❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayIT Security

4 Ways Organisations Create Non-Human Insider Risk

By: The Gurus
10 September 2026 at 11:55

As AI agents become embedded across business operations, they are also creating a new category of insider risk. Unlike traditional insiders, these non-human identities can act at machine speed, operate continuously and access multiple systems without direct human oversight.

The danger rarely stems from one obvious security failure. Instead, it emerges when several weaknesses overlap. Here are four common ways organisations inadvertently create non-human insider risk:

1. Persistent access

Long-lived API keys, OAuth tokens, service accountsΒ and standing privileges give agents constant access long after it is needed.

2. Excessive privilege

Many agents can read, write, modify, approve, deleteΒ or deploy far more than their actual tasks require.

3. Untrusted input

Agents consume information from emails, support tickets, documents, chat conversations, websites and repositories. If attackers can influence those inputs, they may also influence the agent’s decisions.

4. Limited behavioural monitoring

Many organisations can tell that an AI agent performed an action. Far fewer can determine whether that action actually made sense. Logging tells us what happened, understanding whether it should have happened is a different challenge altogether.

You can read the full blog from Erich Kron, CISO Advisor at KnowBe4. Stay tuned for part 2 where Erich will reveal what security teams should do to stay secure.

The post 4 Ways Organisations Create Non-Human Insider Risk appeared first on IT Security Guru.

Former Currys CIO Andy Gamble Joins Core to Cloud as Advisory Board Chair

10 September 2026 at 08:34

UK cybersecurity specialist Core to Cloud has appointed former Currys Group CIO Andy Gamble as Chair of its Advisory Board as the company looks to accelerate the growth of its managed security services.

Gamble brings nearly 30 years of board-level technology leadership and will work with Core to Cloud on its strategic, advisory and commercial direction across the UK enterprise and mid-market sectors.

His appointment adds further experience to the company’s Advisory Board, which includes senior security leaders from major UK organisations.

From cybersecurity buyer to advisor

Gamble spent six years as Group CIO and Chief Transformation Officer at Currys PLC, where his responsibilities included large-scale technology transformation and cyber risk.

His career has also included senior CIO positions at Dyson, Sony Electronics and Essentra PLC. That experience means Gamble has spent much of his career on the customer side of the cybersecurity market, buying and managing the types of services Core to Cloud now provides.

β€œI spent the better part of three decades as a buyer of cybersecurity services, and the experience left me with a clear view of where the market falls short,” Gamble said.

β€œMost organisations understand that cyber risk is real. Far fewer have a security function that can communicate that risk clearly at board level, or a partner that moves fast enough to keep pace with the threat.”

Gamble said Core to Cloud stood out because of its focus on proactive security, adding that he intends to help the business scale its model as a challenger to conventional managed security service providers.

Supporting Core to Cloud’s next stage of growth

Based in Cirencester, Core to Cloud works with more than 150 organisations across sectors including the NHS, retail, financial services and critical national infrastructure.

Its services span Managed Detection and Response, Third-Party Cyber Risk Management, Security Assurance, Dark Web Monitoring and Threat Intelligence, and Cyber Crisis Simulation.

James Cunningham, CEO and Founder of Core to Cloud, said Gamble’s experience at the intersection of technology, risk and commercial strategy would bring a new perspective to the company.

β€œHe understands what good security looks like from the inside and brings a depth of experience and perspective that will be hugely valuable as we continue to grow,” Cunningham said.

β€œWe have an ambitious business, a strong customer base and services we genuinely believe in. Having Andy chair our board will help us build on those foundations, challenge our thinking and accelerate the next stage of Core to Cloud’s growth.”

The post Former Currys CIO Andy Gamble Joins Core to Cloud as Advisory Board Chair appeared first on IT Security Guru.

Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools

9 September 2026 at 10:20

Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote management software to establish persistent access to victims’ devices.

Both incidents, observed in August, began with phishing messages directing victims to attacker-controlled websites. The attackers then used a browser-in-the-browser (BiTB) technique to create what appeared to be a legitimate Adobe webpage, before convincing victims to download malicious software disguised as an Adobe Reader update.

