001team. There is a lot to cover. So, let us get this going. Hopefully, we can do it in the 1 hour and it is recording it looks like. Okay, good. Just wanted to make sure. So, good morning. Thank you for joining us this May. Uh I know uh a lot of schools are either wrapping up their year or have just recently wrapped up the year. Uh so uh thank you for making the time to join us uh for this month's uh CCF. [clears throat] Just a little bit of housekeeping. Uh the webinar is being recorded. Um recording and slides will be available a few days after the webinar ends at the TEA cyber security website. Uh chat has been turned off. Uh, if you have a question, please submit them in the Q&A and we'll
002address them either at the end or we'll follow up by email like we always do. Uh, duplicate login are not allowed and chat bots are not allowed. Uh, so if these are seen, the team will remove them. So if you have them on there, please turn them off and we appreciate your cooperation in that. Um, excuse [clears throat] me. Uh, here's the TEA team. Uh something that we added was to make sure that everybody is familiar with uh the TA team that helps uh in the K12 cyber security initiative and the other things that we do for security operations here at the agency. So my name is Daniel Ramirez. I am the chief information security officer here for TEA. Uh for those of you new to this, welcome. Uh I've been here since August. Uh
003so probably about 10 months now. um the cyber security initiative group. Uh we have Julia Shakroll who's the executive director IT administration and compliance. We have Laura Coffer who is our DCS contract manager and the K12 cyber security project lead. We have Susan Bane who is our cyber security governance risk and compliant analyst. And we have Desiree Odo who is our cyber security governance risk and compliance analyst. Uh in our security operations team we have Sam Miller who was a cyber security operations manager and Miles uh I can never say your last name. Miles apologies Mucha uh who is our cyber security operations associate. I really need to practice on that. So uh this is the entire uh security operations team here for the agency. Uh they are involved in everything uh security including the
004K12 initiative uh and putting together this presentation. Um for you that are new to uh the CCF, the cyber security creative forum uh is a monthly forum for Kato cyber security leaders and partners. Um aimed for type cyber security coordinators, our technology directors, the ESC's and the regional security operations centers. Uh the purpose is to gain insights from uh myself uh on everything security for the state or for the agency or for the schools. Uh we try very hard to uh provide actionable guidance to strengthen uh your cyber security program uh keep you informed on emerging threats, best practices and statewide initiatives. Um we do have a registration link uh for the CCF forum um that we can make available to you uh as part of this presentation later for those that want to share
005that with others who are currently not yet aware of the CCF. We'd like to grow membership. uh we think is a very valuable form of communication for all of our schools to make sure that they're aware of anything cyber uh for the state and anything that may impact the schools. Uh we do ask that you use your school email address and our personal addresses when registering. Uh we do not uh approve of the um uh addresses that we don't recognize from our school systems. Uh we also uh have a K2 cyber security listerve. Uh we are going to spark up again the cyber security newsletter. Um so it is it is we're kind of sweeping up that area and and reforming it. I I was informed that we used to have a little more activity
006in the list serve and it's kind of since dropped and so we're going to bring new life to that and have it as another means to communicate uh anything that we feel is important for the schools to know uh you know in case it happens between CCFs. Um also uh invite your co-workers and peers to join. Uh we want to make sure that everybody has the information uh regarding security for the state and for schools available as needed. Sometimes uh being able to uh take actionable um steps uh quickly is is important uh as threats have uh been reduced from zero days to now negative uh days uh thanks to AI and we'll talk about that probably a little later. [clears throat] Excuse me. Um, so I will be doing the housekeeping introductions which I've
007already started. Uh, and I will also be going over legislative updates and our cyber security advisories. Uh, Miles will go over emergency trends with us. Uh, the K12 initiative updates will be by me and Brent. Uh, and then I will then wrap it up with upcoming events. Um, and then our usual links to some information that may be of value to you guys. So, first off, legislative updates. There's not much to say since the last CCF. So, this slide will remain here because anytime that there is a legislative update that we need the schools to be aware of, it'll be in this area. Just want to remind folks that November 9th is when pre-filing begin. Uh then January 12th of next year uh is when the House and Senate convene. Uh March 12th is the
008last day to file bills. Uh and then May 30, 2027 uh is when the session is over. [clears throat] Some cyber security advisories uh the Canvas uh instructure security incident. So just really high level um the cyber security incident uh impacted Canvas LMS uh and it was reported in late April to early May of 2026. The activity was attributed to Shiny Hunters threat actor group known for large scale data expiltration. Uh and you'll see throughout this uh presentation that they've been very popular in many things. uh exposure of user data including names, email address, student IDs and platform messages is all that instructure has communicated publicly that was impacted. Um no indications that passwords or financial data or government identifiers were were compromised. Uh the impact uh organizations began receiving notifications on May 5th. Uh
009and the link there is for the official uh instructure updates that they provide uh on the onset page. They they did communicate that if your organization was uh part of the data breach that they would communicate with you uh and let you know uh you what what what information from your school was was lost if any. [clears throat] Excuse me. Um, so some risk considerations. So the exposure of contact and communication data increases the risk of fishing and impersonation attempts. So make sure that you tell uh your staff to be mindful of anything claiming to be from Canvas or instructure regarding having to change your your uh password uh because um we might see an increase in fishing uh and and things like that from Canvas or Instructure Fake sites. Uh thread actors often le
