Canvas Pays Ransomware Hackers; AI Chatbots Leak Personal Data
This week saw significant cybersecurity disruptions, headlined by the massive ransomware attack on Canvas, an online learning platform used by over 9,000 schools. The breach locked users out during finals, prompting parent company Infrastructure to pay the hacker group ShinyHunters to restore services and delete stolen data. This decision has drawn criticism for encouraging future ransomware crimes and may not prevent impending class-action lawsuits. In artificial intelligence security, researchers identified hackers using AI to discover zero-day vulnerabilities, though Google successfully intervened to patch a targeted flaw. Meanwhile, Microsoft developed an internal AI model that rapidly identified numerous Windows vulnerabilities. Additionally, a concerning trend emerged where AI chatbots, including Google's Gemini, are inadvertently disclosing individuals' private phone numbers and personal information when prompted, leading to a surge in privacy removal requests. These incidents highlight growing challenges in digital security, ranging from corporate ransomware responses to the unintended privacy risks posed by large language models trained on public data.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection