Advisories & Alerts

Phish Alert - Please Verify Your Yorku Account

A confirmed phishing email with the subject line "Please Verify Your Yorku Account" was sent to a number of mailboxes. Clicking on the provided link will redirect users to an external site hosted on google forms. If you clicked on the link and provided your credentials, please consider your account as compromised. Change your password […]

Job Scam Alert - Open Job Position

Please note that York will NEVER request for passwords, Duo passcodes or other personal information via email or Google Form.  Below is the latest job scam email that was sent to various mailboxes.    The Information Security team has taken action to remove the fraudulent messages. If you receive similar messages, please report it immediately […]

Phish Alert: York University Application Form

Scammers are using compromised accounts to send emails with fake job posting looking for Personal Assistant. Please note that York will NEVER request for passwords, Duo passcodes or other personal information via email or Google Form.  If you texted the requested information to +1 (215) 828-9264, do NOT accept the DUO PUSH, change your PY […]

Job Scam Alert - "YorkU Personal Assistant" OR "Remote Personal Assistant" OR "Virtual Assistant Needed" OR "PA - Team Assistant"

Scammers are using compromised YorkU accounts to send fake job scam offering $550 or $650 USD weekly as a "YorkU Personal Assistant" OR "Remote Personal Assistant" OR "Virtual Assistant Needed" OR "PA - Team Assistant". Following through with the fraudulent employment offer will result in compromised of personal information and potential financial loss. An illustration […]

Advisory Notice - Microsoft Office Remote Code Execution Vulnerability (CVE-2023-36884)

Microsoft recently disclosed a zero-day vulnerability (CVE-2023-36884) which is currently being exploited in the wild. Attackers are coercing users via social engineering phishing techniques into opening a specially-crafted Microsoft Office document that could result in remote code execution. Even though Microsoft Defender for O365 provides protection against attachments designed to exploit CVE-2023-36884, we ask the […]