VMware has published a security advisory regarding a critical out-of-bounds write vulnerability (CVE-2023-34048) that has been fixed in the latest updates released by VMware. The vulnerability shared in this Cybersecurity Threat Advisory has received a critical severity rating by VMware.

Critical VMware Vulnerability – Patch Immediately

Do You Know Four of the Most Common Cyber-Attacks?
The rate of cyber-attacks has significantly increased over the past few years. Districts of all sizes are at risk of becoming victims of them, which is why it’s crucial that district leaders are aware of the most common cyber threats impacting the educational community today.

Tech Tidbit – Making Passwords Simpler and Harder
Last week I discussed the need to have all passwords minimally 12-18 characters to remain safe. While that is an absolute security requirement, we all know that our users are going to be pretty upset with this policy change.

Are Your Educators unknowingly opening your district to attack?
Everyone has heard about the cyber attack on casino giants MGM and Caesars Entertainment in September 2023. It is alleged that the attack on MGM was done via a phone scam that a hacker pulled on a help desk employee.

CISA Step 3 – Perform and Test Backups
Today we continue with our series discussing the highest priority cybersecurity steps as identified in the January 2023 CISA published report “Partnering to SafeGuard K-12 Organizations from Cybersecurity Threats.

Tech Tidbit – The FBI has issued a warning about malware hiding in fake search engine ads
The FBI has just issued a warning that cyber criminals are using search engine fake ads to launch cyber-attacks. Their suggestions are excellent. You can help battle malicious sites by implementing some form of DNS filtering.

CISA Step 2 – Mitigating Known Exploited Vulnerabilities (patching)
Today we continue with our series discussing the highest priority cybersecurity steps as identified in the January 2023 CISA published report “Partnering to SafeGuard K-12 Organizations from Cybersecurity Threats.

Important Information from the Jan 2023 Release of CISA K-12 Cybersecurity Toolkit
We have been talking a lot in these bulletins about the increase in Cybersecurity incidents and what can be done to mitigate that risk. Congress also recognized this heightened risk environment and enacted the K–12 Cybersecurity Act of 2021 (“The Act”), which required the Cybersecurity and Infrastructure Security Agency (CISA) to report on cybersecurity risks […]

Cyber Attack – Are you as protected as you think you are? (Part Six – Vendor Access to Your Network)
Today it seems everything is connected to the internet in some way. At home, you have doorbells, garage doors, TVs, and a myriad of other things. School networks also have a long list of vendors and vendor devices sharing their network.

Tech Tidbit – Endpoint Encryption Must Be Turned On – Everywhere
Today’s Tidbit should be quite simple once you get going. NIST requires data to be encrypted in transit and at rest. Probably you have a number of staff and techs who have laptops that leave the district.