Patch Tuesday, May 2026 Edition

2026-05-14T19:23:28Z02cf630c1f43941bb201e2cf5ac98dd2082d6515209b3cf6b1ea1ee461801ce1
auth-token-harvestbotnetbreachcanisterwormcanvasdata-extortionddosdoxingeducation-sectoriot-botnetiranlaw-enforcement-takedownpatch-tuesdayransomwarerouter-vulnerabilitiesrussiascattered-spidersoftware-vulnerabilitiesstate-sponsoredsupply-chain-securityunknvulnerability-managementwiperzero-day

What happened

A KrebsOnSecurity feed covering May 2026 high-impact cyber events: broad Patch Tuesday activity as major vendors (Microsoft, Google, Apple, Mozilla, Oracle, Adobe) pushed numerous fixes and emergency zero-day patches; a large data-extortion breach of Canvas disrupted classes and threatened data on ~275M students/faculty; a Brazilian anti‑DDoS vendor was implicated in enabling large DDoS campaigns; US/Allied law enforcement disrupted multiple IoT botnets (Aisuru, Kimwolf, JackSkid, Mossad) used in record DDoS attacks; a Russia-linked campaign harvested Microsoft Office authentication tokens by

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
02cf630c1f43941bb201e2cf5ac98dd2082d6515209b3cf6b1ea1ee461801ce1
Enrichment time
2026-05-14T19:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.