惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Vercel News
Vercel News
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Apple Machine Learning Research
Apple Machine Learning Research
T
Tailwind CSS Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
人人都是产品经理
人人都是产品经理
V
V2EX
量子位
Last Week in AI
Last Week in AI
Jina AI
Jina AI
博客园 - 【当耐特】
爱范儿
爱范儿
宝玉的分享
宝玉的分享
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Hugging Face - Blog
Hugging Face - Blog
博客园 - 三生石上(FineUI控件)
有赞技术团队
有赞技术团队
小众软件
小众软件
IT之家
IT之家
博客园_首页
博客园 - 聂微东
S
SegmentFault 最新的问题
阮一峰的网络日志
阮一峰的网络日志
博客园 - 叶小钗

TechSpot

Flagship Rematch: Ryzen 7 5800X3D vs. Core i9-12900K Slack chats and internal data from failed startups are finding a second life in AI training A $5 Bluetooth tracker hidden in a postcard exposed a warship's movements Leakers claim PlayStation 6 could offer at least 3x the performance of the PS5 The Mac Mini is no longer a niche product, it's local AI infrastructure IPv6 traffic reaches parity with IPv4 for the first time, Google data shows Xbox expansion cards are now cheaper than SSDs, and PC users are repurposing them Blue Origin prepares to reuse New Glenn booster in bid to challenge SpaceX Nvidia could bring back the 12GB RTX 3060 as supply issues disrupt GPU roadmap What was the first OS you ever used? SNK revives NeoGeo AES with modern upgrades and HDMI support Valve's Proton 11 beta boosts Linux gaming with better performance and classic game support Researchers warn Microsoft Defender vulnerability is already being exploited A four-day Steam freebie turned into $250,000 for an indie game AMD may relaunch Ryzen 7 5800X3D for AM4's 10th anniversary This humanoid robot can almost run as fast as a human sprinter Two New Jersey men jailed for helping North Korean IT workers infiltrate 100+ companies A $7,000 DIY radar project is taking on hardware that usually costs over $100,000 Metro 2039 is going darker than ever, launching this winter on PC and consoles Gemini arrives on macOS with a dedicated desktop app AI infrastructure boom pushes AMD, Intel and Arm to new valuation heights New self-healing material can repair itself over 1,000 times, extend the lifespan of cars and aircraft Japan's bullet train to debut high-tech private cabins, for an added fee Memory card and flash drive pricing surges 120%, with some models spiking 260% Open-source tool decrypts all private data collected by Windows Recall on Copilot PCs The 2026 PC and Console Gaming Report shows most revenue now comes from games outside the Top 20 PureMac is a new open-source macOS cleanup and app removal tool Your Airbnb host might actually be AI Steam might soon display 30-day price history for game deals Intel brings 18A process to budget laptops with new Core Series 3 CPUs
A cyberattack on Canvas knocked out access for students a...
Skye Jacobs · 2026-05-10 · via TechSpot

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

In a nutshell: An outage on Canvas last week did more than interrupt logins. It exposed how much modern education depends on a single platform – and how vulnerable that platform can be when something goes wrong. Instructure, the company behind the widely used learning platform, said it had been dealing with a cybersecurity incident since at least May 1. By Thursday, the situation had spilled into public view as Canvas was pushed into maintenance mode, briefly cutting off access for students and educators across the US. The timing made the disruption especially noticeable, landing in the middle of finals and end-of-term deadlines at many schools.

The company's chief information security officer, Steve Proud, wrote in an incident log that Instructure had "recently experienced a cybersecurity incident perpetrated by a criminal threat actor." A day later, he added that the exposed data included names, email addresses, student ID numbers, and messages exchanged on the platform. How many users were affected remains unclear.

What is clear is how far the disruption spread. Universities including Harvard University, Columbia University, Rutgers University, and Georgetown University alerted students, while school districts in multiple states also reported issues. Because Canvas is so widely adopted, even a temporary outage created immediate problems. What began as a security incident quickly became an operational one.

The attackers, operating under the name ShinyHunters, did not keep a low profile. As the situation unfolded, they escalated the attack, with some school login pages defaced after the attackers injected their own HTML, replacing standard login screens with messages tied to the breach.

The Harvard Crimson reported that one such message listed the allegedly affected schools and urged institutions to contact the sender before May 12 to avoid having their data released. The paper added that it was unclear what information related to Harvard affiliates was included in the alleged breach.

This combination of intrusion and public pressure is becoming increasingly common. Rather than quietly stealing data, threat groups often try to force a response by creating visible disruption or reputational risk.

The identity behind ShinyHunters is less straightforward. The name has previously been linked to major data breaches, but researchers say it does not necessarily refer to a single, stable group. Allison Nixon, chief research officer at Unit 221b, told Wired that the activity in this case appears tied to a cluster sometimes referred to as ScatteredLapsus$Hunters, part of a broader and shifting network of actors linked to what is known as "the Com."

The group's messaging has also followed a familiar playbook. At one point, a dark-web site associated with the attackers listed Instructure and its customers as victims and included a complaint: "Instructure has not even bothered speaking to us to understand the situation or to even negociate [sic] with us to prevent the release of this data. The Company seemingly does not care about all the students affected and the institutions impacted by this data breach." Later, those references disappeared, and the site itself became unresponsive.

That kind of change is common in these cases. "This is often one of their manipulation tactics to try to encourage the victim to pay," Nixon said. "So while they're negotiating or after they've paid, they might take that victim off the site, or depending on how negotiations go, they might put the victim back on."

In some cases, the pressure escalates further. Nixon said groups tied to this ecosystem have used tactics that go beyond technical attacks, including denial-of-service campaigns, mass phone calls, and direct threats. "These kind of pressure tactics start to look a whole lot more just violent mafia rather than any kind of skilled hacker stuff," she said.

There is also reason to be cautious about the attackers' claims. The same infrastructure has previously listed other high-profile organizations as victims, sometimes using recycled or previously stolen data to make breaches appear larger than they actually are.

Still, the Canvas incident stands out for its immediate real-world impact. It shows how a compromise at the platform level can ripple outward, affecting thousands of institutions at once. In higher education, where ransomware and data extortion are already persistent problems, that level of centralization raises the stakes.

For Nixon, the bigger concern is how long groups like this have been able to evolve. "It's noteworthy that a tiny number of repeat offenders can escalate for years to reach this point," she said. "It speaks to the systemic international issue of cybercrime and the need for governments around the world to set geopolitics aside and cooperate to stop those who extort money and prey on kids."