The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
E-Learning
Breach intelligence, attack campaigns, and threat reports targeting the E-Learning sector.
Explore Other Sectors
E-Learning Threat Reports
Critical Next.js ImageResponse Vulnerability Exposes Servers to Remote Code Execution
A critical vulnerability (CVE-2026-94545) was discovered in Next.js versions 16.2.0 through 16.3.5 affecting the ImageResponse feature used for generating Open Graph social preview images. The flaw, with a CVSS score of 9.5, allows attackers to execute server-side code by injecting malicious SVG content through user-controlled input when using the Node.js runtime. Vercel released a patch in Next.js 16.3.6 on September 22, 2026, addressing the vulnerability in the underlying Satori library that improperly escaped SVG output, enabling crafted payloads to be interpreted as executable code rather than plain text. This incident highlights the growing threat surface of modern web frameworks and the critical importance of input sanitization in server-side image generation features. As web applications increasingly rely on dynamic content generation and social media integration, vulnerabilities in these specialized components pose significant risks to application security and server infrastructure.
1 day ago
Kill Chain
Critical cPanel Vulnerabilities Enable Complete Server Takeover Through Privilege Escalation
In September 2026, cPanel disclosed three critical vulnerabilities affecting its hosting control panel software used by millions of websites worldwide. CVE-2026-87899, the most severe flaw, allows any hosting account holder to execute code as root through the CalDAV/CardDAV service, enabling complete server takeover. CVE-2026-87900 permits unauthorized database modifications across accounts via the WP Toolkit plugin, while CVE-2026-68490 enables reading other users' calendar and contact data. These vulnerabilities affect cPanel versions 120 and later, with fixes released across multiple version branches. These vulnerabilities highlight the growing threat to shared hosting infrastructure, where a single compromised account can lead to full server compromise affecting hundreds or thousands of websites. The timing coincides with increased scrutiny of web hosting security following recent supply chain attacks and the rise in ransomware targeting hosting providers.
1 day ago
Kill Chain
Abandoned CDN Domain Hijack Exposes Supply Chain Blind Spot in Thousands of Websites
In July 2025, an abandoned Content Delivery Network (CDN) domain was re-registered by an unknown actor, creating a massive supply chain vulnerability affecting thousands of websites. The original CDN service had been discontinued years earlier, but its domain was allowed to expire while thousands of sites maintained hardcoded references to resources hosted under that domain. The new domain owner gained wildcard DNS control, enabling them to serve arbitrary content to any website still calling the abandoned hostnames. This incident mirrors the June 2024 polyfill.io compromise, where over 110,000 websites were affected when that JavaScript library domain changed ownership and began serving malicious redirects to mobile visitors. This incident highlights the growing threat of supply chain attacks targeting client-side dependencies and third-party resources. As organizations increasingly rely on external CDNs and JavaScript libraries, abandoned domains represent a significant blind spot in traditional security scanning and dependency management approaches.
6 days ago
Kill Chain
Brevo Supply-Chain Attack Exposes CDN Security Gaps Through ClickFix Campaign
In September 2026, attackers compromised Brevo's Cloudflare API key and deployed malicious Workers that injected ClickFix scripts into the company's websites and customer-embedded JavaScript components for approximately 5.5 hours. The attack affected brevo.com, sendinblue.com, and customer sites using Brevo forms, conversation widgets, and SDK loaders, potentially impacting up to 100,000 websites. Victims were presented with fake Cloudflare verification pages prompting them to execute malicious commands, while WordPress administrators faced additional risks through backdoor plugin installations that created persistent access points with hardcoded authentication bypasses. This incident highlights the growing sophistication of supply-chain attacks targeting content delivery networks and the increasing prevalence of ClickFix social engineering tactics that exploit user trust in legitimate cloud services to distribute malware at scale.
1 week ago
Kill Chain
Supply Chain Attack Compromises Admin Menu Editor Pro Plugin, Backdoors 1,500+ WordPress Sites
In September 2026, threat actors compromised the Admin Menu Editor Pro WordPress plugin distribution infrastructure, affecting over 1,500 websites across 230+ customers. The attackers gained root-level access to adminmenueditor.com and injected malicious code into plugin versions 2.35 and 2.36, creating backdoor access through hidden user accounts and web shells. The compromise lasted approximately seven hours before detection, with the malicious payload (wp-user-consent.php) establishing persistent access on victim sites. Developer Janis Elsts took the distribution site offline and recommended customers restore from pre-September 14 backups to ensure complete remediation. This incident highlights the growing sophistication of supply chain attacks targeting WordPress ecosystems, where attackers increasingly focus on plugin distribution networks to achieve mass compromise. With WordPress powering over 40% of websites globally, such attacks represent a critical threat vector that organizations must address through enhanced vendor security assessments and plugin management practices.
1 week ago
Kill Chain
Critical LiteSpeed Enterprise Flaw Exposes Shared Hosting Infrastructure to Root Access Attacks
A critical privilege escalation vulnerability in LiteSpeed Web Server Enterprise versions before 6.3.7 allows low-privilege hosting account users to gain root access on shared hosting servers. Disclosed by cPanel on September 14, 2026, the flaw bypasses security controls including CageFS that normally isolate hosting accounts from each other. The vulnerability enables attackers with basic hosting accounts to access or alter other customers' websites and compromise the entire server infrastructure. LiteSpeed released version 6.3.7 on September 11 to address the issue, though specific technical details and CVE assignment remain pending. This represents the third LiteSpeed-related privilege escalation flaw reported since May 2026, highlighting ongoing security challenges in shared hosting environments where multiple customer websites coexist on single servers.
