
Sharing a Hands-On Lab Inspired by Recent Canvas Security Incident
CybersecurityCloudSecurityDataBreachesSaaSVulnerabilities
The post references a recent Canvas security incident where Instructure agreed to a ransom deal for stolen data. The author discusses assumptions in large SaaS systems, such as predictable account behavior, isolated access boundaries, and scalable trust relationships, noting that small access-control flaws can create significant exposure risks. They created an isolated lab environment to simulate cloud access-control and tenant-boundary failures for research and learning. The project explores how engineers model tenant isolation risk and validate cross-account assumptions in SaaS systems.