No-frills tech news

User perceptions and behaviours regarding <b>cybersecurity</b>

User perceptions and behaviours regarding cybersecurity are critical factors in the success of digital banking in West Africa; more than half will adopt and regularly use digital banking services when they have a very strong degree of trust in the provider and that their financial assets are protected from risk. This goes especially true in a region with a high percentage of unbanked individuals, who probably are naturally inclined not to use any new technologies involving finances. Several variables can have a substantial impact on how users p User perceptions and behaviours regarding cybersecurity are critical factors in the success of digital banking in West Africa; more than half will adopt and regularly use digital banking services when they have a very strong degree of trust in the provider and that their financial assets are protected from risk. This goes especially true in a region with a high percentage of unbanked individuals, who probably are naturally inclined not to use any new technologies involving finances. Several variables can have a substantial impact on how users p

Security teams are turning to AI to survive alert overload

Security teams are turning to AI to survive alert overload The World Economic Forum white paper “Empowering Defenders: AI for Cybersecurity” identified AI as the biggest driver of change in cybersecurity for 94% of survey respondents. The paper found that 77% of organizations already use AI in cybersecurity, with much of the activity focused on phishing detection, anomaly monitoring, vulnerability management and incident response. “AI has the potential to shift the balance towards defenders,” said Akshay Joshi, Head of the Centre for Cybersecurity, World Economic Forum. “Organizations that treat it as a strategic capability instead of a standalone tool will be better placed to turn growing cyber risk into resilience and competitive advantage.” AI is moving deeper into security operations Security operations centers are changing quickly as teams push more alert handling and investigation work into automated systems. AI tools are being used to filter alerts, summarize investigations and help analysts process large volumes of telemetry and threat data. The report noted that 76% of cybersecurity professionals reported exhaustion in 2025, and 55% of teams reported understaffing. Threat detection remains one of the most common deployment areas. Security tools are examining communication patterns, language cues and impersonation tactics to identify suspicious messages and unusual behavior that older detection methods may miss. Software and cloud security teams are folding automated analysis into routine vulnerability and configuration reviews. Development and infrastructure teams are using AI to identify insecure code, detect configuration weaknesses and prioritize vulnerabilities in large environments. Operational pressure behind adoption is growing on both sides of the threat landscape. Attackers are using automation to speed up reconnaissance, malware development and large-scale campaigns. Defensive teams are pushing more analysis and investigation work into automated systems. Organizations using AI extensively in security shortened breach lifecycles by approximately 80 days and reduced average

Nationwide security incident involving Canvas - UCnet

Nationwide security incident involving Canvas Share This Article Updated May 9, 2026 The University of California continues assessing updates from Instructure and cybersecurity partners regarding the recent Canvas security incident. Based on the latest information available, campuses and locations are evaluating next steps regarding restoration of Canvas services. Additional updates and campus-specific information will be shared through local communications channels as more information becomes available. As always, we encourage community members to remain vigilant regarding potential phishing attempts or suspicious communications. Updated May 8, 2026 Now that Instructure has advised that the incident has been contained and remediated, UC is making risk-based decisions about when to restore access to Canvas at campuses based on their operational needs. UC will continue to work closely with its IT teams across the system and determine next steps based on updates from Instructure. We understand the disruption this incident has caused for students, faculty, and staff. We will continue to monitor the situation and share additional information as it becomes available. Updated May 7, 2026 The University of California is closely monitoring the security incidents involving Instructure, the maker of learning management system Canvas used by thousands of educational institutions globally. Across our locations, we are aware that the Canvas login page displayed a suspicious message originating from the threat actor. The Instructure Security Incident Update & FAQs page provides information about what happened and how Instructure is responding. As always, we encourage our community members to remain vigilant and exercise caution regarding potential phishing attempts. Watch for unexpected messages that seem to come from UC. The university will never ask for passwords, Social Security numbers, birthdates, or bank account information through email, text, or phone calls. Out of an abundance of caution, the University of California Office of the President has instructed all

