I can assert with a high degree of confidence ShinyHunters did not exfiltrate highly sensitive information.
Based on information I've received the primary information stolen from the schools is student names and email addresses. Furthermore, this has been confirmed by various media outlets.
This in of itself isn't bad.
The primary issue with this however is that it would expose children in K-12 online (first and last name). Adults having their full legal name and email address online is something you could (probably) find on LinkedIn or a university directory. Adults will be ignored if data is leaked. K-12 will be a nightmare. Hence, educational institutions must put together a strategy to handle a K-12 potential data leak.
Presumably parents will be outraged and this will inevitably result in a lawsuit against the schools or Canvas.
The much larger issue however is the catastrophic damage ShinyHunters has done to Canvas both operational and reputational.
Exfiltrating data from a compromised host is as simple as initializing a file transfer. The question then: why is Canvas still "in maintenance mode"? The only logical conclusion is ShinyHunters did SOMETHING to prevent Canvas from working as intended.
This places Canvas is a terrible, terrible, terrible position. Their service has resulted in minors having their names (potentially) leaked and educational institutions can't use the platform they pay for. Furthermore, this makes major educational institutions look like a bunch of morons.
Students are paying top dollar for an education and suddenly ... poof ... a good chunk of their work or study material has vaporized because it was stored in a 3rd party platform outside the control of the educational institution.
Basically, the data breach itself isn't bad except the K-12 part. The operational impact is devastating and the fallout will be a nightmare. Canvas employees are probably scrambling, their cybersecurity team is probably having panic attacks, and executive leadership is probably drunk right now screaming at the wall.
DJMAX RESPECT V가 오늘로 정식 서비스 6주년을 맞이했습니다.
6년간 보내주신 사랑과 응원에 진심으로 감사드립니다.
앞으로도 더 좋은 음악과 경험으로 여러분께 보답하겠습니다.
늘 함께해주셔서 감사합니다.
#DJMAX#RESPECT_V#THANK_YOU#6YEARS
ai will replace jobs like this:
- accountant
- investment banker
- lawyer
- consultant
but will create NEW jobs like this:
- vape vending machine owner
- indoor shrimp farmer
- indoor bee/honey farmer
- scrap metal enthusiast, copper looter
- jestermaxxer and or mogger
- mobile gamer
- goonbaiter
- kick stream clipper
> Epstein writes down email and password
> FBI finds it
> Stores as evidence
> Doesn't censor
> Released
> Nerds find Epstein password
> No MFA
> I wonder if anyone logged in?
> Look inside
Yesterday evening someone leaked PlaySation 5 ROM keys online. Emulation nerds are going schizo because this could mean we have PlayStation 5 emulation technology, ability to run non-PlayStation 5 games, etc.
tl;dr Sony executives on New Years eve
Elon Musk emailed me
And asked for my help
What an honor
"Hello sir/ma'am, it is Elons Musk. I am stuck in spaceship here in Mars and need someone to send me a $500 gift cards to Walmart gift card so i can buy space ship fuel to returns home.
Please send and I will return you $50 million when I get back. If you don't beleive me see please attached photo."
I rushed to Walmart to purchase the gift cards and immediately mailed them to his new SpaceX facility in Lagos, Nigeria
Can't wait to receive my $50m in a few months once the wire transfer goes through
Lesson: When a billionaire asks for help, act quickly!
Last week I hosted family for Thanksgiving.
My 12-year-old nephew asked for the WiFi password.
He wanted to play Roblox on his iPad.
I looked at the device.
Unmanaged. No antivirus. No encryption.
I’m an IT Professional. I don't run an open network.
So I didn’t give him the password.
Instead, I spent 45 minutes provisioning a Guest VLAN.
I set up a captive portal.
I throttled the bandwidth down to 56kbps.
Then I blocked all traffic on ports 80 and 443.
He came back crying. He said it wouldn't load.
My sister screamed at me to "just let him play."
I told her that Zero Trust architecture doesn't care about bloodlines.
We didn't have a "fun" Thanksgiving.
But we had a secure perimeter.
You’re welcome for the compliance.