Suspected Chinese Threat Group Targets Universities via Vulnerable Roundcube Servers
2026-07-07T20:52:10Z•d524a551c7daec10ceefbea5443fd7da7a678ca59c2ac7b96b9b746372df4d46
Adobe ColdFusionCISA SASE guidanceCisco Catalyst SD-WANEDR/MDM bypassJadePufferMillenium RATMiraiNCSC guidanceNetNutOracle PeopleSoftPureLog StealerQilinRoundcubeScattered SpiderSimpleHelpTinyRCTVeil#Dropagentic ransomwarehealthcaremacOS XPC flawphishingprompt injectionransomwaresupply-chainuniversities
What happened
A cluster of high-impact cyber activity and vulnerability exploitation was reported across multiple sectors. Threat actors—incl. suspected China-aligned groups and new Iran-linked and Russian clusters—are actively exploiting webmail (Roundcube), RMM (SimpleHelp), Oracle PeopleSoft zero-days, Adobe ColdFusion (CVSS 10.0), Cisco SD‑WAN, and other flaws to harvest credentials, deploy stealers/ransomware (TaskWeaver, Djinn, Qilin-linked activity) and persistent backdoors (TinyRCT). New trends noted include agentic AI ransomware (JadePuffer), abuse of proxies/botnets (NetNut/Popa/Mirai), prompt-inj
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- d524a551c7daec10ceefbea5443fd7da7a678ca59c2ac7b96b9b746372df4d46
- Enrichment time
- 2026-07-07T20:52:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.