Active attack: Dirty Frag Linux vulnerability expands post-compromise risk
2026-05-10T14:52:19Z•01248b62e322f48675671befebb581bc1fd251449d6470fe7895208449949d5d
AI-agent-securityAiTMCVE-2026-31431ClickFixMicrosoft-Defendercopy-failcredential-theftdetectiondirty-fragin-the-wildinfostealerkernel-vulnerabilitylinuxlocal-privilege-escalationmacOSmitigationpasskeyspasswordlessphishingprompt-injectionremote-code-execution
What happened
This collection highlights multiple active, high-impact threats and mitigation guidance from Microsoft Security Blog in May 2026. Notable items: “Dirty Frag” — a newly disclosed Linux local privilege escalation (kernel networking and memory-fragment handling, esp4/esp6/rxrpc) enabling reliable unprivileged→root escalation and observed limited in‑the‑wild activity; “Copy Fail” (CVE-2026-31431) — a high‑severity Linux root escalation affecting cloud and Kubernetes workloads with an active exploit; prompt-injection vulnerabilities in AI agent frameworks that can lead to remote code execution; a “
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 01248b62e322f48675671befebb581bc1fd251449d6470fe7895208449949d5d
- Enrichment time
- 2026-05-10T14:52:19Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.