Instructure reaches 'agreement' with ShinyHunters to stop data leak
ID: 6debbaf6-3670-58e9-abd3-413fe32f1959
STIX ID: report--6debbaf6-3670-58e9-abd3-413fe32f1959
Feed Name: Bleeping Computer
Threat Score
Instructure's Canvas LMS was breached by the ShinyHunters extortion group, which exploited multiple cross-site scripting (XSS) vulnerabilities in the Free-for-Teacher environment to inject JavaScript, obtain authenticated admin sessions, steal roughly 3.6 TB of data, deface login portals, and issue extortion demands; Instructure reports an agreement with the actor and temporary shutdown of affected free accounts while investigating and remediating the flaws.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
