Instructure took a risky approach to recover stolen Canvas data
2026-05-12T14:51:48Z•ae511fede610430f6284fce963480f6dcbf6afce44cfd5af2fa35703939e1b75
AI-securityCVE-2026-44413DNS-cache-poisoningIDE-security-pluginIoT-securityJetBrainsTeamCitydata-breachdata-salednsmasqextortionincident-responselocal-privilege-escalationprivacyransomwareregulatory-settlementsupply-chain-securityvulnerabilityvulnerability-managementzero-trust
What happened
This feed rounds up multiple security and privacy developments: Instructure (Canvas) reportedly negotiated with the ShinyHunters extortion group to prevent leaked stolen data, implying a likely ransom payment; General Motors agreed to a $12.75M settlement with California over unlawful sale of drivers’ location/behavioral data; JetBrains patched a high-severity TeamCity vulnerability (CVE-2026-44413) that allows privilege escalation and possible unauthorized exposure of parts of the REST API; dnsmasq was disclosed to have six serious memory-safety/input-validation flaws enabling DNS cache‑poiso
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- ae511fede610430f6284fce963480f6dcbf6afce44cfd5af2fa35703939e1b75
- Enrichment time
- 2026-05-12T14:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.