A detailed breakdown of the 2026 Instructure Canvas breach, where ShinyHunters exploited a stored XSS vulnerability in a free-tier support ticket system to compromise 275 million student records across 8,809 institutions. The attack chain involved a malicious file in a help-desk ticket firing in a Canvas employee's authenticated session, granting cross-tenant API access. A second XSS in the discussion feature then enabled login portal defacement via the platform's own custom themes feature. The post analyzes how a strict nonce-based Content Security Policy could have blocked script execution at each stage, and how CSP reporting would have surfaced the breach days earlier. Actionable guidance is provided for teams to audit their own SaaS stacks for similar untrusted-content-in-privileged-context patterns.