×
Top 10 Google Gemini Nano Banana AI Prompts for Photos

Top 10 Google Gemini Nano Banana AI Prompts for Photos

AI-generated photography has become more exciting with tools like Google Gemini Nano Banana AI. By using simple prompts, you can instantly produce unique, creative, and polished visuals. From fun experiments to realistic shots, these tools make it easy to bring unique ideas to life. Here are the top 10 prompts you should try for amazing photo results.

1. Create 3D Figurines

Google Gemini’s Nano Banana AI makes it possible to see yourself or your favorite characters as miniature 3D figurines. The results look just like professionally made collectibles, complete with a sleek stand and a toy-style packaging box. Anime fans, gamers, and enthusiasts of pop culture will especially enjoy this activity, as it has the capability of turning an ordinary photo into a display figure.

Prompt: Make a small 1/7 scale figurine of the character from the photo, presented in a real-life desk setting. The figurine should stand on a round, transparent acrylic base with no text. The computer screen should show the 3D modeling work of the figure. Place a packaging box nearby, decorated with original illustrations like those on collector’s figures.

2. Merge Photos

image_for_Merge_Photos_feature_of_google_Gemini

It also allows you to merge different photos into a single candid-style picture. The result appears to have been taken with an instant camera, featuring a soft and warm film aesthetic. You can even place yourself alongside celebrities, friends, or favorite personalities, making the image feel natural and realistic. This prompt is perfect if you want photos that look casual yet artistic.

Prompt: Generate a 4K ultra-realistic motion-blurred instant camera image featuring the people from the reference images, posed together. Preserve their facial features, add a gentle blur, and maintain uniform lighting against a soft, white curtain backdrop for a warm, candid film-style effect. Do not change their faces at all.

3. Try New Outfit

image_to_Try_New_Outfit_in_Google

You can instantly experiment with fashion looks with the integration of Nano Banana AI in Google Gemini. Simply upload yourself and your preferred outfit, and the software will produce a natural preview. You can even use the command “put this dress on me” and get results instantly. It’s a digital fitting room and simpler.

Prompt: Make a new scene out of a combination of pieces from the images you are shown. Put the [element from image 1] next to/at the [element from image 2]. Your final scene should look like a [description of the final scene].

4. Generate Stickers

Image to make stickers in gemini

You don’t need any complicated steps to design stickers anymore. Gemini Nano Banana lets you upload a picture and instantly generates a full sticker set. Options range from playful Pop Art to cool retro looks, giving you endless ways to customize.

5. Create Nostalgic Photos

image_to_Create_Nostalgic

If you’ve always wished your images were captured in an old-school photo studio setting, Nano Banana AI in Google Gemini enables you to do just that. It simulates a retro portrait look with soft lighting and retro backgrounds that immediately bring you back in the past. Images are ethereal and artistic with a lot of vintage flair.

Prompt: Turn this into a retro-style mall studio portrait.

6. Create a 16-Bit Video Game Character

image_to_Create_a_16-Bit_Video_Game_

You can become a pixelated avatar with your looks straight out of the days of the arcade with Nano Banana in Gemini. The AI creates a complete 16-bit world around you with original terrains and throwback pixel art designs so that the end product has you experiencing an old-school video adventure.

Prompt: First, I’m going to upload my portrait. Then convert it as if I am a pixelated 16-bit video game character and place me into a 2D platformer environment with arcade style.

7. Make Holograms

image_to_make_hologram_Nano_Banana_AI

One of the coolest Nano Banana AI tasks of Gemini is that you can create holograms from items in your images. These appear futuristic-looking, almost as if you are viewing a sci-fi film scene, and the AI produces images rapidly with remarkable detail.

Prompt: Convert the (object) into a digital hologram of a 3D line art as if projected onto a sci-fi environment.

8. Gemini PictureMe

image of Gemini PictureMe (1)

PictureMe is a creative app from Google’s Gemini Canvas that makes photo restyling easy. Using Nano Banana, it quickly turns your images into different styles. All you need to do is upload, select a theme, and generate.

With PictureMe, you can explore different looks, including Time Traveler, Hair Styler, Miniature Me, and Pro Headshots. Everything is built in, so you can switch styles instantly without needing any special prompts.

9. Create an Action Figure

image_to_Create_an_Action_Figure

This creative prompt takes your pet’s picture and redesigns it as a collectible action toy. The AI actually comes up with a special package as well, and the entire production looks and feels like an off-the-shelf product. It’s a playful way of visualizing your pet as a superstar collector.

Prompt: Convert my pet into a full plastic action figure and place it alongside a toy-like packaging box.

10. Reimagine Yourself in a Saree with Gemini

image_for_Reimagine_Yourself_in_a_Saree

With this viral saree prompt in Gemini Nano Banana, you can transform your picture into a Bollywood-style scene. All you have to do is upload your selfie, and it dresses you up in a classic red chiffon saree and presents you as a retro heroine. Warm colors lend the photo a dramatic and romantically inclined appearance.

Prompt: Transform the subject into a classic Bollywood actress wearing a red chiffon saree, with soft, wavy hair. Place her against a warm backdrop lit by sunset glow for a romantic, cinematic look.

Source link
#Top #Google #Gemini #Nano #Banana #Prompts #Photos


French prosecutors who are investigating Elon Musk and his social media platform X have summoned the billionaire to France to face preliminary charges. The investigation is now officially a criminal probe, according to French officials.

France opened a probe in 2025 to investigate whether X has violated French law, an investigation that has expanded following incidents last year when Musk’s AI chatbot Grok started denying the Holocaust, praising Hitler, and allegedly generating child sexual abuse material when prompted by users.

According to the Wall Street Journal, Musk and former CEO Linda Yaccarino have been asked to travel to France to face preliminary charges. As the Journal explains, after preliminary charges have been filed in France, an investigating magistrate starts a process that can take months and doesn’t necessarily mean a trial will be held. It’s entirely possible that the case could ultimately be dropped.

French authorities are looking into the “complicity” of Musk in creating sexual abuse images of minors and sexually explicit deepfakes, according to the Associated Press. Grok also allegedly spread misinformation in French, including a claim that Auschwitz wasn’t a death camp during the Holocaust but was used for “disinfection with Zyklon B against typhus.”

Musk purchased Twitter in late 2022 and changed the name to X. The billionaire made many changes to the platform, stripping away safeguards that allowed people to know when an account was verified, and inviting back far-right figures who had previously been banned. Musk welcomed users like white supremacist Nick Fuentes and conspiracy theorist Alex Jones, among a host of others.

Musk also tinkered with the site in ways that turned it into a hotbed of far-right extremism and pro-Trump propaganda in the lead-up to the 2024 presidential election. Musk donated over $290 million to Republicans in the 2024 cycle and even ran a program that paid some voters in swing states up to $1 million to sign a “petition,” a move that was just very clearly an attempt at paying people to vote for Trump.

Musk, who is currently worth $803 billion, was rewarded with a job overseeing the dismantling of agencies in the federal government under the auspices of DOGE, the Department of Government Efficiency. Ultimately, about 300,000 government workers lost their jobs, and USAID was unlawfully dissolved. The cuts to global aid are estimated to lead to 23 million deaths by the year 2030, according to an analysis by The Lancet Global Health.

Last month, the U.S. Department of Justice told French authorities the U.S. wouldn’t assist in any investigation of Musk and X, something that wasn’t a surprise given the billionaire oligarch’s ties to the Trump regime.

“This investigation seeks to use the criminal legal system in France to regulate a public square for the free expression of ideas and opinions in a manner contrary to the First Amendment of the United States Constitution,” the April letter said, according to the Wall Street Journal.

X didn’t immediately respond to questions emailed Thursday about whether Musk planned on traveling to France. Gizmodo will update this article if we hear back.

#French #Prosecutors #Elon #Musk #Linda #Yaccarino #Face #Preliminary #ChargesElon Musk,Grok">French Prosecutors Want Elon Musk and Linda Yaccarino to Face Preliminary Charges
                French prosecutors who are investigating Elon Musk and his social media platform X have summoned the billionaire to France to face preliminary charges. The investigation is now officially a criminal probe, according to French officials. France opened a probe in 2025 to investigate whether X has violated French law, an investigation that has expanded following incidents last year when Musk’s AI chatbot Grok started denying the Holocaust, praising Hitler, and allegedly generating child sexual abuse material when prompted by users. According to the Wall Street Journal, Musk and former CEO Linda Yaccarino have been asked to travel to France to face preliminary charges. As the Journal explains, after preliminary charges have been filed in France, an investigating magistrate starts a process that can take months and doesn’t necessarily mean a trial will be held. It’s entirely possible that the case could ultimately be dropped.

 French authorities are looking into the “complicity” of Musk in creating sexual abuse images of minors and sexually explicit deepfakes, according to the Associated Press. Grok also allegedly spread misinformation in French, including a claim that Auschwitz wasn’t a death camp during the Holocaust but was used for “disinfection with Zyklon B against typhus.” Musk purchased Twitter in late 2022 and changed the name to X. The billionaire made many changes to the platform, stripping away safeguards that allowed people to know when an account was verified, and inviting back far-right figures who had previously been banned. Musk welcomed users like white supremacist Nick Fuentes and conspiracy theorist Alex Jones, among a host of others.

 Musk also tinkered with the site in ways that turned it into a hotbed of far-right extremism and pro-Trump propaganda in the lead-up to the 2024 presidential election. Musk donated over 0 million to Republicans in the 2024 cycle and even ran a program that paid some voters in swing states up to  million to sign a “petition,” a move that was just very clearly an attempt at paying people to vote for Trump.

 Musk, who is currently worth 3 billion, was rewarded with a job overseeing the dismantling of agencies in the federal government under the auspices of DOGE, the Department of Government Efficiency. Ultimately, about 300,000 government workers lost their jobs, and USAID was unlawfully dissolved. The cuts to global aid are estimated to lead to 23 million deaths by the year 2030, according to an analysis by The Lancet Global Health. Last month, the U.S. Department of Justice told French authorities the U.S. wouldn’t assist in any investigation of Musk and X, something that wasn’t a surprise given the billionaire oligarch’s ties to the Trump regime.

 “This investigation seeks to use the criminal legal system in France to regulate a public square for the free expression of ideas and opinions in a manner contrary to the First Amendment of the United States Constitution,” the April letter said, according to the Wall Street Journal. X didn’t immediately respond to questions emailed Thursday about whether Musk planned on traveling to France. Gizmodo will update this article if we hear back.      #French #Prosecutors #Elon #Musk #Linda #Yaccarino #Face #Preliminary #ChargesElon Musk,Grok

Wall Street Journal, Musk and former CEO Linda Yaccarino have been asked to travel to France to face preliminary charges. As the Journal explains, after preliminary charges have been filed in France, an investigating magistrate starts a process that can take months and doesn’t necessarily mean a trial will be held. It’s entirely possible that the case could ultimately be dropped.

French authorities are looking into the “complicity” of Musk in creating sexual abuse images of minors and sexually explicit deepfakes, according to the Associated Press. Grok also allegedly spread misinformation in French, including a claim that Auschwitz wasn’t a death camp during the Holocaust but was used for “disinfection with Zyklon B against typhus.”

Musk purchased Twitter in late 2022 and changed the name to X. The billionaire made many changes to the platform, stripping away safeguards that allowed people to know when an account was verified, and inviting back far-right figures who had previously been banned. Musk welcomed users like white supremacist Nick Fuentes and conspiracy theorist Alex Jones, among a host of others.

Musk also tinkered with the site in ways that turned it into a hotbed of far-right extremism and pro-Trump propaganda in the lead-up to the 2024 presidential election. Musk donated over $290 million to Republicans in the 2024 cycle and even ran a program that paid some voters in swing states up to $1 million to sign a “petition,” a move that was just very clearly an attempt at paying people to vote for Trump.

Musk, who is currently worth $803 billion, was rewarded with a job overseeing the dismantling of agencies in the federal government under the auspices of DOGE, the Department of Government Efficiency. Ultimately, about 300,000 government workers lost their jobs, and USAID was unlawfully dissolved. The cuts to global aid are estimated to lead to 23 million deaths by the year 2030, according to an analysis by The Lancet Global Health.

Last month, the U.S. Department of Justice told French authorities the U.S. wouldn’t assist in any investigation of Musk and X, something that wasn’t a surprise given the billionaire oligarch’s ties to the Trump regime.

“This investigation seeks to use the criminal legal system in France to regulate a public square for the free expression of ideas and opinions in a manner contrary to the First Amendment of the United States Constitution,” the April letter said, according to the Wall Street Journal.

X didn’t immediately respond to questions emailed Thursday about whether Musk planned on traveling to France. Gizmodo will update this article if we hear back.

#French #Prosecutors #Elon #Musk #Linda #Yaccarino #Face #Preliminary #ChargesElon Musk,Grok">French Prosecutors Want Elon Musk and Linda Yaccarino to Face Preliminary ChargesFrench Prosecutors Want Elon Musk and Linda Yaccarino to Face Preliminary Charges
                French prosecutors who are investigating Elon Musk and his social media platform X have summoned the billionaire to France to face preliminary charges. The investigation is now officially a criminal probe, according to French officials. France opened a probe in 2025 to investigate whether X has violated French law, an investigation that has expanded following incidents last year when Musk’s AI chatbot Grok started denying the Holocaust, praising Hitler, and allegedly generating child sexual abuse material when prompted by users. According to the Wall Street Journal, Musk and former CEO Linda Yaccarino have been asked to travel to France to face preliminary charges. As the Journal explains, after preliminary charges have been filed in France, an investigating magistrate starts a process that can take months and doesn’t necessarily mean a trial will be held. It’s entirely possible that the case could ultimately be dropped.

 French authorities are looking into the “complicity” of Musk in creating sexual abuse images of minors and sexually explicit deepfakes, according to the Associated Press. Grok also allegedly spread misinformation in French, including a claim that Auschwitz wasn’t a death camp during the Holocaust but was used for “disinfection with Zyklon B against typhus.” Musk purchased Twitter in late 2022 and changed the name to X. The billionaire made many changes to the platform, stripping away safeguards that allowed people to know when an account was verified, and inviting back far-right figures who had previously been banned. Musk welcomed users like white supremacist Nick Fuentes and conspiracy theorist Alex Jones, among a host of others.

 Musk also tinkered with the site in ways that turned it into a hotbed of far-right extremism and pro-Trump propaganda in the lead-up to the 2024 presidential election. Musk donated over $290 million to Republicans in the 2024 cycle and even ran a program that paid some voters in swing states up to $1 million to sign a “petition,” a move that was just very clearly an attempt at paying people to vote for Trump.

 Musk, who is currently worth $803 billion, was rewarded with a job overseeing the dismantling of agencies in the federal government under the auspices of DOGE, the Department of Government Efficiency. Ultimately, about 300,000 government workers lost their jobs, and USAID was unlawfully dissolved. The cuts to global aid are estimated to lead to 23 million deaths by the year 2030, according to an analysis by The Lancet Global Health. Last month, the U.S. Department of Justice told French authorities the U.S. wouldn’t assist in any investigation of Musk and X, something that wasn’t a surprise given the billionaire oligarch’s ties to the Trump regime.

 “This investigation seeks to use the criminal legal system in France to regulate a public square for the free expression of ideas and opinions in a manner contrary to the First Amendment of the United States Constitution,” the April letter said, according to the Wall Street Journal. X didn’t immediately respond to questions emailed Thursday about whether Musk planned on traveling to France. Gizmodo will update this article if we hear back.      #French #Prosecutors #Elon #Musk #Linda #Yaccarino #Face #Preliminary #ChargesElon Musk,Grok

French prosecutors who are investigating Elon Musk and his social media platform X have summoned the billionaire to France to face preliminary charges. The investigation is now officially a criminal probe, according to French officials.

France opened a probe in 2025 to investigate whether X has violated French law, an investigation that has expanded following incidents last year when Musk’s AI chatbot Grok started denying the Holocaust, praising Hitler, and allegedly generating child sexual abuse material when prompted by users.

According to the Wall Street Journal, Musk and former CEO Linda Yaccarino have been asked to travel to France to face preliminary charges. As the Journal explains, after preliminary charges have been filed in France, an investigating magistrate starts a process that can take months and doesn’t necessarily mean a trial will be held. It’s entirely possible that the case could ultimately be dropped.

French authorities are looking into the “complicity” of Musk in creating sexual abuse images of minors and sexually explicit deepfakes, according to the Associated Press. Grok also allegedly spread misinformation in French, including a claim that Auschwitz wasn’t a death camp during the Holocaust but was used for “disinfection with Zyklon B against typhus.”

Musk purchased Twitter in late 2022 and changed the name to X. The billionaire made many changes to the platform, stripping away safeguards that allowed people to know when an account was verified, and inviting back far-right figures who had previously been banned. Musk welcomed users like white supremacist Nick Fuentes and conspiracy theorist Alex Jones, among a host of others.

Musk also tinkered with the site in ways that turned it into a hotbed of far-right extremism and pro-Trump propaganda in the lead-up to the 2024 presidential election. Musk donated over $290 million to Republicans in the 2024 cycle and even ran a program that paid some voters in swing states up to $1 million to sign a “petition,” a move that was just very clearly an attempt at paying people to vote for Trump.

Musk, who is currently worth $803 billion, was rewarded with a job overseeing the dismantling of agencies in the federal government under the auspices of DOGE, the Department of Government Efficiency. Ultimately, about 300,000 government workers lost their jobs, and USAID was unlawfully dissolved. The cuts to global aid are estimated to lead to 23 million deaths by the year 2030, according to an analysis by The Lancet Global Health.

Last month, the U.S. Department of Justice told French authorities the U.S. wouldn’t assist in any investigation of Musk and X, something that wasn’t a surprise given the billionaire oligarch’s ties to the Trump regime.

“This investigation seeks to use the criminal legal system in France to regulate a public square for the free expression of ideas and opinions in a manner contrary to the First Amendment of the United States Constitution,” the April letter said, according to the Wall Street Journal.

X didn’t immediately respond to questions emailed Thursday about whether Musk planned on traveling to France. Gizmodo will update this article if we hear back.

#French #Prosecutors #Elon #Musk #Linda #Yaccarino #Face #Preliminary #ChargesElon Musk,Grok

ransomware gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software platform so thoroughly disrupted the daily operations of thousands of schools across the United States.

The widely used digital learning platform Canvas was put into “maintenance mode” on Thursday after its maker, the education tech giant Instructure, suffered a data breach and faced an extortion attempt by attackers using the recognizable moniker “ShinyHunters.” Though the hackers have been advertising the breach and attempting to extract a ransom payment from Instructure since May 1, the situation took on additional immediacy for regular people across the US and beyond on Thursday because the Canvas downtime caused chaos at schools, including those in the midst of finals and end-of-year assignments.

Universities like Harvard, Columbia, Rutgers, and Georgetown sent alerts to students about the situation in recent days; other institutions, including school districts in at least a dozen states, also appear to have been affected. In a list published by the hackers behind the attack on their ransom-focused dark web site, they claim the breach affected more than 8,800 schools. The exact scale and reach of the breach is currently unclear, though. And the fact that Canvas was down throughout Thursday afternoon and evening further complicated the picture.

In a running incident update log that began on May 1, Steve Proud, Instructure’s chief information security officer, said that the company had “recently experienced a cybersecurity incident perpetrated by a criminal threat actor.” He added on May 2 that “the information involved” for “users at affected institutions” included names, email addresses, student ID numbers, and messages exchanged by users on the platform.

The situation was ultimately marked as “Resolved” on Wednesday, with Proud writing that “Canvas is fully operational, and we are not seeing any ongoing unauthorized activity.” At midday on Thursday, though, the Instructure status page registered an “issue” where “some users are having difficulties logging into Student ePortfolios.” Within a few hours, the company had added another status update: “Instructure has placed Canvas, Canvas Beta and Canvas Test in maintenance mode.” Late Thursday evening, the company said that Canvas was available again “for most users.”

TechCrunch reported on Thursday that the hackers launched a secondary wave of attacks, defacing some schools’ Canvas portals by injecting an HTML file to display their own message on the schools’ Canvas login pages. According to The Harvard Crimson, attackers modified the Harvard Canvas login page to show a message that included a list of schools that the hackers claim were impacted by the breach.

The message from attackers “urged schools included on the affected list to consult with a cyber advisory firm and contact the group privately to negotiate a settlement before the end of the day on May 12—or else risk their data being leaked,” The Crimson reported. “It is unclear what information tied to Harvard affiliates was included in the alleged breach.”

Instructure did not immediately respond to a request for comment about Thursday’s outages and how they fit into the bigger picture of the breach. But the situation is significant given that a massive trove of student information has potentially been exposed, and the visibility of the incident across the country makes it a key example of a longstanding, yet endlessly escalating problem of data extortion and ransomware attacks.

The ShinyHunters name is associated with massive data dumps and has been linked to the infamous hacker collective known as the Com. But as the constellation of actors has shifted over the years, numerous attackers have taken up the most prominent Com-related monikers. A number of recent attacks have invoked other names, such as Lapsus$, with little or no connection to the original group that operated under the name.

#Canvas #Hack #Kind #Ransomware #Debacleransomware,cybersecurity,malware,hacks,hacking,security,vulnerabilities">The Canvas Hack Is a New Kind of Ransomware DebacleHigher education has long been a target of ransomware gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software platform so thoroughly disrupted the daily operations of thousands of schools across the United States.The widely used digital learning platform Canvas was put into “maintenance mode” on Thursday after its maker, the education tech giant Instructure, suffered a data breach and faced an extortion attempt by attackers using the recognizable moniker “ShinyHunters.” Though the hackers have been advertising the breach and attempting to extract a ransom payment from Instructure since May 1, the situation took on additional immediacy for regular people across the US and beyond on Thursday because the Canvas downtime caused chaos at schools, including those in the midst of finals and end-of-year assignments.Universities like Harvard, Columbia, Rutgers, and Georgetown sent alerts to students about the situation in recent days; other institutions, including school districts in at least a dozen states, also appear to have been affected. In a list published by the hackers behind the attack on their ransom-focused dark web site, they claim the breach affected more than 8,800 schools. The exact scale and reach of the breach is currently unclear, though. And the fact that Canvas was down throughout Thursday afternoon and evening further complicated the picture.In a running incident update log that began on May 1, Steve Proud, Instructure’s chief information security officer, said that the company had “recently experienced a cybersecurity incident perpetrated by a criminal threat actor.” He added on May 2 that “the information involved” for “users at affected institutions” included names, email addresses, student ID numbers, and messages exchanged by users on the platform.The situation was ultimately marked as “Resolved” on Wednesday, with Proud writing that “Canvas is fully operational, and we are not seeing any ongoing unauthorized activity.” At midday on Thursday, though, the Instructure status page registered an “issue” where “some users are having difficulties logging into Student ePortfolios.” Within a few hours, the company had added another status update: “Instructure has placed Canvas, Canvas Beta and Canvas Test in maintenance mode.” Late Thursday evening, the company said that Canvas was available again “for most users.”TechCrunch reported on Thursday that the hackers launched a secondary wave of attacks, defacing some schools’ Canvas portals by injecting an HTML file to display their own message on the schools’ Canvas login pages. According to The Harvard Crimson, attackers modified the Harvard Canvas login page to show a message that included a list of schools that the hackers claim were impacted by the breach.The message from attackers “urged schools included on the affected list to consult with a cyber advisory firm and contact the group privately to negotiate a settlement before the end of the day on May 12—or else risk their data being leaked,” The Crimson reported. “It is unclear what information tied to Harvard affiliates was included in the alleged breach.”Instructure did not immediately respond to a request for comment about Thursday’s outages and how they fit into the bigger picture of the breach. But the situation is significant given that a massive trove of student information has potentially been exposed, and the visibility of the incident across the country makes it a key example of a longstanding, yet endlessly escalating problem of data extortion and ransomware attacks.The ShinyHunters name is associated with massive data dumps and has been linked to the infamous hacker collective known as the Com. But as the constellation of actors has shifted over the years, numerous attackers have taken up the most prominent Com-related monikers. A number of recent attacks have invoked other names, such as Lapsus$, with little or no connection to the original group that operated under the name.#Canvas #Hack #Kind #Ransomware #Debacleransomware,cybersecurity,malware,hacks,hacking,security,vulnerabilities

gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software platform so thoroughly disrupted the daily operations of thousands of schools across the United States.

The widely used digital learning platform Canvas was put into “maintenance mode” on Thursday after its maker, the education tech giant Instructure, suffered a data breach and faced an extortion attempt by attackers using the recognizable moniker “ShinyHunters.” Though the hackers have been advertising the breach and attempting to extract a ransom payment from Instructure since May 1, the situation took on additional immediacy for regular people across the US and beyond on Thursday because the Canvas downtime caused chaos at schools, including those in the midst of finals and end-of-year assignments.

Universities like Harvard, Columbia, Rutgers, and Georgetown sent alerts to students about the situation in recent days; other institutions, including school districts in at least a dozen states, also appear to have been affected. In a list published by the hackers behind the attack on their ransom-focused dark web site, they claim the breach affected more than 8,800 schools. The exact scale and reach of the breach is currently unclear, though. And the fact that Canvas was down throughout Thursday afternoon and evening further complicated the picture.

In a running incident update log that began on May 1, Steve Proud, Instructure’s chief information security officer, said that the company had “recently experienced a cybersecurity incident perpetrated by a criminal threat actor.” He added on May 2 that “the information involved” for “users at affected institutions” included names, email addresses, student ID numbers, and messages exchanged by users on the platform.

The situation was ultimately marked as “Resolved” on Wednesday, with Proud writing that “Canvas is fully operational, and we are not seeing any ongoing unauthorized activity.” At midday on Thursday, though, the Instructure status page registered an “issue” where “some users are having difficulties logging into Student ePortfolios.” Within a few hours, the company had added another status update: “Instructure has placed Canvas, Canvas Beta and Canvas Test in maintenance mode.” Late Thursday evening, the company said that Canvas was available again “for most users.”

TechCrunch reported on Thursday that the hackers launched a secondary wave of attacks, defacing some schools’ Canvas portals by injecting an HTML file to display their own message on the schools’ Canvas login pages. According to The Harvard Crimson, attackers modified the Harvard Canvas login page to show a message that included a list of schools that the hackers claim were impacted by the breach.

The message from attackers “urged schools included on the affected list to consult with a cyber advisory firm and contact the group privately to negotiate a settlement before the end of the day on May 12—or else risk their data being leaked,” The Crimson reported. “It is unclear what information tied to Harvard affiliates was included in the alleged breach.”

