Suspected Chinese Threat Group Targets Universities via Vulnerable Roundcube Servers

2026-07-07T20:52:10Zd524a551c7daec10ceefbea5443fd7da7a678ca59c2ac7b96b9b746372df4d46
Adobe ColdFusionCISA SASE guidanceCisco Catalyst SD-WANEDR/MDM bypassJadePufferMillenium RATMiraiNCSC guidanceNetNutOracle PeopleSoftPureLog StealerQilinRoundcubeScattered SpiderSimpleHelpTinyRCTVeil#Dropagentic ransomwarehealthcaremacOS XPC flawphishingprompt injectionransomwaresupply-chainuniversities

What happened

A cluster of high-impact cyber activity and vulnerability exploitation was reported across multiple sectors. Threat actors—incl. suspected China-aligned groups and new Iran-linked and Russian clusters—are actively exploiting webmail (Roundcube), RMM (SimpleHelp), Oracle PeopleSoft zero-days, Adobe ColdFusion (CVSS 10.0), Cisco SD‑WAN, and other flaws to harvest credentials, deploy stealers/ransomware (TaskWeaver, Djinn, Qilin-linked activity) and persistent backdoors (TinyRCT). New trends noted include agentic AI ransomware (JadePuffer), abuse of proxies/botnets (NetNut/Popa/Mirai), prompt-inj

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
d524a551c7daec10ceefbea5443fd7da7a678ca59c2ac7b96b9b746372df4d46
Enrichment time
2026-07-07T20:52:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.