THREAT OPS › Threat News
Threat Intelligence News
12149 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- The Accidental C2: Exploring Dev Tunnels for Remote Accessspecterops · 2026-05-06
- How We Think about Red Teamingspecterops · 2026-05-06
- LABScon25 Replay | Please Connect to the Foreign Entity to Enhance Your User Experiencesentinelone · 2026-05-06
- [NVD] CVE-2026-6210 — A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. When processing SVG marker references, the renderer retrieves a node by its id attribute and casts it to QSvgMarker* without verifying the node type. A non-markernvd · 2026-05-06
- [NVD] CVE-2026-43216 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: net: Drop the lock in skb_may_tx_timestamp() skb_may_tx_timestamp() may acquire sock::sk_callback_lock. The lock must not be taken in IRQ context, only softirq is okay. A few drivers receive the timestamp via anvd · 2026-05-06
- [NVD] CVE-2026-43198 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done too late. After tcp_v4_syn_recv_sock(), the child socket is already visible fronvd · 2026-05-06
- [NVD] CVE-2026-43197 (CRITICAL 9.1) — In the Linux kernel, the following vulnerability has been resolved: netconsole: avoid OOB reads, msg is not nul-terminated msg passed to netconsole from the console subsystem is not guaranteed to be nul-terminated. Before recent commit 7eab73b18630 ("netconsole: convert to NBCOnvd · 2026-05-06
- [NVD] CVE-2026-43133 (HIGH 7.9) — In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation Commit cc3ed80ae69f ("KVM: nSVM: always use vmcb01 to for vmsave/vmload of guest state") made KVM always use vmcb01 for the fields controlled by VMSAVE/VMnvd · 2026-05-06
- [NVD] CVE-2026-43125 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: dlm: validate length in dlm_search_rsb_tree The len parameter in dlm_dump_rsb_name() is not validated and comes from network messages. When it exceeds DLM_RESNAME_MAXLEN, it can cause out-of-bounds write in dlmnvd · 2026-05-06
- [NVD] CVE-2026-6420 (MEDIUM 6.3) — A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hardcoded challenge nonce for Trusted Platform Module (TPM) quote attestation insteadnvd · 2026-05-06
- 2026-006: Critical Vulnerability in PAN-OScert_eu · 2026-05-06
- [NVD] CVE-2026-43116 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: ensure safe access to master conntrack Holding reference on the expectation is not sufficient, the master conntrack object can just go away, making exp->master invalid. To access exp->masnvd · 2026-05-06
- [NVD] CVE-2026-43114 (CRITICAL 9.4) — In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry New test case fails unexpectedly when avx2 matching functions are used. The test first loads a ranomly generated pipapo set with 'ipv4 nvd · 2026-05-06
- [NVD] CVE-2026-43112 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath When cifs_sanitize_prepath is called with an empty string or a string containing only delimiters (e.g., "/"), the current logic attempts to check *nvd · 2026-05-06
- [NVD] CVE-2026-43089 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: xfrm_user: fix info leak in build_mapping() struct xfrm_usersa_id has a one-byte padding hole after the proto field, which ends up never getting set to zero before copying out to userspace. Fix that up by zeronvd · 2026-05-06
- [NVD] CVE-2026-43088 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: net: af_key: zero aligned sockaddr tail in PF_KEY exports PF_KEY export paths use `pfkey_sockaddr_size()` when reserving sockaddr payload space, so IPv6 addresses occupy 32 bytes on the wire. However, `pfkey_sonvd · 2026-05-06
- [NVD] CVE-2026-43085 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator When batching multiple NFLOG messages (inst->qlen > 1), __nfulnl_send() appends an NLMSG_DONE terminator with sizeof(struct nfgenmsg) paylonvd · 2026-05-06
- [NVD] CVE-2026-23928 (MEDIUM 6.8) — The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicnvd · 2026-05-06
- [NVD] CVE-2026-23927 (MEDIUM 6.5) — A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a named session.nvd · 2026-05-06
- [NVD] CVE-2026-23926 (MEDIUM 6.8) — An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on nvd · 2026-05-06
- Threat Activity Enablers: The Backbone of Today’s Threat Landscaperecordedfuture · 2026-05-06
- Recorded Future Named a Leader in the 2026 Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies. And there’s more.recordedfuture · 2026-05-06
- [NVD] CVE-2026-28780 (CRITICAL 9.8) — Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap banvd · 2026-05-05
- [NVD] CVE-2026-39852 (HIGH 8.2) — Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allows unauthenticated or lower-privileged usernvd · 2026-05-05
- [NVD] CVE-2026-35397 (HIGH 8.8) — Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whose names begin with the same prefix as the rnvd · 2026-05-05
