and Assessments & Compliance teams. The internship is a chance for current Berkeley employees to develop a professional skill set in the information security domain and achieve breadth and depth of knowledge in the field. Interns will strengthen their career path potential, network with new colleagues, and contribute to the campus mission.

February 12, 2019

Summary

Open Containers runc is prone to a local command-execution vulnerability. Runc is a command line utility designed to spawn container systems. It is the container runtime that underpins many open source container management systems including Docker, Kubernetes, containerd, Podman, and CRI-O. [1] [3]

January 28, 2019

We all exist in digital form on the Internet. While online you leave a trail of your digital self in the form of cookies, GPS data, social media posts, browser searches, email exchanges... the list goes on. Your footprint is vast and once something is online, it can be there forever.

That’s what Data Privacy Day is all about. Recognizing that owning your online presence will help to protect your identity, finances, and reputation – both now and in the future.

January 24, 2019

W-2 wage statements became available online this week and every year several convincing phishing messages are crafted by tax scammers and sent to Campus to trick victims into giving out personal information. Taxpayers should continue to watch out for fake emails and/or websites looking to steal personal information during the 2019 filing season.  

January 11, 2019

A widely reported spear phishing scam, termed “Business Email Compromise (BEC),” has been targeting universities and other academic institutions. These attacks are spear phishing scams designed to impersonate someone you know in an attempt to gain access to sensitive information or to encourage you to transfer funds or provide gift cards. There has been an increase of these assaults across the University this new year.

December 20, 2018

Summary

Microsoft just published an out-of-band patch for Internet Explorer. It fixes a memory corruption vulnerability in the scripting engine. This vulnerability is identified as CVE-2018-8653.

When successfully exploited, Internet Explorer could execute arbitrary code in the context of the current user. To exploit the vulnerability, the victim must just visit a malicious web page delivered through a phishing email or social engineering. [1]

October 11, 2018

October 4, 2018

The goal of National Cyber Security Awareness Month (NCSAM) – celebrated every October – is to ensure that all Americans have the resources they need to stay safer and more secure online. Check out these offerings to find an event near you, or a webinar of interest.


***highlighted event***

Oct 16, 11AM-1PM
UCOP Cyber Security Awareness Month Forum
UCOP, 1111 Franklin St., Oakland, CA, Lobby 1 Conference Room