Canvas Hackers ShinyHunters Say Their Official Domain Was Suspended
2026-05-13T08:51:43Z•307e097479ed9a6897741496c20c06492aca67b446935078b9398f115659ce06
.onion0-dayAI platformsAI-assisted exploitsCanvas LMSFirefoxGitHubNVIDIAOperation HumanitarianBaitPwn2OwnPyPIPython spywareShinyHuntersVercel GenAIbrowser passwordscookiescredential stealerdark webdomain suspensionfake aid documentsfake installerphishingphishing kitssupply chainzero-day
What happened
Multiple high-risk developments: threat actor ShinyHunters had its public domain suspended after Canvas LMS attacks and moved to a .onion site; a fake Claude Code installer campaign is stealing browser passwords and cookies from developers; rejected Pwn2Own participants publicly released zero-day exploits affecting Firefox, NVIDIA, and AI platforms; Operation HumanitarianBait uses fake aid documents and GitHub-hosted payloads to deploy Python spyware against Russian-speaking targets; Google reports attackers using AI to craft zero-day exploits, Android backdoors, and automated supply-chain (Py
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 307e097479ed9a6897741496c20c06492aca67b446935078b9398f115659ce06
- Enrichment time
- 2026-05-13T08:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.