Hackers Bypass Security Tools to Target Users Directly

2026-05-19T08:52:11Z285a0de9fbade16d8adab12f412891a0b0c163341aae997a9302a76238703671
agentic-aiai-developed-zero-dayai-securityavada-builderbeagle-backdoorclickfixdirty-fragdonutloaderfdmtpfragnesiagremlin-stealerinterpollinux-kernellocal-privilege-escalationmustang-pandaon-prem-exchangepwn2ownsbomshinyhunterssupply-chain-compromisetencshelltrickmovidarwordpresszero-day

What happened

Infosecurity Magazine roundup (May 2026) highlighting multiple high‑impact security developments: a severe Microsoft zero‑day affecting on‑prem Exchange Server (2016, 2019, Subscription Edition); new Linux kernel local‑privilege‑escalation flaws including 'Fragnesia' and other high‑severity 'Dirty Frag' issues; a modular, evasion‑capable Gremlin stealer; 47 novel vulnerabilities revealed at Pwn2Own Berlin; widespread WordPress risk from Avada Builder flaws (~1M sites); and numerous active malware/espionage campaigns (China‑linked TencShell, Mustang Panda FDMTP backdoor, TrickMo routing via TON

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
285a0de9fbade16d8adab12f412891a0b0c163341aae997a9302a76238703671
Enrichment time
2026-05-19T08:52:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Hackers Bypass Security Tools to Target Users Directly · Baitaphish