The education sector faces escalating cybersecurity threats, with 1,252 data breaches recorded in 2025 according to Verizon's DBIR, over 65% involving ransomware. Third-party SaaS platforms are a primary attack vector — a single breach can cascade across thousands of institutions. High-profile incidents include a ransomware attack on Canvas (Instructure) affecting 30 million users during final exams, and the 2023 MOVEit breach impacting 900 universities. Schools are particularly vulnerable due to legacy systems, limited IT budgets, and heavy reliance on third-party vendors. Recommended mitigations include formal third-party risk management programs, contractual vendor accountability, SSO with MFA, vulnerability management, and business continuity planning. AI-powered security tools may help reduce costs for under-resourced institutions. Experts also call for increased federal cybersecurity funding and a comprehensive U.S. federal privacy law.
Nguồn: https://www.darkreading.com/cyber-risk/third-party-breaches-teaches-education-lesson-vendor-risk. 8sync News chỉ tóm tắt và dẫn link; bản quyền nội dung thuộc tác giả và nguồn gốc.
LastPass xác nhận dữ liệu khách hàng trong môi trường Salesforce bị truy cập sau cuộc tấn công chuỗi cung ứng nhằm vào Klue hôm 12/6. Nhóm tống tiền Icarus đã xâm nhập hạ tầng Klue bằng thông tin đăng nhập cũ, đánh cắp token OAuth kết nối Klue với Salesforce của khách hàng. Dữ liệu bị lộ bao gồm tên, số điện thoại, email, địa chỉ, thông tin hỗ trợ và dữ liệu CRM. LastPass cho biết sản phẩm cốt lõi, dịch vụ và kho dữ liệu khách hàng không bị ảnh hưởng.
Lập trình viên nên đọc bài này để hiểu rõ về cách tấn công supply chain attack hoạt động như thế nào, từ đó nâng cao kiến thức bảo mật cho các ứng dụng và hệ thống của mình, đặc biệt là khi sử dụng các dịch vụ cloud như Salesforce.
France's national statistics agency INSEE suffered a cyberattack exposing personal data of approximately 12,800 current and former staff. The breach, detected on June 19, compromised an internal staff directory (trombi.insee.fr) containing names, identity details, and professional contact information. Critically, passwords, bank details, social-security numbers, and public census data were not affected. A user under the alias 'Saturne' posted the database on a cybercriminal forum. The incident is part of a broader pattern of French government cyberattacks in 2026, with analysts citing chronic underinvestment in cybersecurity and social-engineering vulnerabilities. While the stolen data is low-value in isolation, it can serve as raw material for targeted phishing campaigns against staff.
Huntress discloses it was among multiple victims of a supply chain attack targeting Klue, a market intelligence platform. The threat actor, dubbed Icarus, compromised Klue's backend systems on June 11, 2026, injecting code to steal OAuth tokens used by Klue's customers to connect their CRM tools. This allowed the attacker to directly query and exfiltrate Salesforce data from Huntress and other companies including Recorded Future, Tanium, and Jamf. The stolen Huntress data includes business contact info, pricing, subscription details, and sales communications — no product telemetry, passwords, or payment data was affected. Huntress shares IOCs (IP addresses, User-Agent strings), threat actor attribution details linking to the Icarus extortion group, and five recommended investigation steps for other potentially impacted organizations. The post is being updated in real time as the situation evolves, with a secondary unauthorized party also claiming access to breach data as of June 24.
Klue, the market intelligence firm whose breach exposed customer data at LastPass, HackerOne, and others, says the original hacking group Icarus is now deleting the stolen data. However, a second unnamed hacker group claims to have obtained the data from Icarus and is extorting affected companies directly, demanding payment or threatening to leak everything. Icarus reportedly told Klue the second group only has data samples for a subset of customers, not the full dataset, and instructed Klue to tell customers not to pay the second group. The breach stemmed from a compromised third-party credential from 2022 that was never revoked, granting OAuth access to customers' Salesforce environments. Over a dozen companies including Gong, Jamf, HackerOne, and LastPass have confirmed they were affected.
Russian hackers were behind the 2025 cyberattack on Jaguar Land Rover that halted factory production for nearly six weeks and cost the UK economy an estimated $2.5 billion, according to a New York Times investigation. The breach began with a vishing campaign in which attackers impersonated internal staff to steal employee credentials, then moved laterally through JLR's IT networks. Over 5,000 supply chain organizations were affected, and the UK government issued an unprecedented £1.5 billion emergency loan. Investigators also discovered a separate, unrelated Jordanian hacker had independently breached JLR's infrastructure simultaneously. Attribution was supported by Microsoft, the FBI, NCSC, Google Mandiant, and Palo Alto Networks. The attack is the most financially damaging cyberattack in UK history and comes amid a broader pattern of Russian-linked cyber operations targeting Western infrastructure.
Ransomware attacks in Europe surged 55% in the first four months of 2026 compared to the same period in 2025, with France seeing a 119% increase and Italy 92%. Researchers from Black Kite attribute the shift to US market oversaturation and AI-assisted target research pointing attackers toward European organizations. The number of active ransomware groups has grown from 60 in 2023 to 150 today, filling the vacuum left by law enforcement takedowns of major RaaS operations. Manufacturing and digital services sectors are primary targets, largely because attackers exploit supply chain leverage — breaching one vendor to access hundreds of downstream clients, as demonstrated by the Miljödata attack that exposed data from ~200 Swedish municipalities. Experts recommend organizations map fourth- and fifth-party vendor dependencies and rank vendors by risk proactively rather than reactively.
A New York Times report attributes last year's devastating cyberattack on Jaguar Land Rover to a Russian hacking group, though their exact relationship to the Kremlin remains unclear. The breach halted JLR production for months, cost the British economy an estimated $2.5 billion, and prompted a £1.5 billion UK government bailout. Microsoft identified the hackers and alerted JLR, while the FBI, UK's National Crime Agency, NCSC, Google's Mandiant, and Palo Alto Networks all participated in the investigation. Separately, a Jordanian hacker also independently breached some JLR networks during the same period.

A database of nearly one million passports was leaked online after being stored in an ID verification system used by cannabis dispensaries. The core issue highlighted is that a high-value credential (a passport) was entrusted to a low-value, ancillary authentication system, and when that weaker system was breached, the high-value credentials were exposed. This illustrates the risk of using sensitive identity documents in third-party systems with weaker security postures.