Bharat Threat FeedGlobal threats, decoded for Indian defenders
Government & Defence Sector Edition · August 2026

Government & Defence Sector Edition — August 2026

Education is the most attacked industry in global telemetry, and Indian campuses carry a specific version of that risk: student and parent records that convert directly into financial fraud, examination systems under public scrutiny, and remote-access appliances built for a smaller user base than they now serve. This edition covers the ransomware crews concentrating on higher education, five actively exploited flaws sitting on the campus perimeter, the DPDP dates that now have consequences attached, and a Pakistan-nexus group running education-themed lures against Indian institutions.

1. Sector snapshot

Check Point Research placed education first among all industries in June 2026 at an average of 4,816 weekly attacks per organisation, up 16 percent year on year, against a global all-sector average of 2,270. APAC averaged 3,060, and the region's share of published ransomware victims rose from 16.8 percent in April to 22.6 percent in June. For India, the most recent dated sector telemetry remains Check Point's June 2025 India report, which put education and research at 8,487 weekly attacks per organisation. Ransomware volume against education fell 13 percent in the first half of 2026, but the aggregate conceals a split: school-level attacks fell 26 percent while higher education rose more than 8 percent, and the median ransom demand climbed 53 percent to USD 420,620.

Source (with date): Check Point Research (9 Jul 2026); Comparitech (23 Jul 2026); Check Point Software India threat intelligence report (16 Jun 2025).

2. Threats targeting Education

1

The Gentlemen has concentrated on higher education

Attacks attributed to this group against education rose 275 percent in the first half of 2026 against the second half of 2025, and colleges and universities made up 80 percent of its education operations. It tied with Qilin at 15 claimed education attacks, ahead of LockBit at nine, and recorded the most confirmed cases at six. The largest demand in the period was USD 1.9 million against a Canadian university. Check Point separately ranked it the most prevalent ransomware operation in June 2026 at 17 percent of published attacks. It emerged in mid-2025 as an independent ransomware-as-a-service operation, assessed to have developed from ArmCorp, a former Qilin affiliate. No India-based victim has been publicly attributed to it; the relevance is that a crew now selecting universities by preference has the volume to reach Indian campuses.

SourceComparitech (23 Jul 2026); Infosecurity Magazine (24 Jul 2026); Check Point Research (9 Jul 2026).
2

Indian student records are being worked as a fraud supply chain

CYFIRMA documented a four-stage pattern against Indian institutions: acquisition through exposed portals, insider access, fraudulent institution websites or vendor breaches; contact by email, SMS, WhatsApp or voice call impersonating the institution; exploitation through fraudulent payment links, credential capture or remote-access app installation; and monetisation via account takeover, fabricated fee collection and resale on criminal forums. Record sets referenced include over 12 million from an Indian school search platform, 682,000 from an education services provider and more than 46,000 linked to a major Indian university. The exposed fields are the ones that make impersonation convincing: names, dates of birth, enrolment details, payment records, parent information, photographs and signatures. Universities, coaching institutes, scholarship platforms and EdTech providers are all named as affected categories.

SourceCYFIRMA; CyberSecurityNews; GBHackers (21 May 2026).
3

Learning-platform concentration risk, demonstrated at scale

The Canvas platform operated by Instructure was accessed on 25 April 2026, detected on 29 April and disclosed on 1 May, with a second extortion message on 7 May. ShinyHunters claimed 3.65TB covering roughly 275 million users across 8,809 institutions. Instructure confirmed exposure of names, email addresses, student identification numbers and messages between users, and stated it found no evidence that passwords, dates of birth, government identity numbers or financial information were involved. Confirmed disruption was reported across nine countries. Public incident updates reviewed for this issue did not identify an India-based affected institution. The applicable lesson is third-party concentration: one hosted platform aggregates identity, messaging and academic records for an entire institution.

SourceInstructure incident updates; Reed Smith; McDonald Hopkins (1 May 2026).

