Active attack: Dirty Frag Linux vulnerability expands post-compromise risk
2026-05-09T02:52:26Z•eedbe5bef3a1188d08f5aa2be078d0141eafd8f57132712435257c44101ec036
ai-agent-securityaitmclickfixcloudcopy-failcredential-theftcve-2026-31431detectiondirty-fragesp4esp6exploit-in-the-wildinfostealerkernelkuberneteslinuxlocal-privilege-escalationmacosmicrosoft-defenderpasskeypasswordlessphishingprompt-injectionremote-code-executionrxrpc
What happened
This collection of Microsoft Security Blog posts highlights multiple active and high-impact threats and security developments. A newly disclosed Linux local privilege-escalation vulnerability dubbed “Dirty Frag” (affecting kernel networking/memory-fragment handling components such as esp4, esp6, and rxrpc) enables reliable escalation from unprivileged user to root and is being monitored with detection coverage in Microsoft Defender. Separately, CVE-2026-31431 (“Copy Fail”) is a high-severity Linux root escalation affecting cloud and Kubernetes workloads with a working exploit in the wild. New/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- eedbe5bef3a1188d08f5aa2be078d0141eafd8f57132712435257c44101ec036
- Enrichment time
- 2026-05-09T02:52:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.