Skip to content
Signals
NVD · CVE-2026-18907 · Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filenameNVD · CVE-2026-18897 · 8.8 · A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempENVD · CVE-2026-18896 · 6.3 · A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.phNVD · CVE-2026-18895 · 8.8 · A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulCISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07CISA KEV · CVE-2026-34486 · 7.5 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-18907 · Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filenameNVD · CVE-2026-18897 · 8.8 · A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempENVD · CVE-2026-18896 · 6.3 · A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.phNVD · CVE-2026-18895 · 8.8 · A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulCISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07CISA KEV · CVE-2026-34486 · 7.5 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability · Added 2026-08-04 · Due 2026-08-07
← Campaigns
DormantTLP:GREENConfidence: Medium

Operation EduLock

First seen March 1, 2026 · Last seen May 10, 2026

Public preview

Summary and targeting visible. Pro adds TTP and actor context, Pro+ adds IOC exports and enrichment.

Plans →

Summary

Ransomware campaign specifically targeting educational institutions during enrollment and exam periods. Exploits weak remote access configurations.

Target Sectors

Education

Target Regions

Western EuropeNorth America

Safety Note

Fictional campaign targeting education sector. No real institution names or ransom details included.

MITRE ATT&CK Techniques

T1486Data Encrypted for Impact

Impact

Maintain offline backups. Monitor for mass file modification events. Restrict execution of unknown binaries. Implement endpoint detection for encryption behavior.

T1133External Remote Services

Initial Access

Enforce MFA on all remote access. Restrict VPN/RDP to allowlisted networks where possible. Monitor remote access logs for anomalies. Patch remote access infrastructure promptly.

T1059.001PowerShell

Execution

Enable PowerShell logging (ScriptBlock, Module, Transcription). Restrict PowerShell execution policy. Deploy AMSI-aware endpoint protection. Monitor for encoded command execution.