Known Exploited Vulnerabilities and counting....

A known exploited vulnerability (KEV) refers to a software vulnerability that is being actively exploited by cybercriminals or threat actors. When a vulnerability becomes known to be exploited in the wild, it signals that the vulnerability poses a significant and imminent risk to organizations.

Cybersecurity Brief – May 9, 2026

Major Education Platform Breach Exposes 275 Million Records

Instructure's Canvas learning management system suffered a significant data breach this week, with the ShinyHunters ransomware group claiming responsibility for stealing approximately 275 million records. The attack impacted 8,809 educational institutions across the United States during finals week, disrupting millions of students, teachers, and staff. Canvas has since deployed security patches to restore service, but the scope of compromised personal data—including student and faculty information—represents one of the largest education sector breaches on record. The timing during critical examination periods amplified the operational impact across K-12 schools and universities nationwide.

Regulatory and Infrastructure Developments

The New York Department of Financial Services fined Delta Dental $2.25 million over failures related to the 2023 MOVEit vulnerability incident, marking continued regulatory enforcement stemming from that supply chain compromise. Meanwhile, CISA launched its "CI Fortify" initiative, urging critical infrastructure organizations to develop contingency plans for potential geopolitical cyber crises that could sever internet and telecommunications connectivity. The guidance signals heightened concern about nation-state threats capable of causing widespread infrastructure disruption.

Sources: CNN · WRAL · Malwarebytes · Norton Rose Fulbright · Federal News Network

Woman Looking at Computer Screen

CVEs form a database of known security vulnerabilities that are actively tracked and managed by a group of organizations, such as the U.S. National Cyber Security Alliance. CVEs are an important tool for network security management because they not only provide an inventory of existing vulnerabilities, but also provide information about how the vulnerability can be exploited and instructions on how to protect against it.

Search Known Exploits

Search for CVEs by vendor to identify known exploited vulnerabilities in your environment

Loading vendors...

Upcoming Patch Due Dates

via Binding Operational Directive 22-01

(BOD) 22-01 is a directive issued by the Cybersecurity and Infrastructure Security Agency (CISA) in the United States to federal agencies and federal contractors in order to improve their cybersecurity practices. It provides a set of guidelines and requirements that these agencies and contractors must follow to increase their defenses against cyber threats.

Loading...

News Logo

Cyber Security News

You may have missed...


📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://www.aljazeera.comMay 9

Hacked educational platform partially restored for millions of students | News | Al Jazeera

The hacker group, ShinyHunters, threatened to leak student data after breaching the educational platform Canvas.

https://www.cnn.comMay 9

What is Canvas and why is the hack a big deal? | CNN

A cyberattack on the learning platform Canvas disrupted access for several critical hours, leaving students and educators scrambling just as many ...

https://techcrunch.comMay 9

Poland says hackers breached water treatment plants, and the US is facing the same threat

A report by Poland's top intelligence agency accused Russia of sabotage and hacking activities against the country's military and civilian ...

https://www.cnn.comMay 9

Canvas hack: What we know about apparent cyberattack that impacted thousands of schools

A cyberattack shut down the Canvas education platform used by universities and K-12 schools across the US, impacting millions of students during final...

https://www.highereddive.comMay 9

Canvas owner confirms cybersecurity incident - Higher Ed Dive

Canvas owner confirms cybersecurity incident. Ed tech company Instructure said the data breach affected user names, messages and email addresses, as ....

https://www.inc.comMay 9

The AI Wars Are Having a Surprising Cybersecurity Benefit. Here's How - Inc. Magazine

The AI company announced on Thursday that it is releasing a limited preview of a model called GPT-5.5-Cyber to vetted cybersecurity professionals ...

https://www.sentinelone.comMay 9

The Good, the Bad and the Ugly in Cybersecurity – Week 19 - SentinelOne

The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators. Federal authorities have successfully secured ...

https://www.trmlabs.comMay 9

North Korea Stole 76% of All Crypto Hack Value in 2026 — With Just Two Attacks

North Korean hacking groups stole approximately $577 million in 2026 YTD (76% of all crypto hack losses) through just two highly targeted attacks on D...


Updated daily