September 19, 2018
August 23, 2018
A critical remote code execution vulnerability has been discovered in Apache Struts, a popular open source framework for developing web applications in the Java programming language.  In the past, Apache Struts RCE vulnerabilities have been weaponized in less than 24 hours -- one of which resulted in the Equifax breach that totaled over $600 million in cost. 
August 17, 2018
A vulnerability has been discovered in Oracle Database that could allow for complete compromise of the database, as well as shell access to the underlying server.  . The vulnerability resides in the Java Virtual Machine component of the Oracle Database Server and does not require user interaction. The vulnerability allows low-privileged attackers that have Create Session privilege with network access via Oracle Net to compromise the Java VM component.
August 8, 2018
If you an IT Security professional and want to join a talented and dynamic team, check out our available job openings at: https://security.berkeley.edu/about/job-postings
July 12, 2018
NSF’s new Research Terms and Conditions (effective March 1, 2018) require recipients of NSF funding to protect Personally Identifiable Information within the scope of an NSF award. Article 35 states:
July 9, 2018
The Campus Policy for Minimum Security Standards for Electronic Information (MSSEI)  requires departments to register computer systems and applications containing restricted data. Restricted Data is defined as "any confidential or personal information that is protected by law or policy, and that requires the highest level of access control and security protections whether in storage or in transit"  and further refined based on adverse business impact into "High" or Protection Level 2 and "Moderate" or Protection Level 1. 
June 12, 2018
April 26, 2018
March 28, 2018
NOTE: Drupal core developers have stated that exploits for this vulnerability will likely be developed within days. Drupal site owners must take action immediately or risk complete compromise of their sites.
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. 
This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being completely compromised. 
March 14, 2018
The IST-Telecommunications networking group will begin piloting the new bSecure Campus VPN service in the coming weeks. Eventually, this service will become the replacement for the existing Cisco AnyConnect based Campus Remote Access VPN service.
March 2, 2018
Multiple vulnerabilities have been discovered in PHP, the most severe of which could allow an attacker to execute arbitrary code. PHP is a programming language originally designed for use in web-based applications with HTML content. PHP supports a wide variety of platforms and is used by numerous web-based software applications. 
February 22, 2018
January 31, 2018
The bSecure team would like to provide an update on our planned migration to the new firewall services in the Data Center.
Data Center Firewall Administrator Training
As previously announced, we will be holding two on-campus training sessions for Data Center Firewall Administrators. Both sessions are identical, so you only need to attend one. The Dates for these one day sessions will be:
January 19, 2018
The Internal Revenue Service has reported a big spike in phishing and malware incidents during the 2016 and 2017 tax seasons.
January 12, 2018
The bSecure project team would like to provide the Campus IT community, and especially administrators of existing firewall services, with an update on the planned migration to the new service, and information on what to expect next.
January 5, 2018
A team of security researchers disclosed several software analysis methods that, when used for malicious purposes, have the potential to improperly gather sensitive data from many types of computing devices with many different vendors’ processors and operating systems.
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. 
December 4, 2017
The Network Operations and Services team and the Information Security and Policy group are implementing bSecure, a new firewall and information security service for campus. This service will replace the existing Cisco ASA-based Data Center and Campus Departmental Firewall services.
November 29, 2017
October 18, 2017
October 17, 2017
Researchers have discovered serious weaknesses in WPA2, a protocol that secures all modern protected Wi-Fi networks. This includes everything from computers, tablets, phones, home wireless routers and any device that supports WPA2 over Wi-Fi.
While details are still emerging, not all vendors have released patches as of yet. So, in some cases, there will be little users can do until patches are released. An attacker needs to be in range of an access-point to leverage this attack.