惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
G
Google Developers Blog
Blog — PlanetScale
Blog — PlanetScale
U
Unit 42
A
About on SuperTechFans
Vercel News
Vercel News
B
Blog
Martin Fowler
Martin Fowler
MyScale Blog
MyScale Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
腾讯CDC
D
Docker
V
Visual Studio Blog
博客园 - 叶小钗
The Cloudflare Blog
Jina AI
Jina AI
B
Blog RSS Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
WordPress大学
WordPress大学
T
Tailwind CSS Blog
MongoDB | Blog
MongoDB | Blog
D
DataBreaches.Net
月光博客
月光博客
大猫的无限游戏
大猫的无限游戏

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY
Canvas owner reaches ‘agreement’ with threat actors after...
Anna Merod · 2026-05-13 · via Cybersecurity Dive - Latest News

Instructure “reached an agreement” with an unauthorized threat actor on Monday, just days after cybercriminals twice — within a little over a week — infiltrated the ed tech provider’s Canvas learning management system.  

The latest cybersecurity incident on Thursday caused sweeping disruptions to schools and colleges nationwide after the cyber gang ShinyHunters posted a message that was seen by some users on their Canvas platforms. The post said that schools could negotiate a settlement with ShinyHunters by Tuesday — the same deadline given to Instructure.

Cybersecurity experts suggest Instructure’s agreement appears to be a ransomware payment, a practice the FBI strongly discourages

Instructure said that as a part of its agreement with an unnamed threat actor, the stolen data was returned to the ed tech company, and it had received digital confirmation of data destruction in the form of “shred logs.” The threat actor said no Instructure customers will be extorted from this incident, Instructure said, and no individuals impacted by the breach will need to engage with them.

“While there is never complete certainty when dealing with cyber criminals, we believe it was important to take every step within our control to give customers additional peace of mind, to the extent possible,” Instructure said in a Monday statement on its website. 

No ‘guarantee’ data will be deleted

ShinyHunters has been confirmed as the group behind the Canvas cyberattack, as the group posted about the initial incident to its leak site on May 3, said Rebecca Moody, head of data research at Comparitech, a cybersecurity and online privacy product review website, in a Tuesday statement. 

In its May 3 post, ShinyHunters claimed to have stolen 3.65 TB of data from about 275 million users across 9,000 schools worldwide, according to Moody. Instructure has not confirmed how many schools or users were impacted by the recent data breaches. 

“This post and the individual school-by-school threats ShinyHunters has sent likely put pressure on Instructure to meet the ransom demands to try and prevent data from being leaked,” Moody said. “However, let's not forget that ShinyHunters are cybercriminals. Even by paying this ransom demand, Instructure cannot guarantee the data will be deleted.”

Several class action lawsuits have already been filed against Instructure in federal district courts over the data breach. 

Instructure confirmed last week that hackers gained unauthorized access to its systems through its Free for Teachers platform on April 29 and May 7. The exposed data included usernames, email addresses, course names, enrollment information and messages, Instructure said. The company added that “core learning data (course content, submissions, credentials) was not compromised,” and Canvas is now fully operational and safe to use. 

Michael Klein, senior director for preparedness and response at the Institute for Security and Technology, said that while he agrees with the FBI in most cases that organizations should not pay ransoms to cybercriminals after a data breach, sometimes there are situations in which the compromised data could cause physical harm — such as a ransomware attack on a hospital. In that situation, paying a ransom might be necessary, he said. 

With the Instructure incident, however, Klein said he doesn’t think the reported data that was compromised falls under such a scenario that would necessitate a payment. 

“Also, you can't trust that a cybercriminal group is going to keep their word and not then go and extort all of the people downstream of that anyway,” Klein said.

The need for federal, state supports 

When PowerSchool got hacked in December 2024, Klein was working at the U.S. Department of Education as the senior advisor for cybersecurity. At the time, he was able to convene 41 states and Guam within a few days to share information on the incident including how to understand the challenges, communicate with the company, and mitigate the impact for schools. 

Fast forward to the latest cyberattack on Instructure, and that federal authority and structure no longer exists, Klein said. In his own capacity at the Institute for Security and Technology, Klein said he was only able to convene 22 states on Friday to hold a similar conversation about Instructure after the “widespread” and “understandable freakout” from Thursday’s incident that caused disruptions for many school and college systems.   

When the Education Department convened states a year and a half ago during the PowerSchool incident, that protected gathering was made possible through the Critical Infrastructure Partnership Advisory Council, Klein said. A little over a year ago, however, the U.S. Department of Homeland Security ended that council’s authority, he said. 

A DHS secretary could restore that authority without Congress, Klein said, and then the federal government could immediately assemble similar convenings again.

Klein added that restoring funding for the federal Multi-State Information Sharing Analysis Center, or MS-ISAC, could give school districts and state education agencies no-cost access to as much cybersecurity threat information as possible. 

“This incident, as well as the PowerSchool incident, demonstrates the importance of support from the federal and state level in order to build capacity for institutions that cannot do this work themselves,” Klein said.

Meanwhile, on Tuesday, the Software & Information Industry Association sent letters to lawmakers in both chambers of Congress calling for a $36 million investment in the FY 2027 budget to ensure schools have access to digital security services. 

SIIA called for $20 million to fund MS-ISAC and $10 million for the Readiness and Emergency Management for Schools Technical Assistance Center to reestablish a central hub for school-specific cyber-incident management. The group also urged that another $6 million is needed to support the Education Department in its role as the leading agency for coordinating educational cybersecurity.

“Following the 2025 federal funding shifts that resulted in the ‘offboarding’ of school districts from essential threat monitoring services and the shuttering of key technical assistance centers, America’s K-12 education sector is currently at its most vulnerable state in a decade,” said SIIA’s letter to leaders on the Senate Appropriations Subcommittee on Labor, Health and Human Services, Education, and Related Agencies.