Canvas login portals hacked in mass ShinyHunters extortion campaign

2026-05-08T01:23:33Zd274e08b90dfd1d4051bcfedb92bb84ba764bee6a8e12bfdf64852ae84637db7
Beagle backdoorCanvasClickFixEPMMGoDaddy phishing campaign`,`supply chain compromise`,`DAEMON-TOOGoogle AdsInstructureIvantiManageWPOutlook spreadingPAN-OSPCPJackPalo Alto NetworksShinyHuntersTCLBankerVidar StealerWhatsApp spreadingextortionfake AI sitephishingremote code executionsandbox escapetrojanized MSIvm2zero-day

What happened

Multiple high-impact threats and active campaigns reported: ShinyHunters defaced hundreds of Canvas login portals at Instructure in an extortion campaign; critical zero-days and exploited RCEs were disclosed (Palo Alto PAN-OS under active exploitation, Ivanti EPMM zero-day) alongside a critical vm2 sandbox escape allowing host code execution; malware campaigns and worms observed include TCLBanker (self-spreading via trojanized MSI, WhatsApp and Outlook propagation), PCPJack (credential theft and removal of rival access), Vidar stealer distributed via ClickFix social engineering, and a new Beag

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
d274e08b90dfd1d4051bcfedb92bb84ba764bee6a8e12bfdf64852ae84637db7
Enrichment time
2026-05-08T01:23:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.