Well, that didn't last long! Recording this on Saturday morning my time, I observed ShinyHunters having gone quiet since the massive haul that would have been the Instructure ransom. It was two weeks almost to the hour since I'd first heard

A significant data breach impacting Instructure, the company behind the Canvas learning management system, appears to have been averted or mitigated shortly after it was discovered. The threat actor group ShinyHunters, which had claimed responsibility for the incident, ceased its activity shortly after the initial reports of the breach.
Details surrounding the exact nature and scope of the Instructure incident remain limited. However, the rapid cessation of the threat actor's public activity suggests a swift response from Instructure or a successful disruption of the attackers' operations. The timeframe for this de-escalation was approximately two weeks from the initial awareness of the breach.
ShinyHunters has been a prolific actor in the data breach landscape, known for exfiltrating and selling sensitive information from compromised organizations. Their involvement in the Instructure incident initially raised concerns about the potential exposure of user data.
The specific data that may have been accessed or targeted in the Instructure breach has not been publicly disclosed. Similarly, the precise methods used by ShinyHunters to gain access to Instructure's systems have not been detailed.
The swiftness with which ShinyHunters went silent following the Instructure incident is noteworthy. This could indicate that Instructure successfully contained the breach, restored systems, or otherwise deterred the attackers from further action or data publication.
While the immediate threat appears to have subsided, the incident serves as a reminder of the persistent risks posed by sophisticated threat actors. Organizations, particularly those handling large amounts of sensitive data like educational institutions, must maintain robust security postures.
Standard cybersecurity best practices, such as regular security audits, vulnerability management, and employee training on phishing and social engineering, remain critical in preventing and responding to such incidents. Data encryption and strong access controls are also fundamental layers of defense.
The full impact and any lingering effects of the Instructure incident are not yet fully understood, but the apparent containment by the threat actor's withdrawal is a positive development. Further details may emerge as investigations, if ongoing, progress.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets