Canvas breach uses XSS to deface portals and pressure ransom campaigns

1 min read
Source: BleepingComputer
Canvas breach uses XSS to deface portals and pressure ransom campaigns
Photo: BleepingComputer
TL;DR Summary

Instructure confirmed attackers exploited multiple cross-site scripting flaws in the Canvas Free-for-Teacher environment to hijack authenticated admin sessions, deface login portals, and trigger a ransom demand by ShinyHunters. The initial breach exposed data from about 8,809 educational organizations, with ShinyHunters claiming as many as 275 million records stolen; the defacement itself did not involve direct data loss, and Canvas has since been restored after a temporary shutdown.

Share this article

Reading Insights

Total Reads

0

Unique Readers

9

Time Saved

4 min

vs 5 min read

Condensed

92%

81767 words

Want the full story? Read the original article

Read on BleepingComputer