CISA gives feds four days to patch Ivanti flaw exploited as zero-day
2026-05-08T13:23:38Z•e72d8322a8478c4cc9a96b8a3788101b721ae8a07723a01a226e746b1e406cd4
ACSCBeagle backdoorCISA emergency directiveIvanti EPMMLinux Dirty FragPAN-OSPCPJackPalo Alto NetworksShinyHuntersTCLBankerVidar StealerZaracredential theftdata breachextortionincident responselocal privilege escalationmalwarepatchingremote code executionvulnerabilityzero-day
What happened
Multiple high-impact security incidents and zero-days reported: CISA issued an emergency four-day directive for U.S. federal agencies to patch a high-severity remote-code-execution vulnerability in Ivanti Endpoint Manager Mobile (EPMM) being exploited as a zero-day. Separately, a new Linux local-privilege-escalation zero-day (“Dirty Frag”) grants root on most major distributions, and a critical PAN-OS firewall zero-day has been exploited by suspected state actors. The feed also highlights a 197k-customer Zara data breach, ShinyHunters’ mass Canvas portal defacements, several new malware/famil
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- e72d8322a8478c4cc9a96b8a3788101b721ae8a07723a01a226e746b1e406cd4
- Enrichment time
- 2026-05-08T13:23:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.