✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Higher Education/Acadamia
Breach intelligence, attack campaigns, and threat reports targeting the Higher Education/Acadamia sector.
Explore Other Sectors
Higher Education/Acadamia Threat Reports
BIETA & CIII Unmasked: China’s MSS Deploys Espionage Through Research Firms in 2025
In October 2025, a detailed investigation revealed that Chinese research firms BIETA (Beijing Institute of Electronics Technology and Application) and CIII were directly implicated in cyber operations orchestrated by China’s Ministry of State Security (MSS). The report, based on personnel link analysis and institutional relationships, highlights how BIETA coordinated with MSS operatives and academic partners to conduct covert cyber-espionage campaigns targeting international entities. These campaigns leveraged advanced tactics, including exploitation of internal network flows and the use of encrypted traffic, to exfiltrate sensitive data undetected. The exposure underscores the persistent and sophisticated nature of state-sponsored cyber threats, as well as risks posed by non-traditional actors collaborating with government intelligence agencies. This incident reflects a broader escalation in state-driven cyber espionage, demonstrating that commercial and academic organizations may serve as active operational arms for nation-state threat actors. As attribution capabilities improve, organizations must reassess third-party relationships and reinforce east-west and encrypted traffic controls to mitigate lateral movement and exfiltration risks.
6 months ago
Kill Chain
How Chinese Front Organizations Exploited Western Research to Advance State Cyber Capabilities
In early 2024, coordinated investigations revealed that Chinese government-linked academic and research institutions were covertly collaborating with Western organizations and researchers. Operating under seemingly neutral fronts, these entities facilitated the transfer of advanced cyber technologies and expertise, ultimately benefitting the intelligence apparatus of the People’s Republic of China (PRC). The campaign included joint projects, academic exchanges, and technology partnerships that enabled the PRC to sidestep export controls and gain access to cutting-edge cyber defense and offensive capabilities. The outcome potentially undermines intellectual property protections and heightens risks to network and national security within targeted Western sectors. This incident underscores a marked escalation in supply chain and technology transfer tactics used by nation-state actors. As the global competition for cyber advantage intensifies, regulators and organizations must heighten vigilance around academic, research, and cross-border tech collaborations to mitigate risks of inadvertent technology leakage.
6 months ago
Kill Chain
How Attackers Exploited a Zimbra Zero-Day via iCalendar Files in 2024
In early 2024, attackers exploited a previously unknown zero-day vulnerability in Zimbra Collaboration Suite (ZCS), targeting organizations via specially crafted .ICS (iCalendar) attachments. The vulnerability allowed threat actors to execute code by delivering malicious calendar files through email, bypassing traditional security filters. Incident responders observed attackers using this method for initial access, resulting in potential data theft, lateral movement, and disruption of email communications for affected businesses. The exploitation remained undetected for a significant period, amplifying operational and reputational risks for impacted entities. This incident highlights a growing trend of attackers leveraging supply chain and collaboration software vulnerabilities for sophisticated phishing and malware campaigns, often exploiting zero-days before vendors can respond. Organizations relying on common email and collaboration platforms face increased exposure to targeted file-type exploits and require improved visibility and rapid patching capabilities.
6 months ago
Kill Chain
UAT-8099 Hijacks IIS Servers: SEO Fraud and Data Theft Exposed
In early 2024, the Chinese-language cybercrime group UAT-8099 orchestrated a sophisticated series of attacks targeting Internet Information Services (IIS) web servers belonging to reputable organizations worldwide, including technology firms, telecoms, and universities. Exploiting insecure internet-facing servers with weak file upload controls, the attackers established footholds using open source web shells. They escalated privileges, enabled remote access with OSS reverse proxy tools, and deployed 'BadIIS' implants to perform SEO poisoning, redirecting search engine traffic to fraudulent gambling and scam sites. Simultaneously, the threat actors exfiltrated credentials, configuration files, and certificates, setting the stage for future attacks or data sales on darknet markets. This campaign demonstrates the threat actor's multi-pronged approach, blending fraud and espionage in ways that evade immediate detection. The incident highlights a growing global trend where SEO manipulation and credential theft converge, exposing organizations to operational, reputational, and regulatory risks amidst rising regulatory scrutiny around digital trust and supply chain integrity.
6 months ago
Kill Chain
Volvo NA Employee SSNs Exposed in 2023 Supply Chain Ransomware Attack
In August 2023, Volvo Group North America (Volvo NA) suffered a significant data breach when its third-party HR software provider, Miljödata, was compromised by the DataCarry ransomware group. Attackers exploited weaknesses in Miljödata's cloud infrastructure, gaining unauthorized access and exfiltrating sensitive employee data—including names and Social Security numbers—belonging to nearly 20,000 Volvo NA employees. The incident, discovered days after the intrusion, led to a ransom demand before the stolen data was published on the Dark Web. While Volvo NA's own systems were not directly breached, the exposure of highly sensitive employee data has far-reaching implications for individual privacy and trust. This breach highlights growing risks from supply chain cyberattacks targeting SaaS providers and underscores the importance of rigorous third-party risk management. High-value employee PII leaks also raise urgent questions around operational resilience, compliance, and the potential for subsequent identity-driven fraud.
6 months ago
Kill Chain
Operation Rewrite: 2025 Chinese-Speaking Threat Actor Turns BadIIS Modules into Weaponized SEO Poisons
In March 2025, cybersecurity researchers uncovered Operation Rewrite, a large-scale search engine optimization (SEO) poisoning campaign attributed to a Chinese-speaking threat actor tracked as CL-UNK-1037, with links to Group 9 and DragonRank. Attackers compromised web and application servers, deploying malicious native IIS modules dubbed "BadIIS" to intercept, modify, and proxy web traffic. By injecting SEO content and redirecting legitimate visitors, the attackers increased rankings for illicit sites, harvested sensitive data, and exfiltrated web application source code. Multiple server types—web servers, domain controllers, and high-value hosts—were compromised, indicating substantial operational impact and risk to affected organizations and individuals.
6 months ago
Kill Chain
Apple Patches 100+ Vulnerabilities in 2025: What Enterprises Need to Know
In September 2025, Apple released security updates for iPhones, iPads, Macs, and other products, addressing a total of over 100 vulnerabilities across its ecosystem. While none of the patched vulnerabilities were reported as actively exploited at the time, two severe macOS bugs (CVE-2025-43298 and CVE-2025-43304) were highlighted for their potential to confer root privileges to attackers. The updates followed a year marked by several Apple zero-days, some previously exploited in highly targeted attacks, underscoring ongoing risks to user data and privacy. Devices released prior to 2019 are no longer supported by the latest OS versions, leaving older hardware at higher risk. This incident highlights the persistent and evolving nature of software vulnerabilities targeting consumer platforms, reinforcing the critical importance of timely patching. With increasing regulatory attention and attackers swiftly weaponizing new bugs, organizations must remain vigilant in threat monitoring and adopt robust patch management practices.
6 months ago
Kill Chain
Chinese TA415 Breaches US Economic Policy Experts Using VS Code Remote Tunnels
In mid-2025, the China-aligned threat actor TA415 launched a sophisticated spear-phishing campaign targeting U.S. government agencies, economic policy think tanks, and academic organizations. The attackers leveraged social engineering tactics, masquerading as high-profile U.S. officials, and delivered phishing emails containing malicious links. Through these lures, TA415 exploited Visual Studio Code Remote Tunnels—a legitimate feature used for remote development—to establish persistent, covert remote access within target environments. This allowed them to conduct extended espionage operations, exfiltrate sensitive economic policy data, and evade traditional endpoint and network defenses. The attack highlights the convergence of advanced phishing techniques with legitimate remote access tools, underscoring a shift toward stealthy, “living off the land” tactics by nation-state adversaries. Organizations are urged to address internal monitoring, east-west security, and robust detection of unauthorized remote connectivity, as similar techniques are expected to proliferate across sectors.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports