✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Higher Education/Acadamia
Breach intelligence, attack campaigns, and threat reports targeting the Higher Education/Acadamia sector.
Explore Other Sectors
Higher Education/Acadamia Threat Reports
Dragon Boss Solutions' 2025 Adware Supply Chain Attack: A Wake-Up Call for Cybersecurity
In March 2025, Dragon Boss Solutions LLC, a company based in the United Arab Emirates, distributed adware that exploited an unsecured software update mechanism to disable antivirus programs on over 25,000 systems globally. The adware utilized Advanced Installer's update tool to deploy malicious payloads with SYSTEM privileges, effectively neutralizing security defenses and establishing persistence through scheduled tasks and Windows Management Instrumentation (WMI) event subscriptions. This left numerous high-value networks, including educational institutions, government entities, and critical infrastructure, vulnerable to further exploitation. ([huntress.com](https://www.huntress.com/blog/pups-grow-fangs?utm_source=openai)) This incident underscores the evolving threat landscape where seemingly benign software can transform into significant security risks. The exploitation of legitimate update mechanisms highlights the necessity for organizations to scrutinize software supply chains and implement robust monitoring to detect and mitigate such sophisticated attacks. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/harmless-global-adware-av-killer/?utm_source=openai))
3 months ago
Kill Chain
McGraw Hill's 2026 Data Breach: A Wake-Up Call for Third-Party Security
In April 2026, McGraw Hill, a leading educational publisher, experienced a data breach orchestrated by the cybercriminal group ShinyHunters. The attackers exploited a misconfiguration in McGraw Hill's Salesforce environment, gaining unauthorized access to a webpage hosted on the platform. This breach led to the exfiltration of personally identifiable information (PII) from approximately 13.5 million user accounts, including names, physical addresses, phone numbers, and email addresses. McGraw Hill confirmed the incident, emphasizing that their internal systems, customer databases, and educational platforms remained secure. The company attributed the breach to a broader issue affecting multiple organizations utilizing Salesforce, highlighting the risks associated with third-party service integrations. ([techradar.com](https://www.techradar.com/pro/security/this-activity-appears-to-be-part-of-a-broader-issue-education-company-mcgraw-hill-becomes-latest-to-see-its-salesforce-data-hacked?utm_source=openai)) This incident underscores the escalating threat posed by cybercriminal groups like ShinyHunters, who have shifted focus from traditional ransomware attacks to data extortion schemes. By exploiting vulnerabilities in widely-used platforms such as Salesforce, these actors can access vast amounts of sensitive data, posing significant risks to organizations and their customers. The McGraw Hill breach serves as a critical reminder for companies to rigorously assess and secure their third-party integrations to prevent similar incidents.
3 months ago
Kill Chain
Dragon Boss Solutions' 2026 Adware Supply Chain Attack: A Wake-Up Call for Cybersecurity
In March 2026, security researchers uncovered a sophisticated adware campaign orchestrated by Dragon Boss Solutions LLC, a company claiming to engage in 'search monetization research.' The campaign involved digitally signed software that, under the guise of legitimate applications, deployed payloads with SYSTEM privileges to disable antivirus protections across thousands of endpoints. This operation leveraged an unregistered update domain, allowing potential attackers to hijack the update mechanism and push malicious payloads to over 25,000 infected systems worldwide, including those within critical infrastructure sectors such as education, utilities, government, and healthcare. This incident underscores the evolving nature of adware threats, which are increasingly adopting advanced techniques to escalate privileges and disable security measures. The exploitation of unregistered domains in software update mechanisms highlights a significant supply chain vulnerability, emphasizing the need for organizations to scrutinize third-party software components and ensure the integrity of their update processes to prevent similar attacks.
3 months ago
Kill Chain
McGraw-Hill's 2026 Data Breach: Lessons in Third-Party Platform Security
In April 2026, McGraw-Hill, a leading education company, experienced a data breach due to a misconfiguration in its Salesforce environment. The cybercriminal group ShinyHunters exploited this vulnerability to access internal data. McGraw-Hill confirmed that the breach did not affect its Salesforce accounts, customer databases, or internal systems, and that the exposed data was limited and non-sensitive. However, ShinyHunters claimed to possess 45 million Salesforce records containing personally identifiable information (PII), contradicting the company's statement. The group threatened to leak the stolen data by April 14 unless a ransom was paid. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/mcgraw-hill-confirms-data-breach-following-extortion-threat/?utm_source=openai)) This incident underscores the critical importance of securing third-party platforms and configurations. Misconfigurations in widely used services like Salesforce can serve as entry points for threat actors, leading to significant data breaches and extortion attempts. Organizations must prioritize regular audits and robust security measures to protect sensitive information.
3 months ago
Kill Chain
UNSW's 'Capture the Narrative' Wargame Reveals AI's Power in Social Media Manipulation
In 2025, the University of New South Wales (UNSW) conducted 'Capture the Narrative,' a pioneering wargame where students developed AI-driven bots to influence a simulated election on a fictional social media platform. Over four weeks, participants generated over 7 million posts, with more than 60% of content produced by these bots. The exercise demonstrated how AI can be leveraged to manipulate public opinion, resulting in a 1.78% swing that altered the election outcome. This experiment underscores the growing threat of AI-powered influence operations in real-world scenarios. ([unsw.edu.au](https://www.unsw.edu.au/newsroom/news/2026/01/social-media-wargame-reveals-how-ai-bots-can-swing-election?utm_source=openai)) The relevance of this incident is heightened by the increasing use of AI in disinformation campaigns. For instance, Microsoft reported that China has begun employing generative AI to create realistic images supporting divisive U.S. political content, marking a significant evolution in influence operations. ([axios.com](https://www.axios.com/2023/09/08/china-ai-disinformation-microsoft?utm_source=openai))
3 months ago
Kill Chain
Marimo 2026 Pre-Auth RCE Vulnerability Exploited
In April 2026, a critical pre-authentication remote code execution (RCE) vulnerability, identified as CVE-2026-39987, was discovered in Marimo, a popular open-source Python notebook platform. This flaw allowed unauthenticated attackers to gain full PTY shell access via the /terminal/ws WebSocket endpoint, enabling arbitrary system command execution. Exploitation was observed within 10 hours of public disclosure, with attackers swiftly leveraging the vulnerability to exfiltrate sensitive information. The issue affected all Marimo versions up to 0.20.4 and was addressed in version 0.23.0. ([thehackernews.com](https://thehackernews.com/2026/04/marimo-rce-flaw-cve-2026-39987.html?utm_source=openai)) The rapid exploitation of CVE-2026-39987 underscores the critical need for immediate patching and vigilant monitoring of open-source tools. This incident highlights the growing trend of attackers targeting vulnerabilities in widely-used development platforms, emphasizing the importance of proactive security measures in software development environments.
3 months ago
Kill Chain
Microsoft 2026: Storm-2755's Payroll Pirate Attack Exposes MFA Vulnerabilities
In April 2026, Microsoft identified a financially motivated threat actor, Storm-2755, targeting Canadian employees through sophisticated 'payroll pirate' attacks. The attackers employed adversary-in-the-middle (AiTM) techniques, using malicious Microsoft 365 sign-in pages to intercept authentication tokens and session cookies. This method allowed them to bypass traditional multi-factor authentication (MFA) and gain unauthorized access to employee accounts. Once inside, they created inbox rules to conceal communications from human resources and manipulated payroll systems, such as Workday, to redirect salary payments to accounts under their control. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/09/investigating-storm-2755-payroll-pirate-attacks-targeting-canadian-employees/?utm_source=openai)) This incident underscores the evolving nature of business email compromise (BEC) schemes, highlighting the need for organizations to implement phishing-resistant MFA solutions and monitor for anomalous activities within their systems. The use of AiTM tactics to circumvent standard security measures signifies a shift in cybercriminal strategies, emphasizing the importance of continuous vigilance and adaptive security protocols. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/09/investigating-storm-2755-payroll-pirate-attacks-targeting-canadian-employees/?utm_source=openai))
3 months ago
Kill Chain
Marimo 2026 Pre-Auth RCE Exploit: A Wake-Up Call for Rapid Patch Management
In April 2026, a critical pre-authentication remote code execution (RCE) vulnerability, CVE-2026-39987, was identified in Marimo, an open-source Python notebook platform. This flaw allowed unauthenticated attackers to gain full shell access via the /terminal/ws WebSocket endpoint, bypassing authentication mechanisms. Exploitation was observed within 10 hours of public disclosure, with attackers conducting credential theft and reconnaissance activities. The vulnerability affected all Marimo versions up to 0.20.4 and was patched in version 0.23.0. This incident underscores the rapid weaponization of disclosed vulnerabilities, highlighting the necessity for organizations to promptly apply security patches and review authentication controls, especially in platforms exposed to the internet. The swift exploitation also emphasizes the importance of continuous monitoring and threat intelligence to detect and mitigate emerging threats effectively.