- [NVD] CVE-2026-43002 (MEDIUM 5.3) — An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.nvd · 2026-05-05
- [NVD] CVE-2026-43071 (CRITICAL 9.1) — In the Linux kernel, the following vulnerability has been resolved: dcache: Limit the minimal number of bucket to two There is an OOB read problem on dentry_hashtable when user sets 'dhash_entries=1': BUG: unable to handle page fault for address: ffff888b30b774b0 #PF: supernvd · 2026-05-05
- [NVD] CVE-2026-34956 (MEDIUM 5.9) — A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crnvd · 2026-05-05
- Turn Intelligence into Action Instantly with Retroactive Threat Detection on Verity471intel471 · 2026-05-05
- [NVD] CVE-2026-6322 (HIGH 7.5) — fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a rawnvd · 2026-05-05
- Escalating a Windows driver registry bug to a kernel write primitivetrailofbits · 2026-05-05
- DNSSEC: The Extra Security Layer That Can Break Your Padlocksucuri_blog · 2026-05-05
- Hacking Embodied AIrecordedfuture · 2026-05-05
- Elastic Workflows GA: automation where your security data already liveselastic_security · 2026-05-05
- [Breach] Cushman & Wakefield — 310,431 accounts exposedhibp_breaches · 2026-05-05
- Your UEBA is lying to you: Why entity record quality decides everythingelastic_security · 2026-05-05
- AI-generated hunting leads: The hunt starts before you ask the questionelastic_security · 2026-05-05
- Know who to watch before the incident finds youelastic_security · 2026-05-05
- [NVD] CVE-2026-6321 (HIGH 7.5) — fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalizenvd · 2026-05-04
- [NVD] CVE-2026-42154 (HIGH 7.5) — Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attanvd · 2026-05-04
- [NVD] CVE-2026-42151 (HIGH 7.5) — Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type nvd · 2026-05-04
- [NVD] CVE-2026-42027 (CRITICAL 9.8) — Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description: The ExtensionLoader.instantiateExtension(Class, String) method loads a class by its fully-qualified name via nvd · 2026-05-04
- [NVD] CVE-2026-40682 (CRITICAL 9.1) — XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor class initializes a static SAXParserFactory at class-load time without enabling Fnvd · 2026-05-04
- Copirate 365 at DEF CON: Plundering in the Depths of Microsoft Copilot (CVE-2026-24299)embracethered · 2026-05-04
- [NVD] CVE-2026-33846 (HIGH 7.5) — A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_lengthnvd · 2026-05-04
- One agent, the right skills: Elastic Security 9.4 brings domain expertise on demand to every SOC workflowelastic_security · 2026-05-04
- Elastic Conversational Entity Analytics: threat hunting in a single conversationelastic_security · 2026-05-04
- From plain English to production rule: AI-native Elasticsearch ES|QL detection in Elastic Securityelastic_security · 2026-05-04
- [NVD] CVE-2026-7680 (MEDIUM 4.3) — A weakness has been identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file backend/webserver/api/datasets.py of the component Data Endpoint. Executing a manipulation of the argument folder can lead to path traversal. The attack can be launcnvd · 2026-05-03
- [NVD] CVE-2026-6229 (HIGH 7.2) — The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, which can be bypassed by including 'docs.googlenvd · 2026-05-02
- [NVD] CVE-2026-7598 (HIGH 7.3) — A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The nnvd · 2026-05-01
- [NVD] CVE-2026-43038 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() Sashiko AI-review observed: In ip6_err_gen_icmpv6_unreach(), the skb is an outer IPv4 ICMP error packet where its cb contains an IPv4 inet_skb_pnvd · 2026-05-01
- [NVD] CVE-2026-43037 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the IPv6 receive path as struct inet6_skb_parm. nvd · 2026-05-01
- [NVD] CVE-2026-43009 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: bpf: Fix incorrect pruning due to atomic fetch precision tracking When backtrack_insn encounters a BPF_STX instruction with BPF_ATOMIC and BPF_FETCH, the src register (or r0 for BPF_CMPXCHG) also acts as a destnvd · 2026-05-01
- [NVD] CVE-2026-31710 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: smb: client: fix dir separator in SMB1 UNIX mounts When calling cifs_mount_get_tcon() with SMB1 UNIX mounts, @cifs_sb->mnt_cifs_flags needs to be read or updated only after calling reset_cifs_unix_caps(), othernvd · 2026-05-01
- [NVD] CVE-2026-31700 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() In tpacket_snd(), when PACKET_VNET_HDR is enabled, vnet_hdr points directly into the mmap'd TX ring buffer shared with userspace. The kernel validnvd · 2026-05-01
- Overview of Content Published in Aprildidier_stevens · 2026-05-01
- [NVD] CVE-2026-43003 (HIGH 8.0) — An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.nvd · 2026-05-01
- [NVD] CVE-2026-43001 (HIGH 7.9) — An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted appnvd · 2026-05-01
- Vulnerability & Patch Roundup — April 2026sucuri_blog · 2026-05-01
- The Iran War: What You Need to Knowrecordedfuture · 2026-05-01
- DFIR: From alert to root cause using Osquery without leaving Elastic Securityelastic_security · 2026-05-01
- [NVD] CVE-2026-3833 (MEDIUM 6.5) — A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can explonvd · 2026-04-30
- [NVD] CVE-2026-3832 (LOW 3.7) — A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSPnvd · 2026-04-30
- [NVD] CVE-2026-33845 (HIGH 7.5) — A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of nvd · 2026-04-30
- [NVD] CVE-2025-14543 (CRITICAL 9.1) — Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.*, from 6.0nvd · 2026-04-30
- [NVD] CVE-2026-7246 (HIGH 7.2) — This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Click project. The original CVE record description is preserved below: Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the clnvd · 2026-04-30
- [NVD] CVE-2026-7163 (MEDIUM 6.1) — A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials for arbitrary clusters provisnvd · 2026-04-30
- Post-quantum encryption for Cloudflare IPsec is generally availablecloudflare_security · 2026-04-30
- [NVD] CVE-2025-14576 (HIGH 7.8) — Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead tnvd · 2026-04-30
- 2026-005: High Vulnerability in the Linux Kernel ("Copy Fail")cert_eu · 2026-04-30
- [NVD] CVE-2026-41226 (MEDIUM 4.7) — Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web Image Monitor. When accessing a specially crafted URL, the user may be redirected to an arbitrary website. As a result, the user may become a victim of a phishing attack.nvd · 2026-04-30
- Risk Scenarios for the US’s Strategic Pivotrecordedfuture · 2026-04-30
- Building with AI: Here's What No Briefing Will Tell Yourecordedfuture · 2026-04-30
- [Breach] Reborn Gaming — 126 accounts exposedhibp_breaches · 2026-04-30
- The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940)watchtowr · 2026-04-29
- [NVD] CVE-2026-42198 (HIGH 7.5) — pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very largnvd · 2026-04-29
- Extending Ruzzy with LibAFLtrailofbits · 2026-04-29
- CI/CD pipeline abuse: the problem no one is watchingelastic_security · 2026-04-29
- What is online gambling spam and what can I do about it?sucuri_blog · 2026-04-28
- Cisco Identity Services Engine Remote Code Execution and Path Traversal Vulnerabilitiescisco_psirt · 2026-04-28
- Identity APM Has Gone Mainstream. The Hard Work Is Just Starting.specterops · 2026-04-28
- [NVD] CVE-2025-48431 (HIGH 7.5) — Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Description: Specially crafted requests can crash an c_glinvd · 2026-04-28
- The Money Mule Solution: What Every Scam Has in Commonrecordedfuture · 2026-04-28
- Lazarus Doesn't Need AGIrecordedfuture · 2026-04-28
- [Breach] Vimeo — 119,167 accounts exposedhibp_breaches · 2026-04-28
- [NVD] CVE-2026-3087 (HIGH 7.5) — If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.nvd · 2026-04-27
- [NVD] CVE-2026-7141 (MEDIUM 5.6) — A vulnerability was found in vLLM up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v1/kv_cache_interface.py of the component KV Block Handler. Performing a manipulation results in uninitialized resource. It is possible to initiate the attack renvd · 2026-04-27
- [NVD] CVE-2026-40858 (HIGH 8.8) — The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the Infinispan cache used by a Camel applicanvd · 2026-04-27
- [NVD] CVE-2026-40860 (CRITICAL 9.8) — JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter, class allowlist or class denylist. Becausnvd · 2026-04-27
- [Breach] CTT — 468,124 accounts exposedhibp_breaches · 2026-04-26
- [NVD] CVE-2026-31681 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_multiport: validate range encoding in checkentry ports_match_v1() treats any non-zero pflags entry as the start of a port range and unconditionally consumes the next ports[] element as the range envd · 2026-04-25
- My Website Is Hosting a Phishing Page – Now What?sucuri_blog · 2026-04-25
- Monitoring Claude Code/Cowork at scale with OTel in Elasticelastic_security · 2026-04-25
- [NVD] CVE-2026-42044 (MEDIUM 6.5) — Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into surgical, innvd · 2026-04-24
- [NVD] CVE-2026-42043 (HIGH 7.2) — Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the NO_PROXY protection. This vunvd · 2026-04-24
- [NVD] CVE-2026-42041 (MEDIUM 4.8) — Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), cnvd · 2026-04-24
- [NVD] CVE-2026-42039 (HIGH 7.5) — Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError. This vulnerability is fixenvd · 2026-04-24
- [NVD] CVE-2026-42033 (HIGH 7.4) — Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) silently intercept and modify every JSON responvd · 2026-04-24
- [NVD] CVE-2026-30368 (MEDIUM 5.4) — A client-side authorization flaw in Lightspeed Systems Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to unauthorized control and monitoring of student devinvd · 2026-04-24