Samsung KNOX Kernel UAF Exposes Millions of Galaxy Devices
2026-06-24T02:51:48Z•29d9724cf25d793ea287ced370cf480113b54c65f80d2e039b93bc3ac4bd06d6
ai-securityanthropic-mythosarystingerbackdoorcredential-harvestingcve-2026-20971cve-2026-47729data-breachdifyfortibleedfortinethealthcare-breachkernel-uafmemory-overreadremote-accessroutersshapedpluginsquidbleedsupply-chain-attacktexas-parks-wildlifethird-party-vendoruse-after-freewhatsapp-malwarewordpress-pluginxsolis
What happened
Multiple high-impact security incidents reported June 2026: a Samsung KNOX kernel use‑after‑free (CVE-2026-20971) in PROCA/FIVE was patched in Jan 2026 and could allow kernel corruption on millions of Galaxy devices; Dify (open-source AI platform) has four vulnerabilities (two critical) enabling unauthenticated access and cross-tenant data exposure across ~1M apps; a ShapedPlugin Pro supply‑chain compromise (Apr–Jun 2026) backdoored plugin updates to steal credentials, 2FA secrets and grant full site access; Squidbleed (CVE-2026-47729) is a long-lived Squid memory overread leaking credentials;
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 29d9724cf25d793ea287ced370cf480113b54c65f80d2e039b93bc3ac4bd06d6
- Enrichment time
- 2026-06-24T02:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.