// Alert

Canvas threat report

// CanvasCRITICAL

In late April 2026, ShinyHunters breached Instructure's Canvas Learning Management System through stored cross-site scripting vulnerabilities in the Free-For-Teacher program tier. The attackers exfiltrated 3.65 terabytes of data affecting 8,809 institutions worldwide, defaced login pages at hundreds of schools, and disrupted student access during finals week. Instructure paid a ransom and discontinued the vulnerable freemium tier; a recompromise attempt occurred within 24 hours after the initial disclosure, revealing that the underlying trust boundary flaw persisted.

// Get alerts for Canvas