🛡️ CISO Intel — Tuesday, 05-05-2026
Due to API rate limiting, here is today’s briefing:
Alright, let’s cut through the noise. Tuesday, another day, another fresh hell. This isn’t your grandma’s patch Tuesday, but we’ve got some real headaches brewing.
🔴 Critical Threats & Active Exploitation
Instructure (Canvas LMS) — Active Breach — The ShinyHunters crew hit Instructure, the company behind Canvas LMS. They’re claiming 3.65 TB of data from 275 million users across 9,000 educational institutions. Names, emails, student IDs, and private messages are out there. This is a massive blast radius, affecting students and educators globally. If your organization uses Canvas, assume this data is compromised and act accordingly.
AI Systems — Prompt Injection Attacks — This isn’t theoretical anymore. Google and Cloudflare confirm active “indirect prompt injection” attacks in the wild against production AI systems. Attackers are embedding malicious instructions in web pages, documents, and emails that AI agents then consume and act on. This bypasses traditional security and can lead to data exfiltration or even remote code execution. This is a new zero-day class of vulnerability for your AI-powered tools.
🛡️ CVEs Worth Your Attention
[Clear — enjoy it]
⚡ New TTPs & Attack Research
Prompt Injection Evolution ⚡ — Attackers are getting clever with prompt injection. We’re seeing techniques like embedding “lures” (small text fragments) to trick AI models into thinking malicious code is safe, and hiding instructions within large codebases to evade detection. This is T1566 (Phishing) and T1598 (Phishing for Information) on steroids, directly targeting the AI’s reasoning.
North Korean “Contagious Interview” Campaign (PurpleBravo) 🧪 — North Korea-linked APT PurpleBravo is scaling a social engineering playbook. They’re luring developers with fake recruiter outreach and weaponizing “interview” coding assignments to land malware on endpoints. Classic T1566.001 (Spearphishing Attachment) with a developer twist. Make sure your dev teams are extra vigilant.
AI-Accelerated Phishing 🧪 — Phishing emails are getting scarier. AI is being used to craft hyper-realistic emails that mimic tone, context, and even blend into existing conversations. They’re using lookalike domains and trusted services (Google Drive, SharePoint) to bypass traditional email security. Your users need to be trained for this new level of sophistication.
🏗️ DevSecOps & Cloud Security
Cisco Acquires Astrix Security 🏗️ — Cisco is moving to acquire Astrix Security, a non-human identity (NHI) security firm. This is a clear signal that securing AI agents and their API keys, service accounts, and OAuth tokens is becoming a critical, dedicated area of focus. If you’re deploying AI agents, this is your new attack surface.
AWS Security Updates 🏗️ — AWS published guidance on securing open proxies, optimizing Security Hub, and enhancing IAM Identity Center session tags. Good hygiene, but nothing groundbreaking. They also released an ISO 31000:2018 Risk Management on AWS Compliance Guide.
🔧 Patches & Vendor Releases
Instructure — Canvas LMS — 🟡 partial/workaround needed — Following their breach, Instructure reissued API keys, revoked privileged credentials, and deployed fixes. This is a reactive cleanup. The root cause of the initial compromise needs to be fully understood, and users should assume their data is exposed.
🧪 Threat Intel & Malware
ShinyHunters Ransomware — This group is still very active, now claiming the massive Instructure breach. They specialize in social engineering and extortion.
Nation-State Activity —
- Iran-backed actors are actively targeting over 3,900 exposed U.S. PLCs and SCADA systems. Critical infrastructure is in the crosshairs.
- Pro-Russia hacktivists are escalating disruption campaigns against critical infrastructure and local government in the UK.
- Russian cyber actors are also hitting messaging apps like Signal and WhatsApp with phishing and social engineering.
- World Cup 2026 Threat Landscape: Expect opportunistic criminal activity (phishing, fake ticketing) and nation-state targeting (Iran, Russia, China, North Korea) around the upcoming event. Identity controls, vendor access, and IR are key.
Global Crypto Fraud — An ongoing operation since 2023, registering dozens of lookalike and algorithm-generated domains monthly to distribute malware for surveillance, credential theft, and financial fraud. This is a persistent, evolving threat.
🌐 Industry, Brand & Internet Security
Instructure Data Breach — This is a major incident impacting the education sector, affecting millions of students and faculty. The reputational and privacy implications are significant.
Typosquatting & Brand Impersonation — Still a primary vector for phishing and brand abuse. Attackers are constantly registering fake domains and impersonating brands. External threat protection is no longer optional.
🤖 AI & LLM Security
Prompt Injection is Real and Active 🔴 — This is the big one. Indirect prompt injection is now a confirmed, active enterprise threat. OWASP has ranked it LLM01:2025, the top risk for LLM applications. Attackers are tricking AI systems into overriding safeguards, exposing data, and performing unauthorized actions. Traditional security tools are blind to this.
AI Agents: New Attack Surface — The rise of agentic AI means a rapidly expanding attack surface. These agents, with their access to data and ability to take actions, are being weaponized through prompt injection. Model guardrails alone are not enough; data-layer enforcement and robust non-human identity security are critical.
📋 Compliance & Regulatory
[Clear — enjoy it]
💡 Marcus’s Take
Today’s news is a harsh reminder: the attack surface isn’t just expanding, it’s evolving. The Instructure breach shows that traditional data exfiltration is still a massive problem, but the real shift is in AI. Prompt injection attacks are not a bug in the code; they’re a bug in the language model’s interpretation. Your AI isn’t being hacked, it’s being socially engineered. This means our security models need to shift from code and infrastructure to intent and context. If your AI can read it, it can be poisoned. Prioritize securing non-human identities and implement data-layer enforcement for your AI systems, because your models are already talking to the attackers.