3 months ago
Kill Chain
LucidRook Malware Targets Taiwanese NGOs and Universities in 2025
In October 2025, the threat actor group UAT-10362 launched spear-phishing campaigns targeting non-governmental organizations (NGOs) and universities in Taiwan. These attacks utilized a newly identified Lua-based malware named 'LucidRook,' which was delivered through malicious LNK and EXE files disguised as legitimate software. Once executed, LucidRook embedded a Lua interpreter within a dynamic-link library (DLL) to download and execute staged Lua bytecode payloads, enabling the attackers to update functionality without modifying the core malware. The malware performed system reconnaissance, collecting information such as user and computer names, installed applications, and running processes, which was then encrypted and exfiltrated via FTP to attacker-controlled infrastructure. ([blog.talosintelligence.com](https://blog.talosintelligence.com/new-lua-based-malware-lucidrook/?utm_source=openai)) This incident underscores the evolving sophistication of cyber threats, particularly those targeting educational and non-governmental sectors. The use of modular malware like LucidRook, capable of dynamic updates and extensive obfuscation, highlights the need for organizations to enhance their cybersecurity measures, including employee training on phishing tactics and the implementation of advanced threat detection systems.
3 months ago
Kill Chain
UAT-10362's LucidRook Malware Targets Taiwanese NGOs in Spear-Phishing Attacks
In October 2025, a previously undocumented threat actor, UAT-10362, launched spear-phishing campaigns targeting Taiwanese non-governmental organizations (NGOs) and universities. The attackers distributed a new Lua-based malware named LucidRook, which embeds a Lua interpreter and Rust-compiled libraries within a dynamic-link library (DLL) to download and execute staged Lua bytecode payloads. The malware exhibits region-specific anti-analysis checks, activating only in Traditional Chinese language environments associated with Taiwan. The campaigns utilized malicious LNK and EXE files disguised as antivirus software, leveraging compromised FTP servers and out-of-band application security testing (OAST) services for command-and-control infrastructure. ([blog.talosintelligence.com](https://blog.talosintelligence.com/new-lua-based-malware-lucidrook/?utm_source=openai)) This incident underscores the evolving sophistication of cyber threats targeting specific regions and sectors. The use of multi-language modular design, layered anti-analysis features, and reliance on compromised or public infrastructure indicates a high level of operational maturity by UAT-10362. Organizations, especially those in Taiwan, should enhance their cybersecurity measures to detect and mitigate such advanced persistent threats.
3 months ago
Kill Chain
Storm-2755: Unveiling the 2026 Payroll Pirate AiTM Attack in Canada
In April 2026, a financially motivated threat actor identified as Storm-2755 targeted Canadian employees through a sophisticated 'payroll pirate' campaign. Utilizing adversary-in-the-middle (AiTM) phishing techniques, the attackers intercepted authentication sessions to gain unauthorized access to employee profiles on HR platforms. This access enabled them to divert salary payments to accounts under their control, resulting in direct financial losses for both individuals and organizations. The campaign was notable for its use of malvertising and search engine optimization (SEO) poisoning to lure victims to malicious sites, effectively bypassing traditional multi-factor authentication (MFA) methods. This incident underscores the evolving nature of cyber threats, particularly the increasing prevalence of AiTM attacks that can circumvent standard MFA protections. Organizations must recognize the limitations of traditional security measures and adopt more robust, phishing-resistant authentication methods to safeguard against such sophisticated attacks.
3 months ago
Kill Chain
Storm-1175's High-Velocity Medusa Ransomware Attacks in 2026
In April 2026, the financially motivated cybercriminal group Storm-1175 launched rapid ransomware attacks targeting healthcare, education, professional services, and finance sectors across Australia, the UK, and the US. Exploiting both zero-day and recently disclosed vulnerabilities, the group moved swiftly from initial access to data exfiltration and deployment of Medusa ransomware, often within 24 hours. Their tactics included creating new user accounts, deploying remote monitoring tools, stealing credentials, and disabling security software to facilitate their operations. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/?utm_source=openai)) This incident underscores the critical need for organizations to promptly patch vulnerabilities and enhance monitoring of web-facing assets. The speed and efficiency of Storm-1175's attacks highlight a growing trend among threat actors to exploit the narrow window between vulnerability disclosure and patch deployment, emphasizing the importance of proactive cybersecurity measures. ([darkreading.com](https://www.darkreading.com/threat-intelligence/storm-1175-medusa-ransomware-high-velocity/?utm_source=openai))
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports