Monthly Cyber Threat Intelligence for K-12 Schools and Districts

Monthly Cyber Threat Intelligence for K-12 Schools and Districts

New cyber threats are always emerging, and K-12 schools are becoming an increasingly popular target. Every new exploit and vulnerability risks downtime or worse – a cyber incident that leaks sensitive data, disrupts learning, or hampers day-to-day operations.

Awareness and action are key to keeping emerging threats from landing. Our monthly cyber threat intelligence report helps your district’s technology leaders:

  • Stay ahead of the curve on new exploits impacting operating systems, networking equipment, and more
  • Understand each threat’s severity and relevance to K-12 technology environments
  • Reduce risk by pro-actively addressing vulnerabilities

Each month, our vCISO program publishes a full report with detailed explanations of current areas of focus, as well as a brief that summarizes current threats:

Monthly Cyber Threat Report

A full report that compiles timely analysis of the current threat landscape.

Threat Landscape Summary

 

In August, we said the back-to-school window would be the difference between a normal opening week and a headline. September proved it. Between late August and mid-September, seven school systems in five states reported incidents.

The dominant technical theme continues from August: identity is the perimeter. The platforms districts depend on were just as exposed.

Two broader forces sit behind all of this. First, AI is accelerating the attacker’s side of the clock. Second, defenders have less outside help

 

Monthly Areas of Focus

 

  • PaperCut NG/MF Zero-Day (CVE-2026-81578 / CVE-2026-82078)

  • Ubiquiti UniFi – Three Maximum-Severity Flaws

  • Google Chrome Zero-Day (CVE-2026-85046)

  • BigBear and Passkey-Themed Phishing – MFA Bypass Against Microsoft 365

  • Mathspace Breach – EdTech Vendor Patch Gap

  • IDScan and Florida DMV Breaches – 150M+ Identity Documents Exposed

  • AI Crosses the “Critical” Line – Autonomous Exploit Discovery

  • AI Assistants and Browser Agents Become an Attack Surface

  • Avada WordPress Theme – Zero-Click RCE (CVE-2026-18431)

  • Microsoft 365 Authentication Outage – Cloud Dependency

  • Fake Installers and Malicious Browser Extensions

  • CISA Retires Free Assessments – Shrinking Federal Support

 

Read the full report →

 

Threat Landscape Summary

 

August’s activity kept circling back to one theme: attackers are getting in through stolen passwords and legitimate-looking prompts, not sophisticated new exploits, and the platforms and vendors districts depend on are just as exposed as the districts themselves

 

Monthly Areas of Focus

 

  • Critical macOS Screen Sharing Authentication Bypass — Active Exploitation (CVE-2026-65400) 4

  • MacSync Infostealer — Rotating C2 Domain Infrastructure Targeting State/Local Government 4

  • “WP2Shell” — Unauthenticated Remote Code Execution in WordPress Core (CVE-2026-63030 / CVE-2026-60137) 5

  • Over 24,000 Internet-Exposed Server BMCs Leak Password Hashes via a 22-Year-Old Flaw 5

  • SAP Commerce Cloud Critical RCE (CVE-2026-58231) — Exploited Days After Patch 6

  • Azure/Entra Credential Theft Campaign Exposes Millions of Fortune 500 Employee Records 6

  • ChainDrop — Self-Propagating npm Supply Chain Worm Infects 400+ Packages 7

  • New TrickBot Variant Uses DNS Tunneling for Command-and-Control

 

Read the full report →

 

Monthly Cyber Threat Brief

A summary of current threats, with actionable insights and recommendations.

Summary

 

The back-to-school risk warned about in August became real. Seven school systems in five states reported cyber incidents in roughly three weeks. Springfield Public Schools (MA) closed for four instructional days and later learned from the FBI that student and staff data had been stolen. Other districts ran on paper, lost internet for a week, or shut down every connected device, phones included. Three of the seven appeared on ransomware leak sites.

Identity is the perimeter: phishing platforms now defeat SMS, push, and one-time-code MFA in real time.

The platforms districts depend on were just as exposed, and AI is shortening the time between a flaw’s disclosure and its exploitation while federal support shrinks.

The fundamentals are not optional: phishing-resistant MFA, fast patching of actively exploited flaws, real vendor accountability, and continuity plans that work when the network does not.

 

Read the full full brief →

Summary

 

August’s activity centered on stolen credentials and legitimate-looking prompts rather than sophisticated new exploits — and the vendors and platforms districts depend on were as exposed as districts themselves.

A credential-theft campaign exposed 3.5–4.8 million employee records from Microsoft Entra ID tenants; macOS moved further into attackers’ sights via an authentication bypass and a 30+ domain ClickFix campaign; a new TrickBot variant hid its C2 traffic inside DNS queries; and supply-chain exposure grew through the ChainDrop npm worm (400+ packages) and an unauthenticated WordPress core RCE (“wp2shell”).

This lands during the back-to-school window — the same stretch that forced Newton County, GA, and Sumner County, TN, to delay or shut down schools after cyber incidents last year.

 

Read the full full brief →

Author

Will Brackett
Will Brackett
Director, vCISO Program, Learning Technology Center
View Profile →

Details

For Administrators, Technology Leaders/Support
Grade Levels All Grades (K-12)

Related Resources

See all Resources →

Keep Exploring