Patch Tuesday, May 2026 Edition
(krebsonsecurity.com)
1.
2.
Twin brothers wipe 96 gov't databases minutes after being fired
(arstechnica.com)
3.
US govt seeks Instructure testimony on massive Canvas cyberattack
(bleepingcomputer.com)
4.
CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
(news.ycombinator.com)
5.
Android 17 will soon tell you whether your OS is legit
(androidauthority.com)
6.
7.
8.
UK fines water supplier $1.3M for exposing data of 664k customers
(bleepingcomputer.com)
9.
FCC Says Foreign-Made Routers Can Get Updates Until 2029
(slashdot.org)
10.
12.
13.
14.
SAP fixes critical vulnerabilities in Commerce Cloud and S/4HANA
(bleepingcomputer.com)
15.
FCC Softens Ban on Foreign-Made Routers
(darkreading.com)
16.
TanStack NPM Packages Compromised
(news.ycombinator.com)
17.
Tech Can't Stop These Threats — Your People Can
(darkreading.com)
18.
20 Leaders Who Built the CISO Era: 2 Decades of Change
(darkreading.com)
19.
20.
21.
Official CheckMarx Jenkins package compromised with infostealer
(bleepingcomputer.com)
23.
Google Alarmed by Formidable AI-Powered Zero-Day Cyberattack
(futurism.com)
26.
27.
28.
Webinar this week: Prevention alone is not enough against modern attacks
(bleepingcomputer.com)
29.
Hardware Attestation as Monopoly Enabler
(news.ycombinator.com)
30.
AI tool poisoning exposes a major flaw in enterprise agent security
(venturebeat.com)