The US announced that a group of hackers breached the systems of 62 universities and colleges, exploiting a vulnerability in an ERP web application.
The vulnerability is located in Ellucian Banner Web Tailor, a feature of Ellucian Banner's ERP that allows universities to manage various applications. It also affects Ellucian Banner Enterprise Identity Services, which is used to manage user accounts
A security researcher, Joshua Mulliken, had discovered a while ago that there is a vulnerability in the authentication mechanism of the two services, which could allow hackers to gain access to user accounts remotely.
According to the Ministry of Education, the vulnerability, known as CVE-2019-8978, began to be used by some hackers, who attacked 62 universities.
Police said they have received information indicating that criminals are scanning the internet looking for potential victims (universities) to attack using this specific vulnerability.
The Department of Education said that affected colleges reported that hackers began creating multiple fake accounts once they gained access to the systems.

The fake accounts were created for criminal activities
Police said the fake accounts were used “almost immediately for criminal activity,” but did not provide further information.
What the police fear is that the Ellucian Banner Web Tailor system is connected to the rest of the ERP. This means that hackers could gain access to financial data of student users.
Experts recommend that all universities using vulnerable ERP versions immediately update their systems.
Ellucian, which issued a securityin May, also issued the same advice. However, the company denies that the creation of the fake accounts is related to the ERP flaw and the recent attacks.
In other words, Ellucian believes the Department of Education is wrongly linking the vulnerability, which was discovered in May, to the recent attacks. The company said it is working with the Department to investigate the attacks and clarify the situation.
