Active attack: Dirty Frag Linux vulnerability expands post-compromise risk

2026-05-08T20:52:28Za1c3b3e5af4d680258dbec195c0119615318c93e4a1f5d1a0eee7f46fab0af3d
AiTMCVE-2026-31431agent-365ai-securitycloudcopy-faildirty-fraginfostealerkuberneteslinuxlocal-privilege-escalationlpemacosmicrosoft-defenderpasskeyspasswordlessphishingprompt-injectionrcethreat-intelligence

What happened

This collection of Microsoft Security Blog posts highlights multiple active and emerging threats: a newly disclosed Linux local privilege-escalation vulnerability family (“Dirty Frag”) impacting kernel networking/memory-fragment handling that enables reliable escalation to root post-compromise (Microsoft Defender providing detections); CVE-2026-31431 (“Copy Fail”), a high-severity Linux root escalation now with a working exploit in the wild affecting cloud and Kubernetes workloads; prompt-injection RCE risks in AI agent frameworks; a macOS ClickFix campaign delivering infostealers via fake “re

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
a1c3b3e5af4d680258dbec195c0119615318c93e4a1f5d1a0eee7f46fab0af3d
Enrichment time
2026-05-08T20:52:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.