412-624-HELP

News & Alerts

Security Alerts
A recent breach of a third-party vendor’s CRM system has exposed business contact information held by several vendors in Pitt’s portfolio, increasing the risk of phishing and social engineering attempts. No Pitt systems or student data are known to be involved. If your unit works with affected vendors, please review the guidance below.1. Know how to spot and report phishing scams.
Service Announcements
Beginning Thursday, July 9, InCommon, the consortium that provides Digital Certificates for the University, is transitioning from Sectigo to a new certificate platform, CertiNext. Existing certificates remain valid through their expiration dates, and TLS server certificates remain available without change.
In the News
Pitt Digital helps organize an Air Force Association CyberCamp, a free, weeklong cybersecurity program for high school students now in its 10th year at Pitt. More than 1,400 students have completed the camp since its launch, and this year's program expanded for the first time to include Pitt Greensburg alongside the Pittsburgh campus event. Instructors use curriculum from the national CyberPatriot program and emphasize the logic, reasoning, and ethics behind cybersecurity skills — with an eye toward addressing the hundreds of thousands of unfilled cybersecurity jobs nationwide.
Service Announcements
On Friday, June 26, Pitt Digital will automatically update GlobalProtect VPN to version 6.2.8 on all University Windows and Mac devices. This update brings enhanced security and improved stability to your VPN experience.What to expect: 
PantherBytes Blog
If you’re still using the same password you made up years ago, this is your sign that it’s time for an upgrade. In today’s digital age, we’re responsible for more password-protected accounts than we’d like to be, which makes it easy to take shortcuts. But those shortcuts have consequences — namely, putting your data at risk.
Security Alerts
Pitt Digital will update the University’s PittNet Wi-Fi security certificate at 9 p.m. on Saturday, June 20, as part of our annual renewal to maintain wireless security. Wi-Fi services will remain uninterrupted during the renewal.
Service Announcements
In response to customer feedback and to further enhance security, Pitt Digital is introducing two enhancements on June 10 that will make it simpler and more convenient to recover a forgotten password and log in.
Security Alerts
Timely updates and reboots are essential to maintain the security and integrity of the University’s network. Please take note of the following updates and guidelines in three areas related to cybersecurity:1. Install New Microsoft Patches and RebootToday Microsoft released monthly security updates that affect a wide range of products. It is crucial to promptly identify and install these updates to protect your systems from vulnerabilities. Please adhere to the following installation timelines:
Security Alerts
Timely updates and reboots are essential to maintain the security and integrity of the University’s network. Please take note of the following updates and guidelines in three areas related to cybersecurity:1. Install New Microsoft Patches and RebootToday Microsoft released monthly security updates that affect a wide range of products. It is crucial to promptly identify and install these updates to protect your systems from vulnerabilities. Please adhere to the following installation timelines:
PantherBytes Blog
Every time you tap Approve on a Duo push notification, you’re doing more than logging in — you’re confirming that you’re you.
PantherBytes Blog
If you’re a person with an email address, you’ve probably received a phishing scam. And while there are plenty of obvious signs to watch out for, modern scams have evolved to be even trickier than their typo-ridden predecessors.
Security Alerts
Timely updates and reboots are essential to maintain the security and integrity of the University’s network. Please take note of the following updates and guidelines in three areas related to cybersecurity:1. Install New Microsoft Patches and RebootToday Microsoft released monthly security updates that affect a wide range of products. It is crucial to promptly identify and install these updates to protect your systems from vulnerabilities. Please adhere to the following installation timelines:
Service Announcements
Duo has announced that individuals using Duo Mobile app versions older than 4.85.0 will need to update to the latest version before Tuesday, March 31, to ensure uninterrupted use of Duo multifactor authentication. This update is necessary because Duo is enhancing security by phasing out certain types of digital certificates.Pitt Digital has identified individuals using older versions of the Duo Mobile app and will be contacting them directly via email to ask them to take the following actions:
Service Announcements
Effective Feb. 11, Pitt Digital is updating the requirements for University Computing Account passwords to better protect the Pitt community and align with security best practices. With the new 15-character minimum, we encourage you to think of your password as a passphrase—a memorable sequence of words that's easier to remember than a traditional password. Key changes:
PantherBytes Blog
You probably wouldn’t hand a stranger your wallet, share your Social Security number over the phone, or leave your front door unlocked when you leave for the day. But online, many of us take risks with our personal information that we’d never consider in real life and often without realizing it.
In the News
Congratulations to John Duska, Pitt's chief information security officer, on being named one of the "10 CISOs to Watch in Pittsburgh" by CISO Whisperer, a cybersecurity news and analysis publication. CISO Whisperer recognized Duska for leading security operations across one of the region's largest university systems, noting his focus on resilience, research protection, and campuswide cyber readiness supporting both academic and healthcare operations.
In the News
The University approved two new policies aimed at enhancing identity theft prevention and information security. The Identity Theft "Red Flags" policy aligns with federal requirements to detect and address warning signs of identity theft, particularly concerning student accounts linked to federal aid. Additionally, the Information Security Policy establishes a comprehensive framework to protect the University's data, including student records, research data, and health information, by consolidating existing practices and establishing operational standards.
Digital Risk Bulletin
Given the often-daunting nature of digital communications, particularly within academic circles, a newly unveiled, Pitt-centric digital tool that uses research keywords to help faculty find cross-disciplinary collaborators and their projects hits the utilitarian sweet spot for researchers like Rob Rutenbar.
Success Stories
Pitt Digital successfully transitioned to a new security system, Microsoft Sentinel, within 68 days. This change was facilitated by Cribl tools, which helped organize and manage security data efficiently. This transition not only streamlined their data processes but also resulted in significant cost savings. The university's IT team benefited from Cribl's user-friendly interface, making it easier for them to manage over 1,000 servers and respond to security threats more effectively.
In the News
John Duska, Chief Information Security Officer (CISO) for the University of Pittsburgh, has been recognized as a Top 100 Accelerated CISO Award Winner, a prestigious honor that highlights emerging security leaders with less than five years in the role. The merit-based program celebrates those who have demonstrated exceptional skill, innovation, and a commitment to advancing the cybersecurity industry.
Success Stories
Signing up hundreds of participants to complete a research survey in just a few days is something that most researchers only dream of. One group at Pitt did just that after offering a $10 Amazon gift card incentive. Unfortunately, it was too good to be true. The researchers were the victims of a bot attack.