Canvas login portals hacked in mass ShinyHunters extortion campaign

2026-05-08T07:23:29Z9238331a7eb6e1e8c75ee77ea1f85f0617f426c78a523591f950d2d84886dc83
BeagleCisco DoSClickFixGoogle-AdsIvanti EPMMManageWPOutlookPAN-OSPCPJackRCEShinyHuntersTCLBankerTeamPCPVidarWhatsAppcredential-theftextortionfake-AI-sitephishingsandbox-escapesupply-chaintrojanized-MSIvm2zero-day

What happened

Multiple active campaigns and zero-day exploits reported: ShinyHunters defaced Canvas login portals in an extortion campaign; new malware families (TCLBanker, PCPJack, Vidar, Beagle) are spreading via trojanized installers, WhatsApp/Outlook, social-engineering ClickFix, and fake AI sites to steal credentials and deploy backdoors; supply-chain trojanization (DAEMON Tools, MSI) and Google Ads-based ManageWP phishing observed; critical/zero-day vulnerabilities (Ivanti EPMM RCE, PAN-OS firewall zero-day, vm2 sandbox escape) and a Cisco DoS requiring manual reboot are being exploited in the wild. W

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
9238331a7eb6e1e8c75ee77ea1f85f0617f426c78a523591f950d2d84886dc83
Enrichment time
2026-05-08T07:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Canvas login portals hacked in mass ShinyHunters extortion campaign · Baitaphish