惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
博客园 - 【当耐特】
S
SegmentFault 最新的问题
阮一峰的网络日志
阮一峰的网络日志
大猫的无限游戏
大猫的无限游戏
WordPress大学
WordPress大学
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
The Cloudflare Blog
Apple Machine Learning Research
Apple Machine Learning Research
小众软件
小众软件
博客园 - 三生石上(FineUI控件)
Martin Fowler
Martin Fowler
云风的 BLOG
云风的 BLOG
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
F
Fortinet All Blogs
Y
Y Combinator Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
J
Java Code Geeks
Engineering at Meta
Engineering at Meta
MyScale Blog
MyScale Blog
B
Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
人人都是产品经理
人人都是产品经理

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
CMC Releases Analysis and Guidance for Education Sector A...
https://www.infosecurity-magazine.com/profile/beth-maundrill/ · 2026-06-26 · via www.infosecurity-magazine.com

The UK’s Cyber Monitoring Centre (CMC) has shared its analysis of the Canvas cyber incident affecting Instructure’s Learning Management System as the education technology firm prepares to share its own findings next week.

The CMC said that approximately 160 UK higher education institutions were affected and threat actors exfiltrated confidential course and user data. In total, around 9000 educational institutions are thought to have been affected worldwide.

While the incident has not met the CMC’s minimum category threshold, the review aims to better understand the financial impact of data breach events, inform the development of the CMC’s data breach analysis model and deepen insight into cyber risk within the UK higher education sector.

The CMC considers a cyber-attack a ‘Category 1 event’ if it has loss of £10m ($13m) or impact more than 0.01% of UK organizations. For context, the 2025 cyber-attack against Jaguar Land Rove was ranked as a Category 3 systemic event on the five-point CMC scale.

The CMC said that the Canvas event illustrates how data breach events can differ from large-scale disruption events in their financial profile.

“In this case, losses appear to be driven more by response, recovery, and risk management activity than by prolonged business interruption,” the CMC review said.

How the Canvas Cyber-Attack Unfolded

On April 29, Instructure detected unauthorized activity in Canvas. The company said this activity was carried out by a cybercriminal organization known for large-scale attacks across multiple sectors, including technology and education.

On May 7, 2026, the same threat actor gained additional access through a second Canvas vulnerability. The unauthorized actor made changes to the pages that appeared when some students and teachers were logged in through Canvas

A defacement message which appeared on approximately 330 institutional Canvas login pages led many to conclude that the ShinyHunters extortion group was at the center of the cyber-attack. Attribution has not been confirmed by Instructure.

The firm confirmed on May 9 that Canvas was fully online and available for use.

CrowdStrike is involved in the forensic investigation into the incident, which Instructure said was carried out using one of its Free-For-Teacher accounts.

Cyber Monitoring Centre Review and Recommendations

The CMC said that despite the number of higher education institutions affected, there is no evidence of lateral movement of the threat actors into the other institutional systems.

The recommendations outline by the CMC were described as “common good practice” for higher education establishments that have been reinforced by analysis of the Canvas event. These include:

  • Align architecture with risk: Priorities protection of mission‑critical systems and high‑value services based on the organization’s risk appetite
  • Separate application and data layers: Improve data integrity, recovery and validation by isolating these components where possible
  • Enforce MFA consistently: Ensure multi-factor authentication is properly implemented across all systems
  • Control third‑party access: Limit and closely manage external access privileges across the supply chain
  • Assess offshore dependencies: Understand risks linked to overseas providers, including legal and support limitations
  • Strengthen SaaS security: Follow provider guidance to avoid misconfigurations and reduce breach risk
  • Test incident response plans: Run breach and outage scenarios to improve resilience and business continuity

Canvas Incident Underscores Phishing Risks and Need for Clear Communication

Communication was also a key recommendation for organizations responding to an incident including sharing sufficient technical detail to enable partners and customers to assess their exposure and undertake their own investigation.

Further, the CMC said that software providers should maintain appropriate customer contacts – for example the CIO or CISO – for incident notifications.

Following the incident, the education technology firm said it had "reached an agreement with the unauthorized actor involved in this incident." However, it did not state whether money exchanged hands.

The CMC noted that following a ransom payment, promises to delete data, including passing on apparent technical proof of deletion, are unreliable.

In this case, the ongoing risk to students and others is unlikely to be direct extortion. A more likely risk is that the exfiltrated data could be used to target them with more sophisticated phishing emails.

Canvas said it does not expect the information involved to be made public but highlighted that those affected should remain vigilant for phishing, smishing and vishing scams.