010leverage compromised data for follow on social engineering activity depending on what they learned from the data that they did capture. They can use that to create specific um emails and make it sound convincing especially if for some of the data that that they claim was um was lost included communications between students and teachers. So that might allow them to create uh targeted emails to our students claiming to be from a teacher. Uh so we need to make sure that we're mindful of that. Uh potential risk from reused passwords across systems. So we always uh have a you know the security best practice of not reusing passwords. Um so if if remind your staff that if they were using their district uh password in Canvas that they should be changing immediately even though uh Canvas suggested
011that there was no loss of that type of information. It's always best to error and um with caution and not leave it up to the well we found out later that that it it included passwords. So uh and also remind the staff not to reuse passwords. Uh anything from the district should not be used on any third party sites uh like Canvas um third party integration. So if your district has any type of API attachments or any any um learning tool interoperability uh that may be a weakness. now uh an additional attack vectors that can be used to leverage that. So be mindful of that. Uh organ or organizations should closely monitor communications from instructure uh to to assess the internal impact. And so like I said the the the link here is is where
012you can find additional information recommendations. So force password resets for administrative and impacted user accounts. Uh require unique password across all systems uh and accounts. Enforce MFA where wherever possible, especially for privileged users. Uh review and audit thirdparty integrations with Canvas LTI apps. Uh monitor account activity uh and communications for suspicious behavior. If your organization detects malicious activity involving its Canvas LMS environment, please report it to the Texas Cyber Command immediately uh through the incident response hotline, which the number is there on the screen. Uh they are trying to assess the issues that are being uh that are impacting the state as a whole. Uh and so you know you can use that to to inform the the state on any issues. Uh TA learn is hosted on on canvas. Uh and so we had
013a couple schools asking questions specifically about whether it was still safe or what TEA had done and and what the impact was. Uh so I wanted to provide uh an update specifically on TEA learn which again is is canvas hosted. So TA learn instance uh was reviewed following the uh camera security incident. No TA data exposure was identified. Uh the environment has been validated and cleared for continued use. Uh TA did implement additional safeguards to protect the data and connections. Uh recommended actions for our school systems is again uh same as we've already said is require and encourage password changes for all TEALN users. So if you have a student or a staff member uh who was using TA learn uh we recommend that they rotate their passwords uh for TA learn. Uh increased fishing
014and social engineering awareness may happen uh where you might get something and I think there was a couple schools that reported uh that they had received something from TA learn requiring uh their their password to be changed. Uh most of you guys should know how to get to the website. Uh, and so if you need to update your password, you should use the actual uh, URL link and not anything you receive via email. Uh, remind staff and students to not click on any unknown links and to verify unsuspected requests with your IT staff. Uh, reinforce credential hygiene. Never reuse school account passwords on personal websites. Third party or non-school systems, which includes TA learn or teal, etc. All school system passwords should be only for school systems specifically and not for anything third party, including
015anything from TEA. uh encourage the use of separate credentials for personal accounts uh because once again once one account is compromised that can lead to compromise of other of other areas. Uh key reminder while tea learn remains secure the broader uh incident increases risk of targeted fishing using known school related data. So, please keep an eye on uh on fishing uh emails uh and anything that your your team might be reporting to you regarding anything requesting tea learn or uh canvas related password resets. Keep those red flags up for now. Um since this is still very new, I wanted to give a quick update on the Flet software uh potential data breach. Uh I put potential there in red because Flet has said that it is not aware of the breach. The the the threat
016actors uh have not I guess proven uh that there was a breach and so the company does not say that there's a breach. So what we know a ransomware group called Shiny Hunters claimed a breach of Flet software on April 30, 2026. Uh they alleged access to 4 million sales salesforce records containing PII internal data. Uh it is an unverified claim. No confirmed breach or data leak. Uh no public statement or guidance from Flet to customers. No confirmed impact to specific school systems. Uh so Flet software is widely used by some schools districts for library content and resource management. Uh if validated, it could involve student staff data or system integrations. Uh so recommended precautions at this time is re review your fulllet system integrations. Uh anything single sign on or API access. Uh maybe
017rotate those. uh it's it's usually not a big lift to do those just as a precaution. Uh ensure MFA and credential hygiene for all staff accounts and again monitor for unusual activity tied to fulllet platforms. The bottom line that treated as a credible but unconfirmed thirdparty risk event uh and maintain heightened vigilance until further verified information is available. So again I'm not saying that they were breached. They have not flet has not confirmed the breach. All we're all we are doing is going by what was publicly been uh claimed uh by shiny hunters and that that that that they had data from folet. So just be mindful of that. Um the McGra Hill data breach also in April it's been a positive I'm sorry a successful campaign for uh shiny hunters. Uh so data exposed
018tied to sales was misconfiguration uh and so it was not a systems not a core systems compromise. So there was nothing wrong with McGrill with McGra Hills systems but something that they got through through Salesforce uh misconfiguration. Uh 13.5 million user records confirmed exposed the data set was over 100 gigabytes uh and has been publicly leaked. The data included emails, names, phone numbers, physical address uh inconsistent across most records is what I was able to find online. Uh it was attributed to the Shiny Hunter Extortion Group. Um payer leak there. That's their that's their model. Um status the data has been publicly released on criminal forums. McGraill uh states that internal systems courseware and grading platforms were not impacted. There is no evidence of socials, financial data or credentials exposed based on the current reporting
019as of the writing of this uh webinar. Uh potential risk to schools, increased fishing uh spear fishing targeting students, staff and administrators. Again, with any of these breaches, as information is learned, it makes it easy for for folks to be victims to fishing emails uh because they can use the information that was learned to make them look more believable. When you see email, they're more um they're more specific to an individual or to a to a campus. Uh so be mindful of that. Social engineering using trusted education content such as McGraill references and things like that. So there's a risk of account takeover attempts leveraging reuse credentials. Uh again, uh proper password hygiene is is important here to make sure the credentials aren't reused. Um recommended precautions, alert staff to height and fishing risk tied
020to education vendors, emphasize verification of vendor communications, the email and domain scrutiny. Enforce review MFA on all staff and student facing systems. Uh and review thirdparty SAS access controls uh and data exposure settings. Again, just some some basic uh hygiene that will help protect our school systems regarding these low-level breaches uh and the the reuse of credentials and and fishing attacks potentially that might come afterwards. So, the bottom line, this was a large-scale SAS misconfiguration exposure, not a direct breach of school systems, but the public release of millions of education related content records significantly increases fishing and social engineering risk for districts. So this is why sort of the the the request for heightened uh awareness of of this uh and what might uh come u behind it. And then uh of popular uh has
021been the guidance on the tech cyber command network blocking of prohibited technology. We've had a lot of school districts uh that have concerns around this and have reached out uh and you know we we that your your emails and your communications have not gone through deaf ears. I did speak with Texas Cyber Command uh to get some more uh things uh understood uh and this is and and so this this slide is based on information that they communicated with me uh and the suggestions around that. So the background so Texas Cyber Command implemented network blocking controls targeting high-risk infrastructure. This included high-risk IP addresses and and Cedar which is classless interdommain routing ranges domains including wild cards uh and autonomous system numbers and ASN. So that was the communication that came out via the Texas
022ISO uh with the request for us to to block uh those domains and those IPs. So some key clarification Lenovo and Motorola devices are not listed in the prohibited hardware list. Uh and again the the link to the prohibited hardware list is there uh and can be made available when this slide goes up on the on the website. Uh so actions that are required at this time is network level blocking only and not a device ban. Blocking may impact services tied uh to affected infrastructure. So so be mindful of that. So what does this mean for school systems? No communicated requirement to remove Lenovo or more devices. That has been the biggest question that we have received. The state has not said to not use or to remove a Lenovo or Moto Motorola devices uh
023or replace any existing hardware uh from those communicated uh Texas ISO message. So the focus is on risk reduction via network connectivity controls and not asset removal. [gasps] So immediate actions uh implement the uh tech cyber command provided indicators. Uh so IPs, domains and ASNs, make sure that those are blocked. Monitor for device functionality issues uh because by blocking those IPs uh this may impact uh automatic updates, patching and things like that as those are pulled from from those IP addresses. So something that school can do is the school can uh make an exception for maybe one or two IT staff to be able to very carefully download those updates and patches onto a trusted system. Make sure that those those updates are are and firmware up are are are scanned to be safe and
024then distributed to the devices uh to be updated. Unfortunately, we we are in in in times when threat actors uh from from various uh countries um make it harder for us to do what should be simple IT work. And so sometimes we've got to learn how to to pivot uh uh and do it safely. Uh we don't want any of these uh potential firmware updates or patch updates uh to be the thing that causes our devices to then be listening and exfiltrating data um uh to to any of the uh companies that that were um whose threat was advised that we block on. Uh so procurement and risk management avoid single vendor dependency. I know that's a big ask, right? So the question is that I have also received is is Lenovo or Motorola going
025to be added to the hardware list at some other point. The state says that uh at this time they don't know. They can't say because it's not there yet. There's been no decision to add them there. Uh and so we we don't have a crystal ball to see if if a threat were then to be realized on these devices and that it would be added to something at a later time. Uh it's not the ask at the moment. Uh and so what what the guidance is is to make sure that uh you avoid a a single vendor wherever possible. Uh if if it was determined that without a shadow of a doubt that some of these products were uh seen as exfiltrating data, what would your organization do then? What would be the response to
026these uh there? Right? And so when we use products that are made available by uh countries that are known to be our foreign adversaries, one has to be careful with wi with with that because at any point as as tensions escalate, this can go in either way and I think that's the concern from the state at the moment. So evaluate vendor risk uh geopolitical and supply chain. we are in in in in some weird times as as you all know. Uh and so we need to keep uh up with with with these risks as they change and be ready to pivot uh once requested once a verifiable threat is uh discovered at at this moment. Again, the only thing that's been requested of us all is just to block those IPs, domains and ASN. Uh
027maintain flexibility in contracts where feasible. Uh the operational guidance uh continue plan procurements with due diligence. do not act on speculation regarding future bans. We don't know. We don't know yet. Uh the state has not listed those devices in the prohibited hardware list. Uh and a lot of schools have asked well is it next? We don't know. If it was discovered that this hardware was doing something that it should not be, it might be, but at this time it is not. Uh so rely on official state guidance only and that is that website there. So once those technologies are added to that website there as official that's when uh we will need to escalate the conversation to then what do we do with removing the hardware or or further securing that we are not there
