Past Security Bulletins

December 11, 2025

Chrome High-Severity Vulnerabilities Require Patching

Google has released security updates to its Chrome web browser to fix high-severity vulnerabilities actively being exploited. This update also applies to any web browsers running the same technology (i.e., Microsoft Edge, Brave, Opera, Vivaldi and others).

The Office of Information Technology (OIT) Information Security team recommends updating all affected browsers on both personal and University owned devices. Most University managed computers have automatic updates enabled for Google Chrome—restart your Chrome browser to allow it to update to the latest release.

Instructions for manually updating your Chrome browser are available in this Google Chrome Help web page. If you are using a different web browser, please refer to their support documentation.

While these security updates are specific to Chromium-based web browsers, please ensure security updates are applied regularly for all web browsers.


September 15, 2025

Chrome Vulnerabilities Require Patching

Google has released security updates to its Chrome web browser to fix high-severity and critical vulnerabilities that are actively being exploited. These updates also apply to any web browsers running the same technology (i.e., Microsoft Edge, Brave, Opera, Vivaldi and others).

The Office of Information Technology (OIT) Information Security team recommends updating all affected browsers on both personal and University owned devices. Most University managed computers have automatic updates enabled for Google Chrome—restart your Chrome browser to allow it to update to the latest release.

Instructions for manually updating your Chrome browser are available in this Google Chrome Help web page. If you are using a different web browser, please refer to their support documentation.

While these security updates are specific to Chromium-based web browsers, please ensure security updates are applied regularly for all web browsers.


August 14, 2025

Phishing attack targeting the Notre Dame community

Scam phishing email

A phishing campaign has been aggressively targeting the Notre Dame community. It is coming from real ND email accounts accessed by hackers. While the topic seems official, IT IS NOT LEGITIMATE.

Opening links or attachments in email like this can result in compromised accounts, and can even lead to you losing money.

Remember that official Notre Dame departments will NEVER:

🚨ask you to verify your email is still in use

🚨ask you for your username and password

🚨send you an unsolicited request to authenticate

🚨create a sense of urgency or threaten loss of access

If you have received the email described above, do not click on any links. Report phishing immediately and delete the message. To do so in Gmail, click the three dots in the top right corner of the email, and select “report phishing” from the drop down. You can also forward the message to phishing@nd.edu to prompt an investigation.

Information Security has taken action to suspend the compromised Notre Dame emails and remove the message from inboxes. However, if you entered your credentials into this form, please change your password immediately by either contacting the OIT Service Desk or following the steps in this knowledge article.


July 3, 2025

High Severity Chrome Vulnerability Requires Patching

Google has released security updates to its Chrome web browser to fix high-severity vulnerabilities that are actively being exploited. These updates also apply to any web browsers running the same technology (i.e., Microsoft Edge, Brave, Opera, Vivaldi and others).

The Office of Information Technology (OIT) Information Security team recommends updating all affected browsers on both personal and University owned devices. Most University managed computers have automatic updates enabled for Google Chrome—restart your Chrome browser to allow it to update to the latest release.

Instructions for manually updating your Chrome browser are available in this Google Chrome Help web page. If you are using a different web browser, please refer to their support documentation.

While these security updates are specific to Chromium-based web browsers, please ensure security updates are applied regularly for all web browsers.


June 17, 2025

High Severity GitLab Vulnerability Requires Patching

Who is affected?

  • Developers or system administrators hosting a self-managed GitLab instance.

What You Need to Know

  • GitLab has patched several vulnerabilities in GitLab Community and Enterprise including some enabling attackers to take over accounts and inject malicious jobs in future pipelines.

  • Immediate patching to versions 18.0.2, 17.11.4, and 17.10.8 is required.

Why it matters

  • By leveraging these weaknesses, attackers can take over accounts and inject malicious code and/or malicious CI/CD jobs.

Go deeper

The Office of Information Technology (OIT) Information Security team requires all GitLab installations running an impacted version to be upgraded to the latest version as soon as possible.