Top Cybersecurity News Stories From May 2026
Originally reported viaIllumio Cybersecurity Blog — May 2026 Monthly RoundupMay 2026 was defined by three dominant themes: continued exploitation of edge device vulnerabilities, a surge in healthcare sector ransomware, and renewed state-sponsored activity targeting energy and financial infrastructure across North America and Europe. Illumio's monthly threat roundup aggregates the most operationally significant developments security teams need to act on.
Edge device exploitation reaches new high
CISA added 11 new edge device CVEs to its KEV catalogue in May — more than any prior month in 2026. Ivanti, Fortinet, and Palo Alto Networks products accounted for 8 of the 11 entries. Exploitation timelines continue to compress, with observed attacks beginning within 36 hours of public disclosure for three of the May entries.
Healthcare sector under sustained attack
Three US hospital networks and two European healthcare providers reported significant ransomware incidents in May. The most impactful — a regional hospital network in the US Midwest — saw clinical operations disrupted for 11 days, with patient records for approximately 340,000 individuals exfiltrated prior to encryption.
- Prioritise KEV patch deployment for all internet-facing appliances within 72 hours of catalogue addition.
- Implement network micro-segmentation to prevent lateral movement from compromised edge devices into clinical or OT networks.
- Ensure offline backup copies exist for all critical operational data — encrypted and verified monthly.
Stay ahead of the threat curve
Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.