✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Higher Education/Acadamia
Breach intelligence, attack campaigns, and threat reports targeting the Higher Education/Acadamia sector.
Explore Other Sectors
Higher Education/Acadamia Threat Reports
Instructure Reports Cybersecurity Incident in May 2026
In May 2026, Instructure, the developer of the Canvas learning management system, disclosed a cybersecurity incident involving a criminal threat actor. The company is collaborating with external forensic experts to assess the breach's scope and mitigate its impact. As a precaution, services such as Canvas Data 2 and Canvas Beta have been placed under maintenance, potentially affecting tools dependent on API keys. ([status.instructure.com](https://status.instructure.com/?utm_source=openai)) This incident underscores the escalating trend of cyberattacks targeting educational technology firms, which manage extensive personal data of students and educators. The breach highlights the critical need for robust security measures and proactive threat detection within the edtech sector.
2 months ago
Kill Chain
Cordial and Snarky Spider's Rapid Data Theft and Extortion Attacks
In October 2025, two financially motivated threat groups, Cordial Spider and Snarky Spider, affiliated with The Com, initiated a series of rapid data theft and extortion attacks targeting U.S.-based organizations across sectors such as academia, aviation, retail, hospitality, automotive, financial services, legal, and technology. Utilizing voice-phishing and social engineering tactics, these groups directed employees to fraudulent single sign-on (SSO) pages to capture credentials, enabling them to infiltrate identity platforms and traverse SaaS environments. Once inside, they removed existing multi-factor authentication (MFA) devices, established their own, and deleted alerts to conceal their activities, leading to significant data exfiltration and extortion demands, often in the seven-figure range. This incident underscores a growing trend of cybercriminals leveraging sophisticated social engineering techniques to exploit identity systems, highlighting the urgent need for organizations to enhance their security measures against such evolving threats.
2 months ago
Kill Chain
Vect 2.0 Ransomware: A Flawed Threat Acting as a Data Wiper
In April 2026, the Vect 2.0 ransomware variant was discovered to contain a critical design flaw that causes it to function as a data wiper rather than traditional ransomware. This flaw affects versions targeting Windows, Linux, and VMware ESXi systems. Specifically, for files larger than 128KB, the malware generates four encryption nonces but only retains the final one, rendering the first three-quarters of each large file permanently unrecoverable. Consequently, victims who pay the ransom cannot retrieve their critical data, as the necessary decryption information is irreversibly lost. ([darkreading.com](https://www.darkreading.com/threat-intelligence/vect-ransomware-wiper-design-error?utm_source=openai)) This incident underscores the evolving nature of cyber threats, where even ransomware can inadvertently become more destructive due to coding errors. Organizations must prioritize robust backup strategies and comprehensive security measures to mitigate such risks. The Vect 2.0 case also highlights the importance of thorough threat analysis and the potential unintended consequences of malware development flaws.
2 months ago
Kill Chain
NASA Employees Targeted in Chinese Phishing Scheme
Between January 2017 and December 2021, Chinese national Song Wu orchestrated a sophisticated spear-phishing campaign targeting NASA, the U.S. military, universities, and private companies. By impersonating U.S. researchers and engineers, Wu successfully obtained sensitive aerospace software and source code, violating U.S. export control laws. The scheme led to unauthorized access to defense-related technologies, posing significant national security risks. In September 2024, Wu was indicted on multiple counts of wire fraud and aggravated identity theft but remains at large. This incident underscores the persistent threat of state-sponsored cyber espionage and the critical need for robust cybersecurity measures to protect sensitive information. Organizations must remain vigilant against increasingly sophisticated phishing tactics employed by foreign adversaries.
3 months ago
Kill Chain
Zimbra CVE-2025-48700 XSS Vulnerability Exploitation in 2026
In April 2026, over 10,000 Zimbra Collaboration Suite (ZCS) servers were found vulnerable to active exploitation of a cross-site scripting (XSS) flaw, identified as CVE-2025-48700. This vulnerability allows unauthenticated attackers to execute arbitrary JavaScript within a user's session by sending crafted emails, potentially leading to unauthorized access to sensitive information. Despite patches released in June 2025, a significant number of servers remained unpatched, exposing organizations to ongoing attacks. The continued exploitation of CVE-2025-48700 underscores the critical importance of timely patch management and vigilance against XSS vulnerabilities. Organizations must prioritize updating their systems and implementing robust security measures to mitigate such risks.
3 months ago
Kill Chain
Unveiling 'fast16': The Earliest Known Cyber Sabotage Tool
In April 2026, SentinelOne researchers uncovered 'fast16,' a previously undocumented malware framework dating back to 2005. This sophisticated tool was designed to subtly corrupt high-precision mathematical computations in engineering and scientific software by introducing near-imperceptible errors. The malware employed a 'cluster munition' delivery mechanism, deploying multiple 'wormlets' to propagate the main payload across target environments by exploiting vulnerabilities. This discovery predates the infamous Stuxnet by at least five years, marking 'fast16' as the earliest known cyber weapon aimed at sabotaging critical infrastructure through data integrity manipulation. The revelation of 'fast16' underscores the longstanding and evolving nature of state-sponsored cyber sabotage. It highlights the necessity for organizations, especially those handling sensitive and high-precision computations, to implement robust security measures and maintain vigilance against sophisticated threats that may have been active undetected for extended periods.
