ShinyHunters claims nearly 9,000 schools affected by Canvas data breach

2026-05-08T14:51:44Z1453db85d73455828ca3436605830da615a2762f6d1eb7a0d473aa3452e384cc
AI-securityCISACanvasClaudeDODIvantiNSONorth-KoreaPAN-OSPalo Alto NetworksSchemataShinyHuntersactive-exploitationbrowser-extensioncritical-infrastructuredata-breacheducationlaptop-farmmilitary-dataplugin-hijackspywarevulnerabilityzero-day

What happened

Multiple high-impact cybersecurity stories: threat actor ShinyHunters claims data from nearly 9,000 schools using Canvas was stolen; researchers disclosed a Chrome-extension flaw in Anthropic’s Claude that allowed other plugins to hijack users’ AI sessions; and multiple vendors face actively exploited zero-days — including Ivanti’s ePMM and a critical, in-the-wild PAN-OS firewall zero-day. Separately, a DOD contractor (Schemata) exposed military course materials and service member records via an API flaw. Other coverage includes CISA guidance on isolating critical infrastructure and increased审

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
1453db85d73455828ca3436605830da615a2762f6d1eb7a0d473aa3452e384cc
Enrichment time
2026-05-08T14:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ShinyHunters claims nearly 9,000 schools affected by Canvas data breach · Baitaphish