×
The Canvas Hack Is a New Kind of Ransomware DebacleHigher education has long been a target of ransomware gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software platform so thoroughly disrupted the daily operations of thousands of schools across the United States.The widely used digital learning platform Canvas was put into “maintenance mode” on Thursday after its maker, the education tech giant Instructure, suffered a data breach and faced an extortion attempt by attackers using the recognizable moniker “ShinyHunters.” Though the hackers have been advertising the breach and attempting to extract a ransom payment from Instructure since May 1, the situation took on additional immediacy for regular people across the US and beyond on Thursday because the Canvas downtime caused chaos at schools, including those in the midst of finals and end-of-year assignments.Universities like Harvard, Columbia, Rutgers, and Georgetown sent alerts to students about the situation in recent days; other institutions, including school districts in at least a dozen states, also appear to have been affected. In a list published by the hackers behind the attack on their ransom-focused dark web site, they claim the breach affected more than 8,800 schools. The exact scale and reach of the breach is currently unclear, though. And the fact that Canvas was down throughout Thursday afternoon and evening further complicated the picture.In a running incident update log that began on May 1, Steve Proud, Instructure’s chief information security officer, said that the company had “recently experienced a cybersecurity incident perpetrated by a criminal threat actor.” He added on May 2 that “the information involved” for “users at affected institutions” included names, email addresses, student ID numbers, and messages exchanged by users on the platform.The situation was ultimately marked as “Resolved” on Wednesday, with Proud writing that “Canvas is fully operational, and we are not seeing any ongoing unauthorized activity.” At midday on Thursday, though, the Instructure status page registered an “issue” where “some users are having difficulties logging into Student ePortfolios.” Within a few hours, the company had added another status update: “Instructure has placed Canvas, Canvas Beta and Canvas Test in maintenance mode.” Late Thursday evening, the company said that Canvas was available again “for most users.”TechCrunch reported on Thursday that the hackers launched a secondary wave of attacks, defacing some schools’ Canvas portals by injecting an HTML file to display their own message on the schools’ Canvas login pages. According to The Harvard Crimson, attackers modified the Harvard Canvas login page to show a message that included a list of schools that the hackers claim were impacted by the breach.The message from attackers “urged schools included on the affected list to consult with a cyber advisory firm and contact the group privately to negotiate a settlement before the end of the day on May 12—or else risk their data being leaked,” The Crimson reported. “It is unclear what information tied to Harvard affiliates was included in the alleged breach.”Instructure did not immediately respond to a request for comment about Thursday’s outages and how they fit into the bigger picture of the breach. But the situation is significant given that a massive trove of student information has potentially been exposed, and the visibility of the incident across the country makes it a key example of a longstanding, yet endlessly escalating problem of data extortion and ransomware attacks.The ShinyHunters name is associated with massive data dumps and has been linked to the infamous hacker collective known as the Com. But as the constellation of actors has shifted over the years, numerous attackers have taken up the most prominent Com-related monikers. A number of recent attacks have invoked other names, such as Lapsus$, with little or no connection to the original group that operated under the name.#Canvas #Hack #Kind #Ransomware #Debacleransomware,cybersecurity,malware,hacks,hacking,security,vulnerabilities

The Canvas Hack Is a New Kind of Ransomware Debacle

Higher education has long been a target of ransomware gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software platform so thoroughly disrupted the daily operations of thousands of schools across the United States.

The widely used digital learning platform Canvas was put into “maintenance mode” on Thursday after its maker, the education tech giant Instructure, suffered a data breach and faced an extortion attempt by attackers using the recognizable moniker “ShinyHunters.” Though the hackers have been advertising the breach and attempting to extract a ransom payment from Instructure since May 1, the situation took on additional immediacy for regular people across the US and beyond on Thursday because the Canvas downtime caused chaos at schools, including those in the midst of finals and end-of-year assignments.

Universities like Harvard, Columbia, Rutgers, and Georgetown sent alerts to students about the situation in recent days; other institutions, including school districts in at least a dozen states, also appear to have been affected. In a list published by the hackers behind the attack on their ransom-focused dark web site, they claim the breach affected more than 8,800 schools. The exact scale and reach of the breach is currently unclear, though. And the fact that Canvas was down throughout Thursday afternoon and evening further complicated the picture.

In a running incident update log that began on May 1, Steve Proud, Instructure’s chief information security officer, said that the company had “recently experienced a cybersecurity incident perpetrated by a criminal threat actor.” He added on May 2 that “the information involved” for “users at affected institutions” included names, email addresses, student ID numbers, and messages exchanged by users on the platform.

The situation was ultimately marked as “Resolved” on Wednesday, with Proud writing that “Canvas is fully operational, and we are not seeing any ongoing unauthorized activity.” At midday on Thursday, though, the Instructure status page registered an “issue” where “some users are having difficulties logging into Student ePortfolios.” Within a few hours, the company had added another status update: “Instructure has placed Canvas, Canvas Beta and Canvas Test in maintenance mode.” Late Thursday evening, the company said that Canvas was available again “for most users.”

TechCrunch reported on Thursday that the hackers launched a secondary wave of attacks, defacing some schools’ Canvas portals by injecting an HTML file to display their own message on the schools’ Canvas login pages. According to The Harvard Crimson, attackers modified the Harvard Canvas login page to show a message that included a list of schools that the hackers claim were impacted by the breach.

The message from attackers “urged schools included on the affected list to consult with a cyber advisory firm and contact the group privately to negotiate a settlement before the end of the day on May 12—or else risk their data being leaked,” The Crimson reported. “It is unclear what information tied to Harvard affiliates was included in the alleged breach.”

Instructure did not immediately respond to a request for comment about Thursday’s outages and how they fit into the bigger picture of the breach. But the situation is significant given that a massive trove of student information has potentially been exposed, and the visibility of the incident across the country makes it a key example of a longstanding, yet endlessly escalating problem of data extortion and ransomware attacks.

The ShinyHunters name is associated with massive data dumps and has been linked to the infamous hacker collective known as the Com. But as the constellation of actors has shifted over the years, numerous attackers have taken up the most prominent Com-related monikers. A number of recent attacks have invoked other names, such as Lapsus$, with little or no connection to the original group that operated under the name.

#Canvas #Hack #Kind #Ransomware #Debacleransomware,cybersecurity,malware,hacks,hacking,security,vulnerabilities

Higher education has long been a target of ransomware gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software platform so thoroughly disrupted the daily operations of thousands of schools across the United States.

The widely used digital learning platform Canvas was put into “maintenance mode” on Thursday after its maker, the education tech giant Instructure, suffered a data breach and faced an extortion attempt by attackers using the recognizable moniker “ShinyHunters.” Though the hackers have been advertising the breach and attempting to extract a ransom payment from Instructure since May 1, the situation took on additional immediacy for regular people across the US and beyond on Thursday because the Canvas downtime caused chaos at schools, including those in the midst of finals and end-of-year assignments.

Universities like Harvard, Columbia, Rutgers, and Georgetown sent alerts to students about the situation in recent days; other institutions, including school districts in at least a dozen states, also appear to have been affected. In a list published by the hackers behind the attack on their ransom-focused dark web site, they claim the breach affected more than 8,800 schools. The exact scale and reach of the breach is currently unclear, though. And the fact that Canvas was down throughout Thursday afternoon and evening further complicated the picture.

In a running incident update log that began on May 1, Steve Proud, Instructure’s chief information security officer, said that the company had “recently experienced a cybersecurity incident perpetrated by a criminal threat actor.” He added on May 2 that “the information involved” for “users at affected institutions” included names, email addresses, student ID numbers, and messages exchanged by users on the platform.

The situation was ultimately marked as “Resolved” on Wednesday, with Proud writing that “Canvas is fully operational, and we are not seeing any ongoing unauthorized activity.” At midday on Thursday, though, the Instructure status page registered an “issue” where “some users are having difficulties logging into Student ePortfolios.” Within a few hours, the company had added another status update: “Instructure has placed Canvas, Canvas Beta and Canvas Test in maintenance mode.” Late Thursday evening, the company said that Canvas was available again “for most users.”

TechCrunch reported on Thursday that the hackers launched a secondary wave of attacks, defacing some schools’ Canvas portals by injecting an HTML file to display their own message on the schools’ Canvas login pages. According to The Harvard Crimson, attackers modified the Harvard Canvas login page to show a message that included a list of schools that the hackers claim were impacted by the breach.

The message from attackers “urged schools included on the affected list to consult with a cyber advisory firm and contact the group privately to negotiate a settlement before the end of the day on May 12—or else risk their data being leaked,” The Crimson reported. “It is unclear what information tied to Harvard affiliates was included in the alleged breach.”

Instructure did not immediately respond to a request for comment about Thursday’s outages and how they fit into the bigger picture of the breach. But the situation is significant given that a massive trove of student information has potentially been exposed, and the visibility of the incident across the country makes it a key example of a longstanding, yet endlessly escalating problem of data extortion and ransomware attacks.

The ShinyHunters name is associated with massive data dumps and has been linked to the infamous hacker collective known as the Com. But as the constellation of actors has shifted over the years, numerous attackers have taken up the most prominent Com-related monikers. A number of recent attacks have invoked other names, such as Lapsus$, with little or no connection to the original group that operated under the name.

Source link
#Canvas #Hack #Kind #Ransomware #Debacle

Previous post

T20 Captain: टीम इंडिया से सूर्यकुमार यादव की छुट्टी तय! जिसे नहीं मिली टी20 वर्ल्ड कप में जगह अब वह बनेगा नया कप्तान

Next post

इंदौर में देवास नाका, सत्यसाईं चौराहा, आईटी पार्क और मूसाखेड़ी चौराहे पर बन रहे फ्लाईओवर की सर्विस रोड खराब, सुबह-शाम लगता है जाम


Ubisoft’s biggest franchise found itself in the perfect position to capitalize on ‘The Odyssey’ and its ongoing success.#Odyssey #Big #People #Assassins #CreedAssassin’s Creed,Christopher Nolan,The Odyssey">‘The Odyssey’ Is So Big, It’s Made People Like ‘Assassin’s Creed’ AgainUbisoft’s biggest franchise found itself in the perfect position to capitalize on ‘The Odyssey’ and its ongoing success.#Odyssey #Big #People #Assassins #CreedAssassin’s Creed,Christopher Nolan,The Odyssey
The downside of KeePassXC is that it doesn’t have official mobile clients. However, third-party apps are available for iOS and Android. KeePassXC is a fork of KeePass that offers better cross-platform support, but there are a handful of other forks available, as well.

Download the desktop app for Windows, macOS, or Linux and create your vault. There are also extensions for Firefox, Edge, and Chrome. The project does not offer apps for phones. Instead, it recommends KeePass2Android or Strongbox for iPhone.


Other Password Managers We’ve Tested

Password managers are not a one-size-fits-all solution. Our top picks cover most use cases and are the best choices for most people, but your needs may be different. Fortunately, there are plenty of good password managers out there. Here are some more we’ve tested.

Google Password Manager (Free): Google has offered a password manager within Chrome for years, but it recently broadened with a dedicated Android app. Although storing passwords in your browser has a few security concerns, Google offers top-notch encryption, the option to turn on on-device encryption, and integration with biometric authentication on Android and Windows. It can even store passkeys. For most people, I recommend a third-party password manager, but if you aren’t using a password manager at all, Google Password Manager is a good option.

RoboForm ($30 Per Year, $48 Per Year for a Five-User Family Plan): RoboForm has most of the same features as the rest on this list, but it lacks some of the things that differentiate our top picks, like Bitwarden’s open source aspect and 1Password’s travel features. I’ve been testing the free plan for a while and haven’t run into any problems. There are apps for every common platform, and it’s easy to use. RoboForm recently completed an independent security audit and came out looking good.

Pass (Free): Pass is a command-line wrapper around GPG (GNU Privacy Guard), which means it is only for the nerdiest users. It supports managing encrypted .gpg files in Git, and third-party mobile apps are available. It’s not for everyone. For years, this was my password manager of choice, but eventually, Bitwarden’s ease of use won me over.

Password Managers to Avoid

Most password managers are decent. Some are more secure than others, but the top password managers largely compete on features and pricing. Security is a prerequisite. However, there are a couple of password managers you should avoid for various reasons.

ExpressKeys by ExpressVPN: ExpressKeys is from ExpressVPN (formerly Keys by ExpressVPN that I tested, but it’s the same product), which ranks among the best VPN services on the market. But ExpressKeys doesn’t live up to the same standard. It’s secure, but I struggled to get it to work with any consistency. The browser extension requires the desktop ExpressVPN app to work, and closing either will force you to sign back in all over again. Worse, ExpressKeys wouldn’t recognize that I was signed into my ExpressVPN account about half the time. It needs some serious fixes before I can recommend it. —Jacob Roach

#Password #Managers #Browserbuying guides,passwords,vulnerabilities,security,software,encryption">The Password Managers You Should Use Instead of Your BrowserThe downside of KeePassXC is that it doesn’t have official mobile clients. However, third-party apps are available for iOS and Android. KeePassXC is a fork of KeePass that offers better cross-platform support, but there are a handful of other forks available, as well.Download the desktop app for Windows, macOS, or Linux and create your vault. There are also extensions for Firefox, Edge, and Chrome. The project does not offer apps for phones. Instead, it recommends KeePass2Android or Strongbox for iPhone.Other Password Managers We’ve TestedPassword managers are not a one-size-fits-all solution. Our top picks cover most use cases and are the best choices for most people, but your needs may be different. Fortunately, there are plenty of good password managers out there. Here are some more we’ve tested.Google Password Manager (Free): Google has offered a password manager within Chrome for years, but it recently broadened with a dedicated Android app. Although storing passwords in your browser has a few security concerns, Google offers top-notch encryption, the option to turn on on-device encryption, and integration with biometric authentication on Android and Windows. It can even store passkeys. For most people, I recommend a third-party password manager, but if you aren’t using a password manager at all, Google Password Manager is a good option.RoboForm ( Per Year,  Per Year for a Five-User Family Plan): RoboForm has most of the same features as the rest on this list, but it lacks some of the things that differentiate our top picks, like Bitwarden’s open source aspect and 1Password’s travel features. I’ve been testing the free plan for a while and haven’t run into any problems. There are apps for every common platform, and it’s easy to use. RoboForm recently completed an independent security audit and came out looking good.Pass (Free): Pass is a command-line wrapper around GPG (GNU Privacy Guard), which means it is only for the nerdiest users. It supports managing encrypted .gpg files in Git, and third-party mobile apps are available. It’s not for everyone. For years, this was my password manager of choice, but eventually, Bitwarden’s ease of use won me over.Password Managers to AvoidMost password managers are decent. Some are more secure than others, but the top password managers largely compete on features and pricing. Security is a prerequisite. However, there are a couple of password managers you should avoid for various reasons.ExpressKeys by ExpressVPN: ExpressKeys is from ExpressVPN (formerly Keys by ExpressVPN that I tested, but it’s the same product), which ranks among the best VPN services on the market. But ExpressKeys doesn’t live up to the same standard. It’s secure, but I struggled to get it to work with any consistency. The browser extension requires the desktop ExpressVPN app to work, and closing either will force you to sign back in all over again. Worse, ExpressKeys wouldn’t recognize that I was signed into my ExpressVPN account about half the time. It needs some serious fixes before I can recommend it. —Jacob Roach#Password #Managers #Browserbuying guides,passwords,vulnerabilities,security,software,encryption

desktop app for Windows, macOS, or Linux and create your vault. There are also extensions for Firefox, Edge, and Chrome. The project does not offer apps for phones. Instead, it recommends KeePass2Android or Strongbox for iPhone.


Other Password Managers We’ve Tested

Password managers are not a one-size-fits-all solution. Our top picks cover most use cases and are the best choices for most people, but your needs may be different. Fortunately, there are plenty of good password managers out there. Here are some more we’ve tested.

Google Password Manager (Free): Google has offered a password manager within Chrome for years, but it recently broadened with a dedicated Android app. Although storing passwords in your browser has a few security concerns, Google offers top-notch encryption, the option to turn on on-device encryption, and integration with biometric authentication on Android and Windows. It can even store passkeys. For most people, I recommend a third-party password manager, but if you aren’t using a password manager at all, Google Password Manager is a good option.

RoboForm ($30 Per Year, $48 Per Year for a Five-User Family Plan): RoboForm has most of the same features as the rest on this list, but it lacks some of the things that differentiate our top picks, like Bitwarden’s open source aspect and 1Password’s travel features. I’ve been testing the free plan for a while and haven’t run into any problems. There are apps for every common platform, and it’s easy to use. RoboForm recently completed an independent security audit and came out looking good.

Pass (Free): Pass is a command-line wrapper around GPG (GNU Privacy Guard), which means it is only for the nerdiest users. It supports managing encrypted .gpg files in Git, and third-party mobile apps are available. It’s not for everyone. For years, this was my password manager of choice, but eventually, Bitwarden’s ease of use won me over.

Password Managers to Avoid

Most password managers are decent. Some are more secure than others, but the top password managers largely compete on features and pricing. Security is a prerequisite. However, there are a couple of password managers you should avoid for various reasons.

ExpressKeys by ExpressVPN: ExpressKeys is from ExpressVPN (formerly Keys by ExpressVPN that I tested, but it’s the same product), which ranks among the best VPN services on the market. But ExpressKeys doesn’t live up to the same standard. It’s secure, but I struggled to get it to work with any consistency. The browser extension requires the desktop ExpressVPN app to work, and closing either will force you to sign back in all over again. Worse, ExpressKeys wouldn’t recognize that I was signed into my ExpressVPN account about half the time. It needs some serious fixes before I can recommend it. —Jacob Roach

#Password #Managers #Browserbuying guides,passwords,vulnerabilities,security,software,encryption">The Password Managers You Should Use Instead of Your Browser

The downside of KeePassXC is that it doesn’t have official mobile clients. However, third-party apps are available for iOS and Android. KeePassXC is a fork of KeePass that offers better cross-platform support, but there are a handful of other forks available, as well.

Download the desktop app for Windows, macOS, or Linux and create your vault. There are also extensions for Firefox, Edge, and Chrome. The project does not offer apps for phones. Instead, it recommends KeePass2Android or Strongbox for iPhone.


Other Password Managers We’ve Tested

Password managers are not a one-size-fits-all solution. Our top picks cover most use cases and are the best choices for most people, but your needs may be different. Fortunately, there are plenty of good password managers out there. Here are some more we’ve tested.

Google Password Manager (Free): Google has offered a password manager within Chrome for years, but it recently broadened with a dedicated Android app. Although storing passwords in your browser has a few security concerns, Google offers top-notch encryption, the option to turn on on-device encryption, and integration with biometric authentication on Android and Windows. It can even store passkeys. For most people, I recommend a third-party password manager, but if you aren’t using a password manager at all, Google Password Manager is a good option.

RoboForm ($30 Per Year, $48 Per Year for a Five-User Family Plan): RoboForm has most of the same features as the rest on this list, but it lacks some of the things that differentiate our top picks, like Bitwarden’s open source aspect and 1Password’s travel features. I’ve been testing the free plan for a while and haven’t run into any problems. There are apps for every common platform, and it’s easy to use. RoboForm recently completed an independent security audit and came out looking good.

Pass (Free): Pass is a command-line wrapper around GPG (GNU Privacy Guard), which means it is only for the nerdiest users. It supports managing encrypted .gpg files in Git, and third-party mobile apps are available. It’s not for everyone. For years, this was my password manager of choice, but eventually, Bitwarden’s ease of use won me over.

Password Managers to Avoid

Most password managers are decent. Some are more secure than others, but the top password managers largely compete on features and pricing. Security is a prerequisite. However, there are a couple of password managers you should avoid for various reasons.

ExpressKeys by ExpressVPN: ExpressKeys is from ExpressVPN (formerly Keys by ExpressVPN that I tested, but it’s the same product), which ranks among the best VPN services on the market. But ExpressKeys doesn’t live up to the same standard. It’s secure, but I struggled to get it to work with any consistency. The browser extension requires the desktop ExpressVPN app to work, and closing either will force you to sign back in all over again. Worse, ExpressKeys wouldn’t recognize that I was signed into my ExpressVPN account about half the time. It needs some serious fixes before I can recommend it. —Jacob Roach

#Password #Managers #Browserbuying guides,passwords,vulnerabilities,security,software,encryption

Post Comment