US govt seeks Instructure testimony on massive Canvas cyberattack
2026-05-13T07:23:32Z•07fe57c805e3bfe2f0898f4f3b2a1a9607aae2615d39d348057b88b3ee5cfd3b
CanvasCheckmarxCommerce CloudFortiAuthenticatorFortiSandboxFortinetInstructureJenkins plugin compromise','infostealerKB5087420KB5087544KB5089549MicrosoftPatch TuesdayPyPIRCES/4HANASAPShai-HuludShinyHuntersWindows 10Windows 11data breachextortionnpmsupply-chain
What happened
A series of high-impact security incidents and patches were reported: the U.S. House Committee seeks testimony from Instructure after two ShinyHunters extortion attacks against the Canvas LMS (Instructure later said it reached an agreement to stop leaks); Fortinet released patches for critical RCEs in FortiSandbox and FortiAuthenticator; Microsoft issued May 2026 Patch Tuesday fixes (120 flaws) plus Windows 10/11 cumulative/extended updates; SAP released fixes addressing critical issues in Commerce Cloud and S/4HANA; a new Shai-Hulud supply-chain campaign compromised hundreds of npm and PyPI‑s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 07fe57c805e3bfe2f0898f4f3b2a1a9607aae2615d39d348057b88b3ee5cfd3b
- Enrichment time
- 2026-05-13T07:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.