CVE-2026-2247: HIGH-severity SQL injection in Clickedu SaaS (all versions). Attackers can exploit 'id_alu' in report card URLs to access sensitive data. Persistent session tokens increase risk. Prioritize mitigation! https://radar.offseq.com/threat/cve-2026-2247-cwe-89-improper-neutralization-of-sp-b8f5f03e #OffSeq #SQLi #InfoSec #EduSec
The Case for Making EdTech Companies Liable Under FERPA | TechPolicy.Press

Congress should amend FERPA to hold EdTech vendors, rather than the schools, directly responsible for vendor compliance, Lavanya Sathyamurthy writes.

Tech Policy Press

"Manassas City Public Schools (MCPS) are closed on Monday due to a cybersecurity incident that has led to connectivity disruptions and phone outages across the school system, officials said.

Dr. Kevin Newman, MCPS superintendent, said in a post on Facebook on Sunday that all MCPS schools will be closed on Monday, November 10, as a precautionary measure to ensure the safety and security of students, teachers, and staff. The school campuses are not at risk, he said."

https://wjla.com/news/local/virginia-prince-william-county-manassas-city-public-schools-close-on-monday-due-to-cyberattack-cyber-security-hack-hackers-threat-kevin-newman-mcps

@douglevin @funnymonkey @mkeierleber

#EduSec #cybersecurity #databreach

Manassas City Public Schools close on Monday due to cyberattack

Manassas City Public Schools are closed on Monday due to a cybersecurity incident that has led to connectivity disruptions and phone outages across the system.

WJLA
Breaking Up With Edtech Is Hard to Do

Shedding old edtech is a real pain, district experts say. Worse, student privacy may be at risk.

EdSurge

Entities rush to declare that data hasn't been stolen/they haven't been hacked. They often wind up looking like liars or just more incompetent when the hacker starts dumping or leaking data as proof.

This week's example: U. of Pennsylvania, which quickly declared they hadn't been hacked and it was just a vulgar email sent out. The hacker seems to have proved otherwise.

https://www.bleepingcomputer.com/news/security/university-of-pennsylvania-hacker-claims-1.2-million-donor-data-breach/

#EduSec #databreach #cybersecurity #UPenn

Penn hacker claims to have stolen 1.2 million donor records in data breach

A hacker has taken responsibility for last week's University of Pennsylvania "We got hacked" email incident, saying it was a far more extensive breach that exposed data on 1.2 million donors and internal documents.

BleepingComputer

Two years after an audit highlighted significant concerns, the North Salem Central School District in New York is still leaving sensitive student data at risk.

When I read audits and follow-ups like these, I wonder whether the parents of the students in the district are aware of these reports at all. Maybe local #PTAs should be forwarding copies of these reports to parents and asking the district why more hasn't been done to implement recommendations made years ago.

https://www.osc.ny.gov/local-government/audits/school-district/2025/09/26/north-salem-central-school-district-audit-follow-2022m-140-f

And yes, some of you will remind me to have empathy for school districts and understaffed IT personnel. But if we don't want to see any Kido Schools breach here, we'd better start demanding more security and tolerating fewer explanations for inadequate security of student data.

@douglevin @funnymonkey @mkeierleber

#edusec #infosecurity

Earlier today, Matthew Lane, the 19-year old from Massachusetts who confessed to hacking a telecom and #PowerSchool, was sentenced to 4 years in prison, 3 years supervised release after that, $14M in restitution, and forfeiture of $160k.

#EduSec #cybersecurity #ShinyHunters #G0retrance #databreach

NEW by me:

In a few days, the PowerSchool hacker will learn his sentence, and his life as he has known it will end.

Was he a kid who could have been a "white hat" with just a little encouragement? Are we missing opportunities with some kids?

https://databreaches.net/2025/10/11/in-a-few-days-the-powerschool-hacker-will-learn-his-sentence-and-his-life-as-he-has-known-it-will-end/

#databreach #EduSec

@douglevin @funnymonkey @brett

In a few days, the PowerSchool hacker will learn his sentence, and his life as he has known it will end. – DataBreaches.Net

In November 2021, when "g0retrance" defaced the website of the Massachusetts Interscholastic Athletic Association (MIAA) with a message saying "PWNED," the hack

DataBreaches.Net
PowerSchool hit by Salesloft Drift campaign, but hackers claim that there is no risk of harm or ransom – DataBreaches.Net

As noted on Reddit , PowerSchool appears to have been one of many victims of the Salesloft Drift/Salesforce campaign by Scattered LAPSUS$ Hunters. Like many oth

DataBreaches.Net