✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Higher Education/Acadamia
Breach intelligence, attack campaigns, and threat reports targeting the Higher Education/Acadamia sector.
Explore Other Sectors
Higher Education/Acadamia Threat Reports
Chinese Espionage Group Exploits Roundcube Vulnerabilities to Infiltrate Universities
In May 2026, Proofpoint researchers identified a cyber-espionage campaign targeting physics and engineering departments at U.S. and Canadian universities. The attackers, attributed to a China-aligned group known as UNK_MassTraction, exploited two critical vulnerabilities in the Roundcube email client—CVE-2024-42009 and CVE-2025-49113—to gain unauthorized access. By sending crafted emails, they executed malicious JavaScript and achieved remote code execution, leading to the installation of webshells and backdoors for persistent access. The campaign is ongoing, with several universities potentially affected. This incident underscores the evolving tactics of state-sponsored threat actors, who are increasingly targeting academic institutions to access sensitive research data. The use of email-based exploit chains to compromise mail servers highlights the need for robust email security measures and prompt patching of known vulnerabilities to mitigate such threats.
2 weeks ago
Kill Chain
Iranian Cybercriminal Arrested for $3.4 Billion in Damages
In June 2026, Montenegrin authorities, in collaboration with the FBI, arrested a 39-year-old dual Iranian and Turkish citizen in Kotor. The individual is accused of orchestrating mass cyberattacks since 2013, targeting over 150 U.S. universities and causing damages exceeding $3.4 billion. The stolen data reportedly benefited Iran's Islamic Revolutionary Guard Corps and various Iranian state entities. Extradition proceedings are underway in Montenegro's capital, Podgorica. This arrest underscores the persistent threat posed by state-sponsored cyber activities and highlights the importance of international cooperation in combating cybercrime. Organizations should remain vigilant and enhance their cybersecurity measures to protect against such sophisticated attacks.
3 weeks ago
Kill Chain
Critical SharePoint RCE Vulnerability CVE-2026-45659 Under Active Exploitation
In May 2026, Microsoft addressed a critical remote code execution vulnerability (CVE-2026-45659) in SharePoint Server, stemming from the deserialization of untrusted data. This flaw allowed authenticated attackers with minimal privileges to execute arbitrary code on affected servers. Despite the availability of patches, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog in July 2026, indicating active exploitation in the wild. Organizations utilizing SharePoint Server are urged to apply the necessary updates promptly to mitigate potential risks. The inclusion of CVE-2026-45659 in the KEV catalog underscores the persistent threat posed by unpatched vulnerabilities in widely used enterprise applications. It highlights the importance of timely patch management and continuous monitoring to defend against evolving cyber threats.
3 weeks ago
Kill Chain
Critical SharePoint Server Vulnerability CVE-2026-45659 Actively Exploited
In May 2026, Microsoft disclosed CVE-2026-45659, a critical remote code execution vulnerability in SharePoint Server caused by deserialization of untrusted data. This flaw allows authenticated attackers with minimal permissions to execute arbitrary code over a network, potentially compromising sensitive data and system integrity. Despite the release of patches, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities Catalog on July 1, 2026, indicating active exploitation in the wild. The inclusion of CVE-2026-45659 in CISA's catalog underscores the urgency for organizations to apply the available patches promptly. The vulnerability's low attack complexity and the widespread use of SharePoint in enterprise environments heighten the risk of exploitation, emphasizing the need for immediate remediation to protect organizational assets.
3 weeks ago
Kill Chain
Urgent Alert: Active Exploitation of Oracle EBS CVE-2026-46817
In late June 2026, threat intelligence firm Defused detected active exploitation of a critical vulnerability (CVE-2026-46817) in Oracle's E-Business Suite (EBS) Payments module. This flaw, present in versions 12.2.3 through 12.2.15, allows unauthenticated attackers to execute arbitrary code via HTTP, potentially leading to full system compromise. The initial exploit attempts were observed on June 27, 2026, targeting the 'ibytransmit' endpoint to read sensitive files from the server. Oracle had released a patch for this vulnerability in May 2026, but the recent attacks indicate that many systems remain unpatched and vulnerable. This incident underscores the persistent threat posed by unpatched critical vulnerabilities in widely used enterprise applications. Organizations relying on Oracle EBS must prioritize applying security updates promptly to mitigate risks. The exploitation of CVE-2026-46817 highlights the need for continuous monitoring and proactive defense strategies to protect against emerging threats targeting enterprise resource planning (ERP) systems.
3 weeks ago
Kill Chain
Over 900 Oracle E-Business Instances Exposed to Ongoing Attacks
In late June 2026, over 900 Oracle E-Business Suite (EBS) instances were found exposed online, with active exploitation of a critical vulnerability (CVE-2026-46817) in the Oracle Payments component. This flaw allows unauthenticated attackers with HTTP access to take over vulnerable systems. Oracle released a patch in May 2026, but many systems remain unpatched, leading to successful attacks. The ongoing exploitation of CVE-2026-46817 underscores the persistent threat posed by unpatched enterprise systems. Organizations must prioritize timely application of security updates to mitigate risks associated with such vulnerabilities.
