UNMC’s brand site, Brand Wise, is again available for campus users.
A public-facing WordPress environment at UNMC was down after cyber attackers exploited a WordPress vulnerability, gained access to the web server and deployed malicious web-shell files.
A forensic analysis found no evidence of sensitive data loss.
Since the incident, additional web security controls were implemented, rebuilding affected infrastructure and sites, including Brand Wise. Modernization of the platform also was accelerated to reduce future risk.
Lisa Bazis, UNMC’s chief information security officer, offered her thanks to the UNMC community for patience in the incident’s aftermath. She also praised the work of the Information Security, Infrastructure, Web Services, Networking, and Operations teams for exceptional work in responding to and recovering from the incident.
“Their rapid response, countless hours of forensic analysis, system restoration and security remediation helped contain the threat, restore services safely and strengthen our environment against future attacks.”
The incident is a reminder of the need to remain vigilant against cyber threats.
“Be cautious of unexpected emails, links and requests for credentials, and promptly report anything suspicious,” Bazis said. “The actions of a single attentive user can prevent the next security incident before it occurs.”
Report a security incident through ServiceNow.