Schools on both sides of the Atlantic have been revealed in recent days to have been hit by hackers, reminding all of us that ransomware gangs see educational instituions as targets all year round. Read more in my article on the Hot for Sec

Educational institutions continue to be a prime target for cybercriminals, with recent incidents in the United States and the United Kingdom highlighting the vulnerability of schools. These organizations often possess valuable data and operate with limited cybersecurity resources, making them attractive to malicious actors.
Evanston Township High School (ETHS) in Illinois was forced to close its campus for two days in early June 2026 due to a ransomware attack. The incident disrupted not only computer systems, internet, and phone lines but also critical building safety systems, including door access controls and public address systems. The school stated that these systems were essential for safe operations, necessitating the cancellation of classes, sports camps, and other activities. ETHS has reported the incident to the FBI, secured staff accounts, and engaged external cybersecurity experts to assist in system recovery. Employees have been advised to refrain from using their computers until cleared by IT and to avoid reusing old passwords. The attack also impacted the Home Access Center, a student portal powered by PowerSchool, though it is not believed to be connected to a previous PowerSchool breach in 2024. No ransomware group has claimed responsibility, and it is currently unknown if any personal data was compromised. The school anticipated reopening on June 10, 2026, after emergency systems were restored.
Shortly before the ETHS incident, Powys County Council in Wales disclosed that 13 of its schools had been targeted by hackers. This attack, identified in April but publicly announced two months later, did not lead to school closures. However, personal data belonging to pupils and staff at at least one school was accessed. The council has not named the affected schools due to the sensitive nature of the data and is directly contacting individuals to provide advice on protection measures.
Schools are considered attractive targets for several reasons. They hold sensitive information concerning children, and their cybersecurity budgets are often constrained, leaving them with insufficient defenses. Furthermore, as demonstrated by the ETHS case, many schools rely on networked systems for essential functions ranging from educational platforms to physical security. The education sector also faces internal threats, with reports indicating that pupils themselves can pose a risk by unlawfully accessing computer systems with malicious intent. Given these vulnerabilities, there is a recognized need for increased funding and expertise to bolster the cybersecurity posture of educational institutions.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed