CISA gives feds four days to patch Ivanti flaw exploited as zero-day

2026-05-08T13:23:38Ze72d8322a8478c4cc9a96b8a3788101b721ae8a07723a01a226e746b1e406cd4
ACSCBeagle backdoorCISA emergency directiveIvanti EPMMLinux Dirty FragPAN-OSPCPJackPalo Alto NetworksShinyHuntersTCLBankerVidar StealerZaracredential theftdata breachextortionincident responselocal privilege escalationmalwarepatchingremote code executionvulnerabilityzero-day

What happened

Multiple high-impact security incidents and zero-days reported: CISA issued an emergency four-day directive for U.S. federal agencies to patch a high-severity remote-code-execution vulnerability in Ivanti Endpoint Manager Mobile (EPMM) being exploited as a zero-day. Separately, a new Linux local-privilege-escalation zero-day (“Dirty Frag”) grants root on most major distributions, and a critical PAN-OS firewall zero-day has been exploited by suspected state actors. The feed also highlights a 197k-customer Zara data breach, ShinyHunters’ mass Canvas portal defacements, several new malware/famil­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
e72d8322a8478c4cc9a96b8a3788101b721ae8a07723a01a226e746b1e406cd4
Enrichment time
2026-05-08T13:23:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.