{"id":244045,"date":"2026-05-11T11:26:00","date_gmt":"2026-05-11T15:26:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/05\/11\/instructure-confirms-hackers-used-canvas-flaw-to-deface-portals\/"},"modified":"2026-05-11T21:45:09","modified_gmt":"2026-05-12T01:45:09","slug":"instructure-confirms-hackers-used-canvas-flaw-to-deface-portals","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/05\/11\/instructure-confirms-hackers-used-canvas-flaw-to-deface-portals\/","title":{"rendered":"Instructure confirms hackers used Canvas flaw to deface portals"},"content":{"rendered":"<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/instructure-confirms-hackers-used-canvas-flaw-to-deface-portals\/\">Instructure confirms hackers used Canvas flaw to deface portals<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/instructure-confirms-hackers-used-canvas-flaw-to-deface-portals\/\">https:\/\/www.bleepingcomputer.com\/news\/security\/instructure-confirms-hackers-used-canvas-flaw-to-deface-portals\/<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-05-11 11:26:00<\/a><\/p>\n<p>Source Domain: <a href=\"www.bleepingcomputer.com\">www.bleepingcomputer.com<\/a><\/p>\n<p style=\"text-align:center\">\n<p>Education technology giant Instructure has confirmed that a security vulnerability allowed hackers to modify Canvas login portals and leave an extortion message.<\/p>\n<p>BleepingComputer has learned that both the breach and defacements involved multiple cross-site scripting (XSS) vulnerabilities that enabled the attacker to obtain authenticated admin sessions.<\/p>\n<p>The second hack was to draw attention and to\u00a0pressure Instructure into entering negotiations to pay a ransom following an initial breach disclosed a week before.<\/p>\n<p>Instructure is the developer of Canvas, a popular learning management system (LMS) used by schools and universities around the world to handle assignments and coursework.<\/p>\n<p>On April 29, the company discovered that its network had been breached and \u201cimmediately revoked the unauthorized party\u2019s access, started an investigation, and engaged outside forensic experts.\u201d<\/p>\n<p>A few days later, the company confirmed that data was stolen in the cyberattack, and ShinyHunters published Instructure on their data leak site, stating that they stole more than 3.6 terabytes of uncompressed data.<\/p>\n<p>In an attempt to coerce Instructure into paying a ransom, the threat actor hacked Instructure again on May 7 using the same vulnerability used in the initial intrusion.<\/p>\n<p>ShinyHunters injected malicious JavaScript exploiting\u00a0XSS bugs within user-generated content features, which gave them access\u00a0to\u00a0authenticated admin sessions and allowed them to perform privileged actions.<\/p>\n<p>In an email to BleepingComputer on Sunday, Instructure confirmed that the exploited security issue affected the Free-for-Teacher environment, the free, limited\u00a0version of Canvas LMS for individual educators.<\/p>\n<p>\u201cThe unauthorized actor made changes to the pages that appeared when some students and teachers were logged in through Canvas\u201d &#8211; Instructure<\/p>\n<p>At the time, the organization added that it temporarily took Canvas offline to prevent the malicious activity from spreading, determine the&#8230;<\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/instructure-confirms-hackers-used-canvas-flaw-to-deface-portals\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Instructure confirms hackers used Canvas flaw to deface portals https:\/\/www.bleepingcomputer.com\/news\/security\/instructure-confirms-hackers-used-canvas-flaw-to-deface-portals\/ Publish Date: 2026-05-11 11:26:00 Source&#8230;<\/p>\n","protected":false},"author":1,"featured_media":244046,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.bleepstatic.com\/content\/hl-images\/2026\/05\/01\/instructure-header2.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[30,34,27],"class_list":["post-244045","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-breach","tag-threat-actor","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/244045"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=244045"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/244045\/revisions"}],"predecessor-version":[{"id":244047,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/244045\/revisions\/244047"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/244046"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=244045"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=244045"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=244045"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}