Active attack: Dirty Frag Linux vulnerability expands post-compromise risk

2026-05-10T14:52:19Z01248b62e322f48675671befebb581bc1fd251449d6470fe7895208449949d5d
AI-agent-securityAiTMCVE-2026-31431ClickFixMicrosoft-Defendercopy-failcredential-theftdetectiondirty-fragin-the-wildinfostealerkernel-vulnerabilitylinuxlocal-privilege-escalationmacOSmitigationpasskeyspasswordlessphishingprompt-injectionremote-code-execution

What happened

This collection highlights multiple active, high-impact threats and mitigation guidance from Microsoft Security Blog in May 2026. Notable items: “Dirty Frag” — a newly disclosed Linux local privilege escalation (kernel networking and memory-fragment handling, esp4/esp6/rxrpc) enabling reliable unprivileged→root escalation and observed limited in‑the‑wild activity; “Copy Fail” (CVE-2026-31431) — a high‑severity Linux root escalation affecting cloud and Kubernetes workloads with an active exploit; prompt-injection vulnerabilities in AI agent frameworks that can lead to remote code execution; a “

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
01248b62e322f48675671befebb581bc1fd251449d6470fe7895208449949d5d
Enrichment time
2026-05-10T14:52:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.