Rather than deploying conventional malware, the attackers installed rogue instances of ScreenConnect, legitimate remote monitoring and management (RMM) software, giving them continued remote access to compromised endpoints.

Fake browser makes phishing harder to spot

BiTB attacks create a fake browser window inside a webpage using HTML, CSS and JavaScript. The window can replicate familiar features including an address bar, padlock and legitimate-looking URL, making traditional advice such as checking the web address less effective.

In the first attack, detected on 25 August, a victim clicked a link in a phishing email and was taken to a fake CAPTCHA page. They were subsequently presented with blurred documents and told they needed to download Adobe PDF Reader to view them.

The fake browser page appeared to show Adobe’s legitimate get.adobe.com address. However, the supposed Reader installer was actually ScreenConnect.

Once installed, the attackers deployed two rogue ScreenConnect clients, providing redundant routes for maintaining access. They then executed HideCursor.exe, a defence-evasion tool designed to conceal on-screen activity. Huntress intervened before the attack could progress further.

Second attack follows same playbook

Huntress identified another incident on 31 August involving the same Adobe Reader lure.

This time, the victim interacted with a malicious link delivered through AT&T Office@Hand, a legitimate communications service powered by RingCentral. The attackers again disguised ScreenConnect as an Adobe Reader update and installed two unauthorised instances.

The second ScreenConnect session was used to execute another defence-evasion binary, HideUL.exe. Microsoft Defender detected part of the activity, but the rogue ScreenConnect client still completed its installation before Huntress shut down the attack.

Legitimate tools remain attractive to attackers

The attacks demonstrate how threat actors can combine familiar phishing techniques with trusted software to make malicious activity harder to identify.

RMM abuse is a growing problem. Huntress’ 2026 Cyber Threat Report found RMM abuse increased 277% year on year and appeared in nearly a quarter of the incidents investigated by the company.

Huntress recommends organisations restrict who can install remote management tools, maintain an approved inventory of RMM software and monitor for new or unauthorised ScreenConnect clients. Employees should also be wary of unexpected software updates or file-viewing prompts, even when a webpage appears to display a legitimate address.

Read the full research here.Β 

The post Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools appeared first on IT Security Guru.

Thrown into the SOC: A Black Hat First-Timer’s Story

7 September 2026 at 11:00
A Black Hat SOC analyst shares how agentic workflows, Splunk ES, packet evidence, and human mentorship accelerated triage & investigation in the NOC/SOC.

Black Hat USA 2026: Safeguarding DNS with Secure Access

7 September 2026 at 11:00
Cisco is the Security Cloud Provider for the Black Hat conferences, over a decade providing DNS Security. Learn about protecting DNS with Secure Access.

Innovator Spotlight: Snowflake

By: Stevin
27 August 2026 at 08:05

Giving AI Freedom Without Losing Control Who’s Really in Control? AI agents are stepping into a bigger role inside the enterprise. They are not just providing answers anymore. They are...

The post Innovator Spotlight: Snowflake appeared first on Cyber Defense Magazine.

Manchester Airports Group Cyberattack Exposes Data of 8.7 Million Customers

28 August 2026 at 09:05

Manchester Airports Group (MAG) has suffered a major cyberattack in which data belonging to around 8.7 million customers was reportedly accessed, raising concerns about how the stolen information could now be exploited by cybercriminals.

The incident affected customer information associated with Manchester Airport, London Stansted and East Midlands Airport. Data connected to car park, lounge and Fast Track bookings, as well as airport Wi-Fi registrations, was reportedly accessed.

Email addresses, phone numbers, postcodes and vehicle registration details are among the information affected. However, payment information was not compromised, while airport operations, passenger safety and aviation security were unaffected.

While this limits the immediate operational impact, security experts warn that the combination of information exposed could prove particularly useful for targeted phishing, impersonation and social engineering.

Stolen data could make scams much harder to spot

Simon Pamplin, CTO at Certes, said the fact that operations were unaffected should not distract from the significance of the data exposure.

β€œAround 8.7 million customer records have reportedly been accessed, including email addresses, phone numbers, postcodes and vehicle registration details. Individually these may appear relatively innocuous, but together they create a detailed dataset that can be extremely useful for targeted phishing, impersonation and social engineering.”

The context surrounding the information could make it especially valuable. Criminals could potentially create fraudulent parking notices, travel communications or airport-related messages containing enough genuine information to appear legitimate.

Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, described the combination of information as a β€œprecise targeting profile” for criminals.

β€œScammers now know you travelled, roughly when, and have two direct contact routes to reach you with a convincing story,” he said.

Carole Reeves, Director of Security Operations at ANS, agreed that the absence of payment information should not lead customers to underestimate the risk.

β€œAttackers do not always need financial credentials from the initial breach. They can use the information they have to impersonate a trusted organisation and manipulate someone into revealing further personal or financial details.”

Aviation sector faces growing cyber pressure

Graeme Stewart, Head of Public Sector at Check Point Software, said the incident should serve as a warning to the wider aviation industry.

β€œThe absence of cancelled flights or queues at terminals does not make this a small cyber attack. The data reportedly taken can now be weaponised,” he said.

Knowledge of a customer’s relationship with an airport could potentially be used to create fake parking refunds, Fast Track problems or communications about the breach itself.

β€œAviation needs to behave as though a sustained campaign has begun, because waiting for an attack that stops planes moving before treating this as serious would be a dangerous mistake,” Stewart added.

Complex airport ecosystems create additional risks

The attack also raises questions about the complex technology ecosystems supporting modern airports.

Nathan Davies-Webb, Principal Consultant at Acumen Cyber, said airport groups sit at the centre of numerous booking, parking, loyalty, payment and internet connectivity services, many of which can be operated by subsidiaries or third-party suppliers.

β€œThat’s a sensible commercial model but it creates an uncomfortable reality for security. A breach like this one in a shared upstream system can expose customer data from multiple services at multiple airports simultaneously.”

Davies-Webb also highlighted the speed of MAG’s response, with public disclosure roughly 48 hours after it became aware of the incident.

β€œEither way, it’s a better disclosure posture than we’ve seen from organisations involved in some comparable incidents, and MAG will probably benefit from having been quick and open here,” he said.

Tim Williams, CEO at Quod Orbis, also pointed to the importance of visibility beyond an organisation’s core systems.

β€œWhile the systems targeted were car parking, lounge bookings and WiFi sign-ups, they were not responsible for flight operations; they formed part of the wider digital environment through which customers interact within the airport,” Williams said.

He argued that security teams need visibility across systems, applications and third-party services so that risks can be identified before they become incidents.

β€œRapid response can contain an incident, but having visibility across the wider technology and third-party ecosystem can help organisations identify potential weaknesses earlier, understand their exposure and strengthen their defences before an incident occurs.”

Knowing what data was accessed matters

The breach also highlights the importance of understanding exactly what information has been exposed once an attacker gains access.

Jerry Caviston, CEO at Archive360, said good data governance can provide organisations with the traceability needed during an incident.

β€œHaving good data governance is like having CCTV footage of what data was touched and when,” he said.

Maintaining an event audit history can help organisations trace compromised information back to its original source and provide affected customers with clearer information about the risks they face.

Pamplin argues organisations should go further by attaching security directly to the data.

β€œWe have to work on the assumption that systems will eventually be accessed. The objective should be that when this happens, sensitive data remains encrypted and unusable outside its authorised context,” he said.

β€œIf an attacker can steal information but cannot read or exploit it, the value of the breach changes fundamentally.”

Customers should prepare for follow-on attacks

The immediate concern for affected customers is what criminals could do with the information next.

Jamie Akhtar, CEO and Co-Founder of CyberSmart, advised customers to be particularly cautious of unexpected emails, calls or texts claiming to relate to airport or travel services.

β€œAvoid clicking links or sharing personal information in unsolicited messages and, where possible, verify communications independently through an organisation’s official website or app,” he said.

Shankar Haridas, UK Business Head at ManageEngine, warned that the original breach could be followed by attacks designed to exploit customers’ trust in MAG.

β€œA breach like this doesn’t end when the data is taken. A flood of cloaked attacks, dressed up in the airport’s name is next,” he said.

β€œWith 8.7 million email addresses, phone numbers and postcodes now in criminal hands, every β€˜confirm your booking’ or β€˜update your car park payment’ message must be questioned.”

Brian Higgins, Security Specialist at Comparitech, added that AI is making it easier for criminals to aggregate breached information and find new ways of monetising it.

β€œAs AI makes data aggregation swift and easy, consumers are waking up to the fact that criminals can monetise successful breaches in increasingly inventive ways,” he said.

For those potentially affected, the consequences of the MAG cyberattack may therefore continue long after the initial incident has been contained. Emails or messages referencing airport parking, lounge access, Fast Track services or travel details could contain genuine personal information, making the next wave of scams considerably harder to recognise.

The post Manchester Airports Group Cyberattack Exposes Data of 8.7 Million Customers appeared first on IT Security Guru.

Iran-Linked Hackers Blamed for UK Energy Cyberattack

25 August 2026 at 14:45

A cyberattack reportedly linked to Iran forced a small UK energy generator offline for four days, raising fresh concerns about the security of the country’s critical infrastructure and smaller operators that may sit outside existing regulatory thresholds.

The UK government has confirmed that a small-scale generator was affected by a cyber incident in July. It stressed that the facility represented a tiny proportion of overall generation capacity and that the wider UK energy system was never at risk.

The government has not publicly attributed the attack or named the affected site. However, reports have linked the incident to hackers affiliated with Iran.

Following the incident, the Department for Energy Security and Net Zero (DESNZ) and National Cyber Security Centre (NCSC) have been engaging with energy companies over the cyber threat facing the sector.

Small target, bigger security questions

While the facility itself was small, cybersecurity experts warn that its size should not distract from the fact that a cyber incident reportedly caused several days of operational disruption.

Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, said attackers are unlikely to care whether an operator meets the threshold to be considered critical infrastructure.

β€œIf it can be disrupted, it can be targeted,” Patel said. β€œThe significance isn’t the size of the facility, but that a cyberattack turned into four days of real-world operational disruption.”

Patel said the incident raises questions about whether smaller operators have sufficient monitoring, containment and recovery capabilities.

β€œThere is also a potential visibility gap. If smaller energy operators fall outside mandatory cyber-reporting thresholds, we risk underestimating how frequently this part of our infrastructure is being targeted or successfully compromised.”

Attribution remains uncertain

Despite reports linking the incident to Iran, Cian Heasley, Principal Consultant at Acumen Cyber, cautioned against concluding before further evidence emerges.

β€œAttribution for the incident is by no means concrete; the Iran link originates from press reporting while the UK government has declined to attribute blame or name the site affected,” Heasley said.

He argued that the more important lesson for the energy sector is what the incident demonstrates about the potential vulnerability of smaller energy assets.

β€œThe significance of this incident lies in the precedent rather than the impact. A successful, if limited, intrusion into a power-generating asset demonstrates intent and a degree of capability against British energy infrastructure.”

Heasley said operators should focus on OT security fundamentals, including removing industrial controllers from direct internet exposure, strengthening credential management, separating IT and OT environments, and testing manual fallback and recovery procedures.

Graeme Stewart, head of public sector at Check Point, said the incident should concern organizations responsible for keeping essential services running.

β€œThe fact that this was a relatively small generator and the wider grid was unaffected does not remove the threat,” Stewart said. β€œThe far more serious point is what the attackers appear to have demonstrated: an ability to get inside UK energy infrastructure and stop it working.”

He warned that the bigger question is what happens if a future target is larger or more deeply connected to essential services such as electricity, water, transport, or communications.

β€œWe cannot build our resilience around the assumption that every attacker will be stopped at the door,” he said. β€œOperators of essential services need to know exactly how they keep functioning when systems are compromised, how quickly an attack can be contained and how they recover without allowing disruption to spread.”

The distributed energy system creates new risks

Martin Riley, Chief Technology Officer at Bridewell, said the small size of the facility is precisely why the incident deserves attention.

β€œThe reported attack on a UK gas-fired peaker plant should not be dismissed because the site was small. It should be studied because the site was small,” Riley said.

The UK’s energy system increasingly depends on smaller generators, renewable energy assets and battery storage systems. Many are unmanned and remotely operated.

Riley warned that capacity thresholds mean some smaller operators can fall outside formal cybersecurity regimes even as their collective importance to the energy system grows.

β€œIn an energy system that is deliberately becoming distributed, reliant on thousands of smaller, unmanned, remotely operated generators, secure by design and defence in depth cannot remain conference slideware.”

Neena Sharma, Cybersecurity Expert at Filigran, made a similar point, arguing that critical infrastructure risk is becoming increasingly distributed.

β€œCritical infrastructure risk isn’t concentrated at the β€˜crown jewel’ substations anymore, it’s distributed across hundreds of smaller, less-monitored assets that scale with the energy transition,” Sharma said.

Weak credentials remain a concern

The exact attack path used against the UK generator has not been disclosed.

However, Sai Molige, Senior Manager of Threat Hunting at Forescout, pointed to a familiar weakness seen in attacks against industrial environments.

β€œTwo countries and two sectors faced the same underlying condition: a controller is reachable from the internet and protected by weak, default, or unchanged credentials,” Molige said.

He argued that one of the continuing challenges for operators is translating broad security warnings into an accurate understanding of whether their own environments contain vulnerable or exposed technology.

Supply Chain Risk Adds Another Layer

The incident also comes as the UK looks to tighten security across energy supply chains, where dependence on individual suppliers and technologies can create additional risks.

Jamie Akhtar, CEO and Co-founder of CyberSmart, said supply chain risk is not simply about whether an individual supplier can be compromised.

β€œIf one vendor, country or narrow group of manufacturers underpins equipment that operators cannot quickly replace, that dependency can become a national-security issue,” Akhtar said.

This can be particularly difficult in operational technology environments, where equipment may remain in use for decades and replacing it can require complex integration work.

Akhtar said operators need to consider whether a supplier creates an unacceptable security exposure, whether it can realistically be replaced and whether removing it could create a greater short-term risk to operations.

β€œThe strategic aim should be resilience, not a compliance exercise or a change of logo on the equipment,” he added. β€œOperators need enough diversity, control and recovery capability to keep essential services running if a supplier is compromised, unavailable or deemed too risky to trust.”

Resilience becomes the priority

The incident comes as the UK looks to strengthen cyber resilience across its energy sector and address risks within increasingly complex supply chains.

For Patel, the central lesson is that organizations cannot judge resilience solely by whether an attacker successfully gains access.

β€œThe real measure of cyber resilience is no longer simply whether you can prevent an intrusion,” he said. β€œIt’s whether you can contain one quickly enough that a cyber incident doesn’t become an operational crisis.”

With the wider grid unaffected, the July incident was limited in impact, but the disruption provides a timely warning that smaller assets can still present attractive targets and that cyber resilience needs to extend beyond the largest operators in the UK’s energy infrastructure.

The post Iran-Linked Hackers Blamed for UK Energy Cyberattack appeared first on IT Security Guru.

The Hidden Risk in Data Transfer

19 August 2026 at 11:13

Cybersecurity has become one of the most defining business challenges of recent times. Organisations have invested heavily in protecting their networks, securing cloud environments and strengthening identity and access management. At the same time, organisations are under increasing pressure to prove they are handling sensitive information securely, not just storing it safely but protecting it throughout its journey.

Yet despite this progress, one area continues to receive far less attention than it deserves: how data is shared.

Most organisations have become very good at protecting data while it is stored. Files are encrypted, key handling is properly managed, access is restricted and systems are monitored around the clock. However, once that information needs to leave the organisation, whether it’s being sent to a customer, supplier, auditor or business partner, the controls often become less robust.

Every day, organisations exchange contracts, financial information, employee records, legal documents and commercially sensitive files. More often than not, this happens via email attachments or cloud-based file-sharing services because they are familiar and convenient. The problem is that convenience does not always equal security.

Email remains one of the most common routes for cyber attacks. Phishing, spoofed domains, malicious attachments and business email compromise continue to account for a significant proportion of successful breaches. However, most incidents do not involve a sophisticated bad actor. The official UK annual Cyber Security Breaches Survey continues to show the majority of incidents stem from everyday mistakes.Β  An email sent to the wrong recipient, an attachment forwarded outside the organisation or a file shared with overly broad permissions can expose sensitive information in seconds.

Human error remains one of the biggest cyber risks organisations face, particularly as businesses become increasingly connected. Information now flows constantly between employees, customers, suppliers, consultants and regulators. Every transfer creates another opportunity for something to go wrong.

What is often overlooked is that securing data is not just about protecting where it is stored. It is also about understanding the journey it takes.

Many organisations assume that because they operate in the UK, their sensitive information remains within UK borders. In reality, emails and attachments may be routed through multiple countries and cloud infrastructures before arriving at their destination. While this is often an invisible part of modern digital communications, it raises important questions around governance, compliance and data sovereignty.

For organisations operating in regulated sectors, this matters. Financial services firms, local authorities, healthcare providers and legal organisations are increasingly expected to demonstrate not only that data is protected, but also that it is managed responsibly throughout its entire lifecycle. Knowing where information is stored is only part of the picture. Understanding where it travels, who has access to it and how it is controlled has become equally important.

This is why conversations around geofencing and data sovereignty are gaining momentum. Rather than simply encrypting information and hoping for the best, organisations are beginning to ask whether they should have greater control over where sensitive data is permitted to travel. If businesses routinely place restrictions on the movement of physical assets, it seems only logical that they should apply similar thinking to digital information.

At the same time, regulators and auditors are asking more searching questions about how organisations exchange information with third parties. They want to understand how access is controlled, whether there is a complete audit trail and what safeguards exist once information leaves the organisation. These are no longer technical questions reserved for IT teams. They are governance issues that increasingly involve compliance, procurement, risk and senior leadership.

There is also a growing disconnect between the way organisations work and the security controls they have in place. Hybrid working, cloud collaboration and increasingly complex supply chains mean information rarely stays within a single organisation. Yet many businesses continue to rely on processes that were designed for a very different way of working.

This is where a change in mindset is needed.

Cybersecurity should not end when a document is saved securely on a server or in the cloud. Information is often at its most vulnerable when it is moving between people, organisations and systems. Protecting data in transit should therefore be considered just as important as protecting data at rest.

That does not mean making it harder for employees to do their jobs. Quite the opposite. Security should support the way people work, allowing information to be shared safely without creating unnecessary barriers or encouraging workarounds that introduce even greater risk.

Organisations need to take a more holistic view of information security. Protecting sensitive data means understanding its entire lifecycle, from creation and storage through to sharing, collaboration and eventual deletion. It means knowing not only who can access information, but where that information is travelling and whether that journey aligns with the organisation’s security, compliance and governance obligations.

Threats aren’t standing still, and neither are regulators. Focusing only on data that’s sitting in storage means missing one of the biggest holes in your security. It’s not enough to just lock data away; it needs to stay safe wherever it travels.

*DOQEX provides a secure data exchange and email gateway platform that helps businesses protect confidential information.

Β 

The post The Hidden Risk in Data Transfer appeared first on IT Security Guru.

Education Now the World’s Most-Attacked Sector as Cybercriminals Gear Up for Back-to-School

19 August 2026 at 09:48

Education has overtaken every other industry to become the most targeted sector for cyberattacks worldwide, according to new research from Check Point, with threat actors ramping up activity in the run-up to the new academic year.

Between January and July 2026, schools, colleges, universities and research institutes faced an average of 4,696 weekly cyberattacks per organisation, an 8% rise on the same period in 2025 and more than double the cross-industry average of 2,150 weekly attacks. Education topped all 23 industries tracked by Check Point, recording attack volumes roughly 70% higher than government, the next most-targeted sector. In July alone, weekly attacks against education organisations climbed to 4,848, up 14% year-on-year, as the new term approached.

Regional picture: Europe among the fastest-growing hotspots

APAC recorded the highest overall volume, with organisations facing an average of 7,452 weekly attacks between January and July. But Europe and Latin America saw the sharpest year-on-year growth, up 18% (to 4,759 weekly attacks) and 42% (to 4,299 weekly attacks) respectively, a trend researchers link to the sector’s growing reliance on cloud platforms, digital learning tools and online collaboration systems that widen the potential attack surface. A successful breach, they note, can ripple out beyond the institution itself to affect students, parents, research partners, government bodies and third-party suppliers connected to the education ecosystem.

Attackers building dedicated β€˜back-to-school’ infrastructure

To track how threat actors prepare for the academic calendar, Check Point Research monitored newly registered domains containing education-related terms such as β€œschool”, β€œuniversity”, β€œcollege” and β€œstudent”. In July 2026 alone, researchers identified 18,954 newly registered education-themed domains, up 5% month-on-month and 3% year-on-year.

More striking is the rise in malicious activity among those registrations. Check Point ThreatCloud data shows that in June 2026, one in every 305 newly registered education-related domains was flagged as malicious; by July, that ratio had worsened to one in every 226. Examples uncovered include deceptive domains such as education-gov[.]com, students-portal[.]com, and checkmyschool[.]org, built to mimic legitimate education and government institutions. Researchers also identified coordinated registration campaigns, including a set of ten student loan-themed domains following a studentloansYYYY.com pattern spanning 2026 to 2035, and a network of 48 bootcamp-student domains, evidence, the researchers say, of large-scale, automated registration activity aimed squarely at students and prospective learners.

Phishing campaigns target students and staff directly

Beyond domain registration, researchers documented active campaigns exploiting the seasonal surge in online activity from students, parents and institutions. One scheme used the domain studentdiscount[.]online to impersonate a major US retail chain’s student rewards promotion, dangling a fake $750 reward before redirecting victims to fraudulent offers and gambling-related content.

Researchers also uncovered malicious PDF campaigns impersonating specific schools, routing victims through multiple compromised websites before landing on counterfeit Microsoft 365 and OneDrive login pages designed to harvest credentials. A separate case involved a malicious URL hosted on a compromised school website in Bangladesh, flagged by multiple threat intelligence sources as an information-stealer and malware distribution point; the page had previously displayed a fake Spotify-branded CAPTCHA, a technique often used to deliver malware or dodge automated security analysis.

Taken together, the findings point to a consistent tactic: abusing trusted brands, compromised legitimate websites and familiar academic workflows to make phishing lures more convincing and credential theft more effective.

What institutions should do before term starts

The back-to-school period is a prime opportunity for attackers, thanks to the spike in digital activity that comes with new student onboarding, document sharing, financial transactions and higher email volumes. Researchers recommend institutions act now, ahead of the return, to:

  • Train staff and students to recognise phishing emails, fake reward offers and suspicious login pages
  • Verify website addresses carefully before entering credentials or personal information
  • Enable multi-factor authentication (MFA) on Microsoft 365, email and academic systems
  • Regularly update and patch devices, learning platforms and administrative systems
  • Monitor newly registered domains for education-themed impersonation attempts
  • Review access permissions and secure sensitive student, research and administrative data

As cybercriminals continue to align their campaigns with the academic calendar, researchers say cybersecurity needs to become a core part of back-to-school preparedness and not an afterthought once term is already underway. The data suggests attackers are targeting not just schools and universities, but the wider ecosystem of students, families, and partners that surrounds them.

The post Education Now the World’s Most-Attacked Sector as Cybercriminals Gear Up for Back-to-School appeared first on IT Security Guru.

Black Hat Rewind: Most Creative Booths Part 1

By: Stevin
19 August 2026 at 10:12

Exhibitor booths are a major part of the Black Hat experience, giving companies a chance to bring their technology to life and make a lasting impression. This year, some took...

The post Black Hat Rewind: Most Creative Booths Part 1 appeared first on Cyber Defense Magazine.

❌
❌