Patch Tuesday, May 2026 Edition
2026-05-18T19:23:30Z•3c296df31bb4b5e17aacafce33c71ca37c30ab5dc0cbb9270b9b83663b3b85d4
CanvasDDoSIoT botnetIran-linkedRussia-linkedScattered Spideranti‑DDoS abusebotnetcredential/token theftdata extortiondoxingeducation sectorlaw enforcement takedownphishing/SMS phishingransomwarerouter compromisestate-sponsoredvulnerability managementwiper malwarezero-day/patching
What happened
A string of high-impact incidents and active threats were reported: a large data-extortion attack against the Canvas education platform that threatened leakage of ~275 million student/faculty records and disrupted classes nationwide; a Brazilian anti‑DDoS vendor found enabling a botnet used to attack ISPs; state-linked operations harvesting Microsoft Office authentication tokens via compromised routers; multiple destructive wiper incidents (including CanisterWorm and an alleged Iran-linked attack on Stryker); dismantling of major IoT botnets behind record DDoS campaigns; and criminal prosecuto
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 3c296df31bb4b5e17aacafce33c71ca37c30ab5dc0cbb9270b9b83663b3b85d4
- Enrichment time
- 2026-05-18T19:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.