The Canvas breach and the cost of multi-tenant blast radius

Originally published on arkensec.com Between April 29 and May 7, 2026, ShinyHunters claimed two consecutive breaches of Instructure — the company behind Canvas, the LMS running on 41% of North American higher ed. The group says it pulled 3.65 TB and 275 million records spanning 8,809 schools, then defaced Canvas login pages when Instructure shipped patches instead of negotiating. No exotic CVE. No kernel exploit. The stated vector: "an issue related to its Free-For-Teacher accounts." 8,809 sc...

Original Source

Read the full article at Dev →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.