← All Intelligence

Education Industry Intelligence

8 briefings10 vulnerability reports

Educational institutions, from K-12 schools to research universities, face increasing ransomware attacks, intellectual property theft, and research espionage. Open network environments and limited security budgets create persistent vulnerabilities. defend.network monitors threats targeting educational institutions, research networks, and student data systems.

8
briefings
0
critical
3
high
9%
of all briefings

Threat Briefings

2026-06-12

Critical: Oracle PeopleSoft Zero-Day, Windows BitLocker Bypass, Gentlemen Ransomware

Oracle PeopleSoft CVE-2026-35273 actively exploited by ShinyHunters targeting universities; Windows BitLocker bypassed via XML files; The Gentlemen ransomware claims 478 victims with worm-like spreading capability.

2026-05-24

GitHub, npm, and Drupal under attack: supply-chain threats and active CVE exploitation

Multiple supply-chain attacks targeting Laravel-Lang and Packagist packages, active exploitation of Drupal CVE-2026-9082, and critical CISA AWS credential leak on GitHub.

2026-05-19

Microsoft Exchange zero-day in active use; npm worm clones spread after source leak

Microsoft Exchange zero-day under active exploitation with no patch available. Shai-Hulud worm source code leaked, spawning clones targeting npm developers. INTERPOL Operation Ramz arrested 201 cybercriminals across MENA region.

2026-05-13

npm/PyPI supply-chain; Canvas ransomware; Microsoft 137 patches

Critical supply-chain attacks via compromised npm/PyPI packages, Canvas ransomware disrupting education nationwide, and massive vulnerability patches (Microsoft 137, Adobe 52, Exim critical) require immediate response.

2026-05-12

Checkmarx Jenkins compromise; AI-generated zero-day 2FA bypass

Critical supply chain compromise of Checkmarx Jenkins plugin, first AI-generated zero-day 2FA bypass exploit, and active Canvas education platform extortion campaign require immediate response.

2026-05-11

Canvas ransomware hits universities; Ollama zero-day on 300k servers

Canvas ransomware disrupts universities nationwide; Ollama zero-day affects 300k+ servers; TCLBANKER targets financial platforms; critical infrastructure breached; supply-chain compromises detected.

2026-05-10

Canvas extortion attack; JDownloader, Hugging Face & Trellix hit

Canvas learning platform compromised in extortion attack affecting hundreds of schools; supply-chain attacks hit JDownloader, Hugging Face, and Trellix; banking trojan TCLBANKER targets 59 financial platforms; critical ICS/OT breaches at water treatment plants.

2026-05-09

TCLBANKER trojan; Canvas breach hits education; Ivanti zero-day

Critical threats including TCLBANKER banking trojan, Canvas platform breach disrupting nationwide education, and active Ivanti zero-day exploitation require immediate response across financial, education, and government sectors.

Vulnerability Reports

June 8 – 14

Vulnerability Report – Week 2 of June 2026

Organizations should prioritize patching these vulnerabilities immediately — several are actively exploited in the wild and confirmed in CISA's KEV catalog, most urgently Oracle PeopleSoft (CVE-2026-3

10 critical 10 high
May 18 – 24

Vulnerability Report – Week 3 of May 2026

This week presents an exceptionally high-risk threat landscape with multiple critical vulnerabilities under active exploitation across infrastructure, enterprise, and open-source ecosystems. Immediate

0 critical 2 high
May 11 – 17

Vulnerability Report – Week 2 of May 2026

This week marks a significant surge in actively exploited vulnerabilities, with three critical flaws requiring immediate patching across IT infrastructure and OT systems. The Ollama out-of-bounds read

2 critical 2 high
May 4 – 10

Vulnerability Report – Week 1 of May 2026

This week presents an exceptionally high-risk threat landscape dominated by active exploitation campaigns and critical infrastructure vulnerabilities. Federal agencies face an immediate Sunday deadlin

0 critical 0 high
April 27 – May 3

Vulnerability Report – Week 4 of April 2026

This week presents elevated risk from actively exploited vulnerabilities across network infrastructure, IoT devices, and enterprise software. Immediate patching is required for Cisco Firepower/ASA dev

3 critical 7 high
April 20 – 26

Vulnerability Report – Week 3 of April 2026

This week presents elevated risk across OT/ICS sectors with multiple critical RCE vulnerabilities in industrial control systems and emerging threats to cloud infrastructure. Active exploitation of Mic

5 critical 8 high
April 13 – 19

Vulnerability Report – Week 2 of April 2026

This week presents an elevated threat landscape dominated by actively exploited critical vulnerabilities in both IT and OT environments. Iranian-affiliated threat actors are actively targeting US crit

0 critical 0 high
April 6 – 12

Vulnerability Report – Week 1 of April 2026

This week presents elevated risk with five critical vulnerabilities actively exploited in the wild, including FortiClient EMS and video conferencing systems requiring immediate patching. Organizations

0 critical 0 high
March 30 – April 5

Vulnerability Report – Week 5 of March 2026

This week reflects sustained critical threats across OT/ICS and enterprise systems with multiple actively exploited vulnerabilities. F5 BIG-IP APM (CVE-2025-53521) and Citrix NetScaler (CVE-2026-3055)

0 critical 0 high
March 14–20

Vulnerability Report – Week 3 of March 2026

This week demands immediate attention. Two actively exploited vulnerabilities (VMware ESXi and FortiOS) require emergency patching. Organizations using Windows Server should prioritize the kernel priv

0 critical 0 high

Get the Daily Briefing in Your Inbox

Subscribe free and never miss a threat briefing.