Pipes Feed Preview: FsFTI

  1. untitled

    Thu, 18 Jun 2026 19:02:39 +0000

  2. untitled

    Thu, 18 Jun 2026 19:02:39 +0000

  3. untitled

    Thu, 18 Jun 2026 00:48:49 +0000

  4. untitled

    Wed, 17 Jun 2026 14:10:49 +0000

  5. untitled

    Wed, 17 Jun 2026 14:10:49 +0000

  6. untitled

    Wed, 10 Jun 2026 14:04:36 +0000

    <p><strong>Microsoft</strong> today released software updates to plug nearly 200 security holes across its <strong>Windows</strong> operating systems and supported software, a record number of fixes for the company&#8217;s monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft&#8217;s most dire &#8220;critical&#8221; rating, and exploit code for at least three of the weaknesses is now publicly available.</p> <p>The software giant said in <a href="https://www.microsoft.com/en-us/msrc/blog/2026/05/a-note-on-patch-tuesday" target="_blank" rel="noopener">a blog post</a> last month that both its engineers and the security community are increasing using artificial intelligence tools to find bugs, meaning this month&#8217;s heavy Patch Tuesday may start to become the norm, said <strong>Satnam Narang</strong>, senior staff research engineer at <strong>Tenable</strong>.</p> <p>&#8220;Some surveys put AI usage among security professionals generally at 90%, so it’s unsurprising that this volume of patches may be the norm,&#8221; Narang said. &#8220;Pandora’s proverbial box has been opened, and as more advanced AI models become available, we expect the norm to continue upward across the board, not just for Patch Tuesday.&#8221;</p> <p>June&#8217;s zero-day bugs include <a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-49160" target="_blank" rel="noopener">CVE-2026-49160</a>, a denial of service vulnerability affecting a range of web servers, including Microsoft <strong>Internet Information Services</strong> (IIS). Microsoft says the flaw was reported by OpenAI&#8217;s Codex.</p> <p>Two of the zero-days addressed this month appear to stem from recent vulnerability disclosures by <strong>Nightmare Eclipse</strong>, the nickname chosen by a security researcher who has been dropping exploits for various Windows flaws. One of those, dubbed &#8220;GreenPlasma,&#8221; leverages an elevation of privilege weakness in the Windows Collaborative Translation Framework, the same framework patched today in <a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45586" target="_blank" rel="noopener">CVE-2026-45586</a>.</p> <p>Nightmare Eclipse also last month released &#8220;YellowKey,&#8221; an exploit for a Windows BitLocker vulnerability that allows an attacker with physical access to view encrypted data, and <a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50507" target="_blank" rel="noopener">CVE-2026-50507</a> is a patch for an elevation of privilege bug in BitLocker.<span id="more-73788"></span></p> <p>Microsoft received heavy blowback on social media last month after it said in <a href="https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure" target="_blank" rel="noopener">a blog post</a> that it was considering taking legal action against the security researcher. The company later clarified on Twitter/X that while it has no intention of pursuing legal actions against researchers, it would report them to authorities if they break the law. The advisories for CVE-2026-49160 and CVE-2026-50507 do not credit any researchers in the acknowledgement section, saying only that &#8220;Microsoft recognizes the efforts of those in the security community who help us protect customers through coordinated vulnerability disclosure.&#8221;</p> <p><strong>Nightmare Eclipse </strong>claims to be <a href="https://infosec.exchange/@briankrebs/116661298779426573" target="_blank" rel="noopener">a former employee</a> of Microsoft, although Microsoft has not responded to questions about this claim. <strong>Rapid7</strong> notes that a recent blog post by Nightmare Eclipse included an image of <a href="https://residentevil.fandom.com/wiki/Albert_Wesker" target="_blank" rel="noopener">Albert Wesker</a>, a character from the Resident Evil video game series who formerly worked as a researcher for a technology company before going rogue.