Boosted by jsonstein@masto.deoan.org ("Jeff Sonstein"):
zackwhittaker ("Zack Whittaker") wrote:
Hackers injected a CSS file into the Canvas login page that takes over the screen when it loads. The CSS file is hosted on an AWS bucket owned by Instructure. The file path suggests the hackers uploaded the CSS file through Canvas and directly linked to it.
Read online: https://techcrunch.com/2026/05/07/hackers-deface-school-login-pages-after-claiming-another-instructure-hack/
I saved a copy of the CSS file: https://web.archive.org/web/20260507195732/https://instructure-uploads-apse2.s3.ap-southeast-2.amazonaws.com/account%5F189630000000000001/attachments/130311/canvas-override.css