Pressure mounts on Canvas as data leak extortion deadline looms
2026-05-12T02:51:49Z•5c8a3f022901dcb906cfb542c992a3f9c0a3940f8c18a26a025de3c12a071b4d
ai-developed-exploitai-securitycanvaschrome-extensionclaudecybercrimedata-theftdhseducation-sectorextortiongoogle-threat-intelinstructureivantilaptop-farmnorth-koreansopolicyshinyhuntersspywarethe-comvulnerabilityzero-day
What happened
Multiple CyberScoop reports highlight a cluster of high-impact incidents and policy developments: attackers tied to “The Com”/ShinyHunters claim theft of Canvas/Instructure data from roughly 8,800–9,000 schools and are threatening mass data leaks/extortion; Google’s threat intel discovered an AI-assisted zero-day exploit before widespread use; Ivanti customers are facing an actively exploited zero-day in a mobile endpoint product; a flaw in Anthropic’s Claude Chrome extension allowed other plugins to hijack user AI sessions; and lawmakers (Sen. Schumer, Rep. Summer Lee) are pressing agencies (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cyberscoop
- Record identifier
- 5c8a3f022901dcb906cfb542c992a3f9c0a3940f8c18a26a025de3c12a071b4d
- Enrichment time
- 2026-05-12T02:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.