Active attack: Dirty Frag Linux vulnerability expands post-compromise risk
2026-05-12T02:52:23Z•b24f7033713916f8c2121070868cf5d88a033ccc8f5863c5a1a2763b1a1839e9
AI securityAiTMCVE-2026-31431ClickFixMicrosoft DefenderRCEcloudcontainerscopy-failcredential theftdetectiondirty-fragesp4esp6infostealerkernelkuberneteslinuxlocal privilege escalationmacOSnetworkingphishingprivilege escalationprompt injectionrxrpc
What happened
Microsoft Security Blog highlights multiple high-risk developments: “Dirty Frag,” a newly disclosed Linux local privilege escalation in kernel networking/memory-fragment handling (esp4, esp6, rxrpc) that enables reliable escalation from unprivileged users to root and has limited in‑the‑wild activity; CVE-2026-31431 (“Copy Fail”), a high-severity Linux root privilege escalation with a working exploit impacting cloud and Kubernetes workloads; prompt-injection flaws in AI agent frameworks that can lead to remote code execution; an active macOS ClickFix campaign delivering infostealers via fake “修
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- b24f7033713916f8c2121070868cf5d88a033ccc8f5863c5a1a2763b1a1839e9
- Enrichment time
- 2026-05-12T02:52:23Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.