Security Advisories provide timely information and recommended actions for cybersecurity threats, vulnerabilities, and incidents affecting College systems or users.
Scammers are targeting District students with fake remote job offers and counterfeit checks. Learn how to recognize these scams, prevent financial loss or identity theft, and report suspicious messages.
Warns the District community about an active phishing campaign, tracked as EvilTokens, that abuses the Microsoft device sign-in flow to capture Microsoft 365 access tokens even when multifactor authentication is completed. Explains how to spot the attack, what to do, and how to report a suspected compromise.
An active phishing campaign is targeting California Community College districts with fake SharePoint and OneDrive file-share notifications. The email itself comes from Microsoft, so it passes spam filtering, but the shared document contains a link that steals your password. Use the checklist in this advisory before opening any shared file.