The below email was sent to faculty/staff on Friday 5/12. The ITS Help Desk has since received a number of reports of failed updates and is working to investigate these as quickly as possible. ITS will be directly contacting those who our records show have computers missing the Windows patch that protects against the current ransomware attack and will address those as the top priority.

EMAIL SENT FRIDAY PM 5/12/17
Subject: [DUFacStaff] ALERT – PLEASE TAKE ACTION – Global Ransomware Attack on Windows PCs

To all campus Windows PC users:

Summary
We have been alerted to a worldwide ransomware attack on Windows pcs going on right now. Windows computer users need to immediately apply patches and reboot their computer if their system updates are out of date.

Detail
This attack began around 3:00PM today. It exploits a vulnerability in what appears to be all Windows operating systems. Windows systems (PCs and servers) that do not have current security patches are vulnerable to this cyber attack which could lock down and encrypt your computer hard drive until a ransom is paid. Once a single person clicks on the phishing message, the virus could spread throughout the entire network.

ITS has scanned all computers on campus (with the exception of personally managed systems) and have found 81 computers across campus that have downloaded the Windows updates, but have not taken the time to apply the updates.

It is CRITICAL that you verify that your PC has applied the most recent Windows operating system security update in order to secure your system and university data.

If you are running Windows 7 – Click start, type “windows update” in the search box, then click “Windows update” in the search results. In the left pane click “Check for updates”.

If you are running Windows 10 – Click the “Search Windows” icon next to the start button, type “check for updates” and click the result of the same name. On the window that appears, click “check for updates”.

For questions, please contact the ITS Help Desk 740.587.6395 or helpdesk@denison.edu. Staff will be available Monday morning to assist.

PS: Check your home computers also!

Update: The Banner maintenance has been completed.

ITS will be performing Banner (INB) and Self-Service Banner (SSB) maintenance and upgrades, Sunday, 5/21 – 6:00 AM to 3:00 PM. Banner and all related systems will be unavailable during this maintenance window.

If you have any Banner related problems, please contact the Helpdesk @ helpdedesk.denison.edu or 740-587-6395.

May edition:

Securing Today’s Online Kids

(https://securingthehuman.sans.org/newsletters/ouch/issues/OUCH-201705_en.pdf)

OUCH! is the world’s leading, free security awareness newsletter designed for the common computer user. Published every month and in multiple languages, each edition is carefully researched and developed by the SANS Securing The Human team, SANS instructor subject matter experts and team members of the community. Each issue focuses on and explains a specific topic and actionable steps people can take to protect themselves, their family and their organization.

UPDATE: 5.3.17 6:30PM  As of 5:30PM EST Google has fixed the issue that caused a worldwide sophisticated phishing attack today.

Google spokesperson reports, “We have taken action to protect users against an email impersonating Google Docs, and have disabled offending accounts. We’ve removed the fake pages, pushed updates through Safe Browsing, and our abuse team is working to prevent this kind of spoofing from happening again.”

This Google docs phishing email worked like this: You get an email saying someone added you to a Google Doc; click this link to view it. That takes you to a legitimate account screen, listing all the Google accounts you’re logged into. From there, you choose the one you want to use to view the document (or log in, if you weren’t already authenticated in your browser). There, a malicious service called “Google Docs” awaits, asking for privileges to access your account, your contacts, your password rests, your emails, everything.

Both Google and Denison ITS are working on cleaning up any account who has “Google Docs” showing as an app connected to your Denison account.  However, ITS recommends that you also take the following action to verify your account.

If you already clicked this type of link today (or any day), go to the Permissions page of your Google account and revoke access to the service called “Google Docs.”  Then, we recommend that you change your password.

source: google, www.wired.com, www.theverge.com


5.3.17 3:30PM ITS has received a flood of reports of scam email messages from Denison accounts titled “(Denison Account) has shared a document on Google Docs with you”. Please DO NOT click the “Open in Docs” link in this message. ITS is working to block these scam messages. If you did click on this link, please follow the steps in this FAQ including changing your BigRedID password immediately: http://apps.denison.edu/helpdesk/faq3422.

Update 4/27/17 7:30am:

The network updates are complete. Please report any network issues to the ITS Help Desk at 740-587-6395 or helpdesk@denison.edu. The Help Desk will reply as soon as possible during regular business hours (see www.denison.edu/its/helpdesk for hours).

Original Post:

Facilities will be performing UPS maintenance on Wednesday(4/26/17) & Thursday(4/27/17) from 7:00 – 7:30am which will result in the loss of the wired and wireless network during these timeframes.

Please do not edit files over the network or submit information online during this time period as your work may be lost when the network outages occur.

This post will be updated when the work is complete. If you experience any network connectivity issues after this time, please contact the ITS Help Desk at 740-587-6395 or helpdesk@denison.edu.

If you are being prompted to update Java, ITS recommends that you do NOT update Java at this time. Choose the “Later” or “Run” option when prompted.

If you have already updated Java to the new update (update 131):

  • If you copy/paste into Banner, you will want to roll back to the prior Java update. Please contact the ITS Help Desk to request assistance doing so.
  • If you do NOT copy paste into Banner, you can use update 131 but will need to need to adjust your Java security settings. Please see this ITS Help Desk Online FAQ for instructions: http://apps.denison.edu/helpdesk/faq4552.

If you have any questions or problems, please contact the ITS Help Desk at 740-587-6395 or helpdesk@denison.edu.

April edition:

Passphrases

(https://securingthehuman.sans.org/newsletters/ouch/issues/OUCH-201704_en.pdf)

OUCH! is the world’s leading, free security awareness newsletter designed for the common computer user. Published every month and in multiple languages, each edition is carefully researched and developed by the SANS Securing The Human team, SANS instructor subject matter experts and team members of the community. Each issue focuses on and explains a specific topic and actionable steps people can take to protect themselves, their family and their organization.

Update: 6:45 AM – MyDenison is available for use.

Original Message:

4/2/17 – 10:00 PM – ITS has received and confirmed a report that MyDenison is currently down. Attempts to access it yield a “Bad Gateway” error. ITS technicians have been notified and will address the issue as soon as possible. In the meantime, you can access the following services directly via these URLs:

Denison Apps (email, calendar, Drive, etc.) – https://apps.denison.edu
Blackboard – https://courses.denison.edu
Self Service – http://ssb.denison.edu (requires D-number and 6-digit Self Service PIN)

Banner – (banner.denison.edu) – (VPN required for off-campus access)

NoteBowl – (notebowl.denison.edu)

Update 4/3/2017 10.24 am

We believe that the partial service disruption for Dialpad related to the “Executive-Assistant” pairing has been resolved. Please call the ITS Helpdesk at 740-587-6395 or by email at helpdesk@denison.edu if you are still experiencing issues.

Thank you!

Original Post:

We have reports that external calls from “Assistants” to their “Executives” seem to be dropping calls. We are working with Dialpad to resolve this issue as soon as possible. In the meantime, please remove the “executive-assistant” pairings to be able to transfer to your executives.

Please let us know if you have any questions or concerns by calling the ITS Helpdesk at 740-587-6395 or helpdesk@denison.edu

Thank you!