Canvas Breach Disrupts Schools & Colleges Nationwide
2026-05-08T19:23:32Z•f045ed43f836eb486b9a6a40bd08c29aa38f0193bcbb95f399f7b59e0f4097ec
AisuruBlueHammerCanisterWormJackSkidKimwolfMossadScattered SpiderStrykerUNKN (Daniil Shchukin)anti-ddosbotnetbrazilcanvasdata extortionddoseducationiot botnetmicrosoft office token theftpatch tuesdayransomwarerouter exploitsharepointtylerbwiperzero-day
What happened
Multiple high-impact cyber incidents and disclosures: a large extortion/data-theft campaign defaced Canvas login pages and threatened to leak data on ~275 million students and staff across ~9,000 institutions; a Brazilian anti-DDoS firm was implicated in enabling a botnet that hit ISPs; Russian-linked actors exploited known router flaws to harvest Microsoft Office authentication tokens from ~18,000 networks; Microsoft pushed large Patch Tuesday updates (April) fixing 167 vulnerabilities including a SharePoint zero-day and a publicly disclosed Windows Defender issue dubbed "BlueHammer"; U.S./EU
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- f045ed43f836eb486b9a6a40bd08c29aa38f0193bcbb95f399f7b59e0f4097ec
- Enrichment time
- 2026-05-08T19:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.