Back to the blog
data-breachMay 17, 2026 5 min read

May 2026 Security Brief: Infrastructure Vulnerabilities and Data Exposure

A review of critical Open5GS vulnerabilities and major data breaches from May 2026, highlighting the persistent risks to organizational and user data.

By SecureIDsafe Threat Team · SecureIDsafe Threat Research#data-exposure

In May 2026, the cybersecurity landscape faced significant challenges ranging from critical infrastructure vulnerabilities in 5G core software to massive data exfiltration events. These incidents underscore the fragility of centralized data storage and the necessity of adopting zero-knowledge security architectures to protect sensitive information.

What happened

Instructure (Canvas) Data Breach (May 3, 2026)

On May 3, 2026, the ShinyHunters extortion group claimed responsibility for a breach of Instructure, the parent company of the Canvas learning management system [1]. The incident exposed data belonging to approximately 275 million users, representing a significant portion of the North American higher education sector [1, 9].

Foxconn Cyberattack (May 12, 2026)

Foxconn acknowledged a cyberattack on its North American manufacturing facilities on May 12, 2026 [1]. The Nitrogen ransomware group claimed responsibility for the incident, alleging the theft of 8 terabytes of corporate data [1].

Open5GS Infrastructure Vulnerabilities (May 2026)

Multiple denial-of-service (DoS) vulnerabilities were identified in Open5GS versions up to 2.7.7, impacting critical 5G core components [4, 5, 10]. Specifically, CVE-2026-8222, CVE-2026-8223, and CVE-2026-8224 allow remote attackers to crash the Policy Control Function (PCF) and sm-policies endpoints through manipulated requests [4, 5, 10].

Why this matters

These incidents demonstrate that even large-scale platforms and critical infrastructure are susceptible to both targeted extortion and service-disrupting exploits. When centralized systems are compromised, the resulting exposure of user data or operational downtime can have cascading effects on millions of individuals and global supply chains.

How zero-knowledge changes this

SecureIDsafe’s zero-knowledge architecture is designed to neutralize the impact of such breaches. By utilizing AES-256 client-side encryption, all data is encrypted before it ever leaves the user's device. Because the provider never holds the device-derived keys, even a total compromise of the server infrastructure—like the one experienced by Instructure—would result in the theft of useless, encrypted ciphertext. Furthermore, our non-bypassable 24-word BIP-39 seed recovery ensures that users maintain exclusive control over their identity and data, preventing unauthorized access even if the underlying service provider is targeted by attackers.

Editor's checklist

EDITOR: Add a detailed breakdown of the specific data types exposed in the Canvas breach beyond the user count. EDITOR: Verify if any additional public statements were released by Foxconn regarding the nature of the 8TB of stolen data. EDITOR: Include a technical summary or diagram showing how the Open5GS PCF component interacts with the broader 5G core to explain the DoS impact. EDITOR: Add a section comparing the impact of a traditional database breach versus a zero-knowledge storage model using a hypothetical scenario.

data-breachvulnerability5Gzero-knowledgeransomware

Build your Fortress of Sovereignty.

Single users, business teams and enterprise perimeters — the same non-bypassable security, scaled to your vault.