Edition

Canvas Hackers Paid to Delete 3.65 TB of Stolen Data, NYDFS Fines Delta Dental $2.25M, and FTC Bans a Data Broker From Selling Location Data

SaltyCloud Research Team

Updated May 14, 2026 Read Time 11 min

InfoSec GRC Brief | May 2026

Welcome back to the InfoSec GRC Brief from SaltyCloud, your go-to source for curated insights on governance, risk, and compliance (GRC) in information security. This edition covers the GRC news worth sharing from the first half of May 2026.

Let’s get into it.

Regulatory & Compliance Updates

Instructure Pays Canvas Hackers to Delete Stolen Student Data, Acknowledging Bitcoin Ransom in Rare Public Disclosure

Instructure confirmed it paid the ShinyHunters extortion group after the April 29 breach of its Canvas LMS and accepted “digital confirmation of data destruction” in exchange. The breach disrupted finals at roughly 9,000 universities across the US, Canada, Australia, and the UK, with ShinyHunters threatening to leak 3.65 TB of records covering 275 million students and staff. Same group claimed the 10M-record ADT Salesforce breach we covered last edition.

Paying contradicts standing FBI, NCA, and Five Eyes guidance, which warns that payment fuels future attacks and cannot guarantee deletion. When the NCA infiltrated LockBit in 2024, investigators found stolen data the group had pledged to delete after payment.

Instructure’s public disclosure is unusual, and the decision pattern is now benchmark data for any IR playbook. Boards, legal, and CISOs can pressure-test their ransom-payment policy now:

  • Payment authority
  • OFAC screening
  • Customer notification triggers
  • Whether cyber insurance covers ransom under silent-AI or systemic-attack clauses

Read more →

NYDFS Reaches $2.25M Settlement With Delta Dental Over MOVEit-Era Cybersecurity Violations

NYDFS announced a $2.25M settlement with Delta Dental Insurance and Delta Dental of New York on April 30, resolving alleged Part 500 violations tied to the 2023 MOVEit zero-day breach. The complaint cited failures in incident-response policy, secure data disposal, and notification timing to DFS.

This is NYDFS’s first Part 500 enforcement action of 2026 and continues the pattern from OCR’s $1.7M HIPAA settlements last edition. Regulators are sanctioning the documentation gap, not just the technical compromise. Three years after MOVEit, the enforcement tail is still active and still expensive.

Compliance officers at any Part 500-covered entity can audit notification clocks against actual incident timelines, validate that IR policies match documented procedures, and confirm that secure-disposal controls cover archived data, not just production systems.

Read more →

FTC Bars Data Broker Kochava From Selling Location Data Without Affirmative Express Consent

After four years of litigation, the FTC filed a proposed order permanently barring Kochava and subsidiary Collective Data Solutions from selling, sharing, or disclosing precise location data without affirmative express consent for a service the consumer directly requested. The order also requires Kochava to report any third-party supplier that shares location data without valid consent, effectively conscripting the broker into policing its own supply chain.

The affirmative-consent standard now extends well beyond prior FTC data-broker cases, and opt-out or implied-consent models no longer satisfy federal expectations for sensitive location data. State AGs in Texas, Connecticut, Colorado, and Oregon have signaled increased enforcement appetite under their comprehensive privacy laws, and the FTC’s order is the new federal floor they’ll likely reference.

Privacy officers, DPOs, and vendor-risk teams can use the order as a contract-negotiation lever at the next renewal cycle. Ad-tech, analytics, HR-tech, and IoT vendor agreements can incorporate consent-stack attestation, supplier-reporting expectations, and right-to-audit language tied to the new standard.

Read more →

Canadian Privacy Regulators Find OpenAI’s ChatGPT Training Violated PIPEDA and Three Provincial Privacy Laws

A joint investigation by Canada’s federal and Quebec, BC, and Alberta privacy regulators found that OpenAI’s training of GPT-3.5 and GPT-4 violated PIPEDA and three provincial privacy laws. PIPEDA Findings #2026-002 cites overcollection (including health data, political opinions, and information about minors), lack of valid consent, inadequate access and deletion rights, and premature commercial deployment despite known risks. Privacy Commissioner Philippe Dufresne said OpenAI “launched ChatGPT without having fully addressed known privacy issues.”

This is the most detailed regulatory anatomy of generative-AI training practices from any G7 data protection authority, and its consent-first, data-minimization framing closely mirrors GDPR. Paired with the CISA and G7 SBOM-for-AI framework released the same week (below), it signals coordinated AI governance pressure across G7 jurisdictions.

AI governance leads and privacy officers can use the findings as a vendor due-diligence template covering training-data lineage, consent and lawful-basis documentation, data-subject rights workflows for training data, and contractual commitments around retraining and deletion.

Read more →

EU Council and Parliament Strike Provisional Deal to Delay High-Risk AI Act Deadline to December 2027

Following the failed April 29 trilogue we covered last edition, EU governments and Parliament negotiators reached a provisional agreement on May 7 to extend the AI Act application date for high-risk systems from August 2, 2026 to December 2, 2027. The deal covers biometrics, law enforcement, critical infrastructure, education, and employment, with product-embedded AI pushed to August 2028. New bans on AI-generated non-consensual intimate imagery still take effect December 2026.

The agreement still requires formal Council and Parliament approval, and the same law-firm analyses we cited last edition still apply. No extension takes effect until it’s published in the EU Official Journal.

AI governance programs with EU deployments can use the extended runway to mature documentation, risk management, and post-market monitoring without releasing pressure on the August 2026 timeline. The pragmatic move is to plan to August as a floor and treat any ratified extension as recovered margin, not the new baseline.

Read more →

GRC Strategies

Five Eyes Publish First Coordinated Guidance on Agentic AI as a Distinct Cybersecurity Risk

Cybersecurity agencies from the US (NSA, CISA), Australia, Canada, New Zealand, and the UK jointly released Careful Adoption of Agentic AI Services on April 30, the first coordinated guidance treating autonomous AI agents as a distinct cybersecurity and governance risk. The paper outlines five risk classes:

  • Privilege
  • Design and configuration
  • Behavior
  • Structural
  • Accountability

The agencies recommend integrating agentic AI into existing zero-trust and least-privilege frameworks, deploying agents incrementally, and enforcing strong identity, logging, and human-approval controls for high-impact actions. This document is likely to function as a de facto policy baseline alongside the CISA SBOM-for-AI guidance below, and regulators and auditors will reference both when evaluating AI governance maturity. NCSC-NZ’s companion page also maps the practices to NIST CSF 2.0.

GRC programs can inventory existing AI agents (including shadow deployments), assign each one an identity, and decide which actions require human approval before someone else decides for them.

Read more →

CISA and G7 Partners Release First Multinational SBOM for AI Minimum Elements Framework

On May 12, CISA and G7 cybersecurity partners (Germany’s BSI, France’s ANSSI, the UK’s NCSC, Canada’s CSE, Italy’s ACN, Japan’s NCO, and the European Commission) released SBOM for AI – Minimum Elements. It’s the first multinational consensus framework for what must be documented about AI systems and their supply chains, organized into seven clusters:

  • Metadata
  • Models
  • Dataset properties
  • System-level properties
  • KPIs
  • Security properties
  • Infrastructure

The guidance explicitly states that SBOM for AI must be paired with vulnerability scanning and threat intelligence to deliver real supply chain protection. The framework is voluntary today, but the trajectory mirrors traditional SBOMs, which moved from guidance to federal procurement requirement in under three years. Alongside the PIPEDA OpenAI findings and the Five Eyes agentic AI guidance, the G7 is converging on a coordinated AI accountability posture.

Third-party risk and procurement teams can use the seven-cluster framework now as a vendor due-diligence questionnaire for AI-enabled products, and legal can add SBOM-for-AI disclosure language to AI vendor contracts before the regulatory ratchet tightens.

Read more →

Allianz Transfers Commercial Cyber Insurance Business to Coalition in 10-Year Exclusive Partnership

Allianz Commercial and Coalition announced a 10-year agreement on May 6 under which Allianz will exit its standalone commercial cyber business and transition pricing, product, risk mitigation, and claims management to Coalition as its exclusive global cyber partner. Phased rollout begins in the US, UK, Australia, and Germany. Allianz gets equity in Coalition and a board seat, creating what will likely be the world’s largest active cyber insurer, designed to monitor policyholder security posture in real time and price coverage accordingly.

The model differs structurally from point-in-time questionnaire underwriting. Continuous telemetry feeds into pricing, capacity, and claims decisions throughout the policy term. Combined with the III/Fenix24 severity report below, the cyber insurance market is moving toward continuous monitoring and tighter coverage scope simultaneously.

Risk managers and CISOs renewing cyber policies can clarify how the transition affects current terms, capacity, and the claims-management chain. Controls hygiene that has drifted since binding will now show up in renewal economics, not just at audit time.

Read more →

Cyber Claim Severity Accelerates as AI and Litigation Outpace Falling Premiums, III and Fenix24 Report

A May report from the Insurance Information Institute and Fenix24 found cyber claim severity is rising even as premium rates soften, driven by AI-accelerated attack sophistication and a wave of litigation over policy definitions. The report calls it a “soft market paradox”: lower premiums mask expanding coverage gaps, with silent-AI exclusion language increasingly embedded in renewing policies without prominent disclosure.

The gap matters most when paired with the Google AI-built zero-day disclosure below. Attackers are using AI to iterate exploits faster while underwriters quietly carve out coverage for losses AI helped cause.

Risk managers preparing FY27 cyber budgets can flag the divergence directly to the CFO and board: falling rates do not mean falling exposure. They can also ask brokers for a written analysis of AI, systemic-outage, and state-sponsored-attack exclusion language before any renewal, and the Allianz-Coalition transition is the natural opportunity to make the request.

Read more →

Cyber Incidents & Risk Implications

TeamPCP Compromises Checkmarx Jenkins AST Plugin in Sprawling Developer-Toolchain Supply Chain Campaign

The Checkmarx supply chain campaign we covered in April widened in May. On May 9 and 10, TeamPCP published a backdoored Checkmarx Jenkins AST plugin to the Jenkins Marketplace (CVE-2026-33634, CVSS 9.4). Using credentials stolen in the Trivy attack, the campaign has now compromised Checkmarx GitHub Actions, VS Code extensions, the KICS scanner, the Bitwarden CLI npm package, and 66+ additional npm packages. Over 1,000 enterprise SaaS environments may be exposed.

The pattern matters more than any single CVE. Attackers are systematically targeting the security tooling defenders use to detect attacks, the same dynamic that made Bomgar/BeyondTrust RMM exploitation so effective last edition. A compromised SAST plugin gives the attacker visibility into every codebase it scans and credentials for every CI/CD runner where it executes.

TPRM and software-supply-chain programs can use this as a triggering event: inventory every security tool running inside CI/CD pipelines, rotate every secret visible to Jenkins runners (GitHub tokens, cloud credentials, Docker configs, SSH keys), and add software-supply-chain risk to the standing board cyber agenda.

Read more →

CISA Adds ConnectWise ScreenConnect and Microsoft Windows Shell Flaws to KEV With May 12 Federal Deadline

CISA added two actively exploited flaws to its KEV catalog: CVE-2024-1708, a path-traversal flaw in ConnectWise ScreenConnect (CVSS 8.4) enabling RCE and direct data access, and CVE-2026-32202, a Windows Shell protection-mechanism failure enabling network spoofing. BOD 22-01 required Federal Civilian Executive Branch agencies to remediate both by May 12.

ScreenConnect’s downstream reach is the GRC story, and the pattern matches the Bomgar/BeyondTrust RMM exploitation we covered last edition. The tool backbones many MSP remote-access environments, so a single unpatched MSP instance creates exposure across that MSP’s entire customer base.

Vendor-risk owners can request patch confirmation from every MSP or IT-service supplier still running ScreenConnect. The May 12 deadline works as a pressure point for any contractually obligated supplier slow to respond to standing patch SLAs.

Read more →

Google Confirms First Real-World Zero-Day Exploits Built With Generative AI

Google’s security teams identified real-world zero-day exploits developed with generative-AI tooling rather than handcrafted by human experts. The disclosure is the clearest evidence to date that AI-assisted exploit development has moved from research demos into operational use, landing the same week as the Five Eyes agentic AI guidance and the CISA SBOM for AI framework.

The downstream effect is timeline compression. If attackers iterate exploits faster, the window between disclosure and weaponization shrinks, and patch-management SLAs calibrated to historical exploitation timelines are now dated. Combined with the III/Fenix24 silent-AI exclusion language in renewing policies, organizations face a compounding risk: faster exploitation and narrower insurance coverage for AI-related losses.

GRC teams can re-evaluate patch SLAs for highest-risk assets against KEV inclusion timelines from the last 90 days and revisit any exception process that quietly extends patch windows past stated policy.

Read more →

CISA Adds “Copy Fail” Linux Kernel Local Privilege Escalation to KEV, Most Major Distributions Affected

CISA added CVE-2026-31431, the Copy Fail Linux kernel local privilege-escalation vulnerability, to its KEV catalogafter exploitation in the wild. The flaw affects virtually all major Linux distributions, and attackers are chaining it with initial-access vectors for full system compromise.

KEV inclusion comes with binding patch deadlines for US federal agencies and is increasingly used by regulators and cyber insurers as a benchmark for reasonable remediation. Linux runs most cloud workloads, container hosts, and CI/CD infrastructure, which is exactly the runtime layer the Checkmarx Jenkins campaign above targets.

Vulnerability management teams can use this to stress-test their kernel inventory: surfacing every affected workload within 24 hours. The patch itself is the easier half of the problem.

Read more →

SaltyCloud Research

NIST CSF 2.0 Multi-Framework Crosswalk

A free crosswalk mapping all 106 CSF 2.0 subcategories to NIST 800-53 Rev 5, 800-171 Rev 3, ISO 27001:2022, CIS Controls v8, and SCF at the individual control level, with a Coverage Summary tab showing per-Function coverage at a glance.

Access the crosswalk →

NIST 800-53 Vendor Management: Complete Guide [2026]

How the SA and SR control families govern third-party risk across the vendor lifecycle, including a tiered vendor model, SR-6 assessment cadence, and continuous monitoring expectations under SA-9 and SR-3.

Read the guide →

GLBA Data Breach Notification Requirements: Complete Guide [2026]

What the 2024 Safeguards Rule notification amendment actually requires: trigger thresholds, FTC and consumer notification timelines, incident-response plan elements, and how GLBA interacts with state breach notification laws.

Read the guide →

This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.

Past Editions

Plus, the DoD codifies its CMMC Phase 2 suspension, IDScan breach exposes 153M driver's license scans, and NYDFS risk assessment guidance.

Edition
09.17.2026

Plus, inconsistent CUI markings inflate CMMC scope, CareCloud breach impacts 3.7M patients, and NIST SP 1353, an AI quick-start for CSF 2.0.

Edition
09.17.2026

Plus, California's new DROP deletion platform, EU AI Act transparency enforcement begins, and White House-authorized private hacking.

Edition
09.17.2026
Get the InfoSec GRC Brief
Join 1,000+ CISOs, compliance officers, and risk managers reading the information security GRC news worth sharing.
Let’s Chat
See the GRC Assessment Platform in action
Isora GRC is the GRC Assessment Platform™ that gives security teams one connected workspace to run assessments, manage vendors and assets, track risks, and prove compliance.
Book a Demo