Patch Tuesday, May 2026 Edition
2026-05-15T13:23:26Z•ccd00c23325f0a883dd746d778a6e35747e3ee665e8ababa1eb102784bd178dc
DDoSGandCrabIoT-botnetIranREvilRussiaScattered-Spiderbotnetcredential-theftdata-extortiondoxingeducation-breachincident-responsenation-statepatch-tuesdayransomwarerouter-exploitationsupply-chainvulnerabilitieswiperzero-day
What happened
Collection of KrebsOnSecurity reports (Mar–May 2026) covering multiple high-impact cyber incidents and broad vulnerability activity: large-scale Patch Tuesday fixes from major vendors and multiple zero-days; a mass extortion/defacement attack on Canvas threatening data on ~275M students and faculty; botnet-enabled DDoS campaigns and a Brazilian anti‑DDoS firm implicated in abuse; U.S./Allied takedown of four IoT botnets compromising millions of devices; router-based token-harvesting espionage attributed to Russian-linked actors; wiper/extortion campaigns (CanisterWorm, claimed Iran-backed Stry
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- ccd00c23325f0a883dd746d778a6e35747e3ee665e8ababa1eb102784bd178dc
- Enrichment time
- 2026-05-15T13:23:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.