The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Higher Education/Acadamia
Breach intelligence, attack campaigns, and threat reports targeting the Higher Education/Acadamia sector.
Explore Other Sectors
Higher Education/Acadamia Threat Reports
Fatal Consequences: Nigerian Sextortion Ring Extradited After Teen Deaths
Two Nigerian nationals, Adebola Festus Adekunle (26) and Mudasiru Afeez Olawale (24), were extradited to the United States in August 2026 following their arrest in Nigeria during Operation Artemis in 2023. The men are charged with conducting sextortion schemes that resulted in the deaths of two minor victims in Mississippi and North Carolina. Their crimes involved coercing minors into producing explicit content, then using blackmail and threats to extort victims, leading to tragic outcomes. They face maximum life sentences with mandatory minimums of 30 years for child exploitation resulting in death. This case highlights the escalating severity of international cybercrime targeting minors, with sextortion schemes increasingly leading to fatal outcomes. The successful extradition demonstrates enhanced international cooperation in pursuing cybercriminals, while the tragic deaths underscore the urgent need for stronger digital protection measures and mental health support systems for online exploitation victims.
3 weeks ago
Kill Chain
CISA Adds Critical PaperCut Vulnerabilities to KEV Following Active Exploitation
In August 2026, CISA added two critical PaperCut NG/MF vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation in the wild. CVE-2026-81578 involves missing authentication for critical functions, while CVE-2026-82078 represents an unsafe reflection vulnerability. These vulnerabilities affect PaperCut's widely-deployed print management software used across enterprise environments. The addition to KEV indicates threat actors are actively leveraging these flaws to compromise federal and private sector organizations, potentially leading to unauthorized system access and lateral movement. This incident highlights the continuing evolution of attack vectors targeting enterprise infrastructure software, particularly as organizations increasingly rely on cloud-hybrid print management solutions that bridge on-premises and cloud environments.
3 weeks ago
Kill Chain
Critical GiveWP Plugin Vulnerability Exposes 100K+ WordPress Sites to Remote Code Execution
A critical vulnerability (CVE-2026-82222) in the GiveWP WordPress donation plugin allowed unauthenticated attackers to execute arbitrary commands on hosting servers through a complex chain of PHP deserialization flaws. The vulnerability affected over 100,000 installations running versions 4.16.6 through 4.16.7.1, exploiting unsafe PHP data handling, donation processing flows, and bundled library gadget chains. Attackers could bypass disabled user registration, create accounts, inject malicious serialized objects through crafted donations, and achieve remote code execution when the server processed front-end requests. GiveWP released version 4.16.7.2 on August 27, 2026, addressing the deserialization issues and removing stored malicious payloads from affected databases. This incident highlights the growing sophistication of WordPress plugin vulnerabilities, particularly those targeting donation and e-commerce platforms that handle sensitive financial data. With WordPress powering over 40% of websites and plugin vulnerabilities increasing 35% year-over-year, organizations must prioritize rapid security updates and implement defense-in-depth strategies.
3 weeks ago
Kill Chain
PaperCut Zero-Day Exploits Force Double Emergency Patches for Critical RCE Flaws
In August 2026, PaperCut released emergency patches for two actively exploited zero-day vulnerabilities (CVE-2026-82078 and CVE-2026-81578) affecting PaperCut NG and MF print management software. The vulnerabilities allowed unauthenticated attackers to bypass authentication and achieve remote code execution on vulnerable servers. After security researchers discovered multiple bypass techniques for the initial patches, PaperCut was forced to release a second emergency patch with additional hardening measures. The attacks appear to be limited and targeted, with threat actors conducting system reconnaissance on compromised servers. This incident highlights the persistent threat to network-accessible management interfaces and the growing sophistication of attackers who can quickly develop bypass techniques for security patches. It underscores the critical importance of implementing zero-trust network segmentation and egress controls to limit the impact of successful initial compromises.
3 weeks ago
Kill Chain
Critical PaperCut Vulnerability Chain Enables Unauthenticated Remote Code Execution
In August 2026, threat actors actively exploited two chained vulnerabilities in PaperCut NG and MF print management software to achieve unauthenticated remote code execution. CVE-2026-81578 (CVSS 8.8) allows attackers to bypass authentication through improper access control, while CVE-2026-82078 (CVSS 9.4) enables unsafe dynamic class loading for arbitrary code execution. Huntress researchers observed limited exploitation targeting internet-facing instances, with attackers performing reconnaissance commands and deploying Java payloads to fingerprint systems and exfiltrate data before cleaning up evidence. This incident highlights the growing trend of vulnerability chaining attacks targeting enterprise infrastructure software, particularly as organizations increasingly rely on cloud-connected print management systems that often lack proper network segmentation and access controls.
3 weeks ago
Kill Chain
PaperCut Zero-Day Exploitation: Securing Enterprise Print Infrastructure
In August 2026, PaperCut disclosed that threat actors were actively exploiting a zero-day vulnerability affecting all versions of PaperCut NG and MF print management software. The company confirmed multiple customer incidents and released emergency patches for versions 25 and 26. Attackers targeted internet-exposed PaperCut Application Servers, with indicators including suspicious post-exploitation activity from pc-app.exe processes and manipulated database logs. The vulnerability allowed unauthorized access to print management systems used across enterprise environments globally. This incident highlights the continued targeting of enterprise infrastructure software, particularly print management systems that often have broad network access and limited security oversight in corporate environments.
3 weeks ago
Kill Chain
Critical Security Flaws Expose Unitree Humanoid Robots to Remote Takeover
Security researcher Olivier Laflamme disclosed two critical root remote code execution vulnerabilities affecting Unitree G1 EDU humanoid robots in August 2026. CVE-2026-76639 exploits a path traversal flaw in the chat_go component to reach bashrunner, while CVE-2026-76640 enables Bluetooth Low Energy attacks that can compromise the robot's Locomotion PC without pairing. The vulnerabilities allowed attackers to gain root access through network-adjacent attacks or proximity-based Bluetooth exploitation, with Unitree partially addressing cloud authorization issues in July 2026 but leaving firmware patches unconfirmed. This incident highlights the growing security risks in autonomous robotics and IoT devices as they become more prevalent in industrial and consumer environments. The combination of wireless attack vectors and critical system access demonstrates the urgent need for robust security frameworks in next-generation robotic platforms.
3 weeks ago
Kill Chain
The AI Revolution in Cyber Reconnaissance: Why Everyone Is Now a Target
Artificial intelligence is fundamentally transforming the cybercrime landscape by democratizing sophisticated Open Source Intelligence (OSINT) reconnaissance capabilities. Previously, comprehensive target profiling required specialized skills and significant time investment, limiting such attacks to high-value targets. AI-powered tools now enable threat actors with minimal technical expertise to rapidly collect, correlate, and weaponize publicly available information from social media, professional networks, and web sources at machine speed, dramatically lowering the barrier to entry for personalized social engineering attacks and fraud schemes. This capability shift represents a critical inflection point in cyber threat evolution, as AI enables scalable personalization of attacks previously reserved for advanced persistent threat groups. The convergence of readily available AI tools with abundant personal data creates unprecedented risk exposure for individuals and organizations alike.
3 weeks ago
Kill Chain
PaperCut Zero-Day Exploitation: When Print Management Becomes a Gateway
In August 2026, PaperCut Software issued an urgent security advisory warning of active zero-day exploitation targeting all versions of PaperCut NG and MF print management software. The company confirmed customer incidents involving Internet-exposed servers, with attackers exploiting an undisclosed vulnerability to gain initial access to corporate networks. PaperCut released emergency patches and provided indicators of compromise including suspicious pc-app.exe process activity and modified server.log files with specific database error patterns. The company has a documented history of being targeted by ransomware groups including Clop and LockBit who previously exploited PaperCut vulnerabilities for network access rather than direct document theft. This incident highlights the continued targeting of enterprise print management infrastructure as an attack vector, particularly relevant given the rise of ransomware groups exploiting Internet-facing business applications for initial compromise and the increasing sophistication of zero-day campaigns against widely-deployed enterprise software.
4 weeks ago
Kill Chain
CISA Sounds Alarm: Six Critical Vulnerabilities Under Active Exploitation
In August 2026, CISA added six critical vulnerabilities to its Known Exploited Vulnerabilities catalog, including CVE-2026-8452 affecting Citrix NetScaler ADC and Gateway systems. Active exploitation was observed with attackers deploying web shells and conducting reconnaissance commands across 12 countries. The campaign also leveraged older Linux kernel flaws, Microsoft SQL Server vulnerabilities, and Red Hat system bugs, demonstrating how threat actors continue to exploit unpatched legacy systems alongside newer attack vectors. This incident highlights the persistent challenge of vulnerability management as AI-enabled threat actors increasingly automate exploitation of both recent and legacy flaws. The multi-vector approach demonstrates how attackers combine new and old vulnerabilities to maximize their attack surface against inadequately patched infrastructure.
4 weeks ago
Kill Chain
Ubiquiti UniFi Hit by 22 Vulnerabilities Including Three Perfect 10.0 CVSS Flaws
In December 2024, Ubiquiti disclosed 22 security vulnerabilities across its UniFi product line, including three critical flaws rated 10.0 on the CVSS scale (CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554). These maximum-severity vulnerabilities enable attackers to exploit improper access control mechanisms, potentially gaining elevated privileges on affected devices. The flaws primarily affect network infrastructure equipment used by enterprises and service providers worldwide, with seven of the 22 vulnerabilities involving improper access control issues that could allow authentication bypass or arbitrary command execution. This disclosure highlights the escalating threat landscape targeting network infrastructure devices, which have become prime targets for nation-state actors and cybercriminals seeking persistent access to enterprise networks and critical infrastructure systems.
4 weeks ago
Kill Chain
Critical SharePoint RCE Chain: How CVE-2026-55040 and CVE-2026-63520 Enable Remote Code Execution
In August 2026, threat actors began actively exploiting a chained vulnerability in Microsoft SharePoint servers, combining CVE-2026-55040 (JWT authentication bypass) and CVE-2026-63520 (Business Connectivity Services RCE) to achieve remote code execution on unpatched systems. The attack chain allows unauthenticated attackers to first bypass authentication through JWT token validation flaws, then escalate to full code execution via SharePoint's Business Connectivity Services. With over 8,700 SharePoint servers exposed online and proof-of-concept exploits publicly available, CISA ordered federal agencies to immediately patch their systems as exploitation was detected in honeypots within days of PoC release. This incident represents a critical escalation in SharePoint targeting, with CISA having flagged 15 actively exploited SharePoint vulnerabilities since 2021, eight of which were used by ransomware groups. The rapid weaponization timeline demonstrates how quickly adversaries adapt public exploits for mass scanning and targeted attacks against enterprise collaboration platforms.
4 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports