Category Archives: in the news

RMU Grad Torrie McLaughlin is one of the New Faces of IBM Z

IBM is producing a set of videos that are quick conversations with a new generation of coders and creators on the mainframe.  Watch RMU alumna Torrie McLaughlin, who works on the mainframe at a large financial institution, describe how COBOL is a key asset to her professional toolkit.

TSC Helps Deliver Supplies for Hurricane Harvey Victims

On Tuesday, September 12th, members of the Top Secret Colonials helped prepare supplies for delivery to victims of Hurricane Harvey in Texas. The members helped package dozens of boxes filled with the supplies collected in Wheatley. They delivered the supplies to the Chartier’s Volunteer Fire Department. From there, the boxes were placed on a truck that is headed for Texas.

Pictures of the items and the delivery are shown below.

This slideshow requires JavaScript.

Pictures Causing Your Identity To Be Stolen

A recent thing in news, is how taking pictures with either your hands up or having the peace sign up and your finger prints facing the camera can be a dangerous thing if you post them. Most people are out having fun with their friends and are taking a fun, simple photos but with the way the world is now you have to think twice before taking the picture or posting it.

If the lighting and focus is just right then the they hackers can easily recreate your finger prints as long as it 10 feet from the person. It is hard to believe that we have reached the point where we have to be worried about our finger prints being taken from a photo that is being posted. But as time keeps going on, we need to be aware of these things and we need to be aware that these problems do exist and we all need to second guess before taking and posting pictures.

 

Russian Hacking Panel

The University of Pittsburgh will be hosting a panel on Russian Hacking on Thursday, February 2nd, from 1:30pm to 4:30pm. At this event, several panelists will discuss a variety of topics, including: Russian activities in cyberspace, U.S. and Russian views on cyber tool usage, U.S. response to Russian activities, and Russia’s possible effect on the U.S. presidential election.

There will four panelists at this event:

  • Andrei Soldatov, a Russian investigative journalist and security services expert
  • Ellen Nakashima, a national security reporter for The Washington Post
  • Luke Dembosky, a former Deputy District Attorney General for National Security and former U.S. Department of Justice representative at the U.S. Embassy in Moscow
  • Keith Mularski, a Supervisory Special Agent for the FBI in Pittsburgh

The event will be streamed live at law.pitt.edu/cybertalk. Students can only attend the event at the University of Pittsburgh if they have already registered for it. Registration for the event closed yesterday, January 30th. However, everyone is welcome to watch the event live through the link above.

For more information, there is a flyer posted below.

Russian Hacking Panel Flyer

Alert: Employment Scams Targeting College Students

The Internet Crime Complaint Center (IC3) has issued an alert on employment scams that target college students.  The scam involves phony job opportunities that may be advertised via college employment websites or sent via email (targeting bank accounts).  For additional information and examples of phony emails, please see here.

Don’t fall for this ‘highly effective’ Gmail scam

For several months, a phishing scam has been tricking Gmail users into sharing their passwords. Recently, the security company WordFence released an alert about this scam.

The attack starts when the attacker sends an email to the victim’s Gmail account. The email address of the “sender” usually belongs to someone that the victim knows; however, the sender’s account has already been compromised by the attacker. The email contains what appears to be an image for the victim to click on.

When the victim clicks on the “image”, they are taken to a new tab which prompts for their Gmail account information. Once the victim signs in on this page, their account is compromised. The attacker then has access to the victim’s emails and personal documents. Once the attacker has access to the victim’s account, they will use this account to send the scam to more victims.

What makes this scam “highly effective” is that it is uses email addresses of people that the victim knows. Also, the fake Gmail sign-in page appears to be legitimate, containing the Google logo and normal entry fields for username and password.

In order to prevent yourself from becoming a victim of this scam, it is important to note the following:

  • Although the false attachment contains “accounts.google.com” in its URL, it also has “data:text/htm” at the beginning, which is not found on a normal Gmail URL.
  • When signing into any service, you should check the browser bar to verify the protocol and hostname. The URL should begin with “https:” and there should be a green lock icon next to the URL.
  • Gmail users can also enable two-factor authentication or “2-step verification” to make their account more secure.

For more information: Don’t fall for this ‘highly effective’ Gmail scam and WordFence Article

Beware, iPhone Users: Fake Retail Apps Are Surging Before Holidays

In the past few weeks, there have been hundreds of fake retail and product applications in Apple’s App Store. The fake apps have pretended to be companies such as Dollar Tree, Foot Locker, Nordstrom, and Dillard’s. A company that tracks new shopping apps, Branding Brand, reported a large increase in these fake applications in the past few weeks.

The apps are being created to trick Black Friday shoppers into clicking them. Some apps seem to be harmless, just displaying pop-up ads whenever users click on them. Others, however, are dangerous because users can have their credit card information stolen if the app asks them to input it. Also, some of the apps can contain malware that can steal personal information and even lock the victim’s phone.

The fake apps came from developers in China; they were somehow able to get past Apple’s review process for new apps. Apple’s app screening process is less strict than Android’s; Apple focuses more on blocking malicious software and does not routinely examine the thousands of new apps that are sent to them everyday. It is important for brands and companies themselves to search for and report these fake apps, similar to how they search for and report fake websites. Last week, however, Apple did remove hundreds of fake apps after an article was published about the apps. A spokesperson for Apple claims that they have set up ways for customers to report fake apps. In September, Apple started to look through their two million apps to remove fake and unnecessary ones. Despite this, new fake apps continue to appear.

A recent example of a fake app was one called Overstock Inc. – apparently named to let customers believe that it was the real company app for Overstock.com. The developer of the app is the Chinese company Cloaker Apps. The CEO of Cloaker, Jack Lin, claims that the company only provides the back-end technology for the apps; they do not investigate their clients. However, not even Cloaker is what it seems; the company’s website states that its headquarters is in the middle of Facebook’s campus in Menlo Park, California. When Jack Lin was first interviewed, he claimed that the company only had offices in China and Japan. When asked about the office in California, he claimed to have “tens of employees” there.

China is, by far, the biggest source of fake applications. Many of the fake apps have red flags to show that they are not real, including: nonsensical menus in broken English, no reviews, and no history of previous versions of the app. So far, thousands of individuals have apparently fallen prey to the newest fake apps. However, in most cases, no serious problems have occurred. The fake apps usually target companies either with no apps or multiple apps. Some have even used Apple’s paid search ads to put their fake apps at the top of the search results.

Fake apps on Apple are a new problem, occurring more commonly in the past few months. However, with Black Friday soon approaching, it is important to remember to check the applications that you are planning to download. Also, if possible, try to use alternative methods to applications that ask for banking or personal information. For example, try to use the company’s website on your laptop or computer; also, remember to check the security on the website itself. Criminals are obviously going to take advantage of whatever situation becomes available to them. Therefore, you should always be careful of what you click or download on your phone or computer.

Article Link: Beware, iPhone Users