MAGNET S2 WEEKLY SNAPSHOT – 260510-1200z
UNCLASSIFIED // OSINT // FOR OFFICIAL USE – MAGNET S2 OSINT TEAM
Download PDF version of this report
MAGNET S2 WEEKLY SNAPSHOT
WEEKLY OSINT INTELLIGENCE REPORT
DTG: 260510-1200Z | Reporting Period: 03–09 May 2026 | United States Focus
www.magnethf.com
MAGCON STATUS
MAGCON LEVEL 3 – ELEVATED
The diplomatic track has become the dominant variable this week.
U.S.–Iran MOU negotiations produced brief optimism mid-week before
collapsing Sunday when Trump called Iran’s response “totally
unacceptable.” Brent crude spiked 3% on the news. Gas prices
continued climbing to $4.522/gallon. CISA launched a new CI Fortify
initiative pushing critical infrastructure to plan for geopolitical
cyber crisis. The Canvas LMS breach — the largest educational security
incident on record — hit 8,809 institutions globally mid-week with a
ransom deadline of today (12 May). No confirmed coordinated attack on
the U.S. homeland has been reported.
TREND VS LAST WEEK: WORSENING – DIPLOMATIC / ENERGY / CYBER SECTORS
PRIMARY RISK DRIVERS
- U.S.–Iran MOU talks collapsed Sunday; Trump called Iran’s response
“totally unacceptable”; Brent crude spiked 3% to $104.50/barrel - Canvas LMS breached by ShinyHunters ransomware group; 8,809
institutions globally affected; 275 million records stolen; ransom
deadline today 12 May; largest education security breach on record - National gas average reached $4.522/gallon — up from $4.457 last
week; 12th consecutive week of gasoline inventory decline - CISA launched CI Fortify initiative pushing critical infrastructure
to plan for geopolitical cyber crisis and communications blackout - CISA KEV catalog added Ivanti EPMM and Palo Alto PAN-OS (07 May)
with same-day due dates; active exploitation confirmed - Iran internet blackout now exceeds 1,704 hours — third month of
government-imposed communications suppression
DELTA SUMMARY – CHANGES FROM LAST REPORT (260503-1200Z)
WHAT CHANGED THIS WEEK:
- MOU TALKS EMERGED AND COLLAPSED — Mid-week reporting confirmed
Witkoff and Kushner were negotiating a one-page 14-point MOU to
declare an end to the war and start a 30-day negotiation period.
Trump paused “Project Freedom” convoy operations citing progress.
By Sunday 10 May, Trump blasted Iran’s response as “totally
unacceptable” and talks stalled again. Iranian President Pezeshkian:
“We will never bow our heads before the enemy.” - CANVAS LMS BREACH — NEW THIS WEEK: ShinyHunters ransomware group
executed a two-stage attack on Canvas LMS (Instructure). Initial
breach disclosed 01 May; second attack 07 May replaced Canvas login
pages with a ransom note at 8,809 institutions globally. Largest
educational security breach on record. 3.65 terabytes / 275 million
records claimed stolen including private student/teacher messages.
41% of U.S. higher education affected plus K-12 districts in 12+
states. Ransom deadline is today 12 May. Canvas came back online 08
May after Instructure shut down Free-For-Teacher accounts as the
exploit vector. FBI issued guidance to not engage with threat actors.
No connection to Iranian APT activity — assessed as criminal
ransomware, not state-sponsored. - NUCLEAR FILE HARDENED AS STICKING POINT — U.S. demands Iran halt
enrichment for 12+ years and surrender 440kg of 60%-enriched
uranium. Iran calls enrichment non-negotiable. Fox News reported a
previously unknown Iranian nuclear site — the “Rainbow Site” in
Semnan province — on 09 May. Iran dismissed as propaganda. - BRENT CRUDE SPIKED ON TALKS COLLAPSE — Oil prices rose 3.17% Sunday
to $104.50/barrel and U.S. crude climbed 3.21% to $98.48. Earlier
in the week, prices had fallen on MOU optimism before reversing. - GAS PRICES CONTINUED CLIMBING — National average $4.522/gallon as
of 10 May (AAA), up from $4.457 last week. 12th consecutive
inventory decline. Memorial Day $5/gallon threshold increasingly
likely. - CISA LAUNCHED CI FORTIFY — New nationwide initiative directs water
utilities, transportation, and other critical infrastructure to plan
for geopolitical cyber crisis scenarios involving severed internet,
telecom, and OT access. Pilot assessments underway at defense
critical infrastructure sites. Directly validates MAGNET HF mission. - NEW KEV ENTRIES — Ivanti EPMM (CVE-2026-6973) and Palo Alto PAN-OS
added to CISA KEV catalog 07 May, due date 10 May. Active
exploitation confirmed. Federal agencies required to patch
immediately. - ISRAEL REMAINS A WILD CARD — Netanyahu stated there is still “work
to be done” in Iran and signaled Israel may not accept any deal
leaving Iranian nuclear infrastructure intact. - PROJECT FREEDOM CONVOY PAUSED — U.S. paused naval convoy operation
citing diplomatic progress. With talks now collapsed, convoy
resumption status is unclear. Strait remains effectively closed.
NO CHANGE:
- MAGCON level holds at 3 – ELEVATED
- Iranian APT cyber targeting of U.S. ICS/OT remains active
- Bab el-Mandeb / Red Sea threat stable at ELEVATED
- Civil Unrest remains ROUTINE
- No confirmed coordinated domestic attack
SECTOR THREAT LEVELS
Terrorism / Extremism: ELEVATED
Cyber Activity: ELEVATED [WORSENING – Canvas breach + KEV additions]
Critical Infrastructure: ELEVATED
Energy / Fuel Sector: CRITICAL
Education Sector: ELEVATED [NEW – Canvas breach, ransom deadline today]
Civil Unrest: ROUTINE
Transportation Systems: ELEVATED
Supply Chain / Logistics: ELEVATED
Food / Fertilizer Security: ELEVATED
GLOBAL CHOKEPOINT WATCH
Strait of Hormuz: CRITICAL / EFFECTIVELY CLOSED
[WORSENING – MOU talks collapsed Sunday;
Brent crude spiked 3%; convoy paused;
no resolution timeline visible]
Bab el-Mandeb / Red Sea: ELEVATED [STABLE]
Panama Canal: ROUTINE [STABLE]
Strait of Malacca: ELEVATED [STABLE]
KEY INCIDENTS
IRAN-U.S. – MOU Talks Collapse; Trump Calls Iran Response
“Totally Unacceptable”
After brief mid-week optimism surrounding a one-page 14-point MOU
framework negotiated by Witkoff and Kushner, Iran submitted a formal
response that Trump blasted as “totally unacceptable” on Sunday 10
May. Brent crude spiked 3.17% to $104.50/barrel. The MOU would have
declared an end to the war and started a 30-day negotiation period
covering Hormuz reopening, nuclear curbs, sanctions relief, and frozen
asset release. Core sticking point: Iran’s refusal to halt enrichment
and surrender 440kg of 60%-enriched uranium. Iranian President
Pezeshkian: “We will never bow our heads before the enemy.” Netanyahu
signaled Israel may not accept a deal leaving Iranian nuclear
infrastructure intact.
UNITED STATES / GLOBAL – Canvas LMS Breach; Largest Education Cyber
Incident on Record
ShinyHunters ransomware group executed a two-stage attack on Canvas
LMS (Instructure). Initial breach disclosed 01 May. On 07 May at
approximately 1:20 PM PDT, Canvas login pages at 8,809 institutions
worldwide were replaced with a ShinyHunters ransom message. Group
claims 3.65 terabytes / 275 million records stolen including private
student-teacher messages, names, emails, and student IDs. Canvas used
by 41% of U.S. higher education including Columbia, Princeton, Harvard,
Georgetown, Rutgers, Virginia Tech, and University of Illinois. K-12
districts in CA, FL, GA, OK, OR, NV, NC, TN, TX, VA, and WI also
affected. Canvas came back online 08 May after Instructure shut down
Free-For-Teacher accounts as the exploit vector. Ransom deadline:
today, 12 May 2026. FBI guidance: do not engage with threat actors;
watch for follow-on phishing using Canvas-specific context.
ShinyHunters is a loose affiliation of U.S.- and UK-based criminal
hackers previously linked to Ticketmaster/Live Nation breach. No
connection to Iranian APT activity confirmed — assessed as criminal
ransomware, not state-sponsored.
UNITED STATES – Gas Prices Continue Record Climb
National average gasoline reached $4.522/gallon as of 10 May per
AAA — up from $4.457 last week and $4.39 the week prior. EIA data
for week of 04 May showed $4.581/gallon. 12th consecutive inventory
decline. Summer driving demand has not peaked. $5/gallon by Memorial
Day remains a credible analyst forecast.
UNITED STATES – CISA Launches CI Fortify Initiative
CISA launched CI Fortify, directing water utilities, transportation,
and other critical infrastructure to plan for geopolitical cyber crisis
scenarios involving severed internet and telecom access. CISA is
prioritizing defense critical infrastructure including dams, radars,
weapon systems, and satellite communications for targeted assessments
under a pilot phase already underway. Directly validates MAGNET’s
HF out-of-band communications mission.
UNITED STATES – CISA KEV: Ivanti and Palo Alto Vulnerabilities Added
Ivanti EPMM (CVE-2026-6973) and Palo Alto PAN-OS vulnerabilities added
to CISA KEV catalog 07 May, due date 10 May. Both allow remote code
execution or privilege escalation. Federal agencies required to patch
immediately. Private-sector operators should treat as actively
exploited.
IRAN – Internet Blackout Exceeds 1,704 Hours
NetBlocks confirmed Iran’s government-imposed internet blackout has
surpassed 1,704 hours — third month with no end indicated. Limits
OSINT collection on Iranian internal conditions and increases
analytical uncertainty about Iranian negotiating posture.
CYBER / INFRASTRUCTURE
Canvas Breach – Follow-On Phishing Risk Active Today
The ShinyHunters ransom deadline is today 12 May. Whether Instructure
pays or not, 275 million stolen records create an extensive phishing
and social engineering dataset. MAGNET operators with family members
or colleagues at affected institutions should expect targeted phishing
attempts using Canvas-specific context (course names, instructor names,
assignment details) for weeks to months. FBI guidance: do not respond
to unsolicited contact claiming to be from your school, Canvas, or law
enforcement without verifying through known official channels.
CISA CI Fortify – Validates MAGNET HF Out-of-Band Mission
CISA is explicitly directing critical infrastructure to plan for
scenarios where internet, telecom, and OT access are severed
simultaneously. This directly aligns with MAGNET’s HF radio mission.
Operators supporting local utilities, water, or transportation
infrastructure should be aware CISA is now formally recommending
the kind of resilient communication capability that MAGNET provides.
KEV Bulletin – Patch Immediately
Ivanti EPMM (CVE-2026-6973): RCE via improper input validation.
Palo Alto PAN-OS: out-of-bounds write, unauthenticated attack vector.
Apply vendor patches immediately per CISA BOD 22-01.
CIRCIA – Finalization Pending; CISA Capacity Constrained
CIRCIA mandatory reporting rule finalization remains pending. One-third
staff reduction, CIPAC eliminated, MS-ISAC defunded. Self-reporting
via cisa.gov and IC3.gov remains the reliable path.
EMERGING INDICATORS
- Canvas ransom deadline is today 12 May — data leak or dark web dump
possible; watch for announcement and downstream phishing surge - 275 million stolen education records will fuel targeted phishing
campaigns for months — elevated credential theft risk in academic
sector - Trump-Iran talks collapsed Sunday — watch for U.S. military
signaling or renewed convoy operation week of 11–17 May - Oil markets highly reactive to diplomatic signals — further
breakdown could push Brent toward $110–$120 range - “Rainbow Site” nuclear reporting may be used to argue against
diplomatic settlement — watch for Israeli unilateral action signals - Iran internet blackout limits analytical visibility on Iranian
negotiating flexibility — assessment confidence reduced - 12th consecutive gasoline inventory decline with summer demand
approaching — $5/gallon before Memorial Day increasingly likely - CI Fortify pilot assessments underway — watch for CISA public
reporting on findings
VERIFIED STATUS
✗ NOT CONFIRMED: No coordinated terrorist attack campaign within
the continental United States during the reporting period.
✗ NOT CONFIRMED: No nationwide U.S. critical infrastructure failure
resulting from state-sponsored cyber attack.
✓ CONFIRMED: Canvas LMS breached by ShinyHunters; 8,809 institutions
affected; 275M records claimed stolen; ransom deadline 12 May.
(Wikipedia; CNN; CBS News; NBC News)
✓ CONFIRMED: Trump called Iran’s MOU response “totally unacceptable”
10 May; Brent crude spiked 3.17% to $104.50/barrel.
(CNN Live Updates, 10 May 2026)
✓ CONFIRMED: U.S.–Iran MOU framework negotiated; talks stalled as of
reporting period close. (Axios, 06 May; Al Jazeera, 08 May)
✓ CONFIRMED: National average gasoline $4.522/gallon as of 10 May.
(AAA)
✓ CONFIRMED: Gasoline inventories fell for 12th consecutive week.
(Trading Economics / EIA, 08 May 2026)
✓ CONFIRMED: CISA launched CI Fortify; pilot assessments underway.
(Federal News Network, 07 May 2026)
✓ CONFIRMED: Ivanti EPMM and Palo Alto PAN-OS added to CISA KEV
catalog 07 May, due date 10 May. (CISA KEV Catalog)
✓ CONFIRMED: Iran internet blackout exceeds 1,704 hours per NetBlocks.
(CNN Live Updates, 10 May 2026)
OPERATOR GUIDANCE
- Canvas ransom deadline is today — alert family and colleagues at
affected institutions; do not respond to unsolicited contact
claiming to be from Canvas, your school, or law enforcement without
verifying through known official channels - Watch for U.S. military or diplomatic response to Iran talks
collapse — any escalation signal this week could rapidly affect
fuel prices, supply chains, and maritime security posture - Patch Ivanti EPMM (CVE-2026-6973) and Palo Alto PAN-OS
immediately — CISA KEV due date has passed; actively exploited - Review CI Fortify guidance at cisa.gov — CISA now formally
directing critical infrastructure to plan for internet/telecom
blackout scenarios, validating MAGNET’s HF mission - Monitor diesel availability and fuel pricing; Memorial Day
$5/gallon threshold increasingly likely - Do not rely on unofficial Hormuz transit guidance — convoy
operation is paused and strait remains effectively closed - Report suspicious cyber activity to cisa.gov or IC3.gov
Submit reports through established MAGNET situational awareness
channels. To Learn More About MAGNET, Visit www.MAGNETHF.COM
SOURCE LIST
[1] CNN – Live Updates: Trump Calls Iran Response Totally Unacceptable,
10 May 2026
https://www.cnn.com/2026/05/10/world/live-news/iran-war-news
[2] Wikipedia – 2026 Canvas Security Incident (live article)
https://en.wikipedia.org/wiki/2026_Canvas_security_incident
[3] CNN – Canvas Hack Strands College Students During Finals Week,
07 May 2026
https://www.cnn.com/2026/05/07/us/canvas-hack-strands-college-students-finals-week
[4] CBS News – Canvas Back Online After Cyberattack, 08 May 2026
https://www.cbsnews.com/news/cyberattack-shutters-canvas-learning-platform-for-schools-across-us/
[5] NBC News – Cyberattack Hits Canvas Learning Management System
https://www.nbcnews.com/tech/tech-news/cyberattack-hits-canvas-learning-management-system-rcna344160
[6] ABC7 – Canvas Back Online After Cyberattack
https://abc7news.com/post/canvas-system-back-online-cyberattack-disrupted-thousands-schools/19065668/
[7] Axios – US Iran Closing in on One-Page MOU to End War, 06 May 2026
https://www.axios.com/2026/05/06/iran-us-deal-one-page-memo
[8] Al Jazeera – What We Know About Iran’s Response to Latest US
Ceasefire Proposal, 08 May 2026
https://www.aljazeera.com/news/2026/5/8/what-we-know-about-irans-response-to-the-latest-us-ceasefire-proposal
[9] Al Jazeera – What Are US Proposals to End War and Will Iran Agree,
07 May 2026
https://www.aljazeera.com/news/2026/5/7/what-are-us-proposals-to-end-war-and-will-iran-agree-to-them
[10] Wikipedia – 2025–2026 Iran–United States Negotiations (live)
https://en.wikipedia.org/wiki/2025%E2%80%932026_Iran%E2%80%93United_States_negotiations
[11] Wikipedia – 2026 Strait of Hormuz Crisis (live article)
https://en.wikipedia.org/wiki/2026_Strait_of_Hormuz_crisis
[12] Trading Economics – Gasoline Futures, 08–10 May 2026
https://tradingeconomics.com/commodity/gasoline
[13] AAA – National Gas Price Average, 10 May 2026
https://gasprices.aaa.com
[14] YCharts – US Retail Gas Price Week of 04 May 2026
https://ycharts.com/indicators/us_gas_price
[15] Federal News Network – CISA Tells Critical Organizations to Prepare
for Cyber Outages, 07 May 2026
https://federalnewsnetwork.com/cybersecurity/2026/05/cisa-tells-critical-organizations-to-prepare-for-cyber-outages/
[16] Federal News Network – CISA Cyber Partnerships Face Standstill
Amid Cuts, 29 Apr 2026
https://federalnewsnetwork.com/cybersecurity/2026/04/cisa-cyber-partnerships-face-standstill-amid-cuts/
[17] CISA – Known Exploited Vulnerabilities Catalog, 07 May 2026
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
[18] House of Commons Library – Israel/US-Iran Conflict 2026:
Reopening the Strait of Hormuz, 09 May 2026
https://commonslibrary.parliament.uk/research-briefings/cbp-10636/
[19] SmartAsset – Gas Prices Hit Records 2026: State by State
https://smartasset.com/data-studies/gas-prices-spring-2026
CLASSIFICATION: UNCLASSIFIED // OSINT
PREPARED BY: MAGNET S2 OSINT TEAM
DISTRIBUTION: MAGNET NETWORK OPERATORS
NEXT REPORT: 260517-1200Z