Instructure did not immediately respond to a request for comment about Thursday’s outages and how they fit into the bigger picture of the breach. But the situation is significant given that a massive trove of student information has potentially been exposed, and the visibility of the incident across the country makes it a key example of a longstanding, yet endlessly escalating problem of data extortion and ransomware attacks.

The ShinyHunters name is associated with massive data dumps and has been linked to the infamous hacker collective known as the Com. But as the constellation of actors has shifted over the years, numerous attackers have taken up the most prominent Com-related monikers. A number of recent attacks have invoked other names, such as Lapsus$, with little or no connection to the original group that operated under the name.

#Canvas #Hack #Kind #Ransomware #Debacleransomware,cybersecurity,malware,hacks,hacking,security,vulnerabilities">The Canvas Hack Is a New Kind of Ransomware Debacle

Higher education has long been a target of ransomware gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software platform so thoroughly disrupted the daily operations of thousands of schools across the United States.

The widely used digital learning platform Canvas was put into “maintenance mode” on Thursday after its maker, the education tech giant Instructure, suffered a data breach and faced an extortion attempt by attackers using the recognizable moniker “ShinyHunters.” Though the hackers have been advertising the breach and attempting to extract a ransom payment from Instructure since May 1, the situation took on additional immediacy for regular people across the US and beyond on Thursday because the Canvas downtime caused chaos at schools, including those in the midst of finals and end-of-year assignments.

Universities like Harvard, Columbia, Rutgers, and Georgetown sent alerts to students about the situation in recent days; other institutions, including school districts in at least a dozen states, also appear to have been affected. In a list published by the hackers behind the attack on their ransom-focused dark web site, they claim the breach affected more than 8,800 schools. The exact scale and reach of the breach is currently unclear, though. And the fact that Canvas was down throughout Thursday afternoon and evening further complicated the picture.

In a running incident update log that began on May 1, Steve Proud, Instructure’s chief information security officer, said that the company had “recently experienced a cybersecurity incident perpetrated by a criminal threat actor.” He added on May 2 that “the information involved” for “users at affected institutions” included names, email addresses, student ID numbers, and messages exchanged by users on the platform.

The situation was ultimately marked as “Resolved” on Wednesday, with Proud writing that “Canvas is fully operational, and we are not seeing any ongoing unauthorized activity.” At midday on Thursday, though, the Instructure status page registered an “issue” where “some users are having difficulties logging into Student ePortfolios.” Within a few hours, the company had added another status update: “Instructure has placed Canvas, Canvas Beta and Canvas Test in maintenance mode.” Late Thursday evening, the company said that Canvas was available again “for most users.”

TechCrunch reported on Thursday that the hackers launched a secondary wave of attacks, defacing some schools’ Canvas portals by injecting an HTML file to display their own message on the schools’ Canvas login pages. According to The Harvard Crimson, attackers modified the Harvard Canvas login page to show a message that included a list of schools that the hackers claim were impacted by the breach.

The message from attackers “urged schools included on the affected list to consult with a cyber advisory firm and contact the group privately to negotiate a settlement before the end of the day on May 12—or else risk their data being leaked,” The Crimson reported. “It is unclear what information tied to Harvard affiliates was included in the alleged breach.”

Instructure did not immediately respond to a request for comment about Thursday’s outages and how they fit into the bigger picture of the breach. But the situation is significant given that a massive trove of student information has potentially been exposed, and the visibility of the incident across the country makes it a key example of a longstanding, yet endlessly escalating problem of data extortion and ransomware attacks.

The ShinyHunters name is associated with massive data dumps and has been linked to the infamous hacker collective known as the Com. But as the constellation of actors has shifted over the years, numerous attackers have taken up the most prominent Com-related monikers. A number of recent attacks have invoked other names, such as Lapsus$, with little or no connection to the original group that operated under the name.

#Canvas #Hack #Kind #Ransomware #Debacleransomware,cybersecurity,malware,hacks,hacking,security,vulnerabilities

Post Comment