ShinyHunters Extorts Universities in New Instructure Canvas Hack

2026-05-09T08:51:56Zc8f1fa3763963067a9379061a0fff3e8fa0c4cd3d8754bbc982b167176a7919e
AI securityAWS RexAndroid zero-click RCECISACallPhantomCanvasChrome vulnerabilitiesCopy FailDigiCert false positiveGoogle AppSheetGoogle PlayInstructureLinux kernelMicrosoft DefenderOpenAI passkeysSamsung One UI update','VPN','endpoint encryptionShinyHuntersWhatsApp vulnerabilitiescertificate expirydata-breachextortionpasskeysphishingprompt injectionsecure boot

What happened

This feed aggregates multiple high-impact security stories: ShinyHunters-linked actors defaced and extorted universities via Instructure Canvas portals (disrupting finals and following reports of a broader Canvas breach claiming ~275M users/9,000 schools). Large-scale phishing and abuse incidents include Google AppSheet-driven phishing that compromised ~30,000 Facebook business accounts and 28 CallPhantom scam apps on Google Play with >7.3M downloads. Multiple widely exploited or patched vulnerabilities are highlighted — Google patched an Android zero-click RCE and 30 Chrome flaws (including 4

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
techrepublic_security
Record identifier
c8f1fa3763963067a9379061a0fff3e8fa0c4cd3d8754bbc982b167176a7919e
Enrichment time
2026-05-09T08:51:56Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.