028today team I I know that it's hard uh to make plans around what may or may not be but again the state has said that only if it's in the prohibited technologies hardware list uh is it when it needs to be to be blocked or or or disallowed. At this time it is not there just the IPs and domains. Strategic recommendation stren vend sorry strengthen vendor risk management identify critical dependencies develop contingency plans uh and improve visibility into vendor connectivity. That's all we can do at the moment is just prepare for in case that switches at some point in the future. If you have any questions still uh regarding what we've communicated here, please add it to the Q&A and we will get uh additional answers. If we didn't communicate it here uh and get
029to those responses as soon as we have answers, emerging threats. This is where I believe uh Miles takes over. Miles. >> Yes. Thank you, Daniel. And moving on to emerging threats, I'm going to be discussing a breach uh that that actually happens to uh have been done by Shiny Hunters, which is the the organization or the the hacker group that was involved in the canvas data breach incident. So, Shiny Hunters has really been uh pretty active. Um, next slide, please. All right, looking at the newest data theft and extortion campaign, uh FBI's Flash published a recent alert that highlights uh coordinated threat activity attributed to a group calling itself and this these are three different groups. So the name is Scattered Lapsis Shiny Hunters or SLSH for short. So this isn't a single traditional threat
030actor, but more of a blended group that leverages tactics from multiple well-known cyber cyber criminal organizations. So what makes this joint group notable is how they combine proven techniques from groups like Scattered Spider, Lapsis, and Shiny Hunters. Instead of relying on traditional malware deployment, they prioritize identity compromise, essentially logging in rather than breaking in. And there are three primary operational focuses that are highlighted by the FBI. So the first is identity compromise. So they target credentials, MFA fatigue, and identity and access management systems. Second is data theft from SAS and cloud platforms especially CRM systems and enterprise uh data repositories. And third is extortion combined with real world harassment tactics which is which is a significant escalation compared to typical cyber crime. What makes this activity particularly dangerous is that it leverages legitimate access. This
031is because attackers are using valid credentials which traditional endpoint detection tools often don't generate alerts on. So there are three major risks to keep in mind with this new campaign. So, use of legitimate credentials which allows actors to blend in with normal user behavior, exploitation of trusted relationships, specifically vendors, third party integrations and service providers, and the heavy focus on enterprise SAS along with identity and access management environments where large volumes of sensitive data centralized. Next slide, please. Now that we've introduced the group and why this threat is significant, this slide breaks down their overall tactics and operating model. So the primary entry point for these attacks is social engineering, specifically voice fishing, aka visioning. Uh threat actors impersonate IT support or trusted personnel and manipulate users into providing credentials or approving MFA requests. This
032is important because it bypasses technical controls by targeting the human element. Once access is gained, the actors focus on high value systems. So primarily identity and access management platforms, CRM systems and cloud-based data environments. So these systems are targeted because they centralize access and contain large volumes of sensitive data. The ultimate goal is largecale data expiltration followed by extortion. So unlike traditional ransomware, they don't need to encrypt systems. They already have what they need, which is the data. Uh so one of the most important points here is that malware is often not used at all. These attacks are conducted entirely through legitimate access using valid credentials and authorized platforms. This significantly reduces the likelihood of detection by traditional endpoint security tools. So if the victim organization does not comply with extortion demands, the actors escalate
033aggressively. This includes harassment such as phone calls and messages, uh swatting incidents that target executives and even uh DDoS attacks, denial of service, um which are against public facing systems. So this combination of cyber and real world pressure tactics is a defining characteristic of this threat group. Next slide please. Now to break down how the attack actually unfolds step by step. This is the attack's uh life cycle from initial access all the way to data exfiltration. So step one, the attack typically begins with voice fishing campaigns. Threat actors impersonate IT staff or help desk personnel to build trust with the target. They then direct users to fake login portals designed to capture credentials. In many cases, they also attempt to manipulate users into approving MFA prompts or initiating credential resets. So, at this stage, the
034attacker isn't exploiting a a technical vulnerability. They're exploiting human trust and process gaps. Now, on to step two. Once valid credentials are obtained, the attackers move quickly to abuse that access. They authenticate into identity and access management platforms which serve as the central control point for enterprise access. From there, they pivot into multiple enterprise systems, often SAS, apps, and cloud environments. Again, a key point here is that this expansion happens using legitimate authentication, which allows them to avoid triggering traditional security alerts. This is why identity telemetry becomes very critical. Now, on to step three. To maintain access and avoid detection, the attackers use VPN services and residential proxies. These tools help mask their true location and make activity appear as if it's coming from normal user environments. By blending their activity with expected user behavior,
035they significantly reduce the likelihood of raising red flags and monitoring systems. Once established, attackers operate directly within SAS platforms again without deploying malware. Um, so within step four, they use built-in APIs and administrative tools to uh enumerate available data and extract large volumes of data in bulk. And because this activity often resembles normal admin or user behavior, it can be extremely difficult to detect without proper logging and monitoring. Next slide, please. Now next, one of the most uh concerning aspects of this threat is the use of third-party pivoting. So on to step five. Instead of directly attacking every target, threat actors first compromise vendors or service providers such as CRM integrations or managed service providers. Uh these third parties often have trusted access into multiple customer environments. So once inside the vendor environment, attackers are
