Posts by Charles McBride
Three Active Microsoft 365 Phishing Campaigns Targeting Schools and Government Agencies
School districts, universities, and state and local government agencies share something that makes them high-value targets for threat actors: large, distributed user populations, federated identity environments, and Microsoft 365 tenants running at institutional scale. When a phishing campaign successfully compromises a single account at a K–12 district or county government, the blast radius — student…
Read MoreCritical Microsoft 365 Updates for K–12, Higher Education, and Government IT Teams — July 2026
Your monthly digest from Guardian 365: what’s changing in M365, what it means for your environment, and what to do before enforcement hits. If you manage IT or cybersecurity for a school district, college, university, or state and local government agency, this month’s Microsoft 365 update cycle includes changes that demand attention before the fall…
Read MoreThe Canvas Breach Reached Further Than You Think.
If your institution uses Canvas and Microsoft 365, the risk didn’t stop at Instructure. It’s sitting in your Entra ID tenant right now — and most teams don’t know it’s there. Is Your Microsoft 365 Environment Protected? On May 1, 2026, Instructure disclosed a major security breach affecting Canvas LMS. ShinyHunters claimed responsibility. Within hours,…
Read MoreMicrosoft Defender for Endpoint Now Supports Legacy Windows — What K–12 Districts and Government Agencies Need to Know
Legacy Windows Is Still Running in Schools and Government — And Attackers Know It If your district or agency is still operating Windows 7 SP1 or Windows Server 2008 R2 SP1 machines, you’re not alone. Across K–12 school districts, higher education institutions, and state and local government agencies, legacy operating systems remain deeply embedded —…
Read MoreCritical Microsoft 365 Changes Coming This Summer: What K–12, Higher Ed, and Government IT Teams Need to Know
If you manage Microsoft 365 for a school district, university, or government agency, the next 60 days come with some important deadlines. Microsoft is rolling out two significant platform changes that directly affect how your users collaborate externally and how macOS devices access Microsoft Teams. For IT administrators in the education and state and local…
Read MoreThe Canvas LMS Breach Is a Wake-Up Call for Every School District and University Using Microsoft 365
In late April 2026, the ShinyHunters criminal group quietly slipped past the defenses of Instructure — the company behind Canvas LMS, one of the most widely deployed learning management systems in K–12 and higher education. What followed was a masterclass in how modern attackers exploit the trust we place in third-party applications — and a…
Read MoreCanvas LMS Breach: What Happened, What’s Resolved, and What Comes Next
Executive Summary: On May 1, 2026, Instructure confirmed a major breach of its Canvas LMS platform, attributed to the criminal extortion group ShinyHunters. The attack exposed names, email addresses, student IDs, and private messages across nearly 9,000 educational institutions globally — making it the largest educational security breach on record. After a second-wave defacement attack on…
Read MoreCanvas LMS Breach: What Microsoft 365 and Entra ID Administrators Need to Know
The education technology community is responding to a significant security incident: Instructure’s Canvas LMS was the subject of a breach disclosed on May 1, 2026, with the threat actor group ShinyHunters claiming responsibility. If your institution relies on Canvas — and integrates it with Microsoft 365 or Entra ID — there are immediate steps worth…
Read MoreIranian Cyber Threats Escalate: New Campaigns Targeting Water, Energy, and Enterprise Infrastructure
The Threat Has Grown — Here’s What Changed In March 2026, we published a threat advisory covering emerging cyber activity linked to Iranian state-sponsored threat actors. At the time, activity levels were moderate. That has changed. Between March 16 and April 16, 2026, six U.S. federal agencies issued a joint advisory, the FBI published a…
Read MoreWhen Your Device Management Platform Becomes the Weapon: Lessons from the 2026 Stryker Cyberattack
Security Alert In early 2026, a cyberattack against a major US corporation resulted in attackers using legitimate Microsoft Intune administrative controls to remotely wipe thousands of managed devices — including personal BYOD devices belonging to employees. No custom malware was required. The attackers used the organization’s own tools against it. For IT and security leaders…
Read More