Cybersecurity Hub

MRU Cybersecurity Newsletter archives Jan 4, 2019 to Oct 25,2019

MUST READ

- SIN number scammers calling MRU employees

CYBERSECURITY EVENTS

- Movie Screening - 21st Century Hacker, Oct 29
- Savvy Surfers - beating cyberfraud, Oct 30

Contest entry code: 6nltw2

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for emails about:

- Bank payments

Stop and think before you click.

COMPROMISED & FAKE APPS

If you have one of these apps, you may have a virus on your device.

- 17 apps in the Apple App Store infected with malware

Avoid fake apps, only download ones with good reviews from reputable sites.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- NordVPN

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Alexa & Google Home devices leveraged to phish and eavesdrop on users
- Fake login pages mimic the real thing giving you no clue you have been compromised
- How to replace each Google service with a more privacy-friendly alternative
- Samsung Galaxy S10 fingerprint reader beaten by $3 gel protector

CYBERSECURITY EVENTS

Staff and faculty who participate in cybersecurity events earn contest entry codes for the Cybersecurity Challenge. Each code gives you one chance to win a $250 Best Buy gift certificate.

- Hack the Box - Escape Room Oct 8 & 22
- What the Hacker Sees - Lunch n Learn Oct 9


DATA BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Words with Friends

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Google brings incognito mode to Maps
- WhatsApp bug allows access to content, users should update
- Google launches Password Checkup security tool
- Scammers using Google Alerts to spread malware, fraud


MUST READ

- The Cybersecurity Challenge begins October 1

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for emails about:

- Chase Bank Claim
- Amazon membership status
- Instagram copyright infringement


Stop and think before you click.

COMPROMISED & FAKE APPS

If you have one of these apps, you may have a virus on your device.

- AdBlock Chrome Extension
- UBlocker Chrome Extension

Avoid fake apps, only download ones with good reviews from reputable sites.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Chegg
- DoorDash

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Ransomware: 11 steps you should take to protect against disaster
- Banks blaming customers for etransfer fraud. Here is how to protect yourself
- How to protect yourself from ransomware using Windows 10

MUST READ

- Fake email from Tim Rahilly arriving in spam folders

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for emails about:

- Updating your Amazon account

Stop and think before you click.


SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Lumin PDF

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Apps give your personal information to Facebook.
- LastPass bug leaks credentials
- How to practise good social media hygiene
- Former hacker warns against password reuse

MUST READ

- Campuses seeing the 'trusted friend" credential stealing attack

Trust and intimacy are not dependent on you sharing your password.

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for emails about:

- Order confirmations from Staples

Stop and think before you click.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Facebook
- Foxit
- Yves Rocher
- Monster.com

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Police warn parents of apps kids should avoid as they head back to school
- Spam In your Calendar? Here's What to Do.
- Millions of Android phones vulnerable to phishing attacks
- Fraudsters deepfake CEO's voice to trick manager into transferring $243,000
MRU Cybersecurity Newsletter

MUST READ


- Basic IT Security Awareness 2019 training course coming down

COMPROMISED & FAKE APPS

If you have one of these apps, you may have a virus on your device.

- CamScanner
- Idea Note
- Beauty Fitness

Avoid fake apps, only download ones with good reviews from reputable sites.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Hostinger

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Fraudsters preying on Telus customers impacted by major email outage
- Travel and transportation industry can be a gold mine for hackers
- iPhone hack attack: Hackers placed 'monitoring implants' in iPhones
- How to keep spam from invading your Google Calendar
MRU Cybersecurity Newsletter

MUST READ


- MRU employees receiving email requests over the phone

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for emails about:

- Instagram

Stop and think before you click.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Alberta Health Services
- MoviePass
- Luscious

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Scammers use bogus search results to fool voice assistants
- Don't upload files to free malware scanning websites
- Fake VPN and office software website spread banking trojan
MRU Cybersecurity Newsletter

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for emails about:

- Mailchimp billing dispute
- Microsoft unusual sign-in activity


Stop and think before you click.

COMPROMISED & FAKE APPS

If you have one of these apps, you may have a virus on your device.

- 3Fun

Avoid fake apps, only download ones with good reviews from reputable sites.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Canva
- Poshmark
- StockX
- Choice Hotels
- Chegg


Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Boeing 787 jetliner code found sitting on the internet
- Delete Pet Chat from your child's LeapPad
- Patch your internet-connected printer
- Humans reviewing Facebook Messenger audio
MRU Cybersecurity Newsletter

MUST READ


- MRU targeted by phone

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for emails about:

- LinkedIn

Stop and think before you click.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- CafePress
- Club Penguin

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Smart TVs: Another way for attackers to break into your home
- The risk of weak online banking passwords
- What, when and how to backup
- Don't fall for fake Equifax settlement sites, warns FTC
MRU Cybersecurity Newsletter

MUST READ


- No, your password is not going to expire

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for emails about:

- Equifax

Stop and think before you click.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- CapitalOne

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Beware phony gift card email scams: Here's why attachers love using them
- Humans hear the private info Siri accidentally records
- Browser plug-ins peddled personal data from over 4m browsers
- IoT home security camera allows hackers to listen in over HTTP
MRU Cybersecurity Newsletter

MUST READ


- How to create emails that don't look malicious
Check out the trailer for the Netflix documentary on Cambridge Analytica which claims to have 5000 data points on every American.

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for emails about:

- Office 365
- LinkedIn
- WeTransfer

Stop and think before you click.

COMPROMISED & FAKE APPS

If you have one of these apps, you may have a virus on your device.

- WhatsApp

Avoid fake apps, only download ones with good reviews from reputable sites.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Armor Games
- GameSalad
- Stronghold Kingdoms

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Laurentian University donors targeted by scammers
- A Google exec admits the ugly truth about the smart home
- Incognito mode won't stop porn sites from sharing your preferences with Facebook, Google and Oracle
MRU Cybersecurity Newsletter

MUST READ


- Scammers targeting MRU getting very creative

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for emails about:

- Payment receipts

Stop and think before you click.

COMPROMISED & FAKE APPS

If you have one of these apps, you may have a virus on your device.

- FaceApp Pro

Avoid fake apps, only download ones with good reviews from reputable sites.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Animoto
- Slack
- Roll20

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Rogue Android apps ignore your permissions
- What you need to know before using FaceApp
- 93% of porn sites leak data to a third part
MRU Cybersecurity Newsletter

MUST READ


- Cybersecurity training deadline extended to August 31, 2019

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for emails about:

- OneNote

Stop and think before you click.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Orvibo

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Crave that Instagram verified badge? Don't fall for this login-stealing scam
- University of Ottawa student news site nearly wiped off Internet
- Just for fun, The Passive Aggressive Password Machine
- Amazon Alexa keeps some data even after it is deleted
MRU Cybersecurity Newsletter

MUST READ


- MRU impersonators are spoofing real email addresses

COMPROMISED & FAKE APPS

If you have one of these apps, you may have a virus on your device.

- Scary Granny ZOMBYE Mod: The Horror Game 2019

Avoid fake apps, only download ones with good reviews from reputable sites.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Emuparadise
- Evite



Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- YouTube Queue Chrome extension hijacks search results
- Protect your online identity with these 5 safeguards
- How spammers use Google services
- Protect yourself from holiday and ticket fraud
- Update your Amcrest security camera
MRU Cybersecurity Newsletter

MUST READ


- New email scam impersonates MRFA president
- Another Canadian university targeted by MacEwan-like scam
- Fake benefits enrollment email arriving in MRU inboxes
Remember to lock your mobile devices.

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for emails about:

- Office 365 file deletion alerts
- Encrypted message from Microsoft

Stop and think before you click.

COMPROMISED & FAKE APPS

Found in Google Play Store, 238 applications containing malware. Check the list to see if you have one of these apps.

Avoid fake apps, only download ones with good reviews from reputable sites.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Desjardins
- WeTransfer
- Flipboard


Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- You'd better change your birthday - hackers may know your PIN
- Update your Evernote Web Clipper Chrome extension
- Australian National University discovers hackers have been in their network for 19 years
- The previous owner of your used Nest cam can spy on you.
- Dell SupportAssist bug leaves millions of PCs vulnerable
MRU Cybersecurity Newsletter

MUST READ


- Newsletter is on pause

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Canva
- Flipboard

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Facebook hacker is a dog...an actual dog
- Accounts that should have 2 factor authentication enabled
- How to stay cybersafe this summer
- Researchers uncover Nokelock's horrible security
MRU Cybersecurity Newsletter

MUST READ


- Reply to emails cautiously

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for emails about:

- Threatening legal action

Stop and think before you click.

COMPROMISED & FAKE APPS

If you have one of these apps, you may have a virus on your device.

- Trezor Mobile Wallet
- Coin Wallet - Bitcoin, Ripple, Ethereum, Tether


Avoid fake apps, only download ones with good reviews from reputable sites.