All students, staff may be affected by Canvas breach in Needham

All students, staff may be affected by Canvas breach in Needham, superintendent says Wellesley High School also among affected institutions Wellesley High School also among affected institutions Wellesley High School also among affected institutions Officials in Needham, Massachusetts, are "operating under the assumption that all students and staff were affected" by a cybersecurity incident affecting Canvas, software used widely across schools and colleges. Superintendent Dan Gutekanst of Needham Public Schools wrote in a statement that the district learned of the breach May 1 and learned May 7 that data from the district had been downloaded. The district was also notified of a second breach May 7, he said. According to Gutekanst, the information accessed included first names, last names and email addresses for all Needham Public Schools students and staff. Instructure, Canvas’ parent company, said it detected unauthorized activity April 26 and "immediately revoked the unauthorized party's access" and started an investigation. Instructure on Thursday identified additional unauthorized activity tied to the same incident. "The unauthorized actor made changes to the pages that appeared when some students and teachers were logged in through Canvas. Out of caution, we temporarily took Canvas offline into maintenance mode to contain the activity, investigate, and apply additional safeguards," a spokesperson said. Additionally, Gutekanst said the district was informed that teacher gradebook data connected to our PowerSchool student information system could have been modified." Wellesley High School is also a Canvas client, and district officials said the campus is among approximately 9,000 affected institutions. Response to the breach Gutekanst said NPS disconnected Canvas from PowerSchool "to prevent any further potential compromise of data or systems." According to the superintendent, the district requested a complete report on the incident from Instructure. It asked that the report include information about what data was breached or modified. "We

Intruder launches AI pentesting agents as GCHQ-backed startup automates $50K manual ...

TL;DR Intruder, a GCHQ-accelerated UK cybersecurity startup, launched AI pentesting agents that replicate manual pen testing methodology in minutes. The broader market is racing to automate vulnerability discovery as AI compresses the gap between offence and defence. A manual penetration test costs between 10,000 and 50,000 dollars. It takes weeks to schedule, days to execute, and produces a report that is out of date before the ink dries. Intruder, a London-based cybersecurity company that graduated from GCHQ’s Cyber Accelerator, has launched AI pentesting agents that replicate the methodology of a human pen tester and deliver results in minutes. The company’s chief executive, Chris Wallis, will present the technology at KnowBe4’s KB4-CON conference on 13 May. The pitch is simple: the depth of a manual pentest, available on demand, at a fraction of the cost. The timing is not accidental. The cybersecurity industry is watching AI transform the attack side of the equation faster than the defence side can adapt. Anthropic’s Claude Mythos Preview found thousands of zero-day vulnerabilities across every major operating system and browser in a single evaluation pass. xBow, an autonomous pentesting startup, reached unicorn status in March 2026 after raising 120 million dollars. The question is no longer whether AI will replace human pen testers. It is whether the replacement will happen fast enough to close the gap between the vulnerabilities AI can find and the speed at which organisations can fix them. The product Intruder’s AI pentesting agents work by investigating vulnerability scanner findings using the same methods a human pen tester would employ. When the scanner flags a potential issue, the AI agent interacts directly with the target system, sending requests, analysing responses, and probing for exposed data to determine whether the finding represents a genuine exploitable flaw or a false positive. The investigations cover

Mythos AI is a <b>cybersecurity</b> threat, but it doesn't rewrite the rules of the game

Mythos AI is a cybersecurity threat, but it doesn’t rewrite the rules of the game Mohammad Ahmad, West Virginia University The cybersecurity community went on alert when Anthropic announced on April 7, 2026, that its latest and most capable general-purpose large language model, Claude Mythos Preview, had demonstrated remarkable – and unintended – capabilities. The artifical intelligence system was able to find and exploit software vulnerabilities – the most serious type of software bugs – at a rate not seen before. The news ignited concern among the public, world governments and the information technology sector about the capabilities of today’s AI to undermine cybersecurity, with some people framing the model as a global cybersecurity threat. Claiming that it would be too risky to release the model, and that the company had the moral responsibility to disclose these vulnerabilities, Anthropic said it would not immediately offer the model to the public. Instead, it granted exclusive access to tech giants to test the model’s capabilities, a process Anthropic dubbed Project Glasswing. As a cybersecurity researcher, I think Mythos’ capabilities are impressive, but the AI system does not represent a radical departure. Mythos is less a new threat than a mirror reflecting how people behave and how fragile modern systems already are. What Mythos did During a controlled evaluation, engineers with minimal security experience prompted Mythos to scan thousands of software codebases for vulnerabilities. The model showed striking capabilities in conducting multistep, autonomous attacks that take experts weeks or even months to put together. Mythos was not only able to discover 271 vulnerabilities in Mozilla’s Firefox, it also developed exploits to take advantage of 181 of those. Overall, Anthropic’s red team, which takes on the role of an attacker to test defenses, and the United Kingdom’s AI Security Institute reported that Mythos found

This Week's Top Five Stories in Cyber

This Week's Top Five Stories in Cyber Securing AI: Behind Palo Alto Networks' Portkey Acquisition Standing at the dawn of the autonomous agentic enterprise era, the insider threat risk now has highly-privileged machine form. To mitigate the threat, cybersecurity leader Palo Alto Networks has revealed plans to acquire AI gateway specialist Portkey. The deal is reflective of the growing urgency among organisations as they scramble to keep autonomous AI agent risks at bay, amid rapid deployment in day to day operations. “AI agents have become privileged insiders, reasoning and executing on behalf of users and companies,” notes Nikesh Arora, Chairman and CEO at Palo Alto Networks. World Password Day: Have Passwords Become Obsolete? In a world mired by cyber incidents, another World Password Day has come by as a reminder to secure our digital lives. First launched by Intel Security in 2013, World Password Day aims to encourage stronger password habits and raise awareness around online security. Held annually on the first Thursday of May, the event has evolved from a static reminder to update weak passwords into a wider conversation on the future of authentication – particularly relevant today as governments, businesses and technology providers increasingly push towards passwordless security. "World Password Day is in desperate need of a rebrand," argues Ev Kontsevoy, CEO at Teleport. "Passwords are broken. The industry knows this. Every static credential – every password, API key, private key or any secret of any kind – is a persistent risk." Trend AI: Agentic AI Adoption in Finance Overlooks Security Agentic AI systems are creating new attack surfaces across the financial sector. Autonomous decision-making tools now operate beyond human oversight in many organisations. TrendAI – a business unit of Trend Micro specialising in AI cybersecurity – has published research exposing the security gaps that emerge when

Canvas system is online after a cyberattack disrupted thousands of schools

Canvas system is online after a cyberattack disrupted thousands of schools Canvas system is online after a cyberattack disrupted thousands of schools Tens of thousands of students studying for final exams around the world Friday regained access to a key online learning system after a cyberattack had earlier knocked it offline, throwing schools and universities into turmoil. Elizabeth Polo was in a creative writing class at the University of Maryland late Thursday afternoon when a classmate shouted, “Canvas got hacked.” A message from a hacking collective flashed on her computer screen. “Our whole class just like was like freaking out about it,” said Polo, a junior. “Our poor professor was trying to get everyone to calm down but it was just kind of chaos.” Across academia, the outage set off panic and confusion as students and faculty members found themselves locked out of a platform they rely on to manage grades and access course notes and assignments. Colleges scrambled to reschedule final exams as students lost any way to access materials they needed to study. Instructure, the company behind Canvas, said in an update late Thursday that the system was available for most users. “Instructure discovered the unauthorized actor involved in our ongoing security incident made changes to the pages that appeared when some students and teachers were logged in,” Instructure said Friday in a statement. “Out of an abundance of caution, we immediately took Canvas offline to contain access and further investigate.” Instructure also said it confirmed that the unauthorized actor exploited an issue related to its Free-For-Teacher accounts. The company has temporarily shut down those accounts. Instructure did not say whether it paid a ransom nor has it said what happened with the compromised data. Rich in digitized data, the nation’s schools are prime targets for far-flung criminal

Canvas platform back online after <b>cybersecurity</b> breach, impacting Triad school districts

Canvas platform back online after cybersecurity breach, impacting Triad school districts TRIAD, N.C. — As tens of thousands of students across the Triad are putting the finishing touches on end-of-year assignments and preparing to take final examinations, a cybersecurity breach of a popular, widely used online learning system has left several school districts statewide having to restrict access—leaving students unable to complete online-based instruction and teachers scrambling for alternative options regarding the submission of final grade books. “I still need to check my grades to make sure I’m still even eligible to keep my job as an R.A., so I won’t even be able to do that since Canvas is down,” Bryan said. Malachi Bryan, a senior graphic design major at the University of North Carolina at Greensboro (UNCG), describes the mass hysteria in his classrooms and the pressure classmates faced after attempting to sign in to the platform to no avail—especially during a pivotal time with important deadlines and last-minute studying. “Every single aspect about class is on Canvas. As a matter of fact, I’ve been using Canvas since elementary [and] middle school," Bryan said. "This impact is not just for college students; it’s a nationwide thing. I’m a graphic design major, so my whole scheme is doing art online." The Canvas platform—used across the country by approximately 8,000 schools and universities—provides a digital course dashboard for both instructors and students. Teachers primarily use this online learning system to upload course material, assign/receive assignments, communicate with students, update grade books, and—in some instances—post final examinations. From student perspectives, the digital application is the heartbeat of their classrooms and course instruction. This dashboard allows students to view and/or download necessary course materials, upload homework assignments, and access their grades across all courses throughout each semester. A hacking group known as

Canvas' Utah-based parent company responds to <b>cyber security</b> breach of school data

Canvas' Utah-based parent company responds to cyber security breach of school data SALT LAKE CITY (KUTV) — Canvas is back up and running after a nationwide cyberattack, but questions remain about how far the disruption reached. Lily Weyland, a Weber State University nursing student, said she saw a suspicious message from hackers while submitting an assignment. Weyland said she was working in Canvas when a message took over her screen for a few seconds. She said she captured a screenshot before it disappeared. MORE | Cyberattack on Canvas - Utah schools warn of scams after cyberattack on Canvas causes massive data breach - Cyberattack on Canvas potentially compromises millions of users' personal information She said the message read in part: “If any of the schools in the affected list are interested in preventing the release of their data, please consult with a cyber advisory firm and contact us privately at TOX.” Weyland said she immediately contacted Weber State’s IT department. “They answered right away, and they told me to log out of all Canvas resources and close all tabs,” Weyland said. “The message was only up for a short amount of time, but definitely an unsettling message to receive,” she said. 2News went to Instructure headquarters in Cottonwood Heights, the parent company of Canvas, to ask what the company is doing to prevent something similar from happening again. Instructure sent 2News this statement: “Yesterday, Instructure discovered the unauthorized actor involved in our ongoing security incident made changes to the pages that appeared when some students and teachers were logged in. Out of an abundance of caution, we immediately took Canvas offline to contain access and further investigate. We have confirmed that the unauthorized actor exploited an issue related to our Free-For-Teacher accounts. As a result, we have made the difficult

Oklahoma <b>cybersecurity</b> expert talks 'ShinyHunters' after nationwide breach

An Oklahoma cybersecurity expert spoke to News 9 on Friday about the nationwide breach of Canvas, a popular learning platform used by schools and iniversitys around the country. Canvas is a learning system that allows students to submit assignments, take tests and manage their day-to-day lessons. RELATED: Canvas student portal is down, multiple schools confirm “It’s embedded into like 40% of all education [institutions] in the United States. So, they hit 9,000 educational institutions; got about 275 million personal records,” said Cybersecurity Specialist with EMSCO Solutions Ron Vaughn. The platform is owned by a company called “Instructure.” “They had been breached by a hacking group. That’s actually a hacking supergroup,” Vaughn stated. The supergroup called “ShinyHunters” is “an amalgamation of three different groups that have worked together since, like September, and they’ve been hitting large organizations that have integrations with Salesforce.” RELATED: Who is the group behind the Canvas cyberattack? Vaughn explained that names, email addresses, private messages, government ID’s and login credentials could have been compromised in Thursday’s attack-- which happened during finals week for many college students. “You hit them when they need it the most. It’s the most, like it’s the best leverage to get them to actually pay up. You want someone to pay quickly. You don’t want them to have time to think about it,” he shared. While the public likely won’t hear about how schools resolve their individual breaches, Vaughn said there are things people can do to strengthen their own cybersecurity. “If you’re involved in the breach, obviously, using any passwords you were using in Canvas, you need to stop using them anywhere else. You want to change that password; use multi-factor authentication.” Two-factor authentication is one of the best ways to protect one’s cybersecurity, he added. ShinyHunters gave schools impacted a May

The Good, the Bad and the Ugly in <b>Cybersecurity</b> – Week 19

The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate. Operating as a specialized “cold case” negotiator, Zolotarjovs (aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom. To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration. Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities. The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale SentinelLABS researchers this week exposed PCPJack, a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data. Unlike

Healthcare <b>Cybersecurity</b> Has Become an Operational Risk, Not Just a Security Function

Healthcare cybersecurity is no longer just a technical discipline handled by IT teams. That view has changed. Cybersecurity in healthcare has grown. It now sits at the intersection of operations, compliance, and patient safety. When systems fail, care is disrupted. These disruptions go beyond data loss, reaching clinical outcomes, financial stability, and regulatory exposure. This is not a future concern. It is already happening. Cyber Risk Is Now Operational Risk Healthcare organizations have become deeply dependent on digital infrastructure. Electronic health records, scheduling platforms, imaging systems, connected medical devices, and revenue cycle technologies all work together to support care delivery. That connectivity has created efficiencies yet also introduced fragility. When a cyberattack occurs, it is rarely isolated to a single system. It cascades. Clinicians lose access to patient histories. Scheduling goes offline. Diagnostic workflows slow or stop. Often, organizations revert to manual processes. This introduces delays and increases the risk of errors. This is why cybersecurity cannot be framed as a back-office function. It directly affects whether care can be delivered safely and consistently. Recent healthcare incidents reveal this shift. Ransomware can shut down services, delay procedures and health system operations, and force hospitals into downtime protocols. These strains affect staff and patients, and are not abstract risks. These incidents are increasingly real and causing operational failures with actual consequences. From Privacy Concern to Care Continuity Challenge Historically, healthcare cybersecurity efforts were driven by compliance requirements, particularly those linked to protecting patient data. Regulations required confidentiality and privacy, and organizations built programs designed to prevent unapproved access to sensitive information. That foundation is still important, but it is no longer sufficient. Today’s threat landscape is focused less on stealing data and more on disrupting operations. Attackers increasingly target the systems that enable care delivery rather than just the data those

Canvas <b>Cybersecurity</b> Incident Update

Dear Families and Staff, We are writing to inform you of a cybersecurity incident involving Instructure, the parent company of Canvas. Canvas is not used by Loudoun County Public Schools. However, it is used by entities outside of LCPS that some students and staff may have access to. This includes students dual-enrolled at Northern Virginia Community College (NOVA), students enrolled in a Virtual Virginia (VVa) course, and staff who have participated in VALLSS training through VDOE/VLA. It is important to emphasize that, based on the information provided by the vendor at this time, this incident was limited strictly to Instructure’s internal Canvas tools. Instructure has stated that it has no evidence that passwords, dates of birth, government identification numbers, or financial information were involved. For more information, please refer to the company’s incident status update page. We are awaiting further information from VDOE concerning staff members who have had VALLSS training regarding any potential next steps. Staff with concerns may also contact VDOE directly with questions. If students or staff who use Canvas through other outside organizations have any concerns or questions, they should contact those programs directly. Loudoun County Public Schools (LCPS) employs a multi-layered security strategy to protect student devices and accounts from scams, intrusion, and inappropriate content. By adhering to these digital safety practices at home and during school hours, students and staff can help protect themselves and their assigned technology. As a reminder, students and staff should avoid clicking on suspicious links, opening unexpected attachments, or providing login information in response to emails or messages. Just to be clear, LCPS systems and devices were not impacted. Students and staff who experience anything suspicious should report it through the standard processes. We appreciate your understanding and will provide additional information as needed to support our students, families,