1 week ago
Kill Chain
ThreatsDay September 2026: The Week AI-Powered Attacks and Mass-Scale Scams Converged
A comprehensive security bulletin from September 2026 revealed multiple coordinated cyber campaigns targeting various platforms and services. Key incidents included malicious Chrome and Firefox extensions stealing cryptocurrency wallet data, AI-powered intrusions by Chinese-speaking operators targeting government systems across Asia, and a massive fake e-commerce operation called DoppelCart using over 119,000 domains to steal payment card details. Additional threats encompassed shadow AI risks exposing corporate data, sophisticated M&A wire fraud schemes, phishing campaigns abusing Google services, and various malware deployments leading to ransomware attacks. These incidents highlight the current surge in multi-vector attack campaigns leveraging AI automation, browser extension abuse, and social engineering at unprecedented scale. The convergence of AI-assisted vulnerability discovery, shadow IT adoption, and increasingly sophisticated phishing infrastructure represents a critical inflection point requiring immediate organizational attention to zero trust implementation and egress security controls.
2 weeks ago
Kill Chain
StyleSmuggler Attack: How CVE-2026-75650 Exposes Critical E-Commerce Security Gaps
In September 2026, Adobe disclosed CVE-2026-75650, dubbed 'StyleSmuggler,' a critical remote code execution vulnerability affecting Adobe Commerce, Adobe Commerce B2B, and Magento Open Source platforms. The vulnerability, scoring a maximum CVSS of 10.0, allows unauthenticated attackers to inject PHP code through Magento's email template engine and execute arbitrary commands by triggering payment failure reminder emails. Active exploitation began on September 4, 2026, with threat actors deploying Rust-based Linux backdoors and PHP web shells on compromised e-commerce storefronts worldwide. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog within 24 hours of disclosure, emphasizing the severity and widespread targeting of unpatched Magento installations. This incident highlights the critical security risks facing e-commerce platforms as attackers increasingly target template injection vulnerabilities in widely-deployed content management systems. With millions of online stores running vulnerable Magento versions and the rise of automated exploitation frameworks, organizations must prioritize rapid patching and comprehensive security monitoring for their web applications.
2 weeks ago
Kill Chain
ShineyHunters Exploit Zero-Day to Breach Trezor's Shipping Partner
In August 2026, hardware wallet manufacturer Trezor disclosed that 67,000 U.S. customers had their personal data exposed through a breach at shipping provider ShipMonk. The ShineyHunters extortion gang exploited CVE-2026-72898, a critical SQL injection vulnerability in Metabase with a CVSS score of 10.0, to gain unauthorized access to ShipMonk's systems. The exposed data included customer names, email addresses, phone numbers, shipping addresses, and order numbers from November 2019 to August 2021, despite Trezor's repeated requests for data deletion per their 90-day retention policy. This supply chain attack highlights how third-party vulnerabilities can impact customer data even when primary security measures are robust. This incident demonstrates the growing threat of supply chain compromises targeting logistics and fulfillment providers, with attackers increasingly exploiting zero-day vulnerabilities in business intelligence platforms to access customer databases across multiple organizations simultaneously.
2 weeks ago
Kill Chain
Mass WordPress Plugin Exploitation: 440,000 Attacks Target Critical RCE Flaws
In July-August 2026, threat actors launched widespread exploitation campaigns targeting critical remote code execution vulnerabilities in two popular WordPress plugins: Super Forms (CVE-2026-14894, CVSS 9.8) and Elementor Pro (CVE-2026-32475, CVSS 9.0-9.8). Both flaws allow unauthenticated attackers to upload malicious PHP files through missing file type validation, enabling complete site takeover. Wordfence blocked over 440,000 exploit attempts across both vulnerabilities, with attackers deploying web shells like "Mushr00w_upl.php" to establish persistent access and exfiltrate data. The mass exploitation demonstrates the continued threat to web applications through plugin vulnerabilities. These attacks highlight the accelerating pace of WordPress plugin exploitation in 2026, as threat actors increasingly target content management systems to gain initial access for broader campaigns including ransomware deployment and data theft operations.
2 weeks ago
Kill Chain
Critical Elementor Pro Vulnerability Enables WordPress Site Takeovers
In September 2026, threat actors began actively exploiting CVE-2026-32475, a critical vulnerability in the Elementor Pro WordPress plugin with over 6 million installations. The flaw allows attackers to bypass file upload validation by submitting an empty file as the first array element and a malicious PHP file as the second, enabling arbitrary code execution on vulnerable WordPress sites. Wordfence recorded nearly 200,000 exploitation attempts within days of the August 19 patch release, with attackers successfully deploying webshells to the /wp-content/uploads/elementor/forms/ directory for remote command execution. This incident highlights the persistent risk of web application vulnerabilities in popular content management systems, particularly when exploitation begins immediately after patch availability. The rapid weaponization demonstrates sophisticated threat actor capabilities in identifying and exploiting plugin vulnerabilities that affect millions of websites worldwide.
3 weeks ago
Kill Chain
BraZetsu Malware Transforms Compromised Networks Into Criminal Marketplace Assets
In February 2026, cybersecurity researchers discovered BraZetsu, a sophisticated Python-based malware framework developed by the Exilware threat group targeting Latin American organizations. The malware transforms compromised Windows hosts into commercial assets sold through the 'Infected Marketplace' for initial access brokerage operations. BraZetsu employs AI-enhanced reconnaissance capabilities to scan victim networks, extract financial data including Brazilian CNAB banking files, and maintain persistent command and control through WebSocket protocols. The framework represents a significant evolution in Initial Access Broker (IAB) operations, demonstrating how cybercriminals are leveraging artificial intelligence to automate target prioritization and commercialize network access at scale. This incident highlights the growing sophistication of IAB operations and the increasing use of AI in cybercrime, representing a critical shift in how threat actors monetize initial network access and scale their operations across regional markets.
3 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports