Home

University of Texas RSOC
Cybersecurity Services

Cybersecurity Services

We deliver cutting-edge cybersecurity solutions designed to detect, respond to, and mitigate threats in real time.

Customer Benefits

Customer Benefits

Public-Sector Expertise: Solutions designed to meet the unique cybersecurity needs of government and educational institutions.

Student Employment

Student Employment Program

Paid opportunities allow University of Texas students to develop real-world cybersecurity skills while supporting active operations

new about

About UT-RSOC

Operating under UT Austin and funded by the State of Texas, we are part of a statewide network of Regional Security Operations Centers.

UT-RSOC News

A year after ToolShell, Warlock ransomware is still walking through the same SharePoint door

Oct. 9, 2026
Symantec says the group behind Warlock hit a water utility, a telecom provider, a regional government and a university in the past two months, mostly through on-premises SharePoint flaws first patched in July 2025.

16,326 databases anyone could read: the hidden cost of quick-build apps

Oct. 1, 2026
Researchers found more than 16,000 Supabase databases with tables open to the public, many behind apps built quickly with AI coding tools. Over half held personal information. No hacking required.

The front door to single sign-on had a hole, and attackers found it first

Sept. 24, 2026
F5 patched CVE-2026-94127, a 9.8-rated flaw in BIG-IP APM that lets attackers run code without logging in. It was exploited before the fix shipped, and roughly 15,000 APM systems are reachable from the internet.

Five and a half hours, one stolen key, and 100,000 websites serving malware

Sept. 17, 2026
Attackers used a hardcoded Cloudflare API key to rewrite Brevo's embedded forms and chat scripts at the CDN edge. Visitors to customer sites got fake verification prompts. WordPress admins got a hidden backdoor.

A missed advisory, a reporting tool, and 1,079,819 student and family records

Sept. 10, 2026
Edtech platform Mathspace lost data on more than a million students, parents and teachers through its self-hosted Metabase server. The patch had been out for days. The advisory just never reached anyone who acted on it.

PaperCut is under attack again, and nearly half of servers can't be patched

Sept. 3, 2026
A pre-authentication flaw chain in PaperCut NG and MF is being actively exploited, the first emergency fix was bypassed, and 47% of installations one researcher tracks run versions with no patch at all. Campus print servers are a prime target.

You reset the password. The attacker is still in.

Aug. 27, 2026
A $10,000 phishing kit called iAuthFlow v2 uses a stolen login session to enroll the attacker's own passkey on the victim's account. The standard "reset password, kill sessions" playbook does not remove it.

Your old domain has a new owner, and it might be serving malware

Aug. 20, 2026
Roughly 65,000 expired domains are re-registered every day, and attackers are paying millions for the ones with history. That old conference site, grant project or department vanity URL still carries your name and your traffic.

The recruiter was fake. The Windows zero-day was real.

Aug. 13, 2026
North Korea's Lazarus Group used fake job offers and a doctored PDF reader to reach a Windows kernel flaw nobody else knew about. Microsoft patched it on Aug. 11. Research labs and job-hunting students fit the target profile.

Seven states, one weak spot: attackers are locking operators out of water system controllers

Aug. 6, 2026
The FBI and EPA say attackers are logging into internet-facing PLCs at water utilities, changing the passwords and IP addresses, and leaving operators blind. Some plants saw pressure loss and flooding.

UT-RSOC Events

No events at this time.