Nirad Threat Research
NBTF — Education Sector Edition | 23 September 2026
Education is the most attacked sector globally and the most attacked sector in India, on separate evidence. Check Point Research placed education first among 23 tracked industries between January and July 2026, at 4,696 weekly attacks per organisation, an 8 percent rise year on year and more than double the 2,150 cross-industry average; Asia-Pacific was the heaviest region at 7,452. Seqrite's India Cyber Threat Report 2026 ranks education first among Indian sectors at close to 24 percent of detections over October 2024 to September 2025. The Indian weakness is structural: a large shared network, a permissive device population, research data with export value, and an administrative estate built on third-party platforms the institution neither patches nor can meaningfully audit.
Source (with date): Check Point Blog (19 Aug 2026); Seqrite India Cyber Threat Report 2026, as carried by CXO DigitalPulse (18 Jun 2026).
Oracle PeopleSoft CVE-2026-35273: the student-records system as the way in. An unauthenticated remote code execution flaw in the PeopleSoft Environment Management component, CVSS 9.8, exploited as a zero-day against higher education between 27 May and 9 June 2026. Mandiant and Google Threat Intelligence attribute the activity to ShinyHunters, tracked as UNC6240, and count more than 300 compromised application instances across over 100 organisations, roughly 68 percent of them universities and colleges. Oracle issued an out-of-band patch on 10 June 2026, two weeks after exploitation began. The University of Nottingham confirmed a breach of its student-records system; reporting puts it at 454,600 current and former students across three country campuses. PeopleSoft Campus Solutions and HCM are the system of record for admissions, examinations and payroll at several Indian central and large private universities, which makes this an asset-register question rather than foreign news.
Source (with date): Google Cloud / Mandiant (12 Jun 2026); BleepingComputer; teiss (Jun 2026).
The Canvas incident: concentration is the finding. Instructure detected unauthorised activity in its Canvas environment on 29 April 2026. The extortion group claims data covering 8,809 institutions and roughly 275 million users; that claim is not independently verified. Instructure's own account is narrower: names, email addresses, student identification numbers and in-platform messages, with no evidence that passwords, dates of birth, government identifiers or financial data were involved. The group forced a visible outage on 7 May 2026, during the examination period, and Instructure said it reached an agreement with the attackers on 11 May 2026. For an Indian institution the operative problem is contractual. A foreign-hosted learning platform holding student data leaves the institution accountable as a data fiduciary for a processor it cannot inspect, and the notification chain has to be fast enough to serve a six-hour CERT-In obligation.
Source (with date): Instructure statements; CNN (07 May 2026); Trend Micro (May 2026).
The Gentlemen: a ransomware operation that has selected this sector. Unit 42 documents a ransomware-as-a-service programme running since July 2025 with around 20 operators and a 90 percent affiliate payout against the usual 70 to 80, formed when an affiliate broke away from Qilin. Initial access comes through edge devices, firewalls and VPNs, alongside brute force, purchased credentials and access brokers. Post-access tooling includes a Go backdoor, an endpoint-detection killer the operators call GentleKiller, SystemBC for command and control, Advanced IP Scanner for reconnaissance and wevtutil for clearing logs. Comparitech's half-year count puts the group's attacks on education up 275 percent against the second half of 2025, with 80 percent directed at colleges and universities, level with Qilin as the period's most prolific education attacker.
Source (with date): Unit 42 / Palo Alto Networks (10 Jul 2026); Comparitech; Infosecurity Magazine (Jul 2026).
Two unconfirmed extortion claims against Indian universities. An extortion group listed Vellore Institute of Technology on 22 September 2026, with the intrusion estimated at 13 September. Separately, DYSPHOR1A listed the University of Delhi on 20 August 2026, and that listing was later removed from public trackers. Both claims are unverified, neither institution has issued a public statement, and neither belongs in a board paper as a confirmed breach. We are not describing or itemising any claimed data. The verifiable element sits alongside the Delhi listing: SOCRadar's credential-exposure correlation surfaced 25 credentials tied to du.ac.in student-facing and admissions infrastructure, with log dates running to 21 August 2026. Credentials stolen from personal and hostel devices remain the standing route into Indian campus portals regardless of how either claim resolves. SOCRadar assesses DYSPHOR1A as concentrating on education, government and financial organisations across India and South-East Asia.
