Canvas attack aftermath: What risks come next

2026-05-31T08:51:36Zc75fce33f981a0177b091a1e003f77622b7a6fb775263487faa81f814625ed35
132 CVEsAMOSCanvasFirewallG2GOLD CRYSTALGartnerGitHubMicrosoftPatch TuesdaySMB brute-forceShinyHuntersSynchronized SecurityVS Code extensionWantToCryendpointidentity securitymacOS stealerprivate repositoriesransomwaresupply chain

What happened

Recent Sophos reporting highlights several active and emerging risks: a Canvas-related data compromise tied to actors such as ShinyHunters/GOLD CRYSTAL exposing student data; a supply-chain breach where a malicious VS Code extension cloned private GitHub repositories (reported for sale); a WantToCry ransomware variant performing SMB brute-force to remotely encrypt files; and the macOS Atomic stealer (AMOS) targeting data. Additionally, May Patch Tuesday disclosed 132 CVEs (approaching ~300 with advisories), underscoring urgent patching and identity/endpoint protections.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
c75fce33f981a0177b091a1e003f77622b7a6fb775263487faa81f814625ed35
Enrichment time
2026-05-31T08:51:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Canvas attack aftermath: What risks come next · Baitaphish