Cybersecurity Daily: News & Threats · 12 May 2026 · 4 min

Checkmarx Breached Twice & Canvas Hits 9,000 Institutions

TeamPCP returns to Checkmarx weeks after the first breach — a clear sign incident response failed — while ShinyHunters claims a Canvas LMS compromise affecting nine thousand universities worldwide. Today's briefing breaks down both supply chain attacks and what incomplete remediation really costs.

Cybersecurity Daily: News & Threats
Now Playing
Checkmarx Breached Twice & Canvas Hits 9,000 Institutions

Audio is available on Spreaker — see link below.

What's covered

Checkmarx Breached Again by TeamPCP

Checkmarx was breached again. The same threat actor.

Listen now →

TeamPCP Campaign Scope

To put this in context, TeamPCP has been running a coordinated campaign across the developer toolchain since March. Their targets include Checkmarx's KICS Docker image, VS Code extensions, GitHub Actions workflows, and a compromised Bitwarden CLI package on npm.

Listen now →

Canvas Breach Hits Nine Thousand Institutions

Separately, ShinyHunters claimed a breach of Instructure's Canvas platform. Canvas is the dominant learning management system in higher education globally.

Listen now →

Education Sector's Systemic Exposure

The Canvas breach reinforces a pattern that's worth stating plainly. Education institutions consolidate enormous volumes of sensitive data through third-party SaaS platforms, and those platforms are attractive targets precisely because of that concentration.

Listen now →

What Matters Next

Two things are worth watching closely from here. On the Checkmarx side, the key question is whether they can now identify and close every persistence mechanism TeamPCP established.

Listen now →

Chapter summary auto-generated from the verified script. Listen to the full episode for the complete content.

More episodes

From Cybersecurity Daily: News & Threats