Patch Tuesday, May 2026 Edition
2026-05-18T01:23:29Z•d49baf939f39c997df89dff94540b121d1e87693f5412c63ebef3d937689b854
AisuruCanisterWormCanvasDDoSGandCrabIoT-botnetIran-linkedJackSkidKimwolfMossadREvilScattered-SpiderStrykerUNKNanti-DDoS-abuseauthentication-token-theftdata-extortioninsider-claim/false-flagpatch-tuesdayransomrouter-exploittylerbvulnerability-managementwiperzero-day
What happened
This collection of KrebsOnSecurity items covers numerous high-impact cyber incidents and widespread vulnerability remediation in spring 2026. Key items include a large data-extortion and outage of the Canvas education platform threatening data on ~275 million students and staff; massive vendor patching across Apple, Google, Microsoft, Mozilla and Oracle (multiple zero-days and dozens/hundreds of fixes); a campaign by Russia-linked actors harvesting Microsoft Office authentication tokens via exploited/older routers; U.S./Canadian/German disruption of four large IoT botnets (Aisuru, Kimwolf,Jack
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- d49baf939f39c997df89dff94540b121d1e87693f5412c63ebef3d937689b854
- Enrichment time
- 2026-05-18T01:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.