Instructure confirms hackers used Canvas flaw to deface portals
2026-05-11T19:23:31Z•7e4aa55895332f3676434658e368a85b28f73cc7ba2d5592ceb178468e6d421d
Android bankerCISACanvasClaude.aiEPMMGoogle AdsHugging FaceInstructureIvantiJDownloaderNVIDIA GeForce NOW','Trellix','RansomHouse','crime marketplace',Python RATTON blockchainTrickModata breachdefacementexploitextortioninfostealermac malwaremalvertisingsupply-chainvulnerabilitywebsite compromisezero-day
What happened
Multiple high-impact incidents reported across enterprise and consumer ecosystems. Instructure confirmed a vulnerability was used to deface Canvas login portals and post an extortion message. Google researchers say attackers likely used AI to craft a zero‑day exploit against a popular web admin tool. CISA ordered U.S. federal agencies to urgently patch a high-severity Ivanti Endpoint Manager Mobile (EPMM) flaw being exploited as a zero‑day. Several supply‑chain and distribution compromises were observed: the JDownloader site was altered to ship a Python RAT, a fake Hugging Face repo pushed a 0
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 7e4aa55895332f3676434658e368a85b28f73cc7ba2d5592ceb178468e6d421d
- Enrichment time
- 2026-05-11T19:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.