The Containment Era is here. →Explore

Industry Category

E-Learning

Breach intelligence, attack campaigns, and threat reports targeting the E-Learning sector.

125 threat reports
Page 6 of 11

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

E-Learning Threat Reports

Showing 6172 / 125 reports
Critical Vulnerability in Smart Slider 3 Plugin Affects 500K WordPress Sites
Impact· MEDIUM

Critical Vulnerability in Smart Slider 3 Plugin Affects 500K WordPress Sites

In March 2026, a critical vulnerability (CVE-2026-3098) was discovered in the Smart Slider 3 WordPress plugin, affecting versions up to 3.5.1.33. This flaw allows authenticated users, including those with minimal access like subscribers, to read arbitrary files on the server, including sensitive files such as wp-config.php. Exploitation of this vulnerability could lead to unauthorized access to database credentials and potential full site compromise. The issue arises from missing capability checks in the plugin's AJAX export actions, enabling any authenticated user to invoke them without proper validation. This incident underscores the persistent risks associated with plugin vulnerabilities in the WordPress ecosystem. With over 500,000 websites still running vulnerable versions of Smart Slider 3, it highlights the critical need for timely updates and robust security practices to mitigate potential exploits.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Unveiling the March 2026 Fraud Attack: Bot Signups and Account Takeovers
Impact· HIGH

Unveiling the March 2026 Fraud Attack: Bot Signups and Account Takeovers

In March 2026, a sophisticated fraud campaign was identified, leveraging automated bots to create large volumes of fake accounts using compromised emails and residential proxies. These accounts, appearing legitimate, were later exploited for account takeovers through credential stuffing and phishing, leading to unauthorized transactions and data breaches. The attackers' use of automation and human-driven sessions allowed them to bypass traditional security measures, resulting in significant financial losses and reputational damage for affected organizations. This incident underscores the evolving nature of cyber threats, highlighting the need for multi-layered security approaches that integrate behavioral analytics, device fingerprinting, and real-time threat intelligence to detect and prevent such complex fraud schemes.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Surge in Agentic AI-Driven Retail Fraud in 2026
Impact· HIGH

Surge in Agentic AI-Driven Retail Fraud in 2026

In early 2026, the retail industry witnessed a significant surge in AI-enabled fraud, particularly through the exploitation of agentic AI systems. Cybercriminals leveraged autonomous AI agents to conduct sophisticated scams, including deepfake customer service interactions and unauthorized transactions, leading to substantial financial losses and operational disruptions for retailers. This escalation highlighted the vulnerabilities inherent in integrating AI agents into e-commerce platforms without robust security measures. The incident underscores the urgent need for retailers to implement comprehensive AI security protocols, as the adoption of agentic AI continues to rise. With projections indicating that AI agents could handle up to 25% of e-commerce transactions by 2030, the potential for AI-driven fraud poses a growing threat to the retail sector's integrity and consumer trust.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
LiveChat Phishing Attack Exposes Sensitive User Data
Impact· MEDIUM

LiveChat Phishing Attack Exposes Sensitive User Data

In March 2026, attackers exploited the LiveChat customer support platform to impersonate reputable companies like PayPal and Amazon. They engaged victims in real-time chats, coercing them into divulging sensitive information such as account credentials, credit card details, and multifactor authentication codes. This sophisticated social engineering campaign highlights the evolving nature of phishing attacks, making them increasingly difficult to detect and prevent. The incident underscores a broader trend of cybercriminals leveraging trusted platforms to execute phishing schemes. As attackers refine their methods, organizations must enhance their security measures and user education to mitigate the risks associated with such deceptive tactics.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical SQL Injection Vulnerability in Elementor Ally Plugin Puts Over 250,000 WordPress Sites at Risk
Impact· HIGH

Critical SQL Injection Vulnerability in Elementor Ally Plugin Puts Over 250,000 WordPress Sites at Risk

In March 2026, a critical SQL injection vulnerability (CVE-2026-2313) was discovered in the Ally – Web Accessibility & Usability plugin for WordPress, affecting versions up to 4.0.3. This flaw allows unauthenticated attackers to inject malicious SQL queries via the URL path, potentially leading to unauthorized access to sensitive database information. The vulnerability arises from insufficient escaping of user-supplied URL parameters in the `get_global_remediations()` method, which are directly concatenated into SQL JOIN clauses without proper sanitization. Exploitation is possible when the plugin is connected to an Elementor account with the Remediation module active. Despite the release of a patched version (4.1.0) on February 23, 2026, data indicates that only about 36% of the affected websites have updated, leaving over 250,000 sites vulnerable. This incident underscores the persistent threat posed by SQL injection vulnerabilities in web applications, emphasizing the need for developers to implement robust input validation and sanitization practices. Website administrators are urged to promptly update plugins and maintain regular security audits to mitigate such risks.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Chrome Extensions Compromised Post-Ownership Transfer: A 2026 Case Study
Impact· HIGH

Chrome Extensions Compromised Post-Ownership Transfer: A 2026 Case Study

In February 2026, two Google Chrome extensions, QuickLens and ShotBird, were compromised following ownership transfers. The new owners introduced malicious updates that stripped security headers from HTTP responses, enabling code injection and data theft. These updates allowed attackers to execute arbitrary JavaScript, leading to the exfiltration of sensitive user data, including credentials and browsing history. The incident underscores the risks associated with browser extension supply chains and the potential for legitimate tools to become vectors for malware distribution. This event highlights the growing trend of attackers exploiting trusted browser extensions to infiltrate systems, emphasizing the need for vigilant monitoring of software supply chains and the implementation of robust security measures to detect and prevent such compromises.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Security Alert: WordPress User Registration & Membership Plugin Vulnerability
Impact· CRITICAL

Critical Security Alert: WordPress User Registration & Membership Plugin Vulnerability

In March 2026, a critical vulnerability (CVE-2026-1492) was discovered in the WordPress User Registration & Membership plugin, affecting versions up to and including 5.1.2. This flaw allowed unauthenticated attackers to create administrator accounts by supplying a role value during membership registration, due to improper privilege management. The vulnerability was actively exploited, enabling attackers to gain full control over affected websites, leading to potential data theft and malware distribution. ([wordfence.com](https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/user-registration/user-registration-membership-512-unauthenticated-privilege-escalation-via-membership-registration?utm_source=openai)) The incident underscores the persistent targeting of WordPress plugins by cybercriminals, highlighting the importance of timely updates and robust security practices. Website administrators are urged to update to version 5.1.3 or later to mitigate this risk. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/wordpress-membership-plugin-bug-exploited-to-create-admin-accounts/?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Malicious Laravel Packages Deploy PHP RAT
Impact· HIGH

Malicious Laravel Packages Deploy PHP RAT

In March 2026, cybersecurity researchers identified malicious PHP packages on Packagist, masquerading as Laravel utilities, which deployed a cross-platform remote access trojan (RAT) functional on Windows, macOS, and Linux systems. The packages—nhattuanbl/lara-helper, nhattuanbl/simple-queue, and nhattuanbl/lara-swagger—were published by the user 'nhattuanbl' and contained obfuscated code that, once installed, connected to a command-and-control server, granting attackers full remote access to compromised hosts. This access allowed for execution of shell commands, file manipulation, and system reconnaissance, posing significant security risks to affected applications. ([thehackernews.com](https://thehackernews.com/2026/03/fake-laravel-packages-on-packagist.html?utm_source=openai)) This incident underscores the growing threat of supply chain attacks targeting open-source ecosystems. Developers are urged to exercise caution when incorporating third-party packages, especially from less-known sources, and to implement rigorous security audits to detect and mitigate such vulnerabilities.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Olympique de Marseille's 2026 Cyberattack: A Case Study in Incident Response
Impact· MEDIUM

