Patch Tuesday, May 2026 Edition
2026-05-16T07:23:28Z•488559d269c77877d992904350a070378bd457e2391a44a062f0d0c79cb7dcef
CanisterWormCanvasDDoSGandCrabIoTIranREvilRussiaScattered Spideranti‑DDoS abusebotnetcredential‑theftdata‑breachdata‑extortiondoxingeducationlaw‑enforcementnation‑statepatchespatch‑tuesdayransomrouter‑exploitationvulnerabilitieswiperzero‑day
What happened
A collection of KrebsOnSecurity reports covering widespread security activity in early‑to‑mid 2026: large-scale vendor patching (Apple, Google, Microsoft, Mozilla, Oracle) including multiple zero‑days and high‑volume fixes; a major data‑extortion incident against learning platform Canvas claiming data on ~275M students/faculty and disrupting education services; misuse of DDoS/anti‑DDoS infrastructure and IoT botnets (Aisuru, Kimwolf, JackSkid, Mossad) causing nationwide outages; targeted espionage and credential harvesting via compromised routers to steal Microsoft Office tokens linked to GRU‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 488559d269c77877d992904350a070378bd457e2391a44a062f0d0c79cb7dcef
- Enrichment time
- 2026-05-16T07:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.