3 months ago
Kill Chain
Extradition of Xu Zewei: Unveiling the HAFNIUM Cyber Espionage Campaign
In early 2021, the Chinese state-sponsored threat group HAFNIUM exploited zero-day vulnerabilities in Microsoft Exchange Server to infiltrate approximately 13,000 U.S. organizations. The attackers targeted sectors including infectious disease research, law firms, universities, defense contractors, and policy think tanks, aiming to steal sensitive data such as COVID-19 vaccine research. The campaign involved deploying web shells for persistent remote access and exfiltrating data to external servers. ([cyberscoop.com](https://cyberscoop.com/xu-zewei-extradited-china-national-silk-typhoon-hafnium/?utm_source=openai)) On April 27, 2026, the U.S. Department of Justice announced the extradition of Xu Zewei from Italy to the United States. Xu, allegedly operating under the direction of China's Ministry of State Security, was charged with multiple offenses related to the HAFNIUM campaign. This development underscores the ongoing international efforts to hold cybercriminals accountable and highlights the persistent threat posed by nation-state actors targeting critical sectors. ([cyberscoop.com](https://cyberscoop.com/xu-zewei-extradited-china-national-silk-typhoon-hafnium/?utm_source=openai))
3 months ago
Kill Chain
Chinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research Cyberattacks
In April 2026, Chinese national Xu Zewei was extradited from Italy to the United States to face charges related to cyberattacks conducted between February 2020 and June 2021. Xu, allegedly operating under the direction of China's Ministry of State Security, targeted U.S. universities and organizations to steal COVID-19 research data. He exploited vulnerabilities in Microsoft Exchange Server, compromising thousands of systems worldwide. Xu was arrested in Milan in July 2025 and now faces multiple charges, including wire fraud and aggravated identity theft. ([justice.gov](https://www.justice.gov/opa/pr/prolific-chinese-state-sponsored-contract-hacker-extradited-italy?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber espionage, particularly in the context of global health crises. The extradition highlights international cooperation in combating cybercrime and the ongoing need for robust cybersecurity measures to protect sensitive research and infrastructure.
3 months ago
Kill Chain
UK Issues Warning on Chinese Hackers Using Botnets to Evade Detection
In April 2026, the UK's National Cyber Security Centre (NCSC) and international partners issued a warning about Chinese state-sponsored hackers employing large-scale proxy networks composed of hijacked consumer devices to evade detection. These botnets, primarily consisting of compromised small office/home office (SOHO) routers and Internet of Things (IoT) devices, enable attackers to route malicious traffic through multiple nodes, obscuring their origins and complicating attribution. This tactic has been linked to groups such as Flax Typhoon and Volt Typhoon, which have targeted critical infrastructure sectors including military, government, telecommunications, and IT. The increasing use of such covert networks signifies a strategic shift in cyber operations, highlighting the need for enhanced security measures. Organizations are advised to implement multifactor authentication, monitor network edge devices, utilize dynamic threat intelligence feeds, and adopt zero-trust architectures to mitigate the risks posed by these evolving threats.
3 months ago
Kill Chain
The Gentlemen Ransomware Group's Rapid Rise in 2026
In mid-2025, a ransomware group known as 'The Gentlemen' emerged, rapidly escalating its operations to claim over 320 victims by early 2026. Operating under a Ransomware-as-a-Service (RaaS) model, the group employs sophisticated tactics, including the use of SystemBC proxy malware for covert tunneling and payload delivery. Their attacks span multiple industries and geographies, with a notable focus on corporate environments. The Gentlemen's rapid expansion and advanced techniques underscore the evolving threat landscape posed by modern ransomware groups. Organizations must remain vigilant, as the group's continued activity highlights the persistent risk of ransomware attacks targeting enterprises worldwide.
3 months ago
Kill Chain
Insider Threat: Ransomware Negotiator's Guilty Plea in BlackCat Scheme
In April 2026, Angelo Martino, a former ransomware negotiator at DigitalMint, pleaded guilty to conspiring with the BlackCat/ALPHV ransomware group to extort U.S. companies in 2023. Martino exploited his position by providing BlackCat with confidential information about his clients' insurance policy limits and negotiation strategies, enabling the attackers to maximize ransom demands. Alongside co-conspirators Ryan Goldberg and Kevin Martin, Martino participated in deploying ransomware attacks, resulting in at least $1.2 million in Bitcoin payments from a single victim. Law enforcement has seized approximately $10 million in assets from Martino, including digital currency and luxury items. This case underscores the critical risk posed by insider threats within cybersecurity roles. The incident highlights the evolving tactics of ransomware groups and the importance of stringent internal controls to prevent insider collusion. Organizations must reassess their security protocols and ensure clear separation of duties to mitigate such risks.
3 months ago
Kill Chain
Microsoft's April 2026 Update Causes Domain Controller Reboot Loops
In April 2026, Microsoft released security update KB5082063, which led to unexpected reboot loops in non-Global Catalog domain controllers utilizing Privileged Access Management (PAM). The issue stemmed from crashes in the Local Security Authority Subsystem Service (LSASS) during startup, rendering authentication and directory services inoperable and potentially making the domain unavailable. Affected systems included Windows Server versions 2025, 2022, 23H2, 2019, and 2016. Microsoft acknowledged the problem and advised administrators to contact Microsoft Support for mitigation measures. This incident underscores the critical importance of thorough testing and validation of security updates, especially in environments with complex configurations like PAM. Organizations should implement robust update management processes, including staged rollouts and comprehensive monitoring, to swiftly identify and address such issues, thereby minimizing operational disruptions.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports