Canvas login portals hacked in mass ShinyHunters extortion campaign
2026-05-08T07:23:29Z•9238331a7eb6e1e8c75ee77ea1f85f0617f426c78a523591f950d2d84886dc83
BeagleCisco DoSClickFixGoogle-AdsIvanti EPMMManageWPOutlookPAN-OSPCPJackRCEShinyHuntersTCLBankerTeamPCPVidarWhatsAppcredential-theftextortionfake-AI-sitephishingsandbox-escapesupply-chaintrojanized-MSIvm2zero-day
What happened
Multiple active campaigns and zero-day exploits reported: ShinyHunters defaced Canvas login portals in an extortion campaign; new malware families (TCLBanker, PCPJack, Vidar, Beagle) are spreading via trojanized installers, WhatsApp/Outlook, social-engineering ClickFix, and fake AI sites to steal credentials and deploy backdoors; supply-chain trojanization (DAEMON Tools, MSI) and Google Ads-based ManageWP phishing observed; critical/zero-day vulnerabilities (Ivanti EPMM RCE, PAN-OS firewall zero-day, vm2 sandbox escape) and a Cisco DoS requiring manual reboot are being exploited in the wild. W
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 9238331a7eb6e1e8c75ee77ea1f85f0617f426c78a523591f950d2d84886dc83
- Enrichment time
- 2026-05-08T07:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.