3 weeks ago
Kill Chain
FortiBleed Credential Theft Campaign Exposes Over 73,000 Fortinet Devices
In July 2026, the 'FortiBleed' campaign was uncovered, revealing a massive credential theft operation targeting over 73,000 Fortinet devices. Attackers utilized a custom tool named 'FortiGate Sniffer' to intercept VPN credentials directly from network traffic. Subsequent investigations linked this operation to the INC and Lynx ransomware groups, indicating that the stolen credentials were intended to facilitate future network intrusions. This incident underscores the evolving tactics of ransomware groups, highlighting their focus on exploiting network infrastructure vulnerabilities to gain unauthorized access. Organizations must prioritize securing their network devices and monitoring for unusual activities to mitigate such threats.
3 weeks ago
Kill Chain
ChocoPoC Malware: A New Threat Targeting Cybersecurity Researchers
In July 2026, cybersecurity researchers identified a campaign distributing a Python-based remote access trojan (RAT) named ChocoPoC through trojanized proof-of-concept (PoC) exploits on GitHub. Unlike previous incidents where malware was embedded directly in exploit files, this campaign introduced malicious Python packages into the PoC's dependency list. When victims cloned these repositories, a trojanized package named 'frint' was automatically installed, which subsequently fetched another malicious package, 'skytext.' This package contained a compiled Python extension that decrypted and executed additional code, ultimately downloading the ChocoPoC RAT from a Mapbox dataset. The RAT possessed capabilities such as executing arbitrary commands, uploading files, and collecting sensitive data, including browser credentials and network configurations. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-chocopoc-malware-targets-researchers-via-trojanized-poc-exploits/?utm_source=openai)) This incident underscores a growing trend where threat actors exploit trusted platforms like GitHub to distribute malware, targeting professionals who frequently utilize PoC exploits for research and testing. The sophisticated method of embedding malicious code within dependency packages highlights the need for heightened vigilance when sourcing code from public repositories. As attackers continue to refine their techniques, the cybersecurity community must adapt by implementing stricter code verification processes and promoting awareness about the risks associated with unverified code. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-chocopoc-malware-targets-researchers-via-trojanized-poc-exploits/?utm_source=openai))
3 weeks ago
Kill Chain
Citrix NetScaler Vulnerability CVE-2026-8451: Critical Memory Disclosure Flaw
In June 2026, Citrix disclosed six vulnerabilities in its NetScaler ADC and NetScaler Gateway appliances, notably CVE-2026-8451, a high-severity memory disclosure flaw. This vulnerability arises from improper parsing of SAML authentication requests when the appliance is configured as a SAML identity provider, potentially allowing unauthenticated attackers to access sensitive memory contents. The flaw shares similarities with the 2023 'CitrixBleed' incident, which also involved memory management issues in NetScaler products. The disclosure underscores ongoing challenges in securing critical network infrastructure. Organizations relying on NetScaler appliances should promptly apply the provided patches and review their configurations to mitigate potential exploitation risks.
3 weeks ago
Kill Chain
Critical Vulnerabilities in Indian Government Portals Expose Millions' Data
In April 2026, independent cybersecurity researcher Sushant Bhardwaj discovered 14 vulnerabilities within Indian government IT systems, including two critical and four high-severity issues. These vulnerabilities affected major national platforms, such as education and civil service portals, exposing sensitive personally identifiable information (PII) of millions of students and job applicants, including names, addresses, and bank account numbers. Notably, one critical flaw in the Union Public Service Commission (UPSC) portal allowed unauthorized access to administrative interfaces, potentially enabling full system takeover. The Indian government responded promptly, patching all identified vulnerabilities within two to three weeks. This incident underscores the persistent risks associated with inadequate access controls and outdated security practices in government systems. It highlights the necessity for continuous security assessments, robust access management, and prompt remediation to protect citizen data from unauthorized access and potential exploitation.
3 weeks ago
Kill Chain
Apple's June 2026 Security Updates: Over 25 Vulnerabilities Patched
In June 2026, Apple released security updates for iOS/iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2, addressing over 25 vulnerabilities. The majority of these issues were found in WebKit and related web technologies, potentially leading to crashes, memory corruption, or data disclosure. Additionally, vulnerabilities in the kernel and IOGPUFamily were patched. Notably, Apple expedited these updates in response to concerns about AI-assisted hacking tools, aiming to reduce the window between vulnerability disclosure and patch deployment. ([macrumors.com](https://www.macrumors.com/2026/06/29/apple-ios-26-5-2-early-release/?utm_source=openai)) This proactive approach underscores the growing threat posed by AI-enhanced cyberattacks, highlighting the necessity for organizations to adopt agile security practices and promptly apply software updates to mitigate emerging risks.
3 weeks ago
Kill Chain
Urgent Alert: Oracle E-Business Suite Vulnerability Under Active Exploitation
In late June 2026, threat intelligence firm Defused reported active exploitation of a critical vulnerability (CVE-2026-46817) in Oracle E-Business Suite's Payments component. This flaw, present in versions 12.2.3 through 12.2.15, allows unauthenticated attackers with HTTP access to execute remote code, potentially leading to full system compromise. Oracle had addressed this issue in their May 2026 Critical Security Patch Update, urging immediate patching. Despite this, numerous unpatched systems remain exposed, with over 450 Oracle EBS instances accessible online, nearly 200 of which are in the United States and Europe. The active exploitation of CVE-2026-46817 underscores the critical importance of timely patch management. Organizations using Oracle E-Business Suite must prioritize applying the latest security updates to mitigate this severe risk. Additionally, this incident highlights the broader trend of attackers targeting unpatched enterprise applications, emphasizing the need for robust vulnerability management practices.
3 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports