October is Cybersecurity Awareness Month!

Tags CSAM


                                                      Cyber Security Awareness Month Logo

 

 

2026 marks the 22nd annual Cybersecurity Awareness Month!

On this month in 2004, the President of the United States and Congress declared the month of October to be Cybersecurity Awareness Month, a dedicated month for the public and private sectors, and tribal communities to work together to raise awareness about the importance of cybersecurity.

Changes Since Last Year

Artificial Intelligence... embedded in almost everything!

  • Artificial Intelligence or AI is changing by the day. It's a tool, it can do amazing things, it can also be used by cyber-criminals. This course provides a practical introduction to AI and its intersection with cybersecurity, tailored for employees/student workers in today’s workplace and institutions of higher learning.
    • Analyze AI-enhanced phishing attacks to identify unique characteristics and indicators that distinguish them from traditional phishing attempts.
    • Evaluate the ethical implications of using AI tools in workplace security practices, including data privacy considerations and potential biases.
    • Demonstrate appropriate defensive measures against deepfake attacks in common workplace scenarios like video conferencing and voice authentication.
    • Classify different types of AI-based security threats according to their attack vectors, risk levels, and potential business impacts.
  • Cyber Security Awareness: AI (Spotting other AI-enhanced threats) 4:02s
  • Cyber Security Awareness: AI (whole course) 39:13s

 

Traveling abroad and countries deemed risky

What and why?

  • Due to the ever-changing cybersecurity threat landscape, we began blocking access to the UWRF systems and network from countries deemed as risky.  This includes all applications that you need Falcon credentials to access.

  • See Traveling Abroad and Technology Requirements and Blocked country list: Restricted-access to Falcon Account authentication

  • If you are considering traveling abroad, depending on the country and region, a consult with DoTS may be helpful! We can even provide a more portable, safer loaner device for your trip! dots@uwrf.edu or stop by our Service Center!

πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€πŸ’€

Trick-or-Treat!

Well a trick for sure, but no treat. A Very Real-life Tale of Social Engineering at UWRF!   

A few years ago as the end of September approached and DoTS began preparing for this newsletter our student community was sent an email. The emails appeared to come from prominent faculty members advertising for a student research assistant. The note essentially read "Research assistant needed" and described a believable scenario in which the student position would be on site helping a professor working on out-of-state research. The scam goes on to offer a cell number to text for more info, adding a "first come, first serve" comment, time pressuring the victim. The pay is reasonable, the ask sounds legitimate, the next part is the spooky twist. 

Once a communication line is established and trust fostered, the impostor asks the student to provide a bank account routing number. The impostor claims on-site research needs. This leads to a seemingly real deposit, in this case $1800.00. Once the money "shows up," the impostor claims to have made a mistake and asks for a refund. The student sends their actual real money back to the impostor's account. The bank later informs the student that the check was fraudulent and the money is gone... the impostor now ghosts the victim, keeping their monies.

Although this story happened some time ago, this has happened many times since then and continue to happen every year. Moral of this story... it's hard, and there is no shame in falling victim, these scams work for a reason, but be aware, online bank statements can be deceiving and verifying all cash transactions before leaving your account is advised! Take your time and don't be rushed.

πŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒπŸŽƒ

Election Season is Upon Us!

Emotions run high during election season, which means bad actors are going to try to take advantage of voters. Unfortunately, there are those that engage in voter suppression activities and harvesting information. You can prevent this by going through official channels to check that you are registered to vote. Use vote.gov as your starting place. US government websites exclusively use the .gov domain. Remember, that although there are many legitimate organizations that use the .org domain, anyone can use it. Scammy operators may prop up a website with a .org URL to trick people into thinking they are trustworthy.

Be suspicious of the following communications coming from email, text, phone, and the web:

  • Voter Registration and Voting: Remember, you cannot vote by phone, text, or any website.
  • Political Donations: Be careful to not give your money and information to third party sites or apps. Verify that the funds will actually go to the campaign you support.
  • Surveys/Polls: If there is an offer of a prize or gift for providing your information don’t go for it. Campaigns don’t do this, but it is quite common for a scammer to offer incentives like gift cards for participation.
  • Unsolicited Messages: Never click on links or attachments in messages you aren’t expecting. These can contain malware or be used to harvest your information. Also, do not reply if you are uncertain of who is sending it.
  • Deep Fakes: Do some simple checks to ensure you aren’t spreading disinformation. By your slowing down before sharing or commenting on social media, you can prevent the spread of disinformation.

 

πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡πŸ¦‡

4 Simple Steps to Stay Secure!

Spoiler! At River Falls we’ve got a good start already with Okta multifactor, automated Windows Udpates and strong password requirements! 

  • Use strong passwords and a password manager: Strong passwords are critical to protecting data. They are long, random, unique, and include all four-character types (uppercase, lowercase, numbers, and symbols). Password managers are a powerful tool to help you create long, random, and unique passwords for each of your accounts. Plus, they make storing passwords and user IDs easy. Strong passwords are required at River Falls already β˜‘️

  • Okta multifactor authentication for your campus resources (MFA): You need more than a password to protect your online accounts and enabling MFA makes you significantly less likely to get hacked. Enable multifactor authentication on all your online accounts that offer it, especially email, social media, and financial accounts and use authentication apps or hardware tokens for added security. Available and protecting us here on campus for years β˜‘️

  • Recognize & report phishing: Phishing emails, texts, and calls are the number one way data gets compromised. Be cautious of unsolicited emails, texts or calls asking for personal information. Avoid sharing sensitive information or credentials over the phone or email unless necessary and don’t click on links or open attachments sent from unknown sources. Verify the authenticity of requests by contacting the individual or organization through a trusted channel. Report phishing attempts to the appropriate authorities or IT department. Outlook has built-in reporting tools, but calls with questions to the DoTS Service Center are encouraged! β˜‘️

  • Update software: Ensuring your software is up to date is the best way to make sure you have the latest security patches and updates on your devices. Regularly check manually for updates if automatic updates are not available and keep operating systems, antivirus software, web browsers, and applications up to date. If you're using a UWRF-issued laptop, you're receiving our system updates and security patches! β˜‘️

πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»πŸ‘»

Division of Technology Services - DoTS Security Resources 

Technology Services maintains a portfolio of security tools and processes for handling operational, daily security. We also provide public documentation.

☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️☠️

                                         cemetery banner with scarecrow

  DoTS wishes you a Happy and Cybersafe Autumn!

Print Article

Related Articles (2)

Turn it off and have DoTS take a look at it.
Short information blasts that help keep you and your information safe.