✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Higher Education/Acadamia
Breach intelligence, attack campaigns, and threat reports targeting the Higher Education/Acadamia sector.
Explore Other Sectors
Higher Education/Acadamia Threat Reports
Akira Ransomware’s Disputed Data Breach: What Happened at Apache OpenOffice (2024)
In June 2024, the Akira ransomware group publicly claimed responsibility for a data breach affecting Apache OpenOffice, alleging the theft of 23 GB of sensitive corporate documents. Despite these assertions, the Apache Software Foundation conducted an internal investigation and officially disputed any evidence of compromise or unauthorized access, stating there were no indications of a breach in their infrastructure. This incident highlights the ongoing challenge organizations face with threat actor claims that may not always be substantiated but can cause reputational risk and user concern. Similar ransomware campaigns have surged in 2024, with groups leveraging public exposure even without confirming access to target data. The situation underscores the importance of proactive communication, transparent incident response, and technical validation as attackers increasingly use psychological pressure tactics in addition to technical intrusions.
6 months ago
Kill Chain
WSUS CVE-2025-59287: Mass Scanning and Rapid Exploitation Threaten IT Infrastructure
In late October and early November 2025, security researchers observed a marked uptick in external scans targeting ports 8530/TCP and 8531/TCP, which are related to Microsoft Windows Server Update Services (WSUS). These scans were linked to the rapid exploitation of CVE-2025-59287, a critical vulnerability allowing remote attackers to execute unauthorized scripts on vulnerable WSUS servers. Threat actors leveraged both encrypted (TLS) and unencrypted channels, beginning with reconnaissance sweeps and quickly escalating to full network compromise of exposed endpoints. Given the public availability of exploit details and the speed of attacks, organizations with exposed WSUS servers have likely suffered unauthorized access or larger breaches. This incident highlights a surge in opportunistic exploitation of newly disclosed vulnerabilities, particularly affecting critical IT infrastructure. The level of automated scanning and rapid weaponization is emblematic of a broader trend: attackers systematically hunting for internet-exposed administration interfaces and supply-chain services, increasing regulatory and operational risks for enterprises.
6 months ago
Kill Chain
Remote Code Execution in XWiki: CVE-2025-24893 Exploits Hit Enterprise Wikis
In November 2025, attackers began exploiting a critical remote code execution vulnerability (CVE-2025-24893) in the XWiki SolrSearch component, allowing even low-privileged users to trigger system-level commands via manipulated web requests. Although XWiki released a patch and advisory in February, broad exploitation did not emerge until the vulnerability was highlighted in the U.S. Known Exploited Vulnerabilities catalog in late October and weaponized using publicly available PoC code. The exploit chain involved attackers executing shell scripts fetched from an external server, potentially leading to data theft, malware deployment, or full system compromise in exposed enterprise wikis. This incident demonstrates the persistent risk posed by publicly disclosed vulnerabilities with lagging patch adoption; even niche, enterprise-focused applications can become attractive targets once exploitation is automated and high-profile. Organizations face mounting regulatory and business pressure to identify, patch, and harden externally exposed systems—especially as attackers increasingly weaponize proof-of-concept code for opportunistic campaigns.
6 months ago
Kill Chain
University of Pennsylvania Breach Exposes 1.2 Million Donor Records in 2024
In June 2024, a hacker claimed responsibility for breaching the University of Pennsylvania, exposing sensitive information on approximately 1.2 million donors as well as internal documentation. The threat actor infiltrated the university's IT environment, potentially exploiting weaknesses in data encryption and network segmentation. The attack resulted in the unauthorized access and potential leak of donor personal details, which could include names, contact information, and possibly financial data. The incident became publicly known after a 'We got hacked' email was sent from university channels, alerting stakeholders to the scale of the compromise. This incident highlights the increasing prevalence of large-scale data breaches targeting higher education and non-profit institutions. As threat actors employ more advanced techniques to exploit internal network gaps, organizations face mounting regulatory pressure to strengthen defenses and prevent sensitive data exposure.
