Exploit available for new DirtyDecrypt Linux root escalation flaw
2026-05-18T07:23:25Z•ddbe89b783a4fa0db36de76c1878bcdf25bff69ec1c4b66bc8fecf390b8478b6
avada-builderbackdoorcredential-theftdirtydecryptexploit-availablefunnel-builderinfostealerkazuarlinuxlocal-privilege-escalationmalwareminiplasmanode-ipcnpmpeer-to-peer-botnetphishing-kit','tycoon2fa','device-code-phishing','microsoft-exḥproof-of-conceptpwn2own-2026remusrxgksupply-chainweb-exploitationwindowswordpresszero-day
What happened
This collection of BleepingComputer reports (May 14–18, 2026) highlights multiple high-impact security developments: a proof-of-concept exploit for a recently patched Linux local privilege-escalation in the rxgk module dubbed "DirtyDecrypt" that can yield root on some systems; a released PoC for a Windows privilege-escalation zero-day called "MiniPlasma" that grants SYSTEM on fully patched Windows; and the results of Pwn2Own Berlin 2026 where researchers chained and demonstrated dozens of zero-days across Windows, Exchange, RHEL, and other products. Active exploitation and supply-chain attacks
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- ddbe89b783a4fa0db36de76c1878bcdf25bff69ec1c4b66bc8fecf390b8478b6
- Enrichment time
- 2026-05-18T07:23:25Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.