Canvas login portals hacked in mass ShinyHunters extortion campaign
2026-05-08T01:23:33Z•d274e08b90dfd1d4051bcfedb92bb84ba764bee6a8e12bfdf64852ae84637db7
Beagle backdoorCanvasClickFixEPMMGoDaddy phishing campaign`,`supply chain compromise`,`DAEMON-TOOGoogle AdsInstructureIvantiManageWPOutlook spreadingPAN-OSPCPJackPalo Alto NetworksShinyHuntersTCLBankerVidar StealerWhatsApp spreadingextortionfake AI sitephishingremote code executionsandbox escapetrojanized MSIvm2zero-day
What happened
Multiple high-impact threats and active campaigns reported: ShinyHunters defaced hundreds of Canvas login portals at Instructure in an extortion campaign; critical zero-days and exploited RCEs were disclosed (Palo Alto PAN-OS under active exploitation, Ivanti EPMM zero-day) alongside a critical vm2 sandbox escape allowing host code execution; malware campaigns and worms observed include TCLBanker (self-spreading via trojanized MSI, WhatsApp and Outlook propagation), PCPJack (credential theft and removal of rival access), Vidar stealer distributed via ClickFix social engineering, and a new Beag
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- d274e08b90dfd1d4051bcfedb92bb84ba764bee6a8e12bfdf64852ae84637db7
- Enrichment time
- 2026-05-08T01:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.