✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Higher Education/Acadamia
Breach intelligence, attack campaigns, and threat reports targeting the Higher Education/Acadamia sector.
Explore Other Sectors
Higher Education/Acadamia Threat Reports
NGINX Server Compromise 2026: Understanding the Traffic Redirection Attack
In early February 2026, a sophisticated cyberattack targeted NGINX servers, leading to unauthorized redirection of user traffic through attacker-controlled infrastructure. The threat actors exploited vulnerabilities in NGINX configurations, particularly by injecting malicious 'location' blocks into existing configuration files. This manipulation allowed them to intercept and reroute incoming requests without triggering standard security alerts, as the abuse leveraged legitimate directives like 'proxy_pass'. The campaign primarily affected websites with Asian top-level domains and government and educational institutions, compromising the integrity and confidentiality of user data. This incident underscores the critical need for organizations to regularly audit and secure their web server configurations. The attackers' method of embedding malicious instructions within NGINX configuration files highlights the evolving sophistication of cyber threats and the importance of proactive defense measures to prevent similar breaches.
5 months ago
Kill Chain
Microsoft Warns of Python Infostealers Targeting macOS via Fake Ads and Installers
In late 2025, Microsoft observed a surge in macOS-targeted information-stealing campaigns leveraging Python-based malware. Attackers employed social engineering tactics, including malicious advertisements and fake installers, to distribute infostealers like Atomic macOS Stealer (AMOS), MacSync, and DigitStealer. These campaigns utilized fileless execution, native macOS utilities, and AppleScript automation to harvest sensitive data such as web browser credentials, iCloud Keychain contents, and developer secrets. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/02/02/infostealers-without-borders-macos-python-stealers-and-platform-abuse/?utm_source=openai)) This trend underscores a significant shift in cyber threats, with attackers expanding their focus beyond Windows to target macOS environments. The use of cross-platform languages like Python facilitates rapid adaptation of malware across different operating systems, posing increased risks to organizations with diverse device ecosystems. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/02/02/infostealers-without-borders-macos-python-stealers-and-platform-abuse/?utm_source=openai))
5 months ago
Kill Chain
The Rising Threat of AI-Enhanced Phishing Attacks in 2025
In 2025, phishing attacks surged dramatically, with over 1.35 million incidents reported between May and July alone. ([cybercrimeinfocenter.org](https://www.cybercrimeinfocenter.org/phishing-activity-quarter-over-quarter-numbers-may-july-2025?utm_source=openai)) Cybercriminals increasingly leveraged AI technologies to craft sophisticated and personalized phishing campaigns, leading to a 160% rise in credential theft. ([itpro.com](https://www.itpro.com/security/cyber-attacks/credential-theft-has-surged-160-percent-in-2025?utm_source=openai)) These attacks often exploited psychological tactics such as urgency, fear, and authority to deceive even the most vigilant individuals. The financial impact was substantial, with phishing-related breaches costing organizations an average of $4.88 million per incident. ([deepstrike.io](https://deepstrike.io/blog/Phishing-Statistics-2025?utm_source=openai)) The escalating sophistication of phishing attacks underscores the critical need for organizations to enhance their cybersecurity measures. Implementing AI-driven detection systems, conducting continuous employee training, and adopting phishing-resistant multi-factor authentication are essential steps to mitigate these evolving threats.
5 months ago
Kill Chain
SolarWinds 2026 Unauthenticated RCE Vulnerability: Immediate Action Required
In January 2026, a critical vulnerability (CVE-2025-40551) was discovered in SolarWinds Web Help Desk, allowing unauthenticated remote code execution due to untrusted data deserialization. This flaw enables attackers to execute arbitrary commands on affected systems without authentication, posing significant risks to organizations using this software. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-flags-critical-solarwinds-rce-flaw-as-actively-exploited/?utm_source=openai)) The exploitation of this vulnerability underscores the persistent threat posed by unpatched software vulnerabilities, emphasizing the need for organizations to maintain rigorous patch management practices to safeguard against such attacks.
5 months ago
Kill Chain
macOS Infostealer Campaigns of 2025: Understanding the Threat Landscape
In 2025, a series of sophisticated infostealer campaigns targeted macOS users, exploiting social engineering tactics and trusted platforms to distribute malware. Attackers utilized deceptive websites, fake software installers, and malicious advertisements to deliver infostealers like Atomic macOS Stealer (AMOS), DigitStealer, and MacSync. These malware variants harvested sensitive data, including browser credentials, cryptocurrency wallets, and developer secrets, leading to significant security breaches and financial losses. The increasing prevalence of cross-platform infostealers underscores a critical shift in cyber threats, emphasizing the need for enhanced security measures across all operating systems. Organizations must remain vigilant against evolving tactics, such as the abuse of legitimate platforms and the use of fileless execution methods, to effectively mitigate these risks.
5 months ago
Kill Chain
Cloud Storage Payment Scam 2026: A Global Phishing Threat
In late 2025 and early 2026, a widespread phishing campaign targeted users globally with fraudulent emails claiming their cloud storage subscriptions were at risk due to payment failures. These emails, often personalized with the recipient's name, warned of imminent data loss and urged immediate action. Victims who clicked on the provided links were redirected to phishing sites mimicking legitimate cloud service portals, where they were prompted to enter sensitive information or make payments. The attackers exploited users' fears of losing valuable data to steal personal and financial information. This incident underscores the increasing sophistication of phishing attacks, particularly those leveraging social engineering tactics to impersonate trusted services. The prevalence of such scams highlights the critical need for heightened vigilance and robust cybersecurity measures to protect against evolving threats.
5 months ago
Kill Chain
RedKitten 2026: Iranian State-Sponsored Malware Targets Human Rights NGOs
In January 2026, a cyber espionage campaign named RedKitten targeted non-governmental organizations and individuals documenting human rights abuses in Iran. The attackers employed AI-generated malware, delivered through malicious Excel files disguised as casualty records from recent protests. Upon enabling macros, the malware, dubbed SloppyMIO, was deployed, utilizing GitHub and Google Drive for configuration and Telegram for command-and-control. This operation is attributed to Iranian state-sponsored actors aiming to infiltrate and disrupt human rights documentation efforts. ([harfanglab.io](https://harfanglab.io/insidethelab/redkitten-ai-accelerated-campaign-targeting-iranian-protests/?utm_source=openai)) This incident underscores the escalating use of artificial intelligence in cyber attacks, enabling rapid development and deployment of sophisticated malware. The targeting of human rights organizations highlights the increasing risks faced by civil society groups, emphasizing the need for enhanced cybersecurity measures and vigilance against state-sponsored cyber threats.
5 months ago
Kill Chain
Vivaldi Webmail Phishing Attack Exploits Google Presentations - January 2026
In January 2026, a phishing campaign targeted Vivaldi Webmail users by exploiting Google Presentations to bypass security measures. Attackers sent emails containing links to Google Slides presentations, which, when accessed, redirected users to fraudulent login pages designed to harvest credentials. This method effectively circumvented traditional phishing detection mechanisms by leveraging trusted platforms. The incident underscores a growing trend where cybercriminals abuse legitimate services to execute phishing attacks, highlighting the need for enhanced vigilance and adaptive security strategies to counteract evolving threats.
5 months ago
Kill Chain
Critical Ivanti EPMM Zero-Day Vulnerabilities Exploited in 2026
In January 2026, Ivanti disclosed two critical zero-day vulnerabilities (CVE-2026-1281 and CVE-2026-1340) in its Endpoint Manager Mobile (EPMM) platform, both with a CVSS score of 9.8. These code injection flaws allow unauthenticated remote code execution, enabling attackers to gain full control over affected systems. Exploitation in the wild has been confirmed, with a limited number of customers compromised prior to disclosure. The vulnerabilities affect EPMM versions up to 12.7.0.0, and Ivanti has released RPM patches to address them. Organizations are urged to apply these patches immediately and monitor for signs of compromise. ([ivanti.com](https://www.ivanti.com/blog/january-2026-epmm-security-update?utm_source=openai)) The inclusion of CVE-2026-1281 in CISA's Known Exploited Vulnerabilities catalog underscores the severity and active exploitation of these flaws. This incident highlights the ongoing threat posed by zero-day vulnerabilities in widely used enterprise solutions, emphasizing the need for proactive vulnerability management and rapid response strategies.
5 months ago
Kill Chain
Johnson Controls Metasys Vulnerability: 2026 SQL Exposure Threatens Critical Infrastructure
In January 2026, Johnson Controls disclosed a critical vulnerability (CVE-2025-26385) affecting multiple Metasys products including the Application and Data Server (ADS), Extended Application and Data Server (ADX), LCS8500, NAE8500, System Configuration Tool (SCT), and Controller Configuration Tool (CCT). The flaw, stemming from improper neutralization of special elements used in a command, could allow remote, unauthenticated attackers to execute arbitrary SQL statements, leading to potential alteration or loss of critical data. Attackers could exploit the issue remotely over network-exposed ports, causing high impact to confidentiality, integrity, and availability across critical infrastructure sectors worldwide. This incident underscores the increasing risks posed by vulnerabilities in operational technology and industrial control systems. As attackers continue to target widely deployed OT/ICS solutions, organizations must accelerate patch deployment, network segmentation, and adopt hardened security practices to protect essential services and meet evolving regulatory expectations.
5 months ago
Kill Chain
CISA Flags Four Actively Exploited Vulnerabilities: 2026 Software Risk Alert
In January 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) catalog to include four new software flaws confirmed as actively exploited in the wild. Among these, CVE-2025-68645 in the Synacor Zimbra Collaboration Suite enables remote file inclusion through a PHP vulnerability, presenting severe risks of remote code execution and unauthorized access. Attackers have been leveraging these vulnerabilities to infiltrate enterprise and government infrastructures, resulting in the exposure of sensitive data and disruption of critical collaboration services. This incident exemplifies the accelerating pattern of opportunistic exploitation by cybercriminals and state-backed actors who quickly weaponize disclosed vulnerabilities. It highlights the urgent need for timely patching, robust segmentation, traffic monitoring controls, and adherence to regulatory frameworks such as HIPAA, PCI DSS, and NIST to effectively mitigate operational risk.
6 months ago
Kill Chain
Kimwolf Botnet: How Residential Proxy Infections Fueled a 2025 IoT Crisis
In late 2025, the Kimwolf botnet rapidly infected over 2 million IoT devices—primarily unofficial Android TV streaming boxes—by exploiting insecure residential proxy networks, notably those operated by IPIDEA. Kimwolf used these proxies to scan and compromise additional devices on local networks, enabling attackers to conscript them for distributed denial-of-service (DDoS) attacks and other forms of malicious activity, such as ad fraud and data scraping. Investigations by Infoblox and other security firms found Kimwolf infections active across diverse industry sectors worldwide, including healthcare, finance, utilities, and notably, dozens of sensitive government networks. The Kimwolf incident highlights persistent weaknesses in IoT device security, the risks of unmanaged devices on enterprise networks, and the danger posed by residential proxy services abused for malicious purposes. As threat actors increasingly exploit lateral movement via proxy endpoints, organizations in all industries must strengthen segmentation, east-west traffic monitoring, and endpoint visibility to mitigate future outbreaks.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports