The State of Ransomware in Education 2025
441 IT and cybersecurity share their ransomware experiences, revealing the realities facing lower and higher education providers today.
Sergiu Gatlan reports another reminder of the insider threat: American cybersecurity firm CrowdStrike has confirmed that an insider shared screenshots taken on internal systems with hackers after they were leaked on Telegram by the Scattered Lapsus$ Hunters threat actors. However, the company noted that its systems were not breached as a result of this incident……
Adam Thorn reports: Qantas has obtained a court injunction to prevent any person or organisation from publishing the customer information stolen in its recent hack. The airline called the ruling of the NSW Supreme Court an “important next course of action” but also reiterated that there is still “no evidence” that any data had been…
Oracle continues to deny it had any breach, but customers and researchers are claiming otherwise. Lawrence Abrams reports: Despite Oracle denying a breach of its Oracle Cloud federated SSO login servers and the theft of account data for 6 million people, BleepingComputer has confirmed with multiple companies that associated data samples shared by the threat actor…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added two security flaws impacting Gladinet and Control Web Panel (CWP) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The vulnerabilities in question are listed below – CVE-2025-11371 (CVSS score: 7.5) – A vulnerability in files or directories…
Microsoft has shed light on a now-patched security flaw impacting Apple macOS that, if successfully exploited, could have allowed an attacker running as “root” to bypass the operating system’s System Integrity Protection (SIP) and install malicious kernel drivers by loading third-party kernel extensions. The vulnerability in question is CVE-2024-44243 (CVSS score: 5.5), a medium-severity bug
DPA reports: A cyberattack on Swiss hospital group AMEOS may have exposed sensitive patient and staff data, the company said on Monday. The attack, which took place two weeks ago, caused significant disruption across the group’s German operations. The company described the episode as a targeted assault on its IT infrastructure. In a statement, AMEOS…