</p> <p>Nightmare Eclipse has pledged to release even more zero-day exploits for Windows in what they called a &#8220;bone shattering&#8221; drop planned for July 14 (the same day as next month&#8217;s Patch Tuesday). Immediately following the release of Microsoft patches today, the researcher <a href="https://deadeclipse666.blogspot.com/2026/06/its-patch-tuesday.html" target="_blank" rel="noopener">published an exploit</a> for what they claimed was a zero-day bug in Windows Defender.</p> <p>While 200 vulnerabilities may be a record for Patch Tuesday, the actual number of security flaws Microsoft addressed this month is far higher, said Rapid7&#8217;s <strong>Adam Barnett</strong>.</p> <p>&#8220;So far this month, Microsoft has provided patches to address 360 browser vulnerabilities, which is an order of magnitude more than has been typical in any given month over the past few years,&#8221; Barnett wrote. &#8220;As usual, browser [flaws] are not included in the Patch Tuesday count above. Indeed, the vast, and presumably sustained, uptick in the number of browser vulnerabilities has led to Microsoft no longer enumerating Chromium CVEs in the Security Update Guide.&#8221;</p> <p>Microsoft also patched a zero-day vulnerability in <strong>Visual Studio Code</strong> that allows attackers to steal GitHub tokens with a single click. The company was forced to push a stopgap fix for the flaw on June 3, after a researcher <a href="https://blog.ammaraskar.com/github-token-stealing/" target="_blank" rel="noopener">published instructions</a> showing how to exploit it. The researcher said they opted not to work with Microsoft because of a recent experience wherein Redmond silently patched a flaw they reported without offering credit or recognition.</p> <p>Microsoft battled its own internal zero-day emergencies last week, after at least 72 of the company&#8217;s public code repositories were infected with <a href="https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents" target="_blank" rel="noopener">a variant of the Shai-Hulud worm</a>. Researchers found that all of the affected packages were connected to Microsoft official Azure Durable Task SDK, which got <a href="https://opensourcemalware.com/blog/miasma-reaches-azure" target="_blank" rel="noopener">hit by the same Shai-Hulud worm</a> in May.</p> <p>Other major software makers are also shipping outsized update bundles this month. <strong>Adobe</strong> has released updates to fix a massive number of critical vulnerabilities <a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noopener">across a range of products</a>, including <strong>Adobe Experience Manager</strong>, <strong>Acrobat Reader</strong> and <strong>Cold Fusion</strong>. On June 3, <strong>Google</strong> resolved <a href="https://securityboulevard.com/2026/06/google-patches-429-chrome-vulnerabilities-in-major-browser-update/" target="_blank" rel="noopener">a whopping 429 vulnerabilities</a> in its latest <strong>Chrome</strong> browser update (Chrome automatically downloads updates but installing them usually requires a complete restart of the browser).</p> <p>As ever, please consider backing up your data before applying operating system updates, and drop a note in the comments if you run into any problems with this month&#8217;s patches.</p> <p>Further reading:</p> <p><a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jun" target="_blank" rel="noopener">Microsoft&#8217;s Security Update Guide</a></p> <p><a href="https://www.action1.com/patch-tuesday/patch-tuesday-june-2026/?vyi" target="_blank" rel="noopener">Action1&#8217;s Patch Tuesday breakdown</a></p> <p><a href="https://isc.sans.edu/diary/Microsoft%20June%202026%20Patch%20Tuesday/33064" target="_blank" rel="noopener">SANS Internet Storm Center notes on Patch Tuesday</a></p>
  7. untitled

    Wed, 13 May 2026 18:54:16 +0000

    <p>Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are proving remarkably good at finding security vulnerabilities in human-made computer code. That reality is on full display this month with some of the more widely-used software makers &#8212; including <strong>Apple</strong>, <strong>Google</strong>, <strong>Microsoft</strong>, <strong>Mozilla</strong> and <strong>Oracle</strong> &#8212; fixing near record volumes of security bugs, and/or quickening the tempo of their patch releases.</p> <p>As it does on the second Tuesday of every month, Microsoft today released software updates to address at least 118 security vulnerabilities in its various <strong>Windows</strong> operating systems and other products. Remarkably, this is the first Patch Tuesday in nearly two years that Microsoft is not shipping any fixes to deal with emergency zero-day flaws that are already being exploited. Nor have any of the flaws fixed today been previously disclosed (potentially giving attackers a heads up in how to exploit the weakness).</p> <p>Sixteen of the vulnerabilities earned Microsoft&#8217;s most-dire &#8220;critical&#8221; label, meaning malware or miscreants could abuse these bugs to seize remote control over a vulnerable Windows device with little or no help from the user. <strong>Rapid7</strong> has done much of the heavy lifting in identifying some of the more concerning critical weaknesses this month, including:<span id="more-73582"></span></p> <ul> <li><a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41089" target="_blank" rel="noopener">CVE-2026-41089</a>: A critical stack-based buffer overflow in Windows Netlogon that offers an attacker SYSTEM privileges on the domain controller. No privileges or user interaction are required, and attack complexity is low. Patches are available for all versions of Windows Server from 2012 onwards.</li> <li><a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41096" target="_blank" rel="noopener">CVE-2026-41096</a>: A critical RCE in the Windows DNS client implementation worthy of attention despite Microsoft assessing exploitation as less likely.</li> <li><a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41103" target="_blank" rel="noopener">CVE-2026-41103</a>: A critical elevation of privilege vulnerability that allows an unauthorized attacker to impersonate an existing user by presenting forged credentials, thus bypassing Entra ID. Microsoft expects that exploitation is more likely.</li> </ul> <p>May&#8217;s Patch Tuesday is a welcome respite from April, which saw Microsoft <a href="https://krebsonsecurity.com/2026/04/patch-tuesday-april-2026-edition/" target="_blank" rel="noopener">fix a near-record 167 security flaws</a>. Microsoft was among a few dozen tech giants given access to a &#8220;<strong>Project Glasswing</strong>,&#8221; a much-hyped AI capability developed by <strong>Anthropic</strong> that appears quite effective at unearthing security vulnerabilities in code.</p> <p>Apple, another early participant in Project Glasswing, typically fixes an average of 20 vulnerabilities each time it ships a security update for iOS devices, said <strong>Chris Goettl</strong>, vice president of product management at <strong>Ivanti</strong>. On May 11, Apple shipped updates to address at least 52 vulnerabilities and backported the changes all the way to iPhone 6s and iOS 15.</p> <p>Last month, Mozilla released <strong>Firefox 150</strong>, which resolved <a href="https://arstechnica.com/ai/2026/04/mozilla-anthropics-mythos-found-271-zero-day-vulnerabilities-in-firefox-150/" target="_blank" rel="noopener">a whopping 271 vulnerabilities</a> that were reportedly discovered during the Glasswing evaluation.</p> <p>&#8220;Since Firefox 150.0.0 released, they have been on a more aggressive weekly cadence for security updates including the release of Firefox 150.0.3 on May Patch Tuesday resolving between three to five CVEs in each release,&#8221; Goettl said.</p> <p>The software giant Oracle likewise recently increased its patch pace in response to their work with Glasswing. In its most recent quarterly patch update, Oracle addressed at least 450 flaws, including <a href="https://www.securityweek.com/oracle-patches-450-vulnerabilities-with-april-2026-cpu/" target="_blank" rel="noopener">more than 300 fixes for remotely exploitable, unauthenticated flaws</a>. But at the end of April, Oracle announced it was switching to a monthly update cycle for critical security issues.</p> <p>On May 8, Google started rolling out updates to its Chrome browser that <a href="https://www.forbes.com/sites/daveywinder/2026/05/08/critical-new-google-security-update-127-chrome-security-vulnerabilities-confirmed/" target="_blank" rel="noopener">fixed an astonishing 127 security flaws</a> (up from just 30 the previous month). Chrome automagically downloads available security updates, but installing them requires fully restarting the browser.</p> <p>If you encounter any weirdness applying the updates from Microsoft or any other vendor mentioned here, feel free to sound off in the comments below. Meantime, if you haven&#8217;t backed up your data and/or drive lately, doing that <em>before</em> updating is generally sound advice. For a more granular look at the Microsoft updates released today, checkout <a href="https://isc.sans.edu/forums/diary/Microsoft%20May%202026%20Patch%20Tuesday/32980/" target="_blank" rel="noopener">this inventory</a> by the <strong>SANS Internet Storm Center</strong>.</p>
  8. untitled

    Fri, 19 Jun 2026 15:15:56 +0000

  9. untitled

    Fri, 19 Jun 2026 15:15:56 +0000

  10. untitled

    Fri, 19 Jun 2026 15:15:56 +0000

  11. untitled

    Thu, 18 Jun 2026 00:48:49 +0000

  12. untitled

    Wed, 17 Jun 2026 14:10:49 +0000

  13. untitled

    Sat, 13 Jun 2026 13:37:35 +0000

  14. untitled

    Sat, 13 Jun 2026 13:37:35 +0000

  15. untitled

    Thu, 18 Jun 2026 19:02:40 +0000

  16. untitled

    Thu, 18 Jun 2026 19:02:39 +0000

  17. untitled

    Fri, 12 Jun 2026 14:33:17 +0000

  18. untitled

    Thu, 11 Jun 2026 19:03:42 +0000

    <p>A cybercrime group known as <strong>The Gentlemen</strong> has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.</p> <div id="attachment_73785" style="width: 757px" class="wp-caption aligncenter"><img aria-describedby="caption-attachment-73785" decoding="async" loading="lazy" class=" wp-image-73785" src="https://krebsonsecurity.com/wp-content/uploads/2026/06/thegentlemen.png" alt="" width="747" height="492" /><p id="caption-attachment-73785" class="wp-caption-text">A graphic created and shared by The Gentlemen ransomware group administrator Hastalamuerte on Breachforums in May 2026. Credit: ke-la.com.</p></div> <p>Experts at the security firm <strong>Check Point Software</strong> have been closely covering exploits of The Gentlemen, a so-called &#8220;ransomware-as-a-service&#8221; (RaaS) offering that pays affiliates handsomely to help spread the group&#8217;s malware.</p> <p>&#8220;A 90/10 affiliate revenue split &#8212; compared to the industry standard 80/20 &#8212; is accelerating the group&#8217;s growth by attracting experienced operators from competing programs,&#8221; the researchers wrote in April.</p> <p>Check Point <a href="https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/" target="_blank" rel="noopener">found</a> The Gentlemen are the second most active ransomware group by victim count so far this year, claiming at least 332 published victims since the group&#8217;s inception in mid-2025 and more than 240 in 2026 alone.</p> <p>According to Check Point, the group targets Internet-facing devices (VPNs, firewalls) as their entry point, and once inside moves quickly to encrypt entire networks within hours.</p> <p>Check Point says the administrator and primary operator of the ransomware group uses the nickname <strong>Zeta88</strong> on the Russian-language cybercrime forums, and that this individual was previously known under the moniker <strong>Hastalamuerte</strong>. Check Point noted that <a href="https://www.kelacyber.com/blog/the-gentlemen-ransomware-internal-chat-leak-analysis-2026/" target="_blank" rel="noopener">a breach</a> of the group&#8217;s backend infrastructure made it clear that Hastalamuerte/Zeta88 is the person who assembles the locker and RaaS panel, manages payments, and is essentially the administrator of the entire program who receives 10 percent of all ransoms.<span id="more-73768"></span></p> <h2>WHO IS HASTALAMUERTE?</h2> <p>The cyber intelligence firm <strong>Intel 471</strong> shows that the user Hastalamuerte is a Russian and English speaking person who registered on almost a dozen cybercrime forums between 2019 and the present day, including Exploit, Breachforums, Ramp_V2, BHF, <strong>Raidforums</strong>, and <strong>Nulled</strong>.</p> <p>Intel 471 reveals that Hastalamuerte registered on Breachforums in January 2025 from an Internet address in <strong>Izhevsk</strong>, the capital city of Russia&#8217;s Udmurt Republic. Likewise, the user <strong>Zeta88</strong> signed up at the English-language cybercrime forum Breached in August 2022 from a different Internet address in Izhevsk.</p> <p>Intel 471 finds Hastalamuerte registered on Raidforums in 2020 using the email address <strong>hastalamuerte1488@protonmail.com </strong>(1488 is a common combination of <a href="https://en.wikipedia.org/wiki/Fourteen_Words" target="_blank" rel="noopener">two numeric symbols associated with white supremacy</a>). A lookup on this address at the open source intelligence service <strong>Epieos</strong> shows it is connected to an account at Apple and to a phone number ending in <strong>04</strong>.</p> <p>Epieos says that Protonmail address is also linked to a GitHub account under the username <strong>SantaMuerte</strong>. That account is marked private, but <a href="https://connectionrequired.com/gitspective/#/timeline/SantaLaMuerte" target="_blank" rel="noopener">a history of this user&#8217;s activity</a> shows they are watching and developing a number of malware tools and exploits.</p> <p>In April 2020, Hastalamuerte said on the crime forum Nulled that they could be contacted at the Telegram instant messenger name <strong>@hastalamuerte18</strong>, and the threat intelligence company <strong>Flashpoint</strong> finds this username is assigned the unique Telegram ID number <strong>30907522 </strong>[full disclosure: Flashpoint is an advertiser on this blog].</p> <p>The breach tracking service <strong>Constella Intelligence</strong> reports that Hastalamuerte&#8217;s Telegram ID is connected to another username &#8212; &#8220;<strong>bu4vs</strong>&#8221; &#8212; and to the Russian phone number <strong>79127650004</strong>. Pivoting on this phone number in Constella fetches multiple records from hacked Russian government databases showing it is assigned to one <strong>Alexander Andreevich Yapaev</strong>, a 36-year-old from Izhevsk.</p> <p>Constella reveals that phone number was used to create an account at the Russian social media platform Pikabu under the name &#8220;<strong>4apai18</strong>,&#8221; and shows Mr. Yapaev has signed up at a number of websites using the common surname <a href="https://x.com/bu4vs/status/235798656769470465" target="_blank" rel="noopener">Ivanov</a>, or else &#8220;Chapaev&#8221; (the numeral 4 is often used as shorthand for a &#8220;ch&#8221; sound in Russian).</p> <p>A search in Intel 471 for cybercrime forum members with the nickname SantaMuerte unearths an account by the same name created in 2020 on the Russian hacking forum Codeby. Intel 471 shows this user originally registered on Codeby with the not-so-subtle nickname <strong>Alexandr 4apaev</strong>.</p> <p>Constella finds Mr. Yapaev regularly used the email address <strong>bu4vs@mail.ru</strong>. Meanwhile, Epieos shows this address is connected to a <a href="https://www.linkedin.com/in/yapaev/" target="_blank" rel="noopener">LinkedIn account</a> for Alexander Yapaev, who lists himself as the head of B2B marketing at the company <strong>Uralenergo Udmurtia</strong>, one of Russia&#8217;s largest suppliers of electrotechnical and lighting products.</p> <p>Mr. Yapaev did not respond to multiple requests for comment.</p> <p>Nearly every time we publish one of these <a href="https://krebsonsecurity.com/category/breadcrumbs/" target="_blank" rel="noopener">Breadcrumbs stories</a>, readers are curious to know why it seems like so many cybercriminals from Russia apparently do little to hide their real life identities. The truth is that &#8212; Russian or not &#8212; most didn&#8217;t exactly set out to be arch criminals, but instead got drawn into the scene gradually over several years as their skills broadened and sharpened.</p> <p>Another important dynamic is that the Russian government generally either <a href="https://www.recordedfuture.com/research/dark-covenant-3-controlled-impunity-and-russias-cybercriminals" target="_blank" rel="noopener">co-opts or ignores</a> cybercriminal activity within its borders so long as the hackers do not steal from or attack Russian businesses and citizens. As a result, successful cybercriminals in Russia are usually insulated from prosecution and arrest by foreign law enforcement agencies provided they occasionally pay off the right people and do not travel abroad. And cybercriminals who intend to strictly adhere to those unwritten rules may (at least initially) be less concerned about covering their tracks online.</p> <p>But the simplest explanation is that cybercriminals of all nationalities tend to make a number of basic operational security mistakes early in their careers, when they are less savvy and have far less to lose by their carelessness. A review of Hastalamuerte&#8217;s early posts on the crime forums (circa 2019-2020) shows a relatively unsophisticated and low-skilled hacker still trying to learn the ropes and earn a positive reputation on these communities.</p> <p>For example, in June 2020 Hastalamuerte&#8217;s Telegram account joined a multi-month training program (@pntst) to learn how to use popular penetration testing tools, and their candid posts to this hacker training camp show Hastalamuerte struggling to use these tools effectively. A Google-translated record of Hastalmuerte&#8217;s posts to @pntst is <a href="https://krebsonsecurity.com/wp-content/uploads/2026/06/pntst-chat.txt" target="_blank" rel="noopener">here</a>.</p> <p><strong>Update, June 11, 10:23 a.m. ET:</strong>  The threat research group <strong>PRODAFT</strong> has released <a href="https://catalyst.prodaft.com/public/report/inside-the-phantom-mantis-operation/overview#paragraph-1077|172" target="_blank" rel="noopener">a detailed writeup</a> on the history and current operations of The Gentlemen. PRODAFT said its findings match the same persona with &#8220;high confidence,&#8221; and found the administrator (Zeta88/Hastalamuerte) supplies affiliates with initial access directly, primarily Fortinet SSL-VPN credentials obtained through brute-force attacks or sourced from the group&#8217;s own leak database. They also discovered the administrator is using AI to develop and maintain the ransomware and associated tooling, as well as to assist with post-exploitation activity.</p>
  19. untitled

    Fri, 08 May 2026 13:44:59 +0000

    <p>An ongoing data extortion attack targeting the widely-used education technology platform <strong>Canvas</strong> disrupted classes and coursework at school districts and universities across the United States today, after a cybercrime group defaced the service&#8217;s login page with a ransom demand that threatened to leak data from 275 million students and faculty across nearly 9,000 educational institutions.</p> <div id="attachment_73565" style="width: 706px" class="wp-caption aligncenter"><img aria-describedby="caption-attachment-73565" decoding="async" loading="lazy" class="size-full wp-image-73565" src="https://krebsonsecurity.com/wp-content/uploads/2026/05/shinyhunters-instructure-canvas.png" alt="" width="696" height="704" /><p id="caption-attachment-73565" class="wp-caption-text">A screenshot shared by a reader showing the extortion message that was shown on the Canvas login page today.</p></div> <p>Canvas parent firm <strong>Instructure</strong> responded to today&#8217;s defacement attacks by disabling the platform, which is used by thousands of schools, universities and businesses to manage coursework and assignments, and to communicate with students.</p> <p>Instructure acknowledged a data breach earlier this week, after the cybercrime group <strong>ShinyHunters</strong> claimed responsibility and said they would leak data on tens of millions of students and faculty unless paid a ransom. The stated deadline for payment was initially set at May 6, but it was later pushed back to May 12.</p> <p>In <a href="https://status.instructure.com/incidents/9wm4knj2r64z" target="_blank" rel="noopener">a statement</a> on May 6, Instructure said the investigation so far shows the stolen information includes &#8220;certain identifying information of users at affected institutions, such as names, email addresses, and student ID numbers, as well as as messages among users.&#8221; The company said it found no evidence the breached data included more sensitive information, such as passwords, dates of birth, government identifiers or financial information.</p> <p>The May 6 update stated that Canvas was fully operational, and that Instructure was not seeing any ongoing unauthorized activity on their platform. &#8220;At this stage, we believe the incident has been contained,&#8221; Instructure wrote.</p> <p>However, by mid-day on Thursday, May 7, students and faculty at dozens of schools and universities were flooding social media sites with comments saying that a ransom demand from ShinyHunters had replaced the usual Canvas login page. Instructure responded by pulling Canvas offline and replacing the portal with the message, &#8220;Canvas is currently undergoing scheduled maintenance. Check back soon.&#8221;</p> <p>&#8220;We anticipate being up soon, and will provide updates as soon as possible,&#8221; reads the current message on Instructure&#8217;s <a href="https://status.instructure.com/incidents/m88d7ymwpzpy" target="_blank" rel="noopener">status page</a>.</p> <p>While the data stolen by ShinyHunters may or may not contain particularly sensitive information (ShinyHunters claims it includes several billion private messages among students and teachers, as well as names, phone numbers and email addresses), this attack could hardly have come at a worse time for Instructure: Many of the affected schools and universities are in the middle of final exams, and a prolonged outage could be highly damaging for the company.</p> <p>The extortion message that greeted countless Canvas users today advised the affected schools to negotiate their own ransom payments to prevent the publication of their data &#8212; regardless of whether Instructure decides to pay.</p> <p>&#8220;ShinyHunters has breached Instructure (again),&#8221; the extortion message read. &#8220;Instead of contacting us to resolve it they ignored us and did some &#8216;security patches.'&#8221;</p> <p>A source close to the investigation who was not authorized to speak to the press told KrebsOnSecurity that a number of universities have already approached the cybercrime group about paying. The same source also pointed out that the ShinyHunters data leak blog no longer lists Instructure among its current extortion victims, and that the samples of data stolen from Canvas customers were removed as well. Data extortion groups like ShinyHunters will typically only remove victims from their leak sites after receiving an extortion payment or after a victim agrees to negotiate.</p> <p><strong>Dipan Mann</strong>, founder and CEO of the security firm <strong>Cloudskope</strong>, slammed Instructure for referring to today&#8217;s outage as a &#8220;scheduled maintenance&#8221; event on its status page. Mann said Shiny Hunters first demonstrated they&#8217;d breached Instructure on May 1, prompting Instructure&#8217;s Chief Information Security Officer <strong>Steve Proud</strong> to declare the following day that the incident had been contained. But Mann said today&#8217;s attack is at least the third time in the past eight months that Instructure has been breached by ShinyHunters.</p> <p>In a blog post today, Mann noted that in September 2025, ShinyHunters released thousands of internal University of Pennsylvania files — donor records, internal memos, and other confidential materials — through what the Daily Pennsylvanian and other outlets later determined was, in part, a Canvas/Instructure-mediated access path.</p> <p>&#8220;Penn was the named victim,&#8221; Mann <a href="https://www.cloudskope.com/insights/post/instructure-canvas-ransomware-attack-hits-universities-2026" target="_blank" rel="noopener">wrote</a>. &#8220;Instructure was the mechanism. The incident was treated as a Penn-specific story by most of the national press and quietly handled by Instructure as a customer-specific matter. That framing was wrong then. It is dramatically more wrong in light of the May 2026 events, which now look like the planned escalation of an attack pattern that ShinyHunters had been working against Instructure&#8217;s environment for at least eight months prior. The September 2025 Penn breach was the proof of concept. The May 1, 2026 incident was the production run. The May 7, 2026 recompromise was ShinyHunters demonstrating publicly that the May 2 &#8216;containment&#8217; did not happen.&#8221;<span id="more-73563"></span></p> <p>In February, a ShinyHunters spokesperson told <em>The Daily Pennsylvanian</em> that Penn <a href="https://www.thedp.com/article/2026/02/penn-hack-donor-data-ransom-one-million-shinyhunters-gse-emai" target="_blank" rel="noopener">failed to pay a $1 million ransom demand</a>. On March 5, ShinyHunters published 461 megabytes worth of data stolen from Penn, including thousands of files such as donor records and internal memos.</p> <p>ShinyHunters is a prolific and fluid cybercriminal group that specializes in data theft and extortion. They typically gain access to companies through voice phishing and social engineering attacks that often involve impersonating IT personnel or other trusted members of a targeted organization.</p> <p>Last month, ShinyHunters relieved the home security giant <strong>ADT</strong> of personal information on 5.5 million customers. The extortion group <a href="https://www.bleepingcomputer.com/news/security/home-security-giant-adt-data-breach-affects-55-million-people/" target="_blank" rel="noopener">told BleepingComputer</a> they breached the company by compromising an employee&#8217;s Okta single sign-on account in a voice phishing attack that enabled access to ADT&#8217;s Salesforce instance. BleepingComputer says ShinyHunters recently has taken credit for a number of extortion attacks against high-profile organizations, including Medtronic, Rockstar Games, McGraw Hill, 7-Eleven and the cruise line operator Carnival.</p> <p>The attack on Canvas customers is just one of several major cybercrime campaigns being launched by ShinyHunters at the moment, said <strong>Charles Carmakal</strong>, chief technology officer at the Google-owned <strong>Mandiant Consulting</strong>. Carmakal declined to comment specifically on the Canvas breach, but said &#8220;there are multiple concurrent and discrete ShinyHunters intrusion and extortion campaigns happening right now.&#8221;</p> <p>Cloudskope&#8217;s Mann said what happens next depends largely on whether Instructure&#8217;s customers — the universities, K-12 districts, and education ministries paying for Canvas — choose to apply pressure or absorb the breach quietly.</p> <p>&#8220;The history of education-vendor incidents suggests the path of least resistance is the second one,&#8221; he concluded.</p> <p><strong>Update, May 8, 11:05 a.m. ET:</strong> Instructure has published <a href="https://www.instructure.com/incident_update" target="_blank" rel="noopener">an incident update page</a> that includes more information about the breach. Instructure said its Canvas portal is functioning normally again, and that the hackers exploited an issue related to Free-for-Teacher accounts.</p> <p>&#8220;This is the same issue that led to the unauthorized access the prior week,&#8221; Instructure wrote. &#8220;As a result, we have made the difficult decision to temporarily shut down Free-for-Teacher accounts. These accounts have been a core part of our platform, and we&#8217;re committed to resolving the issues with these accounts.&#8221;</p> <p>Instructure said affected organizations were notified on May 6.</p> <p>&#8220;If your organization is affected, Instructure will contact your organization’s primary contacts directly,&#8221; the update states. &#8220;Please don&#8217;t rely on third-party lists or social media posts naming potentially affected organizations as those lists aren&#8217;t verified. Instructure will confirm validated information through direct outreach to all affected organizations.&#8221;</p> <p><strong>Update, May 11, 10:16 p.m. ET:</strong> Instructure posted <a href="https://www.instructure.com/incident_update" target="_blank" rel="noopener">an update</a> saying they paid their extortionists in exchange for a promise to destroy the stolen data. &#8220;The data was returned to us,&#8221; the update reads. &#8220;We received digital confirmation of data destruction (shred logs). We have been informed that no Instructure customers will be extorted as a result of this incident, publicly or otherwise.&#8221;</p>
  20. untitled

    Fri, 19 Jun 2026 05:55:15 +0000

  21. untitled

    Thu, 18 Jun 2026 19:02:40 +0000

  22. untitled

    Wed, 17 Jun 2026 14:10:49 +0000

  23. untitled

    Wed, 17 Jun 2026 14:10:49 +0000

  24. untitled

    Wed, 17 Jun 2026 14:10:49 +0000