Security Advisories provide timely information and recommended actions for cybersecurity threats, vulnerabilities, and incidents affecting College systems or users.

Articles (3)

Pinned Article Security advisory: Fake job offers and fraudulent checks targeting students

Scammers are targeting District students with fake remote job offers and counterfeit checks. Learn how to recognize these scams, prevent financial loss or identity theft, and report suspicious messages.

Security advisory: Device code phishing targeting Microsoft 365 accounts (EvilTokens)

Warns the District community about an active phishing campaign, tracked as EvilTokens, that abuses the Microsoft device sign-in flow to capture Microsoft 365 access tokens even when multifactor authentication is completed. Explains how to spot the attack, what to do, and how to report a suspected compromise.

Security advisory: Watch for fake SharePoint and OneDrive file-share phishing emails

An active phishing campaign is targeting California Community College districts with fake SharePoint and OneDrive file-share notifications. The email itself comes from Microsoft, so it passes spam filtering, but the shared document contains a link that steals your password. Use the checklist in this advisory before opening any shared file.