036able to extract stored credentials or authentication tokens and reuse that access to pivot into downstream customer systems. From the victim organization's perspective, this activity can appear as legitimate vendor access, which makes detection even more difficult. So lastly, on to step six. Once the data has been exfiltrated, the attackers move quickly into extortion operations. So, victims typically receive emails from shiny hunter branded accounts that demand payment, usually in cryptocurrency, and within a short window of time, usually around 72 hours. Next slide, please. So shifting focus to what we should be actively monitoring for in environments. These are high confidence indicators that align with this threat's behavior. So first authentication anomalies. This is one of the most critical detection layers for this type of attack. So key things to look out for include loginins from new or
037unfamiliar IP addresses, especially those associated with VPNs or proxy infrastructure, uh MFA fatigue patterns such as repeated push notifications or unusual approval behavior. Because these attackers rely on valid credentials, authentication activity is often the earliest and most reliable signal. Next, we look at data related activity, particularly within SAS platforms. So, red flags here include immediate high volume API activity right after a successful login and bulk data exports that don't align with normal user behavior. Now, this is important because once access is established, attackers move quickly to enumerate and extract data. Another key detection area is user behavior inconsistencies. This includes sudden changes in browser type or device usage as well as inconsistent or unusual user agent strings. Uh these mismatches may indicate session hijacking, automated tools or incomplete spoofing by the attacker. And finally, we
038need to pay close attention to thirdparty or vendor account activity. Indicators here to watch out for include vendor accounts accessing multiple systems in a short time frame or accessing large volumes of data outside of normal usage patterns. So, because vendor access is typically trusted, this activity can easily blend in unless it's being monitored closely. Uh, next slide, please. Now when it comes to how we can defend against this, the FBI emphasizes that mitigation here is heavily centered on identity process and visibility rather than traditional endpoint controls. So the first and most critical layer is identity security. Because these attackers rely on valid credentials, protecting identity systems is the most effective control. So key measures uh here include enforcing fishing resistant MFA such as um FID2 or hardware tokens which significantly reduce the effectiveness of fishing
039attacks. Uh next applying conditional access policies to evaluate login risk based on device location and behavior and then res and then restricting or closely monitoring access from anonymized networks. So such as VPNs and proxy services. So the next critical layer is help desk and support process security. Uh as we saw earlier these attackers frequently impersonate IT staff. So the help desk becomes a key attack service. Uh to mitigate this, IT teams should require multi-channel identity verification before making any account changes and strictly prohibit password resets that are based solely on phone requests and MFA changes without proper validation. These controls directly disrupt the attackers's ability to social engineer their way into accounts. The third focus is SAS and API monitoring which is critical since that's where the attackers operate post compromise. Organizations should enable detailed
040logging across identity um and access management systems which is critical since that's where the attackers you know operate. Um, and you should also set up accounts or set up alerts for bulk data access and abnormal API activity and enforce lease privilege to limit how data uh how much data can be stolen within any single account. Next slide, please. Next, when it comes to thirdparty risk management, attackers actively exploit trusted relationships. So, it's essential here to have visibility and control over vendor access. So, key actions here include regularly auditing vendor access. So, understanding who has access to what systems and why, monitoring vendor authentication patterns to identify unusual behavior, and rotating credentials and API keys on a regular basis to reduce the risk of long-term exposure. A single compromised vendor can be used as a gateway
041into multiple environments. Uh, if organizations aren't monitoring vendor activity closely as internal users, these can create a blind spot that attackers can exploit. So the second focus area is organizational readiness which is about uh really how how you are getting ready for that specific specific attack. So organizations really need to make sure that you are, you know, monitoring vendor activity very closely and specifically not only vendor activity but you're you're making sure that your users are aware. So, um, for example, having employees be trained to recognize fishing and fishing attempts because social engineering is the primary attack vector. You know, user education is a key defensive control here. Uh in addition, organizations need strong monitoring across key areas which includes API usage, identity and access management logs and browser session activity. Uh these are the
042exact areas where attackers operate once they gain access. It's also important to regularly review all CRM and cloud integrations. Every integration really represents a potential access path. So we need to ensure those connections are necessary, secure and are properly monitored. Uh next slide please. So here in summary, this slide ties together everything we've covered across the attack life cycle, detection and mitigation. First, this thread is impactful because it targets identity rather than endpoints. Traditional security models are heavily focused on endpoint protection, but this attack bypasses those controls entirely by using valid credentials. Second, it exploits trusted relationships, particularly within vendors and third party integrations. This allows attackers to move laterally across environments without needing to directly breach each organization individually. Third, it enables silent largecale data exfiltration. Uh because the activity occurs within legitimate SAS
043platforms and uses authorized access. It can go undetected for extended periods of time without proper monitoring. And finally, it combines cyber intrusion with real world coercion tactics. So this includes harassment, swatting, and public debt exposure, which increases both operational and reputational impact. So when it comes to organizations that are most at risk, the FBI highlights several categories uh that are particularly vulnerable to this threat. So organizations with exposed or poorly secure uh secured identity and access management systems are at high risk since identity is the primary attack vector. Uh organizations with heavy SAS and cloud usage are also prime targets. um as these environments contain centralized and high value data and additionally environments with extensive third-party integrations have increased exposure due to the potential for vendorbased pivoting. And finally, any organization with access to sensitive
