A security breach of Canvas, a widely-used learning management platform, has disrupted classes and postponed final exams at numerous colleges and primary schools during the academic year's critical closing weeks.
Canvas, owned by Instructure, serves millions of students across educational institutions globally. The breach compromised the platform's infrastructure, forcing administrators to take systems offline while investigating the scope of the intrusion.
Affected schools have been forced to reschedule final exams and move coursework to alternative platforms or delay assessments indefinitely. The timing of the breach creates significant disruption, coming as students prepare for end-of-semester evaluations that impact grades and academic standing.
Canvas hosts critical academic functions including grade posting, assignment submission, and exam administration. The outage has created logistical challenges for institutions attempting to maintain academic calendars while ensuring the integrity of assessments.
Instructure has not yet released detailed information about the breach's scope, including how many user accounts were affected or what data was accessed. The company acknowledged the incident and stated it is working with cybersecurity experts to investigate and restore full service.
Institutions using Canvas have advised students and faculty to monitor communications for updates on when services will resume. Some schools have implemented temporary workarounds using email and document-sharing platforms to continue coursework.
The incident highlights the risks educational institutions face when relying on centralized third-party platforms for critical academic functions. A single breach can cascade across hundreds of schools simultaneously, affecting hundreds of thousands of students.
Instructure has not announced a timeline for full platform restoration or details about what specific security vulnerabilities led to the breach. Affected institutions are preparing contingency plans for final exam administration and grade submission deadlines.
A malicious npm campaign demonstrates how threat actors are evading supply chain protections by embedding malware in package runtime behavior instead of installation scripts. The 'indexed-btree' package exemplifies this evolving attack technique.
Cybercriminals are exploiting lookalike characters from different alphabets to create fake URLs that appear legitimate to the naked eye. These homoglyph attacks bypass traditional security checks and trick users into visiting malicious sites.
The ShinyHunters extortion gang has compromised the Clop ransomware operation's data leak site, defacing it and stealing server data and private encryption keys.
Despite growing concerns about AI-driven cyberattacks, human actors remain the primary cybersecurity risk to critical energy infrastructure. Security experts warn vulnerabilities in power systems continue to expand.