✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Higher Education/Acadamia
Breach intelligence, attack campaigns, and threat reports targeting the Higher Education/Acadamia sector.
Explore Other Sectors
Higher Education/Acadamia Threat Reports
Festo Didactic 2025 Incident: Siemens TIA Portal Supply Chain Vulnerability Exposes Critical Risk
In November 2025, Festo SE & Co. KG disclosed a supply chain vulnerability affecting its Didactic products due to the integration of vulnerable versions of Siemens TIA Portal (V15–V18). The issue, tracked as CVE-2023-26293, stems from improper input validation, allowing attackers to leverage a path traversal flaw. This could result in the creation or overwriting of arbitrary files if a user is tricked into opening a malicious PC system configuration file, leading to potential arbitrary code execution. The exploit, which requires local access with user interaction, impacts engineering systems used globally across critical sectors, including manufacturing, energy, communications, and commercial facilities. This vulnerability is significant as it illustrates the increasing prevalence of supply chain risks in industrial and critical infrastructure software. With threat actors increasingly exploiting the software supply chain and user-driven entry vectors, maintaining rigorous update and validation processes has become a pressing challenge for organizations worldwide.
6 months ago
Kill Chain
CISA Flags New Chromium Browser Exploit: CVE-2025-13223 in Active Use
On November 19, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-13223—an actively exploited type confusion vulnerability in the Google Chromium V8 JavaScript engine—to its Known Exploited Vulnerabilities (KEV) Catalog. This flaw allows remote attackers to execute arbitrary code via a crafted web page, exploiting weaknesses in Chromium-based browsers used by federal and commercial entities. Threat actors have been leveraging this vulnerability to deliver malware and potentially gain unauthorized access to systems, heightening risk across government and enterprise environments. This incident is highly relevant as attackers continue to target zero-day and rapidly weaponized browser flaws, reflecting a broader trend of exploiting client-side vulnerabilities to bypass traditional network defenses. Regulatory and industry pressure for rapid patch management and strong endpoint protection is intensifying as attackers' tactics evolve.
6 months ago
Kill Chain
Unicode: The Hidden Security Threat Fueling 2024's Obfuscated Code Attacks
In late 2024, security researchers highlighted a series of application security vulnerabilities caused by improper handling of the Unicode character set, impacting numerous platforms and development environments. Attackers exploited Unicode features such as confusable characters, variant selectors, and bidirectional text markers, enabling impersonation, injection, and severe obfuscation of code in public repositories. Notably, a self-propagating worm known as "Glass Worm" leveraged invisible Unicode code points to disguise malicious code in Visual Studio Code extensions, bypassing manual code review and automated security checks. These techniques led to increased risk of code injection, credential spoofing, and long-term compromise of software supply chains. Unicode-driven attack techniques continue to gain prominence due to their effectiveness at evading human and automated detection. The recent spike in attacks demonstrates a broader trend towards supply chain risk and advanced code obfuscation, demanding urgent attention to Unicode normalization, secure coding practices, and robust detection mechanisms in compliance-driven industries.
6 months ago
Kill Chain
Hackers Exploit Ray AI to Launch Global Cryptojacking Botnet (2024)
In late 2024, malicious actors exploited an unauthenticated remote code execution vulnerability (CVE-2023-48022) in the open-source Ray AI framework, transforming exposed development environments into a globally distributed cryptojacking operation. Attackers leveraged Ray's scheduling and orchestration APIs to gain unauthorized access and deploy cryptomining payloads, particularly targeting environments with premium NVIDIA A100 GPUs. The campaign, identified by Oligo Security, unfolded in multiple phases: after initial malware delivery via GitLab infrastructure was disrupted, attackers quickly shifted to hosting on GitHub to sustain their operation. Over 200,000 exposed Ray clusters worldwide were at risk, significantly impacting cloud AI operations, startups, and research environments. This incident marks a major evolution in threat actor adaptation: rather than exploiting traditional network vulnerabilities, adversaries weaponized trusted automation features to evade detection and maximize illicit gain. The campaign illustrates mounting risks to cloud-hosted AI workloads, the dangers of insecure API exposure, and the urgent need for stringent internal network controls to defend against cryptojacking and abuse of compute resources.
6 months ago
Kill Chain
Princeton University Data Breach Exposes Alumni and Donor Information
On November 10, 2023, Princeton University experienced a significant data breach when unauthorized actors gained access to a university database containing sensitive information on alumni, donors, students, and faculty. The intrusion exposed personal details such as names, contact information, and donation records, with initial reports indicating the compromise originated from the university’s advancement and fundraising systems. Princeton moved quickly to secure impacted systems, notify affected individuals, and engage cybersecurity experts and law enforcement. The exposure raises concerns regarding the safeguarding of high-value personal and financial data held by educational institutions. This incident underscores the persistent threat higher education institutions face from cyberattacks targeting personal and philanthropic data. The Princeton breach highlights a surge in attacks exploiting third-party platforms and unencrypted internal data flows, aligning with broader trends toward increased ransomware and data extortion pressures observed throughout 2023.
6 months ago
Kill Chain
RondoDox Botnet Exploits Unpatched XWiki Servers via CVE-2025-24893
In November 2025, cybersecurity researchers identified a widescale campaign leveraging the RondoDox botnet to exploit unpatched XWiki server instances. Attackers targeted CVE-2025-24893—a critical eval injection vulnerability with a CVSS score of 9.8—allowing unauthenticated remote code execution through manipulated HTTP requests. Once compromised, affected XWiki servers were conscripted into the botnet, enabling further lateral spread and facilitating command-and-control capabilities for adversaries. Organizations reliant on XWiki for content collaboration faced outages, data exposure, and the threat of secondary attacks as RondoDox rapidly weaponized unremediated systems. The RondoDox campaign underscores a growing trend in the automated exploitation of high-severity vulnerabilities in open-source platforms. As threat actors increasingly target collaborative SaaS and wiki services, enterprises face heightened demands for rapid patch management, proactive threat detection, and adherence to zero trust principles to minimize supply chain risk.
6 months ago
Kill Chain
FBI Flags Akira Ransomware as Top Threat to US Critical Infrastructure in 2024
In September 2024, federal cyber authorities, including the FBI and CISA, issued a joint advisory detailing the significant threat posed by the Akira ransomware group. First identified in March 2023, Akira employs double-extortion tactics—stealing sensitive data before encrypting systems—to pressure victims for ransom. The group is associated with additional threat actors and has links to the former Conti operation. Akira has accumulated over $244 million in illicit proceeds by targeting small and medium-sized businesses, impacting sectors such as manufacturing, education, healthcare, IT, finance, and agriculture. The group leverages known vulnerabilities in critical infrastructure software, exploits stolen credentials, and uses remote access tools to compromise organizations, often exfiltrating data in just over two hours. The FBI considers Akira among its top five most consequential ransomware variants, reflecting a broader trend of increasingly sophisticated, fast-moving, and costly ransomware attacks. Recent activity highlights the group’s adaptability and operational security, reinforcing the urgent need for organizations to harden defenses as ransomware tactics evolve.
6 months ago
Kill Chain
Akira Ransomware 2025: How Edge Device Vulnerabilities Fueled Infrastructure Attacks
In November 2025, the Akira ransomware group and affiliates such as Storm-1567 and Howling Scorpius intensified attacks on critical infrastructure sectors by exploiting edge device and backup server vulnerabilities. Threat actors leveraged techniques including authentication bypass, brute-force credential attacks, and the deployment of new Akira_v2 malware for rapid encryption. Their sophisticated methods involved lateral movement through RDP/SSH, defense evasion with remote tools (Anydesk, LogMeIn), disabling security controls, and stealthy data exfiltration via FTP/SFTP/cloud channels. Impacted sectors ranged from Manufacturing and Education to Healthcare and Finance, resulting in encrypted systems, data theft, and serious operational disruption. This incident underscores the persistent evolution of ransomware tactics and the growing threat to organizations of all sizes. The prevalence of supply chain risks, rapid malware adaptation, and exploitation of misconfigured or outdated security perimeters demand continuous vigilance and investment in advanced detection, rapid patching, and segmentation strategies.
6 months ago
Kill Chain
Credential Stuffing at Scale: 2 Billion Email Addresses and 1.3 Billion Passwords Exposed in 2025
In late 2025, a massive credential stuffing incident came to light when nearly 2 billion email addresses and 1.3 billion unique passwords – sourced over years from various cybercriminal forums and compromised stealer logs – were aggregated and indexed by Synthient, then processed by Have I Been Pwned (HIBP) for user notification. The dataset included credentials from countless breaches, consolidated into one of the largest exposures of its kind to date. While the original leaks stemmed from malware infections, phishing, and prior breaches, the impact was compounded by password reuse and the easy redistribution of these records in the criminal underground. HIBP took technical and privacy-preserving steps to verify and notify affected users while preventing further risk of data linkage. This incident illustrates the ongoing risks posed by credential stuffing and highlights the long lifecycle of exposed data as threat actors continuously recycle and combine compromised information. The event underscores the importance of password hygiene, multi-factor authentication, and proactive notification as recycled data fuels ongoing cyberattacks across industries.
6 months ago
Kill Chain
University of Pennsylvania 2024 Data Breach: Alumni and Donor Information Compromised
In June 2024, the University of Pennsylvania confirmed a data breach involving unauthorized access to several internal systems linked to its development and alumni activities. Attackers infiltrated the university’s IT infrastructure, resulting in the theft of sensitive personal and institutional data. The breach impacted donors, alumni, and staff, exposing information such as names, contact details, and potentially financial data. University officials discovered the intrusion after observing suspicious activity and promptly initiated an investigation. Law enforcement and cybersecurity specialists were engaged to contain the incident, assess affected systems, and notify those impacted. This breach highlights the persistent risks that higher education institutions face from increasingly sophisticated cyberattacks, especially targeting sensitive donor and alumni databases. As ransomware and data exfiltration trends intensify, universities must enhance defenses and closely align with compliance frameworks to mitigate regulatory, reputational, and operational risks.
6 months ago
Kill Chain
SmudgedSerpent 2025: Espionage Hits Policy Experts Amid Iran-Israel Tensions
Between June and August 2025, an advanced threat group dubbed UNK_SmudgedSerpent orchestrated a series of targeted cyber espionage campaigns against U.S.-based academics and foreign policy experts. Leveraging spear-phishing and sophisticated social engineering, the attackers exploited topical Iranian political themes to deliver customized malware, enabling data exfiltration and continuous monitoring of sensitive research communications. The campaign coincided with heightened Iran–Israel tensions, harnessing unauthorized east-west network movement and encrypted C2 channels to bypass traditional security controls, resulting in significant exposure of policy research, analysis drafts, and privileged communications. This intrusion highlights the evolving tactics of nation-state-aligned actors who exploit contextual geopolitical unrest to target civilian research and policy infrastructure. The incident underscores the escalating risk to sectors handling sensitive knowledge, while accelerating demands for retroactive compliance audits and robust zero trust segmentation as espionage techniques continue to proliferate.
6 months ago
Kill Chain
Apple Patches Over 100 Multi-Platform Vulnerabilities in Major 2025 Security Update
In November 2025, Apple released security updates addressing over 100 vulnerabilities affecting core operating systems and components across iPhones, Macs, iPads, Safari, visionOS, watchOS, and Xcode. The update covered 105 vulnerabilities in macOS 26.1, 56 in iOS/iPadOS 26.1, and dozens more in related platforms. While Apple stated that no active exploitation was detected for these flaws, the sheer breadth of affected systems and lack of severity ratings heightened concern among security professionals about potential entry points for future attacks, especially given the criticality of WebKit-related issues and minimal vulnerability detail disclosure by Apple. This incident highlights persistent gaps in vendor transparency on vulnerability risk and the ongoing challenge of prioritizing patching in complex technology environments. As platforms like Apple’s remain in the crosshairs for attackers and as software interdependencies grow, organizations must stay vigilant in rapidly applying updates despite limited public clarity on bug severity.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports