Active attack: Dirty Frag Linux vulnerability expands post-compromise risk
2026-05-08T20:52:28Z•a1c3b3e5af4d680258dbec195c0119615318c93e4a1f5d1a0eee7f46fab0af3d
AiTMCVE-2026-31431agent-365ai-securitycloudcopy-faildirty-fraginfostealerkuberneteslinuxlocal-privilege-escalationlpemacosmicrosoft-defenderpasskeyspasswordlessphishingprompt-injectionrcethreat-intelligence
What happened
This collection of Microsoft Security Blog posts highlights multiple active and emerging threats: a newly disclosed Linux local privilege-escalation vulnerability family (“Dirty Frag”) impacting kernel networking/memory-fragment handling that enables reliable escalation to root post-compromise (Microsoft Defender providing detections); CVE-2026-31431 (“Copy Fail”), a high-severity Linux root escalation now with a working exploit in the wild affecting cloud and Kubernetes workloads; prompt-injection RCE risks in AI agent frameworks; a macOS ClickFix campaign delivering infostealers via fake “re
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- a1c3b3e5af4d680258dbec195c0119615318c93e4a1f5d1a0eee7f46fab0af3d
- Enrichment time
- 2026-05-08T20:52:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.