044customer or enterprise data is a high value target here for extortionbased operations. The final takeaway here from this entire briefing is that this threat represents a shift in how attacks are being conducted. So we are moving away from malware focused attacks toward identitydriven SASbased intrusions. So, organizations that prioritize identity security, visibility into SAS and API activity, and strong thirdparty risk assessment will be in the best position to detect and defend against this type of threat. Uh, next slide, please. And for the sake of time here, I'm going to quickly cover this um Apache active MQ vulnerability. So shifting gears, this critical vulnerability uh has been identified specifically within the platform's web console. Um the web console exposes a management interface that allows administrative actions. So by default, this interface can perform high privilege operations which
045increases risk if prop if improperly secured. So the core issue stems from insufficient validation of incoming requests. Because of this weakness, an authenticated or exposed attacker can load unauthorized configuration files into the system. So once those malicious configurations are loaded, the server can be forced to execute unintended programs effectively giving the attacker um remote command execution capability on that host system. So from a security operations pers perspective this is considered a high impact vulnerability as it can lead to full system compromise if it's exploited. So the effective versions here include uh Apache active MQ versions 5.x prior versions prior to 5.19.4 and Apache active MQ6.x versions prior to 6.2.3 2.3 and any systems running these versions should be considered high risk and require immediate remediation. Um, next slide please. And again, um, the primary action
046here is just to upgrade Apache Active MQ to version 5.19 or later and or version 6.2.3 or later. Thank you. And uh, back to you, Daniel. Thank you, Miles. All right, team. Uh, let's do a review of our K12 cyber security initiative. As a [clears throat] reminder for those new in the audience, TA launched the K12 cyber security initiative in 2023 to address the rising ransomware uh and cyber threats targeting schools. The initiative is funded by the 88th legislature and continued in the 89th to support dedicated cyber security resources. It provides practical solutions to help schools prevent and respond to major cyber incidents. Priority is given to high need school systems. Regional ESC cyber security practitioners are available to assist schools with implementing controls that are aligned with the initiative. Uh current program participation summary.
047Uh school systems that have onboarded with DI. There are 548 school system that have signed the DI interlocal agreement form. Uh endpoint detection and response. 400 school systems have signed up for EDR. That includes installation of uh EDR agents on 316,500 endpoints. Uh 51,000 plus attacks have been blocked uh due to the EDR service. 17,000 uh or and more ransomware threats have been neutralized. The uh initiative also provides free cyber security framework assessments. 71 schools have signed up uh and 52 have completed. Uh the others are in currently in queue and in different varying processes as this has been a busy uh end of the year for assessments. Uh individual results from the assessments are kept confidential and are not shared uh with TEA or with the state. Uh just as an FYI, uh the
048NDR pilot is still currently closed uh just to the nine pilot schools. uh and we are still looking for uh a way to provide it to to additional schools and I think we've we've identified a few different potentials uh but not nowhere close to a final uh solution just yet. Uh for more information on how to sign up for EDR and the TC of assessments uh you can always go to our uh K12 cyber security website for additional information. Uh and I will now lead to Brent who was going to introduce the Tassy office team. Hi, thank you Daniel. My name is Brett Baker. I'm the information security coordinator at the Tassy office. So, I'll take the opportunity here to introduce Tassy and the Tassy office team. In the CCF and the cyber security initiative
049correspondents, you'll sometimes see Tassy referenced. And so, the question is who is TASY? Uh just at the top of the slide here, you'll you'll see it says technology alliance for statewide initiatives. The alliance is the group of 20 regional ESC's and then we come together to work on initiatives. Um the the main one here involved would be the K12 cyber security initiative. So when you see TASI referenced any any material you can translate that to your regional ESC. Couple slides down we're going to splash up your regional contacts. And a couple slides back Daniel referenced the regional support. Uh the group of 20 ESC's is supported by the Tassy office uh working on the cyber security initiative that includes Lee Castillo, our director, uh me and then our resident movie star, Mr. Emlio Estz. Uh
050so sometimes you'll see emails with from us or with us copied or our office email tassie K12 and just know uh when when that's involved with uh providers and partners in the initiative that that's just involving the ESC communication. You can go to the next slide now. So the tassy involvement with the cyber security initiative uh the the first one where it says technology alliance for statewide initiative uh the group of 20 ESC's does receive funding through the initiative to provide support in all aspects uh of what is included in the cyber security initiative that includes informing guiding and assisting with anything even uh if the the control and solution is not provided by tassy. So the point here is feel free at any time to ask your ESC contact if you have any questions
051or need any help. Uh we continue to provide direct support for the the MFA um the ESP which would be the DEARK and then the local administrator access but we're also bringing on some new offerings that we are excited about. So let's talk about those. Uh the first one which is now immediately available is the security awareness training and fishing simulations. Uh this was identified by youth the school systems uh in the survey that TEA sent out last fall about uh a a immediate and high need. And so uh we're happy to to provide this through TASI at no cost. The solution is infosc IQ. While Tassy offers infosc IQ as the solution through our contract, uh the question comes up, are you being forced to use this product and certainly not. If your school
