A security breach of Canvas, a widely-used learning management platform, has disrupted classes and postponed final exams at numerous colleges and primary schools during the academic year's critical closing weeks.
Canvas, owned by Instructure, serves millions of students across educational institutions globally. The breach compromised the platform's infrastructure, forcing administrators to take systems offline while investigating the scope of the intrusion.
Affected schools have been forced to reschedule final exams and move coursework to alternative platforms or delay assessments indefinitely. The timing of the breach creates significant disruption, coming as students prepare for end-of-semester evaluations that impact grades and academic standing.
Canvas hosts critical academic functions including grade posting, assignment submission, and exam administration. The outage has created logistical challenges for institutions attempting to maintain academic calendars while ensuring the integrity of assessments.
Instructure has not yet released detailed information about the breach's scope, including how many user accounts were affected or what data was accessed. The company acknowledged the incident and stated it is working with cybersecurity experts to investigate and restore full service.
Institutions using Canvas have advised students and faculty to monitor communications for updates on when services will resume. Some schools have implemented temporary workarounds using email and document-sharing platforms to continue coursework.
The incident highlights the risks educational institutions face when relying on centralized third-party platforms for critical academic functions. A single breach can cascade across hundreds of schools simultaneously, affecting hundreds of thousands of students.
Instructure has not announced a timeline for full platform restoration or details about what specific security vulnerabilities led to the breach. Affected institutions are preparing contingency plans for final exam administration and grade submission deadlines.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) alerted federal agencies that ransomware gangs are actively exploiting a critical JetBrains TeamCity vulnerability that was patched in July.
A Senate Judiciary Subcommittee criticized automatic license plate reader technology Wednesday, with particular concerns raised about Flock Safety. The company's CEO and others declined to attend the hearing.
The domain third-party.com, widely used in developer documentation as a placeholder, is now hosting a fake Cloudflare verification page designed to trick Windows users into executing malicious PowerShell commands.