Morningstar 1 in 3 Higher Education Vendors Breached Since 2024, UpGuard Reports
Article Content
- •28% of top higher education vendors have had a data breach since 2024.
- •11% of vendors are currently infected with infostealer malware.
- •The complexity of vendor ecosystems is widening the cybersecurity visibility gap.
The 2026 Higher Education Third-Party Cyber Risk Report by UpGuard reveals that 28% of the top 100 vendors used by universities have experienced a data breach since 2024. Additionally, 11% of these vendors currently have active infostealer malware infections, which are a significant source of credential theft. The report highlights that the increasing complexity of vendor ecosystems, coupled with the rapid adoption of AI technologies, has created a growing 'visibility gap' in cybersecurity oversight within higher education. UpGuard analyzed 515 universities and identified over 105,000 vendor relationships, indicating a decentralized and difficult-to-govern ecosystem. The findings emphasize the urgent need for universities to reassess their vendor risk management strategies, especially during the quieter summer months. UpGuard will host a webinar on July 23 to provide actionable insights for managing these risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Education in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…