Ethical Hackers Cracked the Universities Cyber Defenses Within Two Hours

A test carried out by ethical hackers against the cyber defenses of 50 universities found that they can cripple the defense and exfiltrate sensitive data within two hours.

The penetration testing conducted ethical hackers” working for Jisc, who provides internet services for universities in the UK. They stimulated attack on universities and them able to access the personal data, finance systems, and research networks.

They are able to reach student and staff personal information, override financial systems and access research databases within two hours and in some cases within an hour.

In the test attack, they used the spear-phishing technique to drop malware into their system through a phishing email.

John Chapman, head of Jisc’s security operations center told that “we are not confident that all UK universities are equipped with adequate cyber-security knowledge, skills and investment”, told BBC.

Universities and colleges are among the risk group that is mostly affected by the frequent cyber attacks, the attackers may be members of the university staff or students.

The universities and colleges hold a lot of information regarding intellectual property and various researches which may be interesting from the commercial point of view.

Cyber attacks are done for different reasons and in the end, there are different benefits.

UK universities and research centers reported more than 1,000 attempts last year to steal data or disrupt services.

The attacks on universities are often linked to the academic calendar of the educational institutions so that their consequences can bring real damage.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under limited,…

2 hours ago

BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely

A critical vulnerability in BigAntSoft's enterprise chat server software has exposed ~50 internet-facing systems to…

2 hours ago

Bubba AI, Inc. is Launching Comp AI to Help 100,000 Startups Get SOC 2 Compliant by 2032.

With the growing importance of security compliance for startups, more companies are seeking to achieve…

4 hours ago

IBM Storage Virtualize Flaws Allow Remote Code Execution

Two critical security flaws in IBM Storage Virtualize products could enable attackers to bypass authentication…

5 hours ago

Progress WhatsUp Gold Path Traversal Vulnerability Exposes Systems to Remote code Execution

A newly disclosed path traversal vulnerability (CVE-2024-4885) in Progress Software’s WhatsUp Gold network monitoring solution…

5 hours ago

CISA Alerts on Active Exploitation of Cisco Small Business Router Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent warning on March 3,…

6 hours ago