Source (with date): DeXpose; ransomware.live (22 Sep 2026); SOCRadar; GÉANT Security (Aug 2026).
The Pakistan-nexus backdrop is unchanged. APT36, also tracked as Transparent Tribe, continues espionage operations against Indian government, defence and academic targets. Campaigns reported in January 2026 used spear-phishing archives carrying a shortcut file disguised as a PDF, which runs a remote HTA through mshta.exe and loads a remote access trojan in memory while a decoy document opens. Education-themed lures, including an NCERT-themed advisory filename and assignment-themed documents aimed at instructors and students, are long-established practice for this actor. This is standing backdrop rather than a development this cycle. Keep the detections running independently of this issue.
Source (with date): The Hacker News (Jan 2026); CYFIRMA (2026).
Cisco ISE CVE-2026-76460: the campus identity layer, rated 10.0, with no workaround. An authentication bypass in Identity Services Engine and the ISE Passive Identity Connector, caused by insufficient authentication controls on an API endpoint, giving an unauthenticated remote attacker command execution with root privileges. Cisco confirms exploitation in the wild. CISA added it on 16 September 2026 with a 19 September remediation date, and Cisco's advisory followed on 17 September. On an Indian campus, ISE is what hostel Wi-Fi, laboratory VLANs, BYOD onboarding and contractor access authenticate against, and it holds the identity policy for the estate. There is no workaround, so the choice is the fixed release or removing reachability to the management interface.
Source (with date): Cisco; CISA KEV (16 Sep 2026); Help Net Security (17 Sep 2026).
ConnectWise ScreenConnect CVE-2026-84869: the flaw is in the client, not the server. Improper privilege management and missing authorisation, CVSS 9.9, allowing files to be transferred and executed through an active remote session without host confirmation. Huntress reported exploitation in the wild from 20 August 2026. ConnectWise released 26.6.5 on 8 September 2026 and states that servers are unaffected, which is the detail that matters operationally: an institution that patched the server and stopped there is still exposed on every endpoint running an older client. CISA listed it on 11 September with a 14 September due date. On most campuses that endpoint estate includes machines managed by an outsourced annual-maintenance or managed-service partner rather than by campus IT.
Source (with date): ConnectWise bulletin (08 Sep 2026); Help Net Security (07 Sep 2026); CISA KEV (11 Sep 2026).
Fortinet CVE-2025-25249: a January patch now being used to plant an implant. A heap-based buffer overflow in FortiOS, FortiSwitchManager and FortiSASE, CVSS 7.4, allowing unauthorised code or command execution through crafted packets. Fortinet patched in January 2026 and exploitation has been observed since July. SOCRadar reported scanning across more than 30,000 addresses and identified 178 devices carrying the PivotC2 implant. CISA listed it on 9 September 2026 with a 12 September due date. The moderate severity score is precisely why this one stayed in the patch backlog; the exploitation record is the reason it should not stay there.
Source (with date): Fortinet; SOCRadar; CISA KEV (09 Sep 2026); ThaiCERT (11 Sep 2026).
Moodle CVE-2026-7275 and CVE-2026-7274: patched in May, worth confirming on your branch. The first is a remote code execution risk in the Google Drive repository plugin. The second is SQL injection in the external database authentication plugin, auth_db, and affects only sites with that plugin enabled. Both cover 5.1 to 5.1.3, 5.0 to 5.0.6, 4.5 to 4.5.10 and earlier unsupported branches, fixed in 5.1.4, 5.0.7 and 4.5.11. No public reporting describes exploitation in the wild, and we are not implying any. It is listed because the exposure here is version drift rather than novelty: Moodle is widely deployed across Indian universities and affiliated colleges, and an institution that cannot state its branch version this week cannot rule either flaw out. Where the upgrade cannot be scheduled immediately, disable the Google Drive repository.
Source (with date): Moodle security advisories (May 2026); CIRCL vulnerability-lookup (May 2026).
JEE Advanced 2026: an examination cloud store reachable without authentication. A public cloud storage endpoint linked to the results portal was accessible anonymously. The 16-year-old researcher who reported it put the exposure at roughly 179,600 result records and 187,300 admit-card PDFs carrying candidate names, dates of birth and mobile numbers; those figures are his and have not been independently confirmed. IIT Roorkee acknowledged the misconfiguration, corrected it, credited the disclosure, and stated that the stored data was read-only so no alteration was possible, declining the characterisation of a breach. The read-only point is correct and does not reduce the risk to the candidate. A verified name, date of birth and mobile number tied to a known examination is workable material for admission-fee fraud and for phishing a family has no practical way to distinguish from an institutional message.
Source (with date): Deccan Herald; Telangana Today (03 Jun 2026).
DPDP children's data: the date is 14 May 2027, the engineering starts now. Under the DPDP Act 2023 and the DPDP Rules notified on 13 November 2025, everyone below 18 is a child. Processing their data requires verifiable parental consent, with approved methods including DigiLocker-based verification of the parent's identity and of the parent-child relationship. Tracking, behavioural monitoring, profiling and advertising targeted at children are prohibited. Penalties reach ₹250 crore per violation. Schools, coaching institutions and edtech platforms are in scope, as is every university unit processing data for students under 18. Consent capture, consent state and retention are build work with a long lead time, not a policy circular.
Source (with date): MeitY, DPDP Rules 2025 (13 Nov 2025); EY India (2026); Fisher Phillips (2026).
CERT-In CISG-2026-02: twelve hours for internet-facing known-exploited flaws. Issued on 25 May 2026 as a blueprint for reducing exposure to AI-assisted exploitation, it sets an expectation of patching known-exploited vulnerabilities on internet-facing systems within 12 hours where feasible, with graduated timelines extending to five days for lower-risk internal flaws, and compensating controls such as isolation, access restriction and web application firewalls where the patch cannot be applied in time. It sits on top of the six-hour incident-reporting obligation from the April 2022 directions. Applied to this issue, the Cisco ISE and ScreenConnect items are not change-window work.
Source (with date): CERT-In CISG-2026-02 (25 May 2026); The Hacker News; The Register (26 May 2026).
APAAR: consent becomes a documented state, not a registration step. On 20 July 2026 the Supreme Court directed CBSE to provide an express opt-out in the APAAR consent form so a parent or guardian can withhold consent, and held that collection, processing, storage, retention and sharing under the APAAR scheme are subject to the DPDP Act, with student data not to be disclosed to private entities or third parties except in accordance with law. An institution holding APAAR-linked records now needs to be able to show, per student, what was consented to and what was refused.
Source (with date): Supreme Court of India, as reported by SCC Online (27 Jul 2026); LiveLaw (Jul 2026).
Proofpoint published this cluster on 7 July 2026 and assesses it as likely China-aligned and espionage-motivated, operating from covert VPS infrastructure with Chinese-language artefacts in its phishing mail. Active since May 2026, it targets physics and engineering departments at universities in the United States and Canada, with a stated preference for administrators and professors holding national-security links and for organisations working on astrophysics and particle physics.
A phishing mail exploits the Roundcube cross-site scripting flaw CVE-2024-42009 to run JavaScript in the victim's browser, delivering a credential stealer Proofpoint calls IceCube, which takes usernames, passwords, session cookies, two-factor tokens and browser information. Follow-on components exploit the Roundcube deserialisation flaw CVE-2025-49113 through Crypt_GPG_Engine parsing to install a PHP webshell, SquareShell, at plugins/newmail_notifier/mail_preview.php, with the Go-based VShell implant providing interactive shell access and port forwarding.
No named source places Indian universities in this campaign, and we are not suggesting otherwise. The relevance is reach and pattern. Departmental Roundcube webmail running on a server maintained by a faculty member is a common arrangement on Indian campuses, the disciplines named overlap with research that Indian national missions fund, and theft of session cookies and two-factor tokens means mailbox multi-factor authentication does not end the incident.
Source (with date): Proofpoint (07 Jul 2026); CyberScoop; Infosecurity Magazine (Jul 2026).
All indicators below come from named public threat intelligence. None derive from internal telemetry.
| Indicator | Type | Context | Source |
|---|---|---|---|
45.150.109[.]151 | IP | UNK_MassTraction infrastructure | Proofpoint |
194.213.18[.]133 | IP | UNK_MassTraction infrastructure | Proofpoint |
45.86.229[.]111 | IP | UNK_MassTraction infrastructure | Proofpoint |
plugins/newmail_notifier/mail_preview.php | File path | SquareShell webshell location on a compromised Roundcube server | Proofpoint |
a02f124c5ce4180bd130a62ee03262f399c33491de3aed36e0b15155ae4926c0 | SHA-256 | UNK_MassTraction tooling | Proofpoint |
gentlemen | Scheduled task name pattern | The Gentlemen ransomware persistence | Unit 42 |
CVE-2026-76460 | CVE | Cisco ISE authentication bypass, CVSS 10.0, exploited, no workaround | Cisco; CISA KEV |
CVE-2026-84869 | CVE | ScreenConnect client, exploited from 20 Aug 2026 | ConnectWise; CISA KEV |
CVE-2025-25249 | CVE | FortiOS and FortiSwitchManager; PivotC2 implant | Fortinet; SOCRadar; CISA KEV |
CVE-2026-35273 | CVE | Oracle PeopleSoft zero-day used against universities | Mandiant; Rapid7 |
CVE-2025-49113, CVE-2024-42009 | CVE | Roundcube exploitation chain | Proofpoint |
CVE-2026-7275, CVE-2026-7274 | CVE | Moodle; no public reporting of exploitation in the wild | Moodle |
Board. Two decisions, each with a budget line. First, concentration risk: the learning platform, the student-records system and the examination portal are single points of failure operated by third parties, and the institution carries the regulatory exposure without the operational control. Ask for the contractual position on breach-notification timing before the next audit cycle. Second, fund the DPDP children's-data programme against 14 May 2027 as engineering work on consent capture, consent state and retention.
CISO. Treat the three exploited items on the CERT-In 12-hour expectation rather than a change window. Patch Cisco ISE and invalidate existing sessions, since an authentication bypass is not closed by the patch alone. Move ScreenConnect clients to 26.6.5 across campus-managed and partner-managed endpoints, not just the server. Validate FortiOS and FortiSwitchManager versions and review device configuration for unexpected changes. Upgrade Moodle to a supported branch and disable the Google Drive repository until that is done. Review PeopleSoft exposure, and audit admission and result cloud storage for anonymous read access ahead of the next examination cycle. Confirm that LMS and ERP contracts let the institution meet a six-hour CERT-In report and a DPDP Board notification when the incident is on the vendor's side.
SOC. Hunt for unexpected PHP files written under Roundcube plugin directories, including the SquareShell path above. Look for scheduled tasks matching the gentlemen string, SystemBC beacons, Advanced IP Scanner running on servers, and wevtutil log clearing. Alert on ISE administrative API access from unexpected sources, and on ScreenConnect file transfers outside change windows. Watch for mshta.exe launched from archives extracted out of mail, which is the APT36 pattern. Where a named threat-intelligence provider reports credential exposure for your domain, force resets on the affected student and staff accounts and check those accounts for portal logins in the exposure window.
BleepingComputer · Check Point Blog · CIRCL · Cisco · CISA KEV · CNN · Comparitech · ConnectWise · CXO DigitalPulse · CyberScoop · CYFIRMA · Deccan Herald · DeXpose · EY India · Fisher Phillips · Fortinet · GÉANT Security · Google Cloud / Mandiant · Help Net Security · Huntress · Infosecurity Magazine · Instructure · LiveLaw · MeitY / DPDP Rules 2025 · Moodle · Proofpoint · Rapid7 · ransomware.live · SCC Online · Seqrite · SOCRadar · teiss · Telangana Today · ThaiCERT · The Hacker News · The Register · Trend Micro · Unit 42 / Palo Alto Networks
NBTF — Education Sector Edition | 23 September 2026