Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Incident topic

No spam. Unsubscribe anytime.

Board hears update on Canvas breach, members flag identity-based attacks and urge zero-trust and faster patching

Technology Advisory Board · May 28, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

During the May 28 meeting members discussed a Canvas/Instructure data incident and broader identity-based threats (attributed by participants to groups like "Shiny Hunters"), and urged tighter device/identity controls, faster patching cadence and clearer vendor communications.

At its May 28 meeting the Technology Advisory Board discussed a recent security incident involving Canvas (the learning platform from Instructure) and broader cybersecurity risks facing cloud-hosted services. Participants said the board was initially notified that Canvas had experienced a breach and that vendor communications were too generic; the group asked the vendor for a direct statement to the town.

One participant identified the criminal group often called "Shiny Hunters" as an actor in similar incidents and described tactics that can defeat traditional multi-factor authentication (MFA), including vishing and session-token theft. Participants said these identity-based attacks can allow an attacker to use valid credentials to access SaaS accounts even when MFA is enabled.

Board members and participants recommended moving toward a zero-trust posture that requires both device and identity checks for access, and they emphasized improving patch-management velocity. In the meeting a participant said the community should aim to apply critical patches within roughly two days and high-severity patches within about seven days; participants also recommended using device-management and third-party patching tools to accelerate updates.

The meeting also included discussion of emerging AI-driven tooling (referred to as "Mythos" in the transcript). Participants warned that such tools could escalate the number and severity of exploitable chains by linking multiple small vulnerabilities into critical attacks, increasing the volume of urgent patches the town will need to apply in the near term.

Next steps: participants said the board will share Instructure's official disclosure when it is received and will provide a fuller update at the June meeting. No formal action or new cybersecurity policy was adopted at this session.