<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Foss on phasewalk</title>
    <link>https://phasewalk.xyz/tags/foss/</link>
    <description>Recent content in Foss on phasewalk</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 07 May 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://phasewalk.xyz/tags/foss/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Unraveling the Canvas Hack</title>
      <link>https://phasewalk.xyz/posts/canvas-hack/</link>
      <pubDate>Thu, 07 May 2026 00:00:00 +0000</pubDate>
      <guid>https://phasewalk.xyz/posts/canvas-hack/</guid>
      <description>&lt;p&gt;Roughly 9,000 educational institutions across the world have been affected by a large cyberattack mounted against Instructure, the parent company of&#xA;&lt;strong&gt;Canvas LMS&lt;/strong&gt;. Anyone who tried to login&#xA;to their student portal this morning was greeted with the following message&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;:&lt;/p&gt;&#xA;&lt;pre&gt;&lt;code class=&#34;language-plaintext&#34;&gt;SHINYHUNTERS&#xA;rooting your systems since &#39;19 ;)&#xA;ShinyHunters has breached Instructure (again).&#xA;Instead of contacting us to resolve it they ignored us and did some &amp;quot;security patches&amp;quot;.&#xA;&#xA;⚠ WARNING&#xA;If any of the schools in the affected list(*) are interested in preventing the release of their data, please consult with a cyber advisory firm and contact us privately at TOX to negotiate a settlement. You have till the end of the day by&#xA;12 May 2026 before everything is leaked.&#xA;&#xA;Instructure still has until EOD 12 May 2026 to contact us.&#xA;&#xA;▼ DOWNLOAD AFFECTED_SCHOOLS.TXT ▼&#xA;91.215.85.103/pay_or_leak/ instructure_affected_schools_list.txt&#xA;visit us: shnyhntww34phqoa6dcgnvps2yu7dlwzmy5&#xA;Ikvejwjdo6z7bmgshzayd.onion&#xA;&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;blockquote class=&#34;post-callout callout-tip&#34;&gt;&#xA;&lt;span class=&#34;callout-label&#34;&gt;Note&lt;/span&gt;&#xA;&lt;p&gt;The full list of affected institutions (reportedly 8,809) includes major institutions like UC Berkeley, Penn, and Duke. You can find the claimed list here: &lt;a href=&#34;https://databreaches.net/wp-content/uploads/Claimed-Victims-of-Canvas-Cyber-Incident.txt&#34;&gt;https://databreaches.net/wp-content/uploads/Claimed-Victims-of-Canvas-Cyber-Incident.txt&lt;/a&gt;&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
