Cybersecurity News records disclosures as they land: breaches, exploited vulnerabilities, emergency patches, vendor advisories, arrests and regulatory penalties. Entries state who is affected, whether a fix exists and which version carries it. For practitioners who need the day's developments without marketing attached.
Daily record of disclosed breaches, exploited vulnerabilities, vendor advisories, takedowns and enforcement actions, each with patch status noted.
After ShinyHunters set a May 12 ransom deadline and claimed a second intrusion, the U.S. Department of Education warned schools about the ongoing Canvas LMS incident.
A late-April 2026 intrusion and outage hit the learning platform used by millions of students; the extortion crew claimed a massive haul, and schools spent the week assessing exposure.
The April 14, 2026 update patches 163 vulnerabilities — 8 rated critical — with a SharePoint flaw and a Windows Shell flaw both confirmed under active exploitation.
On March 5, 2026, CISA added five flaws with confirmed in-the-wild exploitation to the catalog that sets binding patch deadlines for federal agencies — and sensible ones for everyone else.
Emergency directive ED 26-03, issued February 25, 2026, requires federal agencies to patch actively exploited Cisco SD-WAN vulnerabilities including an authentication bypass rated critical.