Instructure confirms data breach, ShinyHunters claims attack
2026-05-04T07:23:30Z•c03f3b8f0091934ef3c8768a75f7ec2573b8e3e6c7d1f3d3de4fc9f397617902
ALPHVAndroid malwareBlackCatBluekitCVE-2026-41940ConsentFix v3DigiCertMicrosoft DefenderOAuth abuseSecuronixShinyHuntersSorry ransomwareTelegram Mini AppsTrojan:Win32/Cerdigent.A!dhacPanelcertificate removalcrypto scamsdata breachfalse-positiveincident responsemass exploitationphishingphishing kitransomwarethreat intelligence
What happened
A BleepingComputer news roundup: Instructure confirmed a data breach with the ShinyHunters extortion gang claiming responsibility (initial reporting briefly retracted then updated). A critical cPanel flaw (CVE-2026-41940) is being mass-exploited by "Sorry" ransomware operators. Microsoft Defender is producing widespread false positives by flagging legitimate DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha and in some cases removing certificates. Researchers disclosed large-scale abuse of Telegram Mini Apps for crypto scams and Android malware distribution, and a scaled-up ConsentFix
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- c03f3b8f0091934ef3c8768a75f7ec2573b8e3e6c7d1f3d3de4fc9f397617902
- Enrichment time
- 2026-05-04T07:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.