Active attack: Dirty Frag Linux vulnerability expands post-compromise risk
2026-05-09T20:52:28Z•74c469e3d511e9cc2700a7ce1ed702784c06b1b2a08ce7d87e1c6fd3569888b0
ai-securityaitmcloud-securitycopy-failcve-2026-31431detectiondirty-fraginfostealerkernelkuberneteslinuxlocal-privilege-escalationmacosmicrosoft-defendernetworkingpasskeyspasswordlessphishingpost-compromiseprompt-injectionrce
What happened
This Microsoft Security Blog feed highlights multiple active threats and security developments: a newly disclosed Linux local privilege escalation dubbed “Dirty Frag” (affecting kernel networking/memory-fragment handling like esp4, esp6, rxrpc) that enables reliable escalation from unprivileged users post-compromise and is being monitored in the wild; research showing prompt-injection in AI agent frameworks can lead to remote code execution; a macOS ClickFix campaign using fake utilities to deliver infostealers; a multi-stage phishing/AiTM token compromise campaign; and a high-severity Linux “
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 74c469e3d511e9cc2700a7ce1ed702784c06b1b2a08ce7d87e1c6fd3569888b0
- Enrichment time
- 2026-05-09T20:52:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.