Topic of the Week
Welcome to our "Topic of the Week" section, where we spotlight key issues in security, privacy, audit, risk, and compliance. Each week, we look into a relevant topic, offering insights and strategies to help navigating the ever-evolving landscape of regulations and best practices
Permission to break everything
Cybercriminals have taken a classic security feature, CAPTCHAs, and turned it into a clever trap. The ClickFix attack tricks users into proving that they are “not a robot” by following keyboard commands that secretly download malware onto their devices. This particular scam usually starts with a website popup that looks something like this:
Home may be your safe space, but is it a secure space?
Technology continues to advance, and humans continue to find ways to make technology do more work for them. Automation can be used to enhance efficiency, save time, and decrease effort. Implementing automation in your home is growing in popularity since it may increase comfort in our homes, decrease effort in keeping up with them, and become more efficient so we have more time to do things we enjoy. In my home, I have an automated vacuum (that also can mop) and an automatic litter box.
Privacy, you say? Don't know her
In an age where everything is connected and every action online is tracked, privacy has become a rare commodity. But lately, it seems like even that brief notion of privacy is slipping through the cracks, especially when companies, big and small, are making decisions that lean heavily toward profit at the cost of your privacy.
Spring Cleaning - Checking your Drive Space for Sensitive Data
With Spring among us, it is time for a good reset. While you are going through spring cleaning at home, consider also doing some spring cleaning at work and within your Google Drive. All University of Maryland faculty and staff have access to Google Drive and likely utilize this on a daily basis. Google Drive makes file management and collaboration an easy process. While the use of Google Drive is encouraged, it is important to recognize that not everything can be done through or stored on Google Drive.
Be Ethical, my friend
In an era of rapid technological and societal change, traditional ethical approaches to ethics no longer suffice. Universities, now more than ever, collect vast amounts of personal data, ranging from academic performance and demographic information, to health records and financial status. As this data is utilized for services, research, and regulatory compliance, it raises crucial ethical questions, specifically regarding the release of personal information without explicit consent.
Newly Proposed Updates to the HIPAA Security Rule
2025 is starting off with a bang, with the US Department of Health and Human Services (HHS) issuing proposed updates to the HIPAA Security Rule. The HIPAA Security Rule has been in place since 2003 and saw its last round of updates in 2013, making it long overdue for new updates given the changes in technology since then. The proposal draft is a whopping 393 pages, which is indicative of how robust these updates will be.