052system already pays for another product that satisfies this need, that is a local decision, but this is being offered so that schools do have a no cost available. Uh infosc IQ includes simulated fishing. It also includes training modules uh that uh that includes the DIIR approved cyber security training and also the DIR approved AI training. Uh also uh this this is set up to be as far as onboarding goes a low friction process. From the time that you contact your ESC you can be fully deployed running scheduled fishing campaigns within approximately one month. Uh the caveat there is as the school you need to to be able to attend the uh implementation calls to get the service up and running. Uh we're happy to announce in the last two weeks we've added more than 200
053new school systems. So this is really taking off. Uh the next thing that is coming very soon, next week uh you'll receive an offer from your ESC for the cloud hardening guide assistance. And this is going through a process of u a cloud hardening guide that's based on CIS security benchmarks. So this will be available for your cloud environment whether it's Google or Microsoft and uh going through and ensuring security settings and if if necessary changing security settings to uh put yourself in a better uh posture there for your cloud environment. So that will be offered to you next week from your regional ESC contact. And then uh something else that we're really excited about that's coming up um that will be available on contract September 1st is a software deployment solution. Again, another exciting
054and excellent opportunity. Uh at this point, TASI as a group has posted an RFP as part of a formal procurement and contract process to select a solution. So one solution provider will be selected and we hope to be able to communicate that to you this summer. Um the primary outcome of this is to be able to deploy software especially in support of EDR agents. Uh we know that there are a lot of options out there and uh they all have kind of their own bells and whistles. So whatever is selected will will also include additional capability but that is going through a formal selection process and we hope to uh have that communicated to you very soon. You can go ahead to the next slide. And then finally, uh, we wanted to put the current
055list of primary contacts at the ESC's who are available to you in all things cyber security initiative. We won't leave this up too long, but this list is also published on uh, the cyber tea's cyber security initiative website. It's a current and updated list. So, thank you, Daniel. I'll turn it back to you. Thank you, Brent. Thank you for the information. So, yes, excited uh that we have new uh services being made available to all our schools to help them mature their uh security programs. That's that's awesome. [clears throat] Uh one of those uh that has been very popular is the email security service which is available since May. Uh this is a partnership between uh TEA and the UTRSOC uh using their existing email security service which is abnormal AI uh previously called abnormal
056security. Uh this is a service that's available at no cost to schools and all schools are eligible uh and able to uh be onboarded on uh school systems must complete the pre-registration survey uh only one per school. These were sent out uh a couple weeks ago uh I believe at the beginning of May um and are still available. If if you need uh a link resent to your school uh please let the team know and we'll send one uh that's specifically for you out as soon as possible. Uh the other thing that is required is you must have a UtrOC interlocal uh contract in place with the UTRSOC. Um in reviewing some of so we we do get a feed from UTROC that lets us know which schools have uh a completed ILC or are
057in the process of the ILC. And a few of the surveys for the pre-registration, some of the schools said yes, we have an OC in place. Uh but in us looking for that uh from the communication we got from the UTR socket it was not the case. My guess is that schools are are are maybe misunderstanding that having an ILC like currently for the DI program is sufficient and is not. If you have one for the DIMS MSS uh services uh have an IC in place for that that is separate from the your need for an IOC to be in place with a UTROC for the services you receive from them. If you are receiving services from any of the RSOs, whether that is ASU or UTRGV, then know that the R the IOC's you
058have in place with them also are not sufficient uh for the services you would receive from the UTROC because every AROC has uh a a um legal requirement to have an ILC contract in place with whoever they're providing services for. Uh and so if if you are interested in the services for email, those are the initial steps to get onto the queue. You must complete the pre-registration survey and you must uh have uh an IOC contract in place. Uh even if it's just in starting, if you send out the the the email from to the RSC saying, "Hey, we'd like to get started. Send us the OC." And then they send you the OC. they mark you as in progress and we will know that and we can track your your progress and make sure
059that as as that goes forward that you are added to the approved queue. Uh the purpose of the pre-registration survey is because if your school is interested we want to know how ready you are and the targeted frame. This is a this is a first come first- serve service. This is the initial uh year that we make this provided and we want to make sure that the schools that uh request the service are those that are ready to uh receive the service because we want to cover as many schools as we can uh out the gate. Uh we we are not interested at this time in having schools sign up uh for something they may not be ready for until next year. Uh you can still complete the pre-register. You can tell us, hey, we're
060not ready until this date. We will keep an eye on you. uh and and queue you in as as as you communicate on on the form. So, it is very important that you complete the pre-registration survey because this is how we put you in the queue to know uh and communicate with you once you are ready. Uh if your school is not interested, we still want to know that too. We want to know through the pre-registration survey that your school is is considering opt out at this time. Uh this is our way of verifying that your school system is at least aware of the program uh and is uh already has some type of security protection that you are satisfied with uh and are not interested. This way we we are we are able to
061shorten the list of schools that we're going to be communicating with uh that we have had heard nothing from uh just to make sure that all of our schools are are at least aware of the of the service. Um so the email security uh is AIdriven email protection that protects organizations from fishing business email compromise and account takesovers by analyzing behavioral anoms rather than relying on traditional email filtering roles. uh it integrates directly with Microsoft 365 or Google Workspace via the application programming interface. It does not require changes to your email exchange records or any modifications of anything. It is just an API that then has the ability to see your email as it flows through and make decisions on whether or not the email has characteristics that would indicate that it is a malicious