<b>Cybersecurity</b> experts warn the public after Canvas attack impacts Baylor | kcentv.com

WACO, Texas — A nationwide cybersecurity incident involving the Canvas learning platform disrupted colleges and universities across the country this week, including Baylor University, as students prepare for finals and commencement ceremonies. Baylor officials said Canvas access was restored Friday afternoon after a widespread outage forced changes to the university’s finals schedule and raised concerns about cybersecurity and data protection. The university rescheduled Friday’s final exams for the following week, while other exams continued as scheduled. Investigators say the ransomware group “ShinyHunters” claimed responsibility for the attack, allegedly threatening to release personal data unless ransoms were paid. Cybersecurity expert James Turgal said attacks on a platform as large as Canvas can impact millions of users. “When you hit a platform, it’s not like hitting an individual application,” Turgal said. “You’re literally hitting the platform that affects probably some 9,000 schools and up to 275 million students, teachers and staff.” Experts say many cyberattacks begin with phishing emails designed to trick users into clicking on malicious links or entering personal information. Matt Rosenthal, CEO of Mindcore Technologies, said that most of the cybersecurity breaches his company encounters begin in this manner. “Almost every single breach that we deal with, and we deal with them every single day, somebody either clicked on an email that had a link in it, or they actually clicked on it, opened it and entered some information,” Rosenthal said. “As soon as you do that, you’re giving people a key to the front door.” Rosenthal recommends using strong and unique passwords for different accounts, enabling multi-factor authentication and avoiding suspicious emails or downloads. “You’ve got to turn that on for every single account that you have,” Rosenthal said about multi-factor authentication. “It should be your email, the banks, the credit cards. If you don’t have that turned

Canvas owner confirms <b>cybersecurity</b> incident

Dive Brief: - A recent cybersecurity attack on Instructure exposed certain student information, the ed tech company confirmed in a May 1 status update. The following day, it said it believes the incident has been contained. - Information impacted by the data breach includes messages between users, names, email addresses and student ID numbers, according to Instructure. The company said no passwords, dates of birth, government identifiers or financial information were believed to have been compromised as of May 2. - While Instructure said it is actively investigating the incident alongside forensics experts, the company has not disclosed how many school districts were affected. Dive Insight: Instructure, on its homepage, touts itself the “most-visited education website in the world.” The company operates several ed tech products for colleges and K-12 schools, including the widely used Canvas learning management system. Canvas has over 6 million “concurrent users,” according to Instructure’s website. The company did not explicitly say the breach had affected Canvas, but it said it was investigating disruptions to some Canvas tools and putting the system under maintenance around the same time it announced the data breach. Upon request for comment and further details regarding the cybersecurity incident, Instructure told K-12 Dive in a Tuesday email to check the company’s status page, where it said updates on the breach would be provided as they become available. In response to the incident, Instructure said on its status page, the company has revoked privileged credentials and access tokens related to the affected systems, deployed patches to increase system security, and heightened monitoring across all of its platforms. The incident at Instructure marks the latest known data breach for a large ed tech vendor with sweeping implications for institutions’ sensitive student and staff data. Other recent high-profile cyberattacks targeted PowerSchool, a cloud-based K-12

UIUC postpones finals and assignments amid widespread Canvas <b>cybersecurity</b> breach

Champaign, IL (CHAMBANA TODAY) – The University of Illinois Urbana-Champaign has postponed all final exams and assignments through Sunday after an ongoing cybersecurity incident disrupted the Canvas learning platform used by students and faculty. University officials say the disruption stems from a security breach involving Instructure, the parent company of Canvas, which reported the incident affecting more than 8,000 institutions nationwide. According to University of Illinois Technology Services, the breach occurred Friday at the vendor level and involved unauthorized access to user information. Exposed data may include names, email addresses, student identification numbers, and course-related messages. In addition to the security concerns, students across campus have reported widespread issues accessing coursework and course materials. University officials say learning content will remain unavailable until the platform’s parent company resolves the issue and restores secure access. The university says it is actively monitoring the situation and coordinating with the vendor while providing updates to students and faculty as more information becomes available.