Active attack: Dirty Frag Linux vulnerability expands post-compromise risk

2026-05-10T08:52:32Z8e9ea9af568dbe92a4c99b4183cf57dd86eab8dc1f9a3248ba025cf97faa77df
agent-365','security-operations','soc','email-threatsai-agent-rceaitmclickfixcloud-securitycopy-failcredential-theftcve-2026-31431dirty-fragesp4esp6in-the-wildinfostealerkernel-vulnerabilitykuberneteslinuxlocal-privilege-escalationmacosmicrosoft-defenderpasskeypasswordlessphishingprompt-injectionremote-code-executionrxrpc

What happened

The feed highlights multiple active and high-impact threats: “Dirty Frag” is a newly disclosed Linux local privilege escalation (LPE) in kernel networking/memory-fragment handling (components esp4, esp6, rxrpc) that reliably escalates unprivileged users to root and is being observed in the wild; Microsoft Defender is providing detections and monitoring. Separate research shows prompt-injection in AI agent frameworks can lead to remote code execution. A high-severity Linux LPE (CVE-2026-31431, “Copy Fail”) with working exploit is impacting cloud and Kubernetes workloads. Other notable items: a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
8e9ea9af568dbe92a4c99b4183cf57dd86eab8dc1f9a3248ba025cf97faa77df
Enrichment time
2026-05-10T08:52:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Active attack: Dirty Frag Linux vulnerability expands post-compromise risk · Baitaphish