Phoenix Cast

← Phoenix Cast14 mei · 55 min

Canvas Hack, Firefox Using Mythos & Dirty Frag

Canvas Hack, Firefox Using Mythos & Dirty Frag14 mei55 min

<p>In this episode of Phoenix Cast, hosts John and Kyle break down a packed week in cyber: the Canvas ed-tech breach by Shiny Hunters that hit 9,000 schools and 275 million records right at testing season (both of their kids&#39; schools are scrambling to go non-digital), Firefox&#39;s eye-opening collaboration with Anthropic&#39;s Mythos model that surfaced 271 vulnerabilities in a single release for a fraction of the cost of a traditional bug bounty, and the Dirty Frag Linux kernel zero-day that escalates to root in seconds — but whose fix breaks IPsec VPNs and file sharing. They also dig into the new MAR ADMIN making AI training mandatory for every Marine, and John collects on Kyle&#39;s gaslighting from two episodes ago about model quality degradation (Anthropic basically said &quot;whoops&quot;). Stick around for John&#39;s hot take that ASIs — Authorized Service Interruptions — are officially dead in a world where chained vulnerabilities and 271 patches can drop in a single release.</p><p>We’d love to hear your thoughts! Tweet us @ThePhoenixCast, and don&#39;t forget to join our LinkedIn Group to connect with fellow Phoenix Casters. If you enjoyed the episode, help us out by leaving one of those coveted 5-star reviews on Apple Podcasts. Thanks for listening!</p><p>Links - Canvas Hack:</p><p>Canvas Login Portals Hacked - ShinyHunters Extortion Campaign (BleepingComputer)</p><p><a href="https://www.bleepingcomputer.com/news/security/canvas-login-portals-hacked-in-mass-shinyhunters-extortion-campaign/"><u>https://www.bleepingcomputer.com/news/security/canvas-login-portals-hacked-in-mass-shinyhunters-extortion-campaign/</u></a></p><p>Hackers Deface School Login Pages After Claiming Another Instructure Hack (TechCrunch)</p><p><a href="https://techcrunch.com/2026/05/07/hackers-deface-school-login-pages-after-claiming-another-instructure-hack/"><u>https://techcrunch.com/2026/05/07/hackers-deface-school-login-pages-after-claiming-another-instructure-hack/</u></a></p><p>2026 Canvas Security Incident (Wikipedia)</p><p><a href="https://en.wikipedia.org/wiki/2026_Canvas_security_incident"><u>https://en.wikipedia.org/wiki/2026_Canvas_security_incident</u></a></p><p>Links - Firefox Using Mythos:</p><p>Claude Mythos Has Found 271 Zero-Days in Firefox (Schneier on Security)</p><p><a href="https://www.schneier.com/blog/archives/2026/04/claude-mythos-has-found-271-zero-days-in-firefox.html"><u>https://www.schneier.com/blog/archives/2026/04/claude-mythos-has-found-271-zero-days-in-firefox.html</u></a></p><p>The Zero-Days Are Numbered (Mozilla Blog)</p><p><a href="https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/"><u>https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/</u></a></p><p>Behind the Scenes Hardening Firefox with Claude Mythos Preview (Mozilla Hacks)</p><p><a href="https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/"><u>https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/</u></a></p><p>Claude Mythos Finds 271 Firefox Flaws, Mozilla Believes It Shifts Security Toward Defenders (Help Net Security)</p><p><a href="https://www.helpnetsecurity.com/2026/04/22/claude-mythos-mozilla-vulnerabilities-scanning/"><u>https://www.helpnetsecurity.com/2026/04/22/claude-mythos-mozilla-vulnerabilities-scanning/</u></a></p><p>Claude Mythos Finds 271 Firefox Vulnerabilities (SecurityWeek)</p><p><a href="https://www.securityweek.com/claude-mythos-finds-271-firefox-vulnerabilities/"><u>https://www.securityweek.com/claude-mythos-finds-271-firefox-vulnerabilities/</u></a></p><p>Mythos and Cybersecurity (Schneier on Security)</p><p><a href="https://www.schneier.com/blog/archives/2026/04/mythos-and-cybersecurity.html"><u>https://www.schneier.com/blog/archives/2026/04/mythos-and-cybersecurity.html</u></a></p><p>Links - Dirty Frag:</p><p>New Linux ‘Dirty Frag’ Zero-Day With PoC Exploit Gives Root Privileges (BleepingComputer)</p><p><a href="https://www.bleeping