Patch Tuesday, May 2026 Edition

2026-05-18T19:23:30Z3c296df31bb4b5e17aacafce33c71ca37c30ab5dc0cbb9270b9b83663b3b85d4
CanvasDDoSIoT botnetIran-linkedRussia-linkedScattered Spideranti‑DDoS abusebotnetcredential/token theftdata extortiondoxingeducation sectorlaw enforcement takedownphishing/SMS phishingransomwarerouter compromisestate-sponsoredvulnerability managementwiper malwarezero-day/patching

What happened

A string of high-impact incidents and active threats were reported: a large data-extortion attack against the Canvas education platform that threatened leakage of ~275 million student/faculty records and disrupted classes nationwide; a Brazilian anti‑DDoS vendor found enabling a botnet used to attack ISPs; state-linked operations harvesting Microsoft Office authentication tokens via compromised routers; multiple destructive wiper incidents (including CanisterWorm and an alleged Iran-linked attack on Stryker); dismantling of major IoT botnets behind record DDoS campaigns; and criminal prosecuto

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
3c296df31bb4b5e17aacafce33c71ca37c30ab5dc0cbb9270b9b83663b3b85d4
Enrichment time
2026-05-18T19:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.