Instructure confirms hackers used Canvas flaw to deface portals

2026-05-11T19:23:31Z7e4aa55895332f3676434658e368a85b28f73cc7ba2d5592ceb178468e6d421d
Android bankerCISACanvasClaude.aiEPMMGoogle AdsHugging FaceInstructureIvantiJDownloaderNVIDIA GeForce NOW','Trellix','RansomHouse','crime marketplace',Python RATTON blockchainTrickModata breachdefacementexploitextortioninfostealermac malwaremalvertisingsupply-chainvulnerabilitywebsite compromisezero-day

What happened

Multiple high-impact incidents reported across enterprise and consumer ecosystems. Instructure confirmed a vulnerability was used to deface Canvas login portals and post an extortion message. Google researchers say attackers likely used AI to craft a zero‑day exploit against a popular web admin tool. CISA ordered U.S. federal agencies to urgently patch a high-severity Ivanti Endpoint Manager Mobile (EPMM) flaw being exploited as a zero‑day. Several supply‑chain and distribution compromises were observed: the JDownloader site was altered to ship a Python RAT, a fake Hugging Face repo pushed a 0

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
7e4aa55895332f3676434658e368a85b28f73cc7ba2d5592ceb178468e6d421d
Enrichment time
2026-05-11T19:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.