Olympique de Marseille's 2026 Cyberattack: A Case Study in Incident Response

In February 2026, Olympique de Marseille, a prominent French football club, experienced a cyberattack targeting its official website. A hacker claimed to have accessed and offered for sale a database containing personal information of approximately 400,000 supporters. The club promptly addressed the incident, confirming an attempted intrusion but disputing the scale of the breach. They assured that no banking details or passwords were compromised and took immediate steps to secure their systems, including reissuing e-tickets for upcoming matches as a precautionary measure. This incident underscores the growing trend of cybercriminals targeting sports organizations, highlighting the critical need for robust cybersecurity measures in the sector. The swift response by Olympique de Marseille serves as a case study in effective incident management and the importance of transparent communication with stakeholders.

5 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
ManoMano Data Breach 2026: Lessons in Third-Party Risk Management
Impact· HIGH

ManoMano Data Breach 2026: Lessons in Third-Party Risk Management

In January 2026, French DIY e-commerce giant ManoMano experienced a significant data breach affecting approximately 38 million customers. The breach occurred when hackers compromised a third-party customer service provider, leading to unauthorized access to personal data, including full names, email addresses, phone numbers, and customer service communications. Notably, account passwords and financial information remained secure, as they were not stored with the subcontractor. Upon discovery, ManoMano promptly disabled the compromised account, initiated an internal investigation, and notified relevant authorities, including CNIL and ANSSI. The company also established a dedicated helpline for affected customers and issued warnings about potential phishing attempts leveraging the stolen data. This incident underscores the critical importance of securing third-party service providers, as supply chain vulnerabilities can lead to substantial data breaches. Organizations must rigorously assess and monitor the security practices of their subcontractors to prevent similar incidents. Additionally, customers are advised to remain vigilant against phishing attempts and verify the authenticity of communications purportedly from ManoMano or its partners.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Malicious StripeApi NuGet Package Mimics Official Library to Steal API Tokens
Impact· MEDIUM

Malicious StripeApi NuGet Package Mimics Official Library to Steal API Tokens

In February 2026, a malicious NuGet package named StripeApi.Net was discovered impersonating the legitimate Stripe.net library. Uploaded by a user named StripePayments on February 16, 2026, the package closely resembled the official library, using the same icon and nearly identical documentation. The threat actor artificially inflated the download count to over 180,000 across 506 versions to appear credible. The package replicated some of Stripe.net's functionality but modified critical methods to collect and exfiltrate sensitive data, including users' Stripe API tokens, to the attacker. The package was removed shortly after its discovery, minimizing potential damage. ([thehackernews.com](https://thehackernews.com/2026/02/malicious-stripeapi-nuget-package.html?utm_source=openai)) This incident underscores the persistent threat of supply chain attacks targeting software repositories. The use of typosquatting and artificial download inflation highlights the need for developers to exercise caution when integrating third-party libraries. Ensuring the authenticity of packages and monitoring for suspicious activity are crucial to maintaining software supply chain security.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Keenadu Backdoor: A Deep Dive into the 2026 Android Firmware Compromise
Impact· HIGH

Keenadu Backdoor: A Deep Dive into the 2026 Android Firmware Compromise

In February 2026, Kaspersky researchers uncovered a firmware-level backdoor named Keenadu embedded in Android tablets from multiple manufacturers, including Alldocube. This malware, integrated during the firmware build process, injects itself into the Zygote process, granting attackers extensive control over the device. Keenadu enables remote execution of malicious payloads, such as hijacking browser searches, monetizing app installations, and interacting with advertising elements. The backdoor has been detected in firmware dating back to August 2023, affecting over 13,700 users worldwide, with significant concentrations in Russia, Japan, Germany, Brazil, and the Netherlands. The discovery of Keenadu underscores the escalating threat of supply chain attacks targeting device firmware. This incident highlights the critical need for manufacturers to secure their development processes and for consumers to remain vigilant about device integrity. The integration of malware at such a fundamental level poses significant challenges for detection and removal, emphasizing the importance of robust security measures throughout the supply chain.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports