Active attack: Dirty Frag Linux vulnerability expands post-compromise risk

2026-05-09T20:52:28Z74c469e3d511e9cc2700a7ce1ed702784c06b1b2a08ce7d87e1c6fd3569888b0
ai-securityaitmcloud-securitycopy-failcve-2026-31431detectiondirty-fraginfostealerkernelkuberneteslinuxlocal-privilege-escalationmacosmicrosoft-defendernetworkingpasskeyspasswordlessphishingpost-compromiseprompt-injectionrce

What happened

This Microsoft Security Blog feed highlights multiple active threats and security developments: a newly disclosed Linux local privilege escalation dubbed “Dirty Frag” (affecting kernel networking/memory-fragment handling like esp4, esp6, rxrpc) that enables reliable escalation from unprivileged users post-compromise and is being monitored in the wild; research showing prompt-injection in AI agent frameworks can lead to remote code execution; a macOS ClickFix campaign using fake utilities to deliver infostealers; a multi-stage phishing/AiTM token compromise campaign; and a high-severity Linux “

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
74c469e3d511e9cc2700a7ce1ed702784c06b1b2a08ce7d87e1c6fd3569888b0
Enrichment time
2026-05-09T20:52:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Active attack: Dirty Frag Linux vulnerability expands post-compromise risk · Baitaphish