A data extortion attack against Instructure’s Canvas platform defaced login pages and threatened to leak data allegedly tied to 275 million student and faculty accounts, disrupting coursework and finals across K–12 and higher education. The incident underscores the fragility of ed‑tech ecosystems and the downstream risk to SSO credentials and synced third‑party tools. Institutions should enforce MFA, monitor for credential reuse, and review SSO/OAuth app scopes tied to Canvas.
Source: KrebsOnSecurity
Nation‑state operators exploit Palo Alto PAN‑OS zero‑day for weeks
A critical buffer overflow in PAN‑OS’s User‑ID Authentication Portal (CVE‑2026‑0300) has been exploited since early April, granting unauthenticated remote code execution and root‑level access on exposed firewalls. Researchers say the campaign bears hallmarks of Chinese state hacking. Urgently apply vendor mitigations/patches, remove public exposure of the Auth Portal, rotate credentials, and hunt for tunneling tools and suspicious config changes.
Source: SecurityWeek
Dirty Frag: new Linux kernel LPE (CVE‑2026‑43284) follows “Copy Fail”
Researchers detailed “Dirty Frag” (CVE‑2026‑43284), a local privilege escalation affecting major Linux distributions and related to last month’s “Copy Fail” kernel bug. The flaw enables unprivileged users to escalate to root, raising concern for multi‑tenant servers and container hosts where local footholds are common. Limit untrusted local access, enable kernel hardening where possible, and prioritize kernel updates as vendor patches land.
Source: Wiz
Ivanti EPMM admin RCE (CVE‑2026‑6973) added to CISA KEV amid active exploitation
Ivanti patched a high‑severity flaw in Endpoint Manager Mobile that allows authenticated admins to execute arbitrary code, and CISA added the bug to its Known Exploited Vulnerabilities catalog. Ivanti and multiple researchers report limited, targeted exploitation in the wild. Organizations should patch to the latest fixed versions immediately, audit admin actions, rotate credentials, and review device management trust relationships.
Source: Security Affairs
Attackers used Claude AI to steer toward OT assets in water utility breach
Dragos reports threat actors leveraged the Claude AI assistant during an intrusion at a Mexican water and drainage utility to identify pathways into operational technology environments. The case highlights how LLMs can accelerate reconnaissance and technique selection against IT/OT networks. Utilities should enforce strict IT/OT segmentation, monitor for AI tool usage, and implement egress controls and AI access policies for contractors and staff.
Source: SecurityWeek
Claude Code OAuth tokens can be stolen via stealthy MCP hijacking
Mitiga researchers found that attackers can silently redirect Model Context Protocol (MCP) traffic used by Claude Code, intercept OAuth tokens, and maintain persistent access to connected SaaS platforms. The finding adds to a growing class of AI‑agent and extension risks, where over‑privileged connectors and implicit trust chains expand blast radius. Lock down MCP endpoints, restrict extension permissions, rotate OAuth tokens, and apply vendor updates.
Source: SecurityWeek
Cisco patches high‑severity flaws enabling SSRF, code execution, and DoS
Cisco released fixes across multiple enterprise products, including Unity Connection SSRF issues that could enable code execution or service disruption. Given attackers’ growing focus on edge and collaboration systems, administrators should prioritize these updates, disable unnecessary network exposure, and monitor for anomalous service requests that could indicate SSRF probing.
Source: SecurityWeek
You May Also Be Interested In...
Ransomware group takes credit for Trellix hackESET: 7M+ downloads of fraudulent Android “call history” apps
Chrome 148 ships with 127 security fixes