6 months ago
Kill Chain
University of Pennsylvania 2024 Email Account Compromise: Lessons for Higher Ed
In June 2024, the University of Pennsylvania experienced a cybersecurity incident involving unauthorized access to internal email accounts. Students and alumni received a series of offensive emails from compromised university email addresses, with messages claiming data had been stolen in a security breach. Attackers leveraged email compromise, impersonating trusted university entities, and threatened to leak sensitive data, causing significant alarm among recipients. The university responded swiftly by investigating the breach, working with law enforcement, and reassuring the community that containment efforts were underway. This incident underscores the ongoing threat of email compromise and phishing-driven data breaches within higher education. With educational institutions facing increased attacks targeting both user trust and sensitive information, this event highlights the urgent need for robust email security, lateral movement detection, and strategic incident response planning.
6 months ago
Kill Chain
2024 Smart Building Zero-Day: Global Infrastructure Exposed
In early 2024, cybersecurity researcher Gjoko Krstic uncovered hundreds of zero-day vulnerabilities within legacy building automation systems still widely deployed in hospitals, schools, and commercial facilities globally. The investigation, codenamed "Project Brainfog," revealed that outdated codebases, some as old as 18 years, exposed critical physical infrastructure to remote compromise by unauthenticated attackers. Exploitable weaknesses in authentication, encryption, and access controls allowed for the manipulation of HVAC, security, and energy systems, putting sensitive environments such as medical and educational facilities at operational risk, and making them potential targets for ransomware and espionage. This incident highlights the growing threat of unpatched operational technology in critical sectors, as attackers increasingly target IoT and building control systems for both sabotage and lateral movement. As digital-physical convergence accelerates, organizations must rapidly modernize and secure these legacy environments to mitigate cascading risks.
6 months ago
Kill Chain
Iranian Hacker Training School Hit by Major Data Leak in 2024
In June 2024, a significant data breach struck Ravin Academy, an institution linked to training operatives for Iran’s Ministry of Intelligence and Security (MOIS). Unknown attackers infiltrated Ravin Academy’s infrastructure and exfiltrated sensitive personal information on students, instructors, and internal operations. The breach exposed emails, full names, contact info, assignment details, and evidence of the academy’s ties to cyberespionage. Responsibility was claimed by hacktivists aiming to publicly reveal Iranian cyber capabilities. The school is believed to have failed in securing internal East-West traffic, and evidence suggests lack of robust threat detection or network segmentation allowed attackers to maintain persistence long enough to extract substantial records. The breach is under investigation, but sensitive intelligence operations may have been compromised. This incident draws renewed focus on “learning supply chain” vulnerabilities: attacker interest in targeting not just state actors, but their feeder institutions and ecosystems. Such breaches underscore mounting regulatory concern over insider risk, inadequate segmentation, and the risks of unencrypted internal communications in institutions developing offensive cyber capabilities.
6 months ago
Kill Chain
Microsoft 2024 DNS Outage Paralyzes Azure & Microsoft 365 Globally
On June 20, 2024, Microsoft experienced a global DNS outage that disrupted access to Azure and Microsoft 365 services for customers worldwide. The outage was triggered by an internal DNS configuration issue that affected service resolution and authentication to corporate networks. Users reported being unable to access several core Microsoft services, including email, cloud storage, and collaboration tools. Microsoft’s engineering teams identified the root cause and began remediation, but the incident resulted in widespread operational downtime lasting several hours and affected businesses dependent on Microsoft’s cloud infrastructure. This incident highlights the increasing business impact of cloud infrastructure dependencies and emphasizes the importance of resilient and redundant DNS architectures. Service disruptions of this magnitude reinforce regulatory and customer scrutiny regarding cloud service reliability and prompt renewed attention to business continuity, availability controls, and third-party risk management.
