Patch Tuesday, May 2026 Edition

2026-05-13T19:23:28Z164d3212626b66930f25810cbe325924fbedc5534a2c801afec9828ff9595ce7
CanvasDDoSGandCrabIoTIran-linkedMicrosoftPatch TuesdayREvilRussia-linkedScattered Spiderauthentication token theftbotnetdata breacheducation sectorransomware/extortionrouter vulnerabilitiesstate-sponsoredwiper malwarezero-day/patches

What happened

A set of high-impact security incidents and patching activity: a large-scale extortion/data-breach attack against Canvas that defaced logins and threatens data on ~275 million students and staff across ~9,000 institutions; multiple active destructive campaigns (CanisterWorm and an Iran-linked wiper against Stryker); evidence of state-linked espionage using known router flaws to harvest Microsoft Office authentication tokens; a Brazilian anti‑DDoS vendor implicated in enabling DDoS botnet campaigns; U.S./Allied disruption of several massive IoT botnets (Aisuru, Kimwolf, JackSkid, Mossad); and a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
164d3212626b66930f25810cbe325924fbedc5534a2c801afec9828ff9595ce7
Enrichment time
2026-05-13T19:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.