Active attack: Dirty Frag Linux vulnerability expands post-compromise risk
2026-05-10T08:52:32Z•8e9ea9af568dbe92a4c99b4183cf57dd86eab8dc1f9a3248ba025cf97faa77df
agent-365','security-operations','soc','email-threatsai-agent-rceaitmclickfixcloud-securitycopy-failcredential-theftcve-2026-31431dirty-fragesp4esp6in-the-wildinfostealerkernel-vulnerabilitykuberneteslinuxlocal-privilege-escalationmacosmicrosoft-defenderpasskeypasswordlessphishingprompt-injectionremote-code-executionrxrpc
What happened
The feed highlights multiple active and high-impact threats: “Dirty Frag” is a newly disclosed Linux local privilege escalation (LPE) in kernel networking/memory-fragment handling (components esp4, esp6, rxrpc) that reliably escalates unprivileged users to root and is being observed in the wild; Microsoft Defender is providing detections and monitoring. Separate research shows prompt-injection in AI agent frameworks can lead to remote code execution. A high-severity Linux LPE (CVE-2026-31431, “Copy Fail”) with working exploit is impacting cloud and Kubernetes workloads. Other notable items: a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 8e9ea9af568dbe92a4c99b4183cf57dd86eab8dc1f9a3248ba025cf97faa77df
- Enrichment time
- 2026-05-10T08:52:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.