Canvas attack aftermath: What risks come next?

2026-05-29T20:51:37Zb7c67ec1ebce70d7e835299203f13030e4f13986b00e3a55dc364de6536eeaa1
AMOSCanvasEDRGOLD CRYSTALGitHubMicrosoft CVEsPatch TuesdaySMB brute forceShinyHuntersVS Code extensionWantToCryXDRendpointfirewallidentity securityinfostealermacOSransomwarerepository theftstudent data breachsupply chain

What happened

Sophos published a multi-article briefing covering several active and emerging threats: a Canvas student-data compromise attributed to groups including ShinyHunters/GOLD CRYSTAL, a supply-chain/code-editor incident where a malicious VS Code extension led to cloned private GitHub repositories, and WantToCry ransomware using SMB brute-force to remotely encrypt files. Additional research highlights the AMOS macOS infostealer operating at scale and a heavy May Patch Tuesday with ~132 Microsoft-related CVEs (advisories approaching 300). The feed also includes Sophos product/market updates and an "I

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
b7c67ec1ebce70d7e835299203f13030e4f13986b00e3a55dc364de6536eeaa1
Enrichment time
2026-05-29T20:51:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Canvas attack aftermath: What risks come next? · Baitaphish