Fake misconduct complaints are the new phishing lure targeting universities
Picture getting an email that looks like it's from your university president, accusing you of a Title IX violation. That's exactly the trap researchers at Cofense have been tracking — a phishing campaign that weaponizes sexual misconduct allegations to scare university staff and students into installing malware, and it's working well enough to slip past modern email security tools.
The emails spoof real university letterheads and forge the signatures of campus leaders, including ones impersonating figures at Notre Dame, the University of Virginia, and the Medical College of Wisconsin. There's no sketchy attachment to trip up filters — instead, the message links to a Google Drive file, which in turn links to an installer for a modified version of Zoho Assist, a legitimate remote-access tool Cofense is calling "Zoho RAT." Victims are walked through installing it themselves, believing they're cooperating with an internal investigation. Once it's running, attackers can view and control the screen, pull files, and push down additional payloads, including ransomware.
The targeting isn't random: over 80% of identified victims are healthcare-linked universities and teaching hospitals, part of a sector the government classifies as critical infrastructure. Combine that with a template simple enough to bypass current cloud email security controls, and you've got a campaign built for scale. Read on for our full breakdown of the attack chain and what your security team should be watching for.
https://hackread.com/fake-sexual-misconduct-emails-universities-zoho-rat/Did someone forward you this? Subscribe to this newsletter.
In other cybersecurity stories this week:
BlueMoon, a shared Chrome and Windows exploit kit, shows why “patch later” is becoming a dangerous gamble. Security updates are easy to put off. The browser still opens, Windows still works, and choosing to relaunch your browser or restart your computer later can feel harmless. But a newly documented exploit kit called “BlueMoon” shows how quickly patching delays can become dangerous. Proofpoint Researchers found four espionage groups using the same exploit chain against Chrome browsers running on Windows within days of one another.
https://www.malwarebytes.com/blog/bugs/2026/09/bluemoon-exploit-kit-turns-chrome-and-windows-flaws-into-attacks
A cyberattack reportedly linked to Iran forced a small UK electricity generator offline for four days in July, according to reporting first published by The Telegraph. The UK Government has not publicly attributed the attack to Iran, but Energy Minister Michael Shanks confirmed that a cyber incident had affected a small-scale generator and said there had been no threat to the wider electricity grid and no loss of power to customers. Reuters later reported that energy company chiefs had been briefed on steps to protect their assets following the incident. https://www.techerati.com/news-hub/uk-energy-cyberattack-raises-fresh-critical-infrastructure-concerns/
Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender. The researcher named the exploit ShieldCrash, it triggers an arbitrary file read as SYSTEM. The researcher claims that Microsoft has not fully fixed the ShieldBreak vulnerability CVE-2026-69414). According to the researcher, Microsoft closed several ways to exploit the flaw but missed a specific condition that still allows the same attack.
Chaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-Day
The researcher Chaotic Eclipse released ShieldCrash, a PoC exploit for a Microsoft Defender Zero-Day vulnerability.
Revolut, the London, United Kingdom-based global digital banking and financial technology platform, provided sensitive customer information to an unauthorized third party after being tricked by fraudulent requests sent through the legitimate email domain of a government agency. The incident did not involve attackers breaching Revolut’s systems. Instead, the fraudulent requests came from an unauthorized email account using the government agency’s official domain and carried valid domain authentication credentials.
https://hackread.com/revolut-gave-customer-data-to-scammers-fake-requests/
A cybersecurity working group at the G7 is urging governments to accelerate defenses against quantum computers that could break some existing forms of public key encryption. The working group’s report, prepared in June at the G7 Summit in France, said organizations “can no longer afford to postpone” work transitioning critical systems and data to “post-quantum” forms of encryption.
https://cyberscoop.com/g7-quantum-computing-encryption-warning/
A large-scale and sophisticated voice-phishing (vishing) campaign is actively targeting employees at some of the world's largest financial institutions. The targets include private-equity giants Blackstone and KKR, hedge funds like Citadel and Point72, and the exchange operator CME Group. The financially motivated threat actor, tracked as UNC6671 (also known as BlackFile and now rebranding as Redact), is using AI-powered voice cloning technology to impersonate corporate IT helpdesk personnel. The attackers socially engineer employees, directing them to adversary-in-the-middle (AitM) phishing sites designed to steal Microsoft 365 and Okta credentials, including real-time MFA tokens. The campaign's success in targeting high-value financial firms underscores the increasing effectiveness of AI-enhanced social engineering attacks.
https://cyber.netsecops.io/articles/wall-street-giants-targeted-in-ai-voice-phishing-campaign
MIT tested what happens when AI explains its reasoning to you. The explanation turned out to be dangerous. When the AI was right, the explanation helped people land on the right answer. When it was wrong, that same explanation walked them straight into the wrong one, and they felt surer about it than the people who saw no explanation at all. Confident wrong answers, delivered well can result in us making wrong decision in health, wealth and business.
Divergent impacts of explainable AI for dermatological diagnosis on clinicians versus lay people | Nature Medicine
Explainable AI, implemented for large language models that assist with dermatological diagnoses, has differing effects depending on whether the assistance is provided to primary care physicians or to lay users.
StyleSmuggler (CVE-2026-75650) is a vulnerability in affected releases of Magento Open Source and Adobe Commerce, two closely related platforms for running online shops. Sansec reported that attackers could execute code on a shop’s server without logging in. This is remote code execution (RCE): the server runs instructions chosen by someone outside the application’s trusted users.
https://fortbridge.co.uk/research/stylesmuggler-magento-unauthenticated-rce
Microsoft has disclosed two active attack campaigns that should concern any organisation running Microsoft 365 or using passkeys for account protection. The first involves attackers using passkey-themed social engineering to breach Microsoft cloud accounts and exfiltrate data, exploiting the enrolment and recovery steps around passkey authentication rather than the cryptography itself. The second involved sending over a million financial fraud emails between 3 and 5 August 2026, with attackers masquerading as chief executive officers and routing the messages through abused third-party email delivery infrastructure to slip past sender reputation checks.
https://softnet.com.my/insights.html#post-2026-09-14-002
Continuous Analysis Report of Settra Ransomware Group
https://theravenfile.com/2026/09/14/settra-ransomware/
Hilltop National Bank, based in Casper, Wyoming, closed all offices and internal systems after detecting a cybersecurity incident that disrupted online, mobile, phone, and scheduled payment services. The bank isolated its network, notified regulators, and said it would reimburse fees and charges caused by the incident.
https://www.hendryadrian.com/hilltop-national-bank-shuts-wyoming-branches-after-cybersecurity-incident/
“Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, was sentenced today to four years in prison for conspiracy to commit wire fraud in connection with a conspiracy to deploy Conti, a ransomware variant that infected the computers of more than 1,000 victims worldwide.” reads the announcement by DoJ. “According to court documents, Lytvynenko, formerly of Cork, Ireland, conspired with others to deploy Conti ransomware to extort victims and steal their data. From 2020 until 2022, Conti was used to attack computers and networks in 47 states, 31 foreign countries, the District of Columbia, and Puerto Rico. The FBI estimates that, as of January 2022, there had been victim payouts associated with Conti ransomware exceeding $150,000,000.”
https://securityaffairs.com/198931/cyber-crime/conti-hacker-who-built-malware-and-attacked-victims-gets-four-year-sentence.html
GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository commits API. CVE-2026-85706 affects GitLab’s repository commits API and can let attackers access files they should not see. A crafted request may expose SSH keys, database credentials, deploy tokens, CI/CD variables, and other sensitive configuration data. By September 11, active probing and exploitation attempts were already underway. CISA has since added the flaw to its Known Exploited Vulnerabilities catalog.
https://securityaffairs.com/198945/hacking/gitlab-cve-2026-85706-one-http-request-no-authentication-full-file-read-exploited-within-24-hours.html
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API keys.
https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html
The diagnostic imaging service provider Lumexa Imaging has been affected by a security incident involving one of its vendors. FMRS Health Systems, a West Virginia-based provider of mental health services, is investigating a January 2026 data breach.
https://www.hipaajournal.com/data-breaches-lumexa-imaging-fmrs-health-systems/
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent’s Sogou Input Method for Windows to deploy the GrayRabbit backdoor. Researchers at cybersecurity company Gen Digital warn that the security issue is a one-click remote code execution (RCE) flaw. "We observed this vulnerability actively exploited in the wild by the UNC3569 threat group to deploy the GRAYRABBIT backdoor through a crafted link," Gen Threat Labs says. https://www.bleepingcomputer.com/news/security/hackers-exploit-tencent-app-flaw-to-deploy-grayrabbit-malware/
In the Linux kernel, the following vulnerability has been resolved: NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock nfsd4_ssc_expire_umount() walks nn->nfsd_ssc_mount_list with list_for_each_entry_safe(ni, tmp, ...). For each expired entry it sets nsui_busy = true, drops nfsd_ssc_lock to run mntput() on the source vfsmount, then reacquires the lock to list_del + kfree the entry and continue iterating via the macro's saved tmp pointer. The nsui_busy flag protects the current ni from concurrent nfsd4_ssc_setup_dul() finders during the lock-drop window, but it does not pin tmp.
https://www.thehackerwire.com/vulnerability/CVE-2026-89712/
Acronis fixed a high-severity Acronis cPanel plugin vulnerability in its Backup plugin for cPanel and WHM. Attackers are already exploiting it in the wild. All users should update to a fixed build right away.
https://securityonline.info/acronis-cpanel-plugin-vulnerability-exploited
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. BlueMoon combines two security issues in Chromium-based browsers that allow remote code execution and sandbox escape with a kernel local privilege escalation in Windows. The kit appears to be a shared modular tool that supports exploit additions and was used in distinct operations. https://www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/
The police believe that Dutch criminals were involved in the massive Odido hack in which the data of some 6.2 million people was stolen in February. Shortly before the hack, a Dutch-speaking man called Odido’s customer service. He posed as an Odido IT employee and phished his way into gaining access to the company’s systems, the police said on Thursday.
https://nltimes.nl/2026/07/09/voice-fake-employee-links-dutch-criminals-odido-hack
On 27 August 2026, Manchester Airports Group told customers that "an unauthorised third party" had stolen their data. Car park bookings, lounge bookings, Fast Track purchases for airport security and passport control, along with airport WiFi sign-ups across Manchester, Stansted and East Midlands. Roughly 8.8 million people.
https://scotthelme.co.uk/no-hacking-required-manchester-airports-group-data-breach/
ID verification service IDScan has confirmed that a data breach involved the theft of driver’s licenses from its systems, a week after a report said the identity document checker had been breached during a year-long hack. The company said in a website notice that hackers stole the driver’s licenses from the company’s cloud; the stolen information includes people’s full names and driver’s license numbers, along with identity numbers from other government-issued documents, such as passports. https://techcrunch.com/2026/09/10/id-verification-giant-idscan-confirms-data-breach-with-more-than-150-million-drivers-licenses-stolen/