Canvas attack aftermath: What risks come next?
2026-05-28T20:51:36Z•550f1419b0bd534a3f23c8f0c920598ebec9f681da87b826744f38dbf5990399
132 CVEsAI agent riskAMOSCanvasGOLD CRYSTALGitHubPatch TuesdaySMB brute-forceShinyHuntersWantToCryblast radiusdata breachinfostealermacOSmalicious-vscode-extensionprivate-repositoriesransomwarestudent datasupply chainvulnerability management
What happened
Sophos published multiple security updates and incident analyses: a data compromise tied to Canvas (attributed to groups/tags including ShinyHunters and GOLD CRYSTAL) exposing student data; a supply-chain breach where a malicious VS Code extension allowed cloning of private GitHub repositories which were offered for sale; active WantToCry ransomware campaigns using SMB brute-force to remotely encrypt files; coverage of the AMOS macOS infostealer stealing data at scale; and a May Patch Tuesday roundup noting 132 CVEs (many already mitigated). Sophos also published guidance on reducing AI-agent/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- 550f1419b0bd534a3f23c8f0c920598ebec9f681da87b826744f38dbf5990399
- Enrichment time
- 2026-05-28T20:51:36Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.