LIVE · cybersecurity feed
Live wire
Malware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on Host
patch

Weekly Update 505

Well, that didn't last long! Recording this on Saturday morning my time, I observed ShinyHunters having gone quiet since the massive haul that would have been the Instructure ransom. It was two weeks almost to the hour since I'd first heard

zeroday.news ·

A significant data breach impacting Instructure, the company behind the Canvas learning management system, appears to have been averted or mitigated shortly after it was discovered. The threat actor group ShinyHunters, which had claimed responsibility for the incident, ceased its activity shortly after the initial reports of the breach.

Details surrounding the exact nature and scope of the Instructure incident remain limited. However, the rapid cessation of the threat actor's public activity suggests a swift response from Instructure or a successful disruption of the attackers' operations. The timeframe for this de-escalation was approximately two weeks from the initial awareness of the breach.

ShinyHunters has been a prolific actor in the data breach landscape, known for exfiltrating and selling sensitive information from compromised organizations. Their involvement in the Instructure incident initially raised concerns about the potential exposure of user data.

The specific data that may have been accessed or targeted in the Instructure breach has not been publicly disclosed. Similarly, the precise methods used by ShinyHunters to gain access to Instructure's systems have not been detailed.

The swiftness with which ShinyHunters went silent following the Instructure incident is noteworthy. This could indicate that Instructure successfully contained the breach, restored systems, or otherwise deterred the attackers from further action or data publication.

While the immediate threat appears to have subsided, the incident serves as a reminder of the persistent risks posed by sophisticated threat actors. Organizations, particularly those handling large amounts of sensitive data like educational institutions, must maintain robust security postures.

Standard cybersecurity best practices, such as regular security audits, vulnerability management, and employee training on phishing and social engineering, remain critical in preventing and responding to such incidents. Data encryption and strong access controls are also fundamental layers of defense.

The full impact and any lingering effects of the Instructure incident are not yet fully understood, but the apparent containment by the threat actor's withdrawal is a positive development. Further details may emerge as investigations, if ongoing, progress.

patch
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

Hackers infect Android car head units with proxy botnet malware

A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]

security

Postal Service moves to finalize mail ballot regs before SCOTUS ruling

The rules have already been rejected by multiple state courts, but the Trump administration said it’s preparing in case of a favorable Supreme Court decision. The post Postal Service moves to finalize mail ballot regs before SCOTUS ruling appeared first on CyberScoop.

vulnerability

ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries

ToxicPanda 2.0 targets 349 financial apps and abuses Android Wireless Debugging to gain deeper device access and steal banking credentials. ToxicPanda used to be a Europe-focused nuisance targeting a manageable list of banks. That version is gone. Zimperium’s zLabs team just documented ToxicPanda 2.0, and the numbers alone tell the story: 349 targeted financial institutions […]

ai

If you're not using AI to attack your own systems, your adversaries will

Agents are also the new attack surface - cue defenders' existential angst

privacy

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

TikTok has agreed to a $400 million settlement with the U.S. Department of Justice to resolve a lawsuit alleging violations of child privacy laws. The lawsuit, filed in 2024, accused the company of improperly collecting data from users under 13 and failing to comply with parental requests to delete accounts. The settlement includes an immediate payment of $300 million and an additional $100 million contingent on the dissolution of a prior consent decree related to Musical.ly.

security

Named Pipes Under Attack: Securing Windows Interprocess Communication

Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict input validation, and narrowly scoped privileges can help secure named-pipe communication. [...]