The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Higher Education/Acadamia
Breach intelligence, attack campaigns, and threat reports targeting the Higher Education/Acadamia sector.
Explore Other Sectors
Higher Education/Acadamia Threat Reports
macOS Screen Sharing Vulnerability Leads to Unauthorized Monero Mining
In August 2026, a critical vulnerability identified as CVE-2026-65400 was discovered in Apple macOS's Screen Sharing component. This flaw allowed attackers to bypass authentication and gain remote root access to systems with port 5900 exposed to the internet. Exploiting this vulnerability, attackers installed Monero cryptocurrency mining software on compromised machines. Apple promptly released emergency patches for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 to address this issue. The incident underscores the importance of timely software updates and the risks associated with exposing remote access services to the internet. Organizations are advised to apply security patches promptly and review network configurations to minimize exposure to such vulnerabilities.
1 month ago
Kill Chain
Cybercriminals Invest Millions in Expired Domains for Malicious Activities
In the first half of 2026, cybercriminals have increasingly exploited expired domains, known as 'dropcatch' domains, to conduct large-scale scams and malware distribution. By re-registering these domains, threat actors inherit their previous reputation and traffic, enabling them to evade detection and effectively target victims. Notably, the group 'Sable Squirrel' invested over $7 million to acquire more than 10,000 such domains, which they utilized for illegal streaming, online gambling, and as command-and-control servers for various malware families, including Quasar RAT and AsyncRAT. This trend underscores a significant shift in cybercriminal tactics, leveraging the residual trust of expired domains to facilitate malicious activities. The prevalence of this method highlights the urgent need for organizations to monitor and manage their domain portfolios proactively, ensuring that expired domains are not left vulnerable to exploitation. Additionally, it emphasizes the importance of enhancing detection mechanisms to identify and mitigate threats originating from re-registered domains.
1 month ago
Kill Chain
Urgent: macOS Screen Sharing Vulnerability (CVE-2026-65400) Exploited in the Wild
In August 2026, a critical vulnerability (CVE-2026-65400) was discovered in macOS's Screen Sharing feature, allowing remote attackers to bypass authentication and gain root access to systems exposed via port 5900. Exploiting this flaw, attackers installed Monero cryptocurrency miners on compromised machines. Apple released out-of-band patches on August 6, 2026, for macOS versions Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 to address this issue. ([tomshardware.com](https://www.tomshardware.com/tech-industry/cyber-security/macos-screen-sharing-flaw-exploited-to-root-macs-and-plant-monero-miners?utm_source=openai)) This incident underscores the importance of promptly applying security updates and reassessing the exposure of remote access services. The active exploitation of this vulnerability highlights the ongoing risks associated with unpatched systems and the necessity for robust security practices.
1 month ago
Kill Chain
Brightly Software Data Analyst Sentenced for $2.5M Extortion Scheme
In December 2023, Cameron Curry, a former data analyst contractor for Brightly Software, exploited his access to the company's payroll and corporate data to steal sensitive employee information. After his contract ended, Curry initiated an extortion scheme, sending over 60 emails to Brightly employees between December 11, 2023, and January 24, 2024, demanding a $2.5 million ransom in cryptocurrency. He threatened to release the stolen data and report the company to the SEC for failing to disclose the breach. Brightly paid $7,540 in Bitcoin before involving law enforcement. The FBI's investigation led to Curry's conviction in March 2026 on six counts of cyber extortion, resulting in a two-year prison sentence. This incident underscores the significant risks posed by insider threats, especially when individuals with authorized access misuse their privileges. Organizations must implement robust access controls, continuous monitoring, and employee training to mitigate such risks. The case also highlights the importance of swift incident response and collaboration with law enforcement to address cyber extortion attempts effectively.
1 month ago
Kill Chain
Critical Command Injection Vulnerability in Johnson Controls Metasys (CVE-2025-26385)
In January 2026, a critical command injection vulnerability (CVE-2025-26385) was identified in Johnson Controls' Metasys building automation system. This flaw allowed unauthenticated remote attackers to execute arbitrary SQL commands, potentially compromising the confidentiality, integrity, and availability of affected systems. The vulnerability impacted multiple Metasys components, including the Application and Data Server (ADS), Extended Application and Data Server (ADX), and various tools integrated with SQL Express, across versions 12.0 through 14.1. Johnson Controls promptly released patches and provided mitigation strategies to address the issue. This incident underscores the importance of securing building automation systems, especially as they become increasingly interconnected. Organizations are urged to apply the latest patches, follow vendor-recommended hardening guidelines, and implement network segmentation to protect critical infrastructure from similar vulnerabilities.
1 month ago
Kill Chain
Armored Likho's 2026 Cyber-Espionage Campaign: A Deep Dive into BusySnake Infostealer
In July 2026, the previously undocumented APT group 'Armored Likho' launched sophisticated cyber-espionage campaigns targeting government agencies and electric power entities in Russia, Brazil, and Kazakhstan. Utilizing spear-phishing emails disguised as official communications, they deployed the Python-based 'BusySnake' infostealer to exfiltrate sensitive data, including credentials and cryptographic keys. The malware's advanced obfuscation techniques and modular architecture enabled persistent access and evasion of detection mechanisms. This incident underscores the escalating threat posed by APT groups leveraging AI-generated malware to target critical infrastructure. Organizations must enhance their cybersecurity posture to defend against such evolving tactics.
1 month ago
Kill Chain
Urgent: Microsoft SharePoint CVE-2026-55040 Exploited in the Wild
In July 2026, a critical vulnerability identified as CVE-2026-55040 was discovered in Microsoft SharePoint's JWT token validation pipeline. This flaw allowed unauthenticated attackers to impersonate any SharePoint user, including administrators, by bypassing authentication mechanisms. Microsoft addressed this issue in their July 2026 Patch Tuesday updates, urging organizations using SharePoint Enterprise Server 2016 and SharePoint Server 2019 to apply the patches promptly. The urgency of this patch was underscored when, shortly after its release, proof-of-concept exploit code became publicly available and was actively used in attacks targeting unpatched SharePoint servers. This rapid weaponization highlights the critical need for organizations to maintain up-to-date security measures and promptly apply patches to mitigate emerging threats.
1 month ago
Kill Chain
FBI Issues Warning on Rising Sextortion Threats Targeting Online Accounts
In August 2026, the FBI issued a public service announcement warning that cybercriminals are targeting both adults' and children's online accounts to steal sexually explicit images and videos. These attackers gain unauthorized access through methods such as phishing, social engineering, and exploiting weak passwords. Once obtained, the explicit content is used to blackmail victims, sold on criminal marketplaces, or shared with other malicious actors, leading to further exploitation and harassment. This incident underscores a growing trend in cyber threats where personal and sensitive data are exploited for financial gain and coercion. The increasing sophistication of these attacks highlights the urgent need for enhanced cybersecurity measures, public awareness, and proactive defense strategies to protect individuals from such exploitation.
1 month ago
Kill Chain
Enterprise Defenses: Strong Perimeter, Weak Interior
In the first half of 2026, Picus Labs conducted over 338 million attack simulations across client production environments, revealing a significant disparity in defense effectiveness. While perimeter defenses showed improvement, blocking approximately 69% of attacks, internal defenses were notably weaker, with a post-compromise prevention rate of only 37%. This indicates that once attackers breach the perimeter, they face minimal resistance, especially during reconnaissance and credential theft phases. This trend underscores the urgent need for organizations to bolster internal security measures. As attackers increasingly employ stealthy techniques to evade detection, focusing solely on perimeter defenses is insufficient. Enhancing internal monitoring and response capabilities is crucial to mitigate the risks associated with these evolving threats.
1 month ago
Kill Chain
CISA Confirms Exploitation of SharePoint Vulnerability CVE-2026-45659
In May 2026, Microsoft disclosed CVE-2026-45659, a high-severity remote code execution vulnerability in SharePoint Server, stemming from the deserialization of untrusted data. This flaw allows authenticated attackers with minimal privileges to execute arbitrary code on unpatched servers. By July 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities Catalog, confirming active exploitation by ransomware groups. Organizations utilizing SharePoint Server are urged to apply the latest patches promptly to mitigate this risk. The exploitation of CVE-2026-45659 underscores a broader trend of threat actors targeting collaboration platforms to deploy ransomware. This incident highlights the critical need for organizations to maintain rigorous patch management practices and to monitor for signs of compromise, especially in widely used enterprise applications.
1 month ago
Kill Chain
AI-Assisted Exploit Chain Unveiled: Unauthenticated RCE in Microsoft SharePoint
In August 2026, security researchers identified a critical vulnerability in Microsoft SharePoint, designated as CVE-2026-55040, which allows unauthenticated attackers to impersonate any user, including administrators, without valid credentials. This flaw affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Exploiting this vulnerability requires knowledge of the target account's Active Directory security identifier (SID) or user principal name (UPN). Rapid7 further discovered that chaining this authentication bypass with another vulnerability, CVE-2026-63520, enables remote code execution on the server without authentication. Microsoft released patches in July 2026 to address these issues. The discovery underscores the evolving threat landscape, where attackers increasingly leverage AI-assisted tools to identify and exploit vulnerabilities. Organizations must remain vigilant, ensuring timely application of security patches and adopting proactive measures to mitigate such sophisticated attack vectors.
1 month ago
Kill Chain
Zoom Annotation Vulnerabilities Expose Clients to Hijacking - August 2026
In August 2026, critical vulnerabilities were discovered in Zoom's annotation feature, allowing meeting participants to hijack other attendees' clients without any user interaction. These flaws, identified as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, stemmed from improper input validation and message handling within the annotation tool. Exploitation could lead to unauthorized control over participants' systems, posing significant security risks. Zoom addressed these issues by releasing patches in June and July 2026, with no reported exploitation as of the disclosure date. This incident underscores the growing concerns over the security of widely-used collaboration tools, especially as remote work continues to be prevalent. The rapid identification and patching of such vulnerabilities highlight the importance of proactive security measures and the need for organizations to stay vigilant against potential threats in digital communication platforms.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports