Threat Intelligence Suspected Chinese spies target universities with Roundcube exploit July 9, 2026 Share By SC Staff (Adobe Stock) As reported by The Register, suspected Chinese intelligence operatives have been actively compromising major universities in the United States and Canada since May, leveraging vulnerabilities in Roundcube mail servers to exfiltrate sensitive data from physics and engineering departments. The threat actor, tracked by Proofpoint as UNK_MassTraction, exploits CVE-2024-42009, a cross-site scripting vulnerability in Roundcube, to gain initial access. This vulnerability allows attackers to steal credentials, session tokens, and cookies once a user opens a specially crafted email in the webmail client. The attackers then use a deserialization exploit, CVE-2025-49113, to install a webshell called SquareShell and a VShell implant, enabling remote code execution. Proofpoint observed "less than 10" universities directly targeted, but estimates the total number could be in the dozens. The targeted departments, focusing on areas like astrophysics and particle physics, suggest intelligence-gathering motives aligned with Beijing's goals. The campaign's sophistication, including reconnaissance and the use of shared infrastructure with other China-aligned actors, indicates a moderately aware threat actor. The attack chain begins with generic phishing emails, potentially broadening the targeting scope beyond what Proofpoint has directly observed. Source: The Register SC Staff Related Threat Intelligence Suspected pro-Russia hacktivist arrested in Spain with FBI support SC Staff July 7, 2026 The arrest is a component of Operation Riptide, an international initiative focused on disrupting malicious cyber activity and holding perpetrators accountable. Threat Intelligence Iranian hackers use new modular C2 framework against Israeli organizations SC Staff July 6, 2026 The threat cluster, dubbed Cavern Manticore by Check Point Research, exhibits tactical similarities with known groups like MuddyWater and Lyceum. Threat Intelligence 7 arrested in Vietnam for operating large anime piracy site HiAnime SC Staff July 6, 2026 HiAnime, which operated under various domains including Zoro.to and Aniwatch, provided free access to a vast library of anime, attracting hundreds of millions of monthly visitors and briefly surpassing legal streaming platforms in web traffic. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Account Harvesting Backdoor DNS Spoofing Defacement Denial of Service Dictionary Attack Distributed Scans Domain Hijacking Information Warfare Reconnaissance You can skip this ad in 5 seconds