062type email or has a malicious attachment or has a malicious link. uh easy implementation and it's minimal work for for the schools. Uh there is a FAQ that was published on the TEA cyber security website. Uh so if you have any questions uh you can send them to the team. I would recommend you look at the FAQ first to see if your questions have been answered by another school. Um or uh if not then let us know and we'll we'll add them to the FAQ so that we are all learning the questions uh that are being asked by our schools. uh if you are already receiving ARSOC services from the UT Grand Valley or Angelo State uh let the UT ars know and they will coordinate this service with your existing ARSOC. If you already
063receive services from another RSOC and you want to they will remain your primary ARSOC, the service has to be uh enabled by the UTROC but they will communicate with your current RSOC uh and make sure that they have access to view those logs and that information on your behalf and they will still be the ones that alert you on anything that requires your attention. So the email security initiative uh there are 13 schools uh which are TEA funded already using the service. We remember that we we started this uh in May um with with the preparation survey these schools had already in place uh and so as of as of the as of this e as of this webinar as of this session there are 13 schools for which tea is providing the service for
064them. There are 56 school systems. Uh they were UTRSA customers prior to the initiative. Uh and so there are a total then of 69 school systems that are protected today by Admiral AI email security. There are 31 additional schools uh that are already TA approved and in the queue. That means that the schools have completed their preation survey have an IOC in place and are queued to be uh added as as customers. So we have kept Utrock busy and they are going through configurations as quickly as they can but they have a process uh and they want to make sure nothing is missed. Uh so once you're in the queue you will receive an email saying that you're in the queue. Uh and the rest of the communication is done by the UTR sock so
065they can schedule that with you uh and get you on boarded on. So we are definitely off to a great start with this new initiative service. It is as all of our services are first come first served. Uh and again just to sort of uh reiterate uh what you need to do to get the service is to complete the UTRSOC IOC with UTRSC and to submit the pre-registration to TEA uh and the rest of it will be through communications that either TEA or the RSOC does with you uh to get you onboarded on. If you have any other questions regarding the service or anything like that, please let the team know by by emailing us. [clears throat] uh something that we wanted to make sure that we communicate uh a lot of the information that
066we send out regarding the newsletters that are going to be coming out soon or uh queries or surveys or anything like that is based on email that we receive from ASED. So we pull public data from Azte that list all of the cyber security coordinators and the IT coordinators from Azte for all of the school systems add them to to a system that then we can email against. A lot of schools have said, "Hey, this individual is no longer with us." Uh that is currently the only source of information that we have. As we communicate with schools, we do uh keep up with our own list, but for schools that we don't have any communication with for any reason, all we have is to go by are the what's in TED. So, we ask that
067if your information is incorrect or you're not receiving communication from us that you please check uh in Azte uh to see what your district lists for its IT uh coordinator and cyber security coordinator. Um changes uh in the portal can only be made by your school's TED administrator. Uh you can also look up who the Aztec administrator in is in the Aztec portal for your school. Uh update your Aztec contact information at least once a year and anytime there are staff changing key positions. Unfortunately, we don't have even though we're TA we uh the security team does not have the ability to make any changes uh to to what's listed on there. It has to be done through the school. Uh here um just real quickly is sort of the steps of of how you
068can look for those individuals that we mentioned. Uh you can do a search by your district, put your district name, select personnel uh and and click on the include other district roles from the list. Uh select cyber security coordinator, technology coordinator, and your Aztec coordinator. And then you have a list of the important folks uh for your school system. Those are the folks who we typically communicate with. Uh so if they are currently not correct, please uh uh update them so that we have current information on our next sync. Here's a example of what that looks like uh when you complete the search and the information that's provided uh for for the folks uh once you click. Again, all this is public information made available to anybody. quickly upcoming events because we're actually out of
069time. So, our next CCF will be June 24th uh at 11:00 a.m. Uh it's the exact same format uh as you've seen here. If you are currently have anybody that needs to register, uh please share with them the link there so they can actually register their account. Uh there will be no CCF meetings in July and August. Uh and we will resume in September. So, the one in June is our last one. uh and and so we'll provide some some some information on on that and we hope to carry important updates and information through the newsletter which is why we're standing that up uh so that we can still communicate with the schools on important things until the next CCF and as a wrap-up again the K12 cyber security initiative website uh is there uh
070the steps to onboarding for any of the services can be found on the website including frequently asked questions and if you need to get a hold of or have any questions regarding the program that is the email that you need to use that is that goes to the entire team and we will get back to you as soon as possible or whatever and it's the best way to send questions or concerns to us on the list. So I hope that the today's webinar has been in in informal. If you um I'm sorry beneficial not informal has beneficial to you uh if you would like to see any information added uh to to our current um uh setup uh for the different slides or whatever. If you want a specific section to be edited or anything
071added u you know please let us know. Also we want to make sure that we provide you the information that that that's best needed uh for all of our school systems in the state. Thank you guys and have a great rest of your day.