Patch Tuesday, May 2026 Edition
2026-05-14T07:23:30Z•5c7e2b462850222e7ac8104c4b7c698500682be9985d3e56ea2ab8cbc8ddadf1
CanvasDDoSGandCrabIoT-botnetREvilScattered SpiderStrykerauthentication-tokensbotnetcredential-theftcybercrime-groupdata-extortionnation-statepatch-managementpatch-tuesdayransomwareroutersvulnerabilitieswiperzero-day
What happened
KrebsOnSecurity roundup covering multiple high‑impact incidents and large patch efforts in Mar–May 2026: major vendors (Apple, Google, Microsoft, Mozilla, Oracle, Adobe) released near‑record patch volumes and emergency fixes (including several zero‑days). A widespread data‑extortion attack against Canvas defaced login pages and threatened leaks for ~275 million students/faculty across ~9,000 institutions. Other highlights: a Brazilian anti‑DDoS vendor was tied to botnet DDoS campaigns; a Scattered Spider member pleaded guilty to SIM‑swap/SMS phishing intrusions; Russian-linked actors harvested
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 5c7e2b462850222e7ac8104c4b7c698500682be9985d3e56ea2ab8cbc8ddadf1
- Enrichment time
- 2026-05-14T07:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.