Active attack: Dirty Frag Linux vulnerability expands post-compromise risk

2026-05-11T02:52:23Z1c5d193709a96cca0b873ad0f4aa916242143dc840a9484ddc8ce0d5a726192b
CVE-2026-31431agent-365ai-agent-securityaitmcloud-securitycopy-faildetection-mitigationdirty-fragesp4esp6exploitin-the-wildinfostealerkernelkuberneteslinuxlocal-privilege-escalationmacosmicrosoft-defenderpasskeypasswordlessphishingprompt-injectionrcerxrpc

What happened

This feed highlights multiple active threats and vulnerabilities Microsoft is tracking: a newly disclosed Linux local privilege escalation (Dirty Frag) in kernel networking/memory-fragment handling (esp4, esp6, rxrpc) that enables reliable escalation from unprivileged users to root and is being observed in limited in-the-wild activity; a separate high-severity CVE (CVE-2026-31431, “Copy Fail”) enabling Linux root escalation with a working exploit in the wild affecting cloud and Kubernetes workloads; plus related malicious activity including AI-agent prompt-injection → RCE risks, macOS ClickFix

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
1c5d193709a96cca0b873ad0f4aa916242143dc840a9484ddc8ce0d5a726192b
Enrichment time
2026-05-11T02:52:23Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Active attack: Dirty Frag Linux vulnerability expands post-compromise risk · Baitaphish