Protect Yourself: Fighting MFA Fatigue

MFA FatigueLast week, OIT notified the campus of a successful phishing campaign targeting the SMU community. In this campaign, we noted that cybercriminals had begun using a new technique where they repeatedly send Duo requests to users who have shared their username and password to annoy users into approving the two-factor request.

This technique, referred to as “MFA fatigue,” has become increasingly common, and over the next several weeks, OIT will begin implementing measures to combat this trend. In the meantime, we recommend you take the following actions if you notice something suspicious: Continue reading Protect Yourself: Fighting MFA Fatigue

Phishing Email Simulations Return After Hiatus

AnitPhish (Anti-Phishing Campaign)Phishing attempts—those pesky emails that try to lure you into revealing personal info like passwords and financial information—are constantly evolving to thwart the University’s effort to stop them. While users only receive a small percentage of these emails in their inboxes, it takes one wrong click to start off a chain of new attempts.

For several years, SMU has worked to make our community more aware of these phishing attempts by sending simulated phishing emails. While we all have had to pivot and change our routines over the past couple of years, it was decided it was best not to add one more thing to everyone’s plate, so we took a break from the simulation. Yet, with the recent influx of successful phishing messages, the OIT Information Security Team will relaunch the simulated phishing email campaign in the coming weeks. Continue reading Phishing Email Simulations Return After Hiatus

Cyber Wellness Program Helps SMU Community Discover Its Strengths

Cybersecurity Wellness ProgramLast October, SMU offered employees the option of participating in a pilot of our first-ever Cyber Wellness Program. The Cybersecurity Wellness Program is based on the award-winning book, Well Aware: Master the Nine Cybersecurity Habits to Protect Your Future by SMU’s CSO, George Finney. Well Aware helps make security easy by making security a habit.

As we all should now realize, cybersecurity is critical for success in our modern world, and learning to master your cybersecurity habits will not only help you to protect your company and your career but also your family and your future.

The nine cybersecurity habits are Continue reading Cyber Wellness Program Helps SMU Community Discover Its Strengths

University Moves to Restrict Common Words for Passwords

Password iconIn an effort to strengthen password security, starting December 19, 2022, any new password may not contain all or part of the user’s account name, common passwords, or words related to an SMU campaign that are vulnerable to password-guessing attacks. Continue reading University Moves to Restrict Common Words for Passwords

Duo Mobile Ends Support for Android 8/9 and iOS 13

DuoOver the past several years, we have begun to rely heavily on Duo Security for our Two-Factor Authentication. With the ending of support for SMS and Phone Callback verification this year, the Duo Mobile app has become our preferred method of authenticating with our services. Because of that, changes to the app impact us all, and we want you to be aware that effective February 9, 2023, Duo Mobile will no longer support Android 8, Android 9, and iOS 13. Due to this change, we highly recommend the SMU community upgrades their devices’ operating systems by February 1, 2023. Continue reading Duo Mobile Ends Support for Android 8/9 and iOS 13