OTHER NEWS


- How a typo caused Edmonton Economic Development to loose $375, 000
- How to keep your data safe from Facebook while using Facebook
- Hackers' forum gets hacked, Karma is sweet
- Is it spam or is it phishing?
MRU Cybersecurity Newsletter

MUST READ


- Job scam landing in MRU inboxes
- U of C journal impersonated by scammers
Sextortion email from yourself? It doesn't mean you've been hacked.

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for emails about:

- Tracking package delivery

Stop and think before you click.

COMPROMISED & FAKE APPS

If you have one of these apps, you may have a virus on your device.

- Ever
- WhatsApp

Avoid fake apps, only download ones with good reviews from reputable sites.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Forbes magazine

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Amazon's Echo for kids saves information, even when asked to forget
- Types of backup and five backup mistakes to avoid
- Etransfer isn't as secure as you think it is
- Alexa is listening, recording and storing more information than you thought
MRU Cybersecurity Newsletter

MUST READ


- Another Rahilly phish making the rounds

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for emails about:

- Avengers: Endgame
- Microsoft

Stop and think before you click.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Freedom Mobile

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- 60 min investigates ransomware and how to prevent it
- U of C online bookstore victim of skimming scam
- Limit how long Google keeps your data
- Airbnb host jailed for recording guests
MRU Cybersecurity Newsletter

MUST READ


- Another Rahilly phish making the rounds

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for emails about:

- Avengers: Endgame
- Microsoft

Stop and think before you click.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Freedom Mobile

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- 60 min investigates ransomware and how to prevent it
- U of C online bookstore victim of skimming scam
- Limit how long Google keeps your data
- Airbnb host jailed for recording guests
MRU Cybersecurity Newsletter

MUST READ

- Campus receiving fake CRA calls

- No we don't have a secret email service

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for emails about:

- Game of Thrones

Stop and think before you click.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Bodybuilding.com
- WiFi Finder
- Facebook data leak: Province-by-province breakdown of affected Canadians

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Internet Explorer vulnerability lets hackers steal your data even if you don't use it
- JetBlue starts using facial recognition software to board passengers
- How to control your privacy for Google Services
- What to do with email in your Spam folder
Mount Royal University Logo
MRU Cybersecurity Newsletter

MUST READ


- Impersonators have figured out we have a new president

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for emails and messages about:

- Instagram 'Nasty List'

Stop and think before you click.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Outlook, Hotmail, MSN and other Microsoft web mail services

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Authenticator apps, the good, the bad and the ugly
- Hoax! Nope, hackers aren't posting invisible sexual videos on your wall
- Android 7.0+ phones can now double as Google security keys
- The most common phishing email subject lines
Mount Royal University Logo
MRU Cybersecurity Newsletter

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for emails about:

- Google 2FA

Stop and think before you click.

COMPROMISED & FAKE APPS

If you have one of these apps, you may have a virus on your device.

- Facebook apps expose user's data

Avoid fake apps, only download ones with good reviews from reputable sites.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- DataCamp

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Amazon employees listen in to your conversations with Alexa
- Facial recognition: Apple, Amazon, Google and the race for your face
- Game of Thrones is the most popular malware lure
- How to enable two-factor authentication on Instagram
Mount Royal University Logo
MRU Cybersecurity Newsletter

MUST READ


- Another variation of the MRU imposter phishing email

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Toyota

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- ASUS updates full of malware
- Identity thieves want your child's personal data
- How to enable 2FA on LinkedIn
- Georgia Tech stung with data breac
Mount Royal University Logo
MRU Cybersecurity Newsletter

MUST READ


- MRU inboxes receive malicious Google Drive file share

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for emails about:

- Boeing 737 Max tragedy
- Child porn accusations
- Amex
- Netflix


Stop and think before you click.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- MyPillow
- Amerisleep
- 8fit
- Hautelook

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Two-Thirds of Android Antivirus Apps Are Total BS
- Stolen email credentials being used to pry into cloud accounts
- If it seems to good to be true, it is.
- Facebook stored passwords in plaintext - change yours now
Mount Royal University Logo
MRU Cybersecurity Newsletter

COMPROMISED & FAKE APPS

Avoid fake apps, only download ones with good reviews from reputable sites.


SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Houzz

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Don't want to rely on a phone for 2FA? Use a security key
- How to stop your iPhone from tracking you
- Fake Facebook login pages targeting iOS users
- Hackers break into system that houses college application data
Mount Royal University Logo
MRU Cybersecurity Newsletter

MUST READ


- How to print sensitive documents on public printers
PHISHING EMAILS
Give your emails 100% of your attention. Watch out for emails about:

- Netflix membership renewal

Stop and think before you click.
SECURITY BREACHES
Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- ShareThis

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Facebook abusing phone numbers used for 2FA
- Outdoor Tech's Chips 2.0 speakers lets you eavesdrop
- Hackers creating perfect copies of the Facebook login prompt
- Enabling 2FA on LinkedIn

Mount Royal University Logo
MRU Cybersecurity Newsletter

MUST READ


- The MRU impersonators are ramping things up


What is two-factor authentication?

COMPROMISED & FAKE APPS

If you have one of these apps, you may have a virus on your device.

- Android battery optimization tool

Avoid fake apps, only download ones with good reviews from reputable sites.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- TurboTax

Keep your accounts safe, use a unique password for each one.

OTHER NEWS


- Why enabling two-factor authentication is more important now than ever
- Google's Nest Guard Has a Microphone It Forgot to Mention
- The Momo Challenge urban legend - what on earth is going on?
Mount Royal University Logo

MRU Cybersecurity Newsletter


Criminals are getting more and more sophisticated. Find out how to protect yourself against pretexting.
SECURITY BREACHS
Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- EyeEm
- MyFitnessPal
- MyHeritage

Keep your accounts safe, use a unique password for each one.

ALERT: If you have traveled to Arizona, North Dakota or Minnesota between January3, 2019 and January 24, 2019 your credit card may have been compromised. Check the list of affected hotels and restaurants and keep an eye on your credit card statement.
OTHER NEWS

- Fake Norton Security scam loading malware onto computers
- Mobile phone montion sensors can be used to crack your PIN
- How to stop Apple and Google from tracking you
Mount Royal University Logo

IT Security Newsletter


MUST READ

- Check the email address before responding to an email

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for:

- Requests from your boss to reschedule a board meeting

Stop and think before you click.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Houzz

Keep your accounts safe, use a unique password for each one.
OTHER NEWS
- Chrome can now tell you if your password is part of a data breach
- Jack'd dating app is showing users' intimate pics to strangers
- Siri shortcuts vulnerable to abuse
Mount Royal University Logo

IT Security Newsletter

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for:

- Voicemail links

Stop and think before you click.

COMPROMISED & FAKE APPS

If you have one of these apps, you may have a virus on your device.

- Photo editing apps on Google Play

Avoid fake apps, only download ones with good reviews from reputable sites.
OTHER NEWS

- Protecting yourself against cyber crime
- 750 million newly compromised credentials added to data breach list
- Someone with your name could hurt your job prospects
- Prevent tracking with Firefox's new privacy controls
Mount Royal University Logo

IT Security Newsletter


MUST READ

- Hard to detect MailChimp phish hits MRU

SECURITY BREACHES


Have I Been Pwned has found a huge collection of compromised credentials sitting on the web. Read the article, Are your credentials part of the latest data breach? to find out if you are affected. Change your password if you are.

What can you do to determine if your credentials have been compromised?
OTHER NEWS

- Bell wants to track its customers
- Employees of Witchita State University fall victim to phishing email and have their paycheck deposits diverted
- WhatsApp user gets a new phone number and the messages of the previous owner
- Cyber security lecture by Brigadier-General coming to MRU
Mount Royal University Logo

IT Security Newsletter


MUST READ

- Do you know how much of your personal information is on the web?

COMPROMISED & FAKE APPS

If you have one of these apps, you may have a virus on your device.

- FlashLight, HZ Permis Pro, Arabe, Win7imulator, Win7Launcher, Flappy Bird or Flappy Birr Dog

Avoid fake apps, only download ones with good reviews from reputable sites.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Reddit

Keep your accounts safe, use a unique password for each one.
OTHER NEWS
- How to navigate the tricky balance between security and convenience
- The 2019 Consumer Electronics Show - Home items are getting smarter and creepier, like it or not
- Alexa may be recording more than you realize
- Apps sending your data to Facebook even if you aren't a user
Mount Royal University Logo

IT Security Newsletter

A little fun to start the year off right. Watch James Veitch toy with a scammer.

PHISHING SCAMS

Give your emails 100% of your attention. Watch out for:

- Netflix payment update emails
- Account compromise notifications

Stop and think before you click.

SECURITY BREACHES

Change your password if you use one of these websites or applications. Watch for signs of identity theft.

- Town of Salem

Keep your accounts safe, use a unique password for each one.
OTHER NEWS
- Canadian hacker tells owner how to secure his security camera
- Most popular and insecure passwords of 2018
- A new year, a new Facebook hoax