✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Higher Education/Acadamia
Breach intelligence, attack campaigns, and threat reports targeting the Higher Education/Acadamia sector.
Explore Other Sectors
Higher Education/Acadamia Threat Reports
Instructure Canvas Data Breach: A Wake-Up Call for Educational Cybersecurity
In April 2026, Instructure, the company behind the Canvas learning management system, experienced a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers accessed personal information of approximately 275 million individuals across nearly 9,000 educational institutions, including names, email addresses, student ID numbers, and user communications. Although sensitive data such as passwords and financial information were reportedly not compromised, the breach led to widespread disruptions as Canvas was temporarily taken offline to mitigate further damage. ([instructure.com](https://www.instructure.com/incident_update?utm_source=openai)) This incident underscores the escalating threat posed by sophisticated cybercriminal groups targeting educational platforms. The breach highlights the critical need for robust cybersecurity measures and proactive incident response strategies within the education sector to safeguard sensitive user data and maintain operational continuity. ([malwarebytes.com](https://www.malwarebytes.com/blog/news/2026/05/shinyhunters-escalates-canvas-attacks-with-school-login-defacements?utm_source=openai))
2 months ago
Kill Chain
Instructure Canvas Breach 2026: A Wake-Up Call for Educational Cybersecurity
In April 2026, Instructure, the developer of the Canvas Learning Management System (LMS), experienced a significant data breach executed by the cybercriminal group ShinyHunters. The attackers exploited vulnerabilities in the Free-for-Teacher environment, leading to unauthorized access and the exfiltration of approximately 3.6 terabytes of data, affecting over 8,800 educational institutions and 275 million users. Compromised information included names, email addresses, student ID numbers, and private messages. Subsequently, in May 2026, ShinyHunters leveraged the same vulnerabilities to deface Canvas login portals, displaying ransom messages and demanding payment to prevent further data exposure. This incident underscores the critical need for robust security measures in educational platforms, especially as cybercriminals increasingly target the education sector. The exploitation of cross-site scripting (XSS) vulnerabilities highlights the importance of regular security assessments and prompt patching to mitigate such risks.
2 months ago
Kill Chain
ShinyHunters Breach Exposes 275 Million Canvas Users in 2026
In early May 2026, Instructure, the parent company of the Canvas learning management system, experienced a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers exploited vulnerabilities related to 'Free-For-Teacher' accounts, accessing personal information of approximately 275 million users across nearly 9,000 educational institutions worldwide. Compromised data included names, email addresses, student ID numbers, and private messages, though passwords and financial information were reportedly unaffected. The breach led to widespread disruptions, including the postponement of final exams in numerous colleges and universities. ([instructure.com](https://www.instructure.com/incident_update?utm_source=openai)) This incident underscores the escalating threat posed by sophisticated cybercriminal groups targeting educational platforms. The timing, coinciding with critical academic periods, highlights the potential for significant operational disruptions. Educational institutions must prioritize robust cybersecurity measures to safeguard sensitive user data and ensure continuity of educational services.
2 months ago
Kill Chain
Fake OpenAI Repository on Hugging Face Delivers Infostealer Malware
In May 2026, a malicious repository named 'Open-OSS/privacy-filter' was discovered on Hugging Face, impersonating OpenAI's legitimate 'Privacy Filter' project. This repository contained a 'loader.py' script that, when executed, downloaded and ran a Rust-based infostealer malware on Windows systems. The malware targeted sensitive data, including browser credentials, cryptocurrency wallets, and system information. The repository reached the top of Hugging Face's trending list with over 244,000 downloads before being removed. This incident underscores the growing trend of supply chain attacks targeting AI and machine learning platforms. As these platforms become integral to various industries, ensuring the integrity of shared repositories is paramount to prevent the distribution of malicious code.
2 months ago
Kill Chain
ShinyHunters' 2026 Breach of Instructure's Canvas LMS: A Wake-Up Call for Educational Cybersecurity
In early May 2026, Instructure, the company behind the Canvas learning management system, suffered a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers accessed personal information of approximately 275 million individuals across nearly 9,000 educational institutions worldwide. Compromised data included names, email addresses, student ID numbers, and billions of private messages exchanged between students and educators. Although Instructure reported that passwords and financial information were not affected, the breach led to widespread disruptions, including defaced login portals and service outages during critical academic periods. ([techradar.com](https://www.techradar.com/pro/security/canvas-school-login-portals-hacked-as-instructure-hack-apparently-gets-even-worse?utm_source=openai)) This incident underscores the escalating threat posed by cyber extortion groups targeting large-scale educational platforms. The breach highlights the vulnerabilities inherent in centralized educational systems and the potential for significant operational disruptions and data privacy concerns. Educational institutions must reassess their cybersecurity strategies to mitigate risks associated with third-party service providers and ensure the protection of sensitive user information. ([insidehighered.com](https://www.insidehighered.com/news/tech-innovation/administrative-tech/2026/05/05/pay-or-leak-hackers-target-big-higher-ed-vendor?utm_source=openai))
2 months ago
Kill Chain
ShinyHunters Breach Canvas: 275 Million Users' Data Exposed
In early May 2026, the cybercriminal group ShinyHunters executed a data extortion attack on Instructure's Canvas learning management system, compromising personal information of approximately 275 million users across nearly 9,000 educational institutions worldwide. The breach exposed names, email addresses, student ID numbers, and private messages between students and faculty. The attackers defaced Canvas login pages with ransom demands, leading to widespread disruptions during critical academic periods, including final exams. ([apnews.com](https://apnews.com/article/446c240d5aeb1b1a1e3795fb92237563?utm_source=openai)) This incident underscores the escalating threat of cyberattacks targeting educational platforms, highlighting the urgent need for robust cybersecurity measures in the education sector. The timing of the attack, coinciding with final exams, emphasizes the potential for significant operational impact and the importance of proactive defense strategies against such threats.
2 months ago
Kill Chain
Critical Vulnerability in MAXHUB Pivot Client Application: CVE-2025-53704
In December 2025, a critical vulnerability (CVE-2025-53704) was identified in the MAXHUB Pivot client application versions prior to v1.36.2. This flaw involved a weak password recovery mechanism, allowing remote attackers to request password resets and gain unauthorized access to user accounts without prior authentication. The vulnerability posed significant risks, including potential data breaches and unauthorized control over affected systems. The incident underscores the importance of robust authentication mechanisms and timely software updates. Organizations are advised to upgrade to version 1.36.2 or newer to mitigate this risk. This case highlights the ongoing need for vigilance against authentication vulnerabilities in widely used applications.
2 months ago
Kill Chain
ShinyHunters' 2026 Canvas Data Breach: A Wake-Up Call for Educational Cybersecurity
In early May 2026, the cybercriminal group ShinyHunters executed a significant data breach targeting Instructure's Canvas learning management system. This attack compromised personal information—including names, email addresses, student ID numbers, and user communications—of approximately 275 million users across nearly 9,000 educational institutions worldwide. Notable universities such as MIT, Harvard, Oxford, and UC Berkeley were among those affected. The breach led to widespread disruptions, particularly as students were preparing for final exams. ([apnews.com](https://apnews.com/article/446c240d5aeb1b1a1e3795fb92237563?utm_source=openai)) This incident underscores the escalating threat posed by cybercriminal groups like ShinyHunters, who have a history of targeting educational platforms. The breach highlights the critical need for robust cybersecurity measures within educational institutions to protect sensitive data and maintain operational continuity. ([apnews.com](https://apnews.com/article/a0d7719689263e6b5f90d0e633391b5b?utm_source=openai))
2 months ago
Kill Chain
ShinyHunters' Exploitation of Instructure's Vulnerability Leads to Canvas Login Portal Defacements
In May 2026, the ShinyHunters extortion group exploited a vulnerability in Instructure's systems to deface Canvas login portals for approximately 330 educational institutions. The defacements displayed messages claiming responsibility for a prior breach and threatened to leak stolen data unless a ransom was paid by May 12, 2026. Instructure responded by taking Canvas offline to address the cyberattack. This incident underscores the escalating threat posed by cyber extortion groups targeting educational institutions. The breach highlights the critical need for robust cybersecurity measures and prompt incident response to protect sensitive student and staff data from unauthorized access and potential exploitation.
2 months ago
Kill Chain
Instructure Data Breach 2026: Lessons for Educational Institutions
In May 2026, Instructure, the company behind the Canvas learning management system, disclosed a significant data breach. The cybercriminal group ShinyHunters claimed responsibility, alleging the theft of 3.65 terabytes of data affecting approximately 275 million users across nearly 9,000 educational institutions. The compromised data includes names, email addresses, student ID numbers, and user communications. Instructure responded by revoking credentials, patching vulnerabilities, rotating keys, and enhancing monitoring. This incident underscores the critical need for educational institutions to assess and strengthen their third-party vendor security practices to protect sensitive student and staff information.
2 months ago
Kill Chain
MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks
In April 2026, a critical vulnerability identified as CVE-2026-29014 was discovered in MetInfo CMS versions 7.9, 8.0, and 8.1. This unauthenticated PHP code injection flaw allows remote attackers to execute arbitrary code by sending crafted requests containing malicious PHP code. The vulnerability stems from insufficient input neutralization in the execution path, specifically within the "/app/system/weixin/include/class/weixinreply.class.php" script, leading to potential full control over affected servers. ([thehackernews.com](https://thehackernews.com/2026/05/metinfo-cms-cve-2026-29014-exploited.html?utm_source=openai)) As of May 2026, active exploitation of this vulnerability has been observed, with attackers targeting MetInfo CMS instances, particularly in China and Hong Kong. The ease of exploitation and the critical nature of the flaw underscore the urgency for organizations using affected versions to apply the available patches promptly to mitigate the risk of server compromise. ([thehackernews.com](https://thehackernews.com/2026/05/metinfo-cms-cve-2026-29014-exploited.html?utm_source=openai))
2 months ago
Kill Chain
Instructure Data Breach: ShinyHunters Compromise 275 Million Records in 2026
In May 2026, Instructure, a leading educational technology company known for its Canvas learning management system, confirmed a significant data breach. The cyber extortion group ShinyHunters claimed responsibility, alleging the theft of data from nearly 9,000 schools worldwide, affecting approximately 275 million individuals. The compromised information includes names, email addresses, student ID numbers, and private messages exchanged between users. Instructure has stated that, to date, there is no evidence that passwords, dates of birth, government identifiers, or financial information were involved. The company has implemented patches, increased monitoring, and rotated application keys as precautionary measures. This incident underscores the escalating threat posed by cyber extortion groups targeting educational institutions. The breach highlights the critical need for robust cybersecurity measures and proactive incident response strategies within the education sector to protect sensitive personal information and maintain trust.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports