Instructure confirms hackers used Canvas flaw to deface portals
ID: 3e568974-55f5-5ccd-9cf2-670f7b299987
STIX ID: report--3e568974-55f5-5ccd-9cf2-670f7b299987
Feed Name: Bleeping Computer
Threat Score
Instructure's Canvas LMS was breached via multiple cross-site scripting (XSS) vulnerabilities that allowed attackers (ShinyHunters) to hijack authenticated admin sessions, exfiltrate data (reported ~3.6 TB / 275M records), and later deface login portals with an extortion demand; Free-for-Teacher instances were temporarily shut down while the company revoked access and engaged forensic help.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