6 months ago
Kill Chain
WordPress Plugin Flaw Exposes Sensitive Data to Subscribers in 2024
In June 2024, a critical vulnerability was disclosed in the widely used WordPress 'Anti-Malware Security and Brute-Force Firewall' plugin, which is active on over 100,000 websites. The flaw enables authenticated subscriber-level users to exploit improperly validated file access mechanisms, granting them read access to arbitrary files stored on the web server. This could allow the exposure of sensitive configuration files, credentials, or proprietary business data, significantly undermining site security and user privacy. Plugin maintainers were alerted, and a patched version was released to mitigate the issue. This incident emphasizes the risks posed by third-party plugin vulnerabilities within content management platforms, which remain a persistent attack vector as organizations contend with rapid plugin adoption and reliance on open-source tools.
6 months ago
Kill Chain
Microsoft WSUS RCE Vulnerability (CVE-2025-59287): Supply Chain Attack Exposes Critical Gaps
In November 2025, a critical remote code execution (RCE) vulnerability, CVE-2025-59287, was identified and exploited in Microsoft’s Windows Server Update Services (WSUS). Threat actors leveraged this flaw by sending malicious payloads via unpatched WSUS endpoints, enabling them to execute arbitrary code on affected servers. The attackers’ methodology consistently involved targeting organizations with exposed WSUS interfaces, compromising update mechanisms, and gaining privileged access. The attack resulted in the deployment of malware, lateral movement within enterprise networks, and in certain cases, potential data exfiltration and operational disruptions. This incident highlights an increasing threat trend involving supply chain attacks that target software update infrastructure. The exploitation of a widely-used service like WSUS underscores the evolving sophistication of attackers and the importance of rapid patching, robust segmentation, and east-west traffic controls in mitigating emerging remote code execution threats.
6 months ago
Kill Chain
How Memento Labs' ForumTroll Campaign Exploited Chrome Zero-Day with Dante Spyware
In early 2024, cybersecurity researchers at Kaspersky uncovered an advanced malware campaign, codenamed 'Operation ForumTroll,' targeting Russian government entities, media outlets, financial institutions, and research organizations. The campaign was linked to Memento Labs, the successor to the notorious Italian surveillance company Hacking Team. Leveraging a zero-day vulnerability in Google Chrome, attackers distributed personalized phishing emails which, when clicked, led victims to malicious websites; no further interaction was required to infect devices. The campaign enabled espionage, data exfiltration, and surveillance with high sophistication, including the deployment of a new commercial spyware tool known as 'Dante.' This incident highlights the increasing commercialization and sophistication of spyware operations, the targeting of Russian organizations by state-aligned APTs, and the ongoing exploitation of zero-day vulnerabilities in popular software. It underscores the urgency for organizations to proactively monitor threat activity and patch systems swiftly.
6 months ago
Kill Chain
Operation ForumTroll 2025: Memento Labs Revives APT Espionage with Chrome 0-day
In March 2025, Kaspersky uncovered Operation ForumTroll, a sophisticated espionage campaign targeting Russian government agencies, critical institutions, and media organizations. The threat actors employed personalized spear-phishing emails carrying unique, short-lived links; merely visiting these sites using Chrome or Chromium-based browsers enabled a zero-day exploit (CVE-2025-2783) to escape the browser sandbox. The attackers established system persistence via COM hijacking, then operated stealthy malware—LeetAgent and the commercial Dante spyware, attributed to Memento Labs (formerly Hacking Team)—to exfiltrate sensitive files and credentials, while leveraging cloud infrastructure for their C2 communications and tool delivery. This campaign exemplifies a new wave of highly targeted, sophisticated APT activity leveraging commercial spyware and advanced zero-day exploitation. As browser vulnerabilities and commercial surveillance tools increasingly intersect, organizations must urgently review security for endpoints, threat detection, and privileged access to counter fast-evolving espionage operations.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports