Patch Tuesday, May 2026 Edition

2026-05-18T01:23:29Zd49baf939f39c997df89dff94540b121d1e87693f5412c63ebef3d937689b854
AisuruCanisterWormCanvasDDoSGandCrabIoT-botnetIran-linkedJackSkidKimwolfMossadREvilScattered-SpiderStrykerUNKNanti-DDoS-abuseauthentication-token-theftdata-extortioninsider-claim/false-flagpatch-tuesdayransomrouter-exploittylerbvulnerability-managementwiperzero-day

What happened

This collection of KrebsOnSecurity items covers numerous high-impact cyber incidents and widespread vulnerability remediation in spring 2026. Key items include a large data-extortion and outage of the Canvas education platform threatening data on ~275 million students and staff; massive vendor patching across Apple, Google, Microsoft, Mozilla and Oracle (multiple zero-days and dozens/hundreds of fixes); a campaign by Russia-linked actors harvesting Microsoft Office authentication tokens via exploited/older routers; U.S./Canadian/German disruption of four large IoT botnets (Aisuru, Kimwolf,Jack

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
d49baf939f39c997df89dff94540b121d1e87693f5412c63ebef3d937689b854
Enrichment time
2026-05-18T01:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.