Canvas Breach 'Deal' With ShinyHunters, AI Zero-Day Warning, Checkmarx Hit Again

Canvas Breach 'Deal' With ShinyHunters, AI Zero-Day Warning, Checkmarx Hit Again

Cybersecurity Today

C1May 13, 202616 min
Play

Cybersecurity Today examines a troubling set of new security developments affecting schools, software supply chains, and account security. Instructure says it reached an "agreement" with the ShinyHunters threat group after the massive Canvas breach that may have affected up to 275 million users across 9,000 educational institutions. Reports indicate attackers exploited multiple cross-site scripting (XSS) vulnerabilities to hijack administrator sessions and post extortion demands. Checkmarx has been breached again. This time, attackers reportedly inserted a malicious Jenkins Application Security Testing (AST) plugin designed to steal credentials. The same threat actor, believed to be Team46/TeamTNT-linked infrastructure or...

Transcript

Automatically generated from the audio. May contain errors.

Instructure cuts deal with shiny hunters. Checkmarks hit again in another supply chain attack. Microsoft and Google warn Pasky's are not a security silver bullet. And Google reports its first evidence of hostile use of AI to develop a zero day.

This is Cyber Security Today, and I'm your host, David Shippley. Let's get started. In structure, the company behind the massively breached learning platform Canvas has officially used the word agreement to describe its new arrangement with the criminal group Shiny Hunters.

In a statement on Tuesday, Instructure confirmed it has reached what it's calling an agreement with the Thread Actor responsible for the Canvas breach. The canvas breach affects as many as 9,000 schools worldwide and as many as 275 million people.

According to Bleeping Computer, the company says Shiny Hunters has returned the stolen data and provided what Instructure calls Shredlogs confirming its destruction. The agreement covers all impacted customers. The company says no one will need to negotiate separately and no individual customer will

be extorted as a result of this incident. It's worth noting that an agreement with a criminal organization is hardly a binding guarantee. At best, it's a talking point.

Shiny hunters can keep a copy of the data, sell it tomorrow, or come back in six months under a different name, and no court, regulator, or insurer can enforce anything against What the agreement actually is, is likely a line in Instructure's legal defense that its lawyers will use in civil suits that are likely already being developed.

One useful new technical detail in bleeping computers reporting, the breach was enabled by multiple cross-site scripting vulnerabilities, also known as XSS flaws, in Canvas' user-generated content features. hunters injected malicious JavaScript to let them hijack authenticated administrative sessions

and perform privileged actions inside the platform. It was the same vulnerability class for both the April 29th Data Theft and the May 7th Defacement. Instructure is hosting a webinar today to share more about what they've done to secure their platform going forward. The longer term question now is what message this move sends to the next shiny hunter's affiliate or similar

gang looking to attack the next ed tech platform. And that sign likely reads something like open season. As we noted on Monday, shiny hunters is a young opportunistic group. They watch what's and what worked here was breach the platform, deface the login pages, make the

threat public, and walk away with a deal. Criminal hackers are mocking software security firm checkmarks after breaching the company for the third time in seven weeks. According to bleeping computer, a malicious version of checkmarks Jenkins application security testing plugin was published to the Jenkins marketplace on

on Saturday, May 9th. Jenkins is one of the world's most widely deployed automation platforms in software engineering. It builds, tests, and deploys code

across an enormous portion of the world's software supply chain. The check marks AST plugin sits inside that pipeline scanning code for vulnerabilities as it's built.

That plugin was itself backdoor to deliver credential stealing malware. The group behind the breach calls itself TeamPCP. We've been talking about them a lot this year.

The same group also claimed responsibility for the shy Hulud campaign on the NPM package registry and the massive Trivy vulnerability scanner breach back in March. And it looks like the Trivy breach attack explains this latest breach. A checkmark spokesperson confirmed a bleeping computer that Team PCP got into the company's

GitHub repositories using credentials stolen during the trivia attack. They used it to publish malicious versions of checkmark's Kix analysis tool to Docker, OpenVSX, and VS Code in April. And now, in May, they've published a rogue version of the Jenkins plugin using the

same access approach. So attackers even left a taunt in the Repositories About section, needling the company for not rotating its secrets properly. The malicious version is labeled as 20265.09.

If you've downloaded the Jenkins AST plugin from checkmarks in the past week, assume your credentials are compromised, rotate everything, and hunt for lateral movement. If credentials stolen from one vendor can be reused again to attack another vendor weeks later, the credential rotation gap across the security supply chain is clearly the soft

target. And right now, that gap is wide enough to drive three breaches through in less than two months. Another cybersecurity silver bullet just bit the dust.

This time it's PASCIs. The so-called phishing-resistant authentication standard that was supposed to make passwords obsolete and put a serious dent in account takeover attacks. Google and Microsoft both issued new warnings this week that pass keys, on their own, are

not the complete defense some in the industry have been promoting. Microsoft put the point plainly. Each account is only as secure as its weakest credential. on accounts where you've deployed pass keys, if any weaker credential or recovery method

remains attached, a password, an SMS code, a security question, that weaker option is now the attack surface. Attackers will simply ignore the pass key and target the recovery flow instead. According to Forbes coverage of the joint warning, Google's specific guidance is that

even when you normally use a pass key, you still need two step verification turned on. The reasoning is straightforward. Someone can impersonate you, claim to have lost the passkey, and ride the account recovery

process back into your account. The takeaway for individual users is clear. Stop relying on SMS one-time codes wherever you can as your second factor. Both Google and Microsoft are pushing people towards authenticator apps that they both

offer and device-based confirmations instead. Microsoft, on the enterprise side, is recommending that high assurance account recovery require

This is the opening of the episode. Open the player for the full interactive transcript with clickable words, translation and flashcards.

Open full transcript

Audio belongs to its publisher and is played from their feed. Rights holders can request removal — copyright & takedown policy

Episodes · Cybersecurity Today