Third-Party Breaches Teach Education Sector a Costly Lesson in Vendor Risk
2026-06-27T14:51:43Z•8e7d361722b6a97be19b6f10e322e819f1e0dae7ee985b8ed48648fa84a2fda7
Cisco CUCMCisco SD‑WANCordycepsDifyTapEurope targetingFortiBleedFortiGateFortinetIcarusKlueOAuth token theftOpenClawSSRFSalesforceSocGholishcredential harvestingeducation/edtech attacks','cloud securitymacOS security gapmalicious packagesprivilege escalationransomwaresupply chainthird-party risktraffic distribution systems (TDS)vendor risk
What happened
A DarkReading roundup highlights accelerating active exploitation and supply‑chain attacks across sectors. Key trends: rapid weaponization of disclosed flaws (Cisco CUCM SSRF -> local root, SD‑WAN pre‑disclosure exploitation), large‑scale credential harvesting campaigns targeting FortiGate/Fortinet devices (FortiBleed/credential‑sniffing), and expanding third‑party/vendor risk that exposed Salesforce customers via compromised apps (Klue/Icarus). Developer and AI supply chains are under pressure from malicious packages and pull requests (Cordyceps, OpenClaw), while platform gaps (DifyTap chat‑‘
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 8e7d361722b6a97be19b6f10e322e819f1e0dae7ee985b8ed48648fa84a2fda7
- Enrichment time
- 2026-06-27T14:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.