Patch Tuesday, May 2026 Edition
2026-05-13T19:23:28Z•164d3212626b66930f25810cbe325924fbedc5534a2c801afec9828ff9595ce7
CanvasDDoSGandCrabIoTIran-linkedMicrosoftPatch TuesdayREvilRussia-linkedScattered Spiderauthentication token theftbotnetdata breacheducation sectorransomware/extortionrouter vulnerabilitiesstate-sponsoredwiper malwarezero-day/patches
What happened
A set of high-impact security incidents and patching activity: a large-scale extortion/data-breach attack against Canvas that defaced logins and threatens data on ~275 million students and staff across ~9,000 institutions; multiple active destructive campaigns (CanisterWorm and an Iran-linked wiper against Stryker); evidence of state-linked espionage using known router flaws to harvest Microsoft Office authentication tokens; a Brazilian anti‑DDoS vendor implicated in enabling DDoS botnet campaigns; U.S./Allied disruption of several massive IoT botnets (Aisuru, Kimwolf, JackSkid, Mossad); and a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 164d3212626b66930f25810cbe325924fbedc5534a2c801afec9828ff9595ce7
- Enrichment time
- 2026-05-13T19:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.