LIVE · cybersecurity feed
Live wire
breach

Weekly Update 503

Well, it's the day before the Instructure "pay or leak" deadline (at least by my Aussie watch), and the company remains removed from the ShinyHunters website. In its place sits a press statement that amounts to "we're not making any stateme

zeroday.news · 82d ago

Instructure, the company behind the Canvas learning management system, has not yet publicly addressed a potential data breach, despite a deadline set by a ransomware group known as ShinyHunters. The group had threatened to leak data allegedly stolen from Instructure by November 20th.

As of November 19th, the ShinyHunters website did not feature any data attributed to Instructure. Instead, a press statement from Instructure was present, which the company described as "we're not making any statements." This indicates a lack of public communication from Instructure regarding the alleged incident.

The situation remains fluid, with the deadline for the alleged data leak approaching. It is unclear whether ShinyHunters will proceed with releasing any information or if a resolution has been reached between the ransomware group and Instructure.

This incident highlights the ongoing threat posed by ransomware groups targeting organizations and the potential consequences of data exfiltration. Companies are often faced with difficult decisions when confronting such attacks, balancing the risks of data exposure against the demands of cybercriminals.

Further updates are expected as the situation develops. Organizations are generally advised to maintain robust cybersecurity practices, including regular data backups, strong access controls, and employee training on phishing and social engineering tactics, to mitigate the impact of potential cyberattacks.

breachpatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]