3. Sector tech & exposures

Cisco ASA and FTD, CVE-2026-20349. CVSS 8.6. Insufficient error checking when the Remote Access SSL VPN service processes a crafted HTTP request reloads the appliance. No authentication or user interaction is required. Secure Firewall ASA 9.16.1 through 9.24.1 and FTD 7.0 through 10.0 are affected where IKEv2 Remote Access VPN with client services, SSL-VPN or Zero Trust Network Access is configured. Cisco PSIRT confirmed exploitation in the wild and there are no workarounds. CISA listed it on 11 August 2026 with a 14 August federal deadline. Campus VPN head-ends carrying hostel, remote-faculty and examination access sit in this path.

Source (with date): Cisco PSIRT; The Hacker News (12 Aug 2026); CISA KEV (11 Aug 2026).

SonicWall SMA 1000, CVE-2026-15409 and CVE-2026-15410. The first is a server-side request forgery in the Workplace interface at CVSS 10.0, needing no credentials. The second is code injection in the Appliance Management Console. SonicWall advised on 14 July 2026 after investigating active exploitation. Volexity attributes pre-disclosure exploitation from 22 June to a cluster tracked as UTA0533, deploying KNUCKLEBALL, Suo5, ROOTRUN and ORANGETAIL; INC Ransomware has since become the dominant actor. The post-exploitation detail matters here: operators took credentials, active session databases and TOTP multi-factor seed configurations, so a password reset alone does not evict them. Affected are SMA 6210, 7210 and 8200v on the 12.4.3 and 12.5.0 branches.

Source (with date): Rapid7; Volexity; SecurityWeek; The Hacker News (3 Aug 2026).

Fortinet August authentication batch. CVE-2026-26035 lets an unauthenticated remote attacker log in to the FortiWeb GUI or CLI with an arbitrary username and password where non-default wildcard administrator account settings are enabled; fixed in 8.0.3, 7.6.7, 7.4.12 and 7.2.13. CVE-2026-70468 is a FortiManager authentication bypass allowing a remote attacker with a valid certificate to impersonate any managed FortiGate under specific CLI settings. CVE-2026-70465 is a buffer overflow in FortiClient for Windows reachable by an attacker able to tamper with DNS responses, which is a realistic condition on open campus and hostel networks. No active exploitation was reported at disclosure.

Source (with date): Fortinet PSIRT; SecurityWeek; H-ISAC (13 Aug 2026).

Citrix NetScaler, CVE-2026-3055. CVSS v4.0 9.3. An unauthenticated memory overread affects NetScaler ADC and Gateway configured as a SAML identity provider. Citrix published fixes on 23 March 2026, watchTowr observed in-the-wild exploitation by 27 March, and CISA listed it on 30 March with a 2 April deadline. Where NetScaler fronts campus single sign-on, treat it as identity infrastructure rather than a network appliance and rotate what it protects after patching.

Source (with date): Rapid7; SecurityWeek; CISA KEV (30 Mar 2026).

University webmail treated as an edge device. Proofpoint tracked a campaign running since May 2026 against physics and engineering departments at universities in the United States and Canada. It phishes from compromised legitimate senders, exploits CVE-2024-42009 in Roundcube to run the IceCube JavaScript stealer against credentials, cookies and authentication data, then uses CVE-2025-49113 to drop the SquareShell PHP webshell or load the VShell Go backdoor in memory. Proofpoint assesses a likely China-aligned espionage actor. This campaign was not reported as India-targeted and we are not presenting it as such. What does apply is the platform exposure: CVE-2025-49113 has been in the KEV catalogue since 20 February 2026 and remains exploited, and Shadowserver's June 2025 scan placed India second globally at roughly 15,500 vulnerable internet-facing Roundcube instances of 84,925. Self-hosted departmental webmail is common across Indian universities and rarely on a patch schedule.

Source (with date): Proofpoint (7 Jul 2026); The Register (8 Jul 2026); Shadowserver via BleepingComputer (9 Jun 2025).

4. Regulatory & compliance watch

DPDP Rules 2025 — the next hard date is 13 November 2026. MeitY notified the rules on 13 November 2025 with a phased schedule. The Data Protection Board and core definitions took effect immediately. From 13 November 2026, consent-manager registration opens and the enforcement and penalty framework begins. From 13 May 2027 the substantive obligations apply in full: notice, security safeguards, breach notification, erasure, children's data, rights management, cross-border transfers and Significant Data Fiduciary duties. Penalties reach ₹250 crore. Educational institutions are data fiduciaries, and processing the personal data of minors requires verifiable parental consent, which is the hardest requirement for schools and boards to retrofit.

Source (with date): MeitY, DPDP Rules 2025 (13 Nov 2025); Fisher Phillips; iPleaders (2026).

CERT-In patching guidance, and the reporting clock beside it. CERT-In published a 38-page blueprint on 26 May 2026. It recommends rather than mandates, using the phrase "where feasible": known exploited vulnerabilities on internet-facing systems within 12 hours, critical externally exposed flaws within one day, known exploited internal flaws within one day absent mitigations, critical internal flaws on high-value systems within three days, and high-severity flaws within five days on a risk basis. Where no patch exists it points to isolation, access restriction and WAF or API protection. This sits alongside the April 2022 directions requiring incident reporting within six hours. Read against section 3, a campus running an unpatched KEV-listed VPN appliance is outside the recommended window by a wide margin.

Source (with date): CERT-In; The Hacker News (26 May 2026).

Vulnerability disclosure is the process gap. CBSE's On-Screen Marking portal is the domestic case study. A researcher reported flaws identified during the February 2026 examination period to CERT-In and disclosed publicly on 22 May 2026 after more than three months without resolution. Reported issues included hardcoded master passwords, OTP authentication bypass, examiner impersonation and examination material reachable on a misconfigured cloud storage bucket. CBSE initially defended the system and has since stated the identified vulnerabilities were contained. Separately it filed a complaint in June 2026 over coordinated traffic against its post-result portal, stating no data breach or unauthorised access was detected. The point for other institutions is procedural: without a published intake route and a named owner for external reports, disclosure escalates into the press.

Source (with date): Medianama; ThePrint; Business Standard (5 Jun 2026).

5. Actor in focus — Transparent Tribe (APT36)

Transparent Tribe is a Pakistan state-aligned espionage actor active since at least 2013, with SideCopy operating as a subdivision. Its targeting of Indian government, academic and strategically relevant organisations has been continuous rather than episodic, and academia is not a secondary target for this group.

The campaign documented by CYFIRMA and reported in early January 2026 is the one campus teams should model against. A spear-phishing email carries a ZIP archive holding an LNK file disguised as a PDF, relying on Windows hiding the shortcut extension. Execution runs an HTA script through mshta.exe, which decrypts and loads the RAT payload in memory while a decoy PDF opens to reduce suspicion. The second stage is a custom DLL named iinneldc.dll providing remote command execution, file management, screenshot capture, clipboard access and process control, with its C2 endpoint strings stored reversed in the binary to defeat signature matching. Persistence adapts to the antivirus present: a Startup-folder LNK launching HTA via mshta.exe where Kaspersky is detected, a batch file plus Startup LNK where Quick Heal is detected, a direct payload copy to Startup where Avast, AVG or Avira is present, and batch execution with registry persistence where none is detected. That last branch is the one that matters on unmanaged student and research machines. The education relevance is the lure: one decoy was named NCERT-Whatsapp-Advisory.pdf.lnk, imitating the advisory-circular flow that school boards, registrars and academic administrative offices open without hesitation every working day.

Source (with date): CYFIRMA; The Hacker News (2 Jan 2026).

Follow-on reporting tied APT36 and SideCopy to cross-platform RAT activity against Indian entities using Geta RAT, Ares RAT and DeskRAT across Windows and Linux, delivered through phishing with LNK files, ELF binaries, PowerPoint add-in files carrying macros, and a Go binary dropping a Python payload. Research was credited to Aryaka, CYFIRMA, Seqrite Labs, Sekoia and QiAnXin XLab.

Source (with date): The Hacker News; Seqrite Labs; Aryaka; CYFIRMA (11 Feb 2026).

6. IOC pack

Every indicator below is already public in the named source and is reproduced with attribution. These are not Nirad observations.

IndicatorTypeContextSource
dns.wmiprovider[.]comDomain (C2)APT36 RAT command and controlCYFIRMA
aeroclubofindia.co[.]inCompromised legitimate sitePayload staging as reported; the domain owner is not implicatedCYFIRMA
iinneldc.dllFileAPT36 second-stage RAT DLLCYFIRMA
NCERT-Whatsapp-Advisory.pdf.lnkFilename (lure)APT36 decoy shortcut posing as an advisory PDFCYFIRMA
/retsiger, /taebtraeh, /dnammoc_tegURI pathsAPT36 C2 endpoints, stored as reversed stringsCYFIRMA
45.150.109[.]151IPUNK_MassTraction infrastructureProofpoint
194.213.18[.]133IPUNK_MassTraction infrastructureProofpoint
45.86.229[.]111IPUNK_MassTraction infrastructureProofpoint
a02f124c5ce4180bd130a62ee03262f399c33491de3aed36e0b15155ae4926c0SHA-256UNK_MassTraction payloadProofpoint
CVE-2026-20349CVECisco ASA/FTD SSL VPN reload, exploitedCisco PSIRT; CISA KEV
CVE-2026-15409CVESonicWall SMA1000 SSRF, CVSS 10.0, exploitedRapid7; Volexity; CISA KEV
CVE-2026-15410CVESonicWall SMA1000 code injection, exploitedRapid7; SonicWall PSIRT
CVE-2026-3055CVENetScaler SAML IdP memory overread, exploitedRapid7; CISA KEV
CVE-2026-26035CVEFortiWeb improper authenticationFortinet PSIRT
CVE-2025-49113CVERoundcube deserialisation RCE, exploitedProofpoint; CISA KEV
CVE-2024-42009CVERoundcube XSS used for credential theftProofpoint

7. Tiered actions

Board. Put two dates on the institutional risk register: 13 November 2026, when the DPDP enforcement and penalty framework begins, and 13 May 2027, when the substantive obligations apply. Commission an inventory of student and parent data held by EdTech, learning-platform and admissions vendors, since the Canvas incident showed the concentration sits outside the campus boundary. Fund a published vulnerability-disclosure route with a named owner.

CISO. Within seven days, patch or take offline any internet-facing SonicWall SMA 1000, Cisco ASA or FTD, and NetScaler appliance matching the affected versions above. For the SonicWall flaws, assume credential, session and TOTP seed compromise: rotate MFA seeds and invalidate active sessions. Audit FortiWeb for non-default wildcard administrator settings and move to 8.0.3, 7.6.7, 7.4.12 or 7.2.13. Inventory every self-hosted Roundcube instance, including departmental servers outside central IT, and bring them to a patched release. Set an internal SLA against CERT-In's 12-hour window for KEV-listed internet-facing flaws, and confirm the six-hour reporting path is documented and tested rather than assumed.

SOC. Hunt the APT36 chain: LNK files spawning mshta.exe, HTA execution followed by in-memory loading, Startup-folder and registry Run-key persistence on staff and research endpoints, and outbound connections to the domain and URI paths in section 6. On webmail, alert on new or modified PHP files in the Roundcube webroot, unexpected child processes from the web server account, and connections to the listed addresses. On appliances, monitor for unexplained VPN reloads, FortiWeb administrative logins from unfamiliar sources, anomalous NetScaler SAML responses, and SMA1000 management-console access from outside the administrative network. Where an examination or results portal is public-facing, baseline its normal request volume before the results window rather than during it.

8. Source index

BleepingComputer · Business Standard · CERT-In · Check Point Research · CISA KEV · Cisco PSIRT · Comparitech · CyberSecurityNews · CYFIRMA · Fisher Phillips · Fortinet PSIRT · GBHackers · H-ISAC · Infosecurity Magazine · Instructure · iPleaders · McDonald Hopkins · Medianama · MeitY / DPDP Rules 2025 · Proofpoint · Rapid7 · Reed Smith · SecurityWeek · Sekoia · Seqrite Labs · Shadowserver Foundation · SonicWall PSIRT · The Hacker News · The Register · ThePrint · Volexity · watchTowr

9. Byline

4

Nirad Threat Research

NBTF — Education Sector Edition | 19 August 2026