Duane Dycus, info security officer for the Murray State information security team, discussed the rise of cybersecurity vulnerabilities and the effects it will have on campus.
Dycus presented a summary of the Instructure Canvas breach that occurred during late April to early May 2026. As a result of this hack, the perpetrators compromised the names, email addresses, student IDs, course enrollment details and private user messages of its users, with over 8,000 schools affected.
Following a second breach, the group instructed institutions to negotiate with them through an extortion screen.
Cybersecurity flaws are globally reported as Common Vulnerability and Exposures. The daily average of CVEs published in 2025 was 132, while in 2026, it has increased to 211. Across the entire year, approximately 50,000 were published in 2025, while only 40,000 were the previous year.
All third-party software vendors are required to submit a completed security questionnaire as well as documentation of their security measures. In addition, the information security team routinely conducts security reviews of any software in use by the University. They also assess the history of cyberattacks and any prevention measures in place. Dycus discussed one of several questions the team asks vendors.
“One of the things we ask them is if they’ve had a security breach within the least five years, and a lot of the times they’re honest, and we don’t look down upon them for that because I personally believe that the most secure organizations in the world are the ones who have had a major breach like this,” Dycus said.
Dycus said a new era of cybersecurity is in reach, one where the gap between the intentional discovery of software vulnerabilities and their exploitation is being closed. Dycus said AI is responsible for this shrinking gap by discovering new vulnerabilities daily across university infrastructure. He said its prevalence has helped highlight design flaws around the world.
Dycus also spoke of the effects of time restraints may have on the student population. In the event of a vulnerability being detected, the information security team is now able to provide a fix within seven days, formerly 30.
Should a crucial design flaw be discovered, one that puts the entire institution at risk, it is now imperative that it should be resolved within hours. This may result in abrupt outages of services instead of scheduled downtimes.
An automated threat detection software has also been implemented at Murray State University to filter out malicious emails.
