U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
2026-07-06T01:24:07Z•802d7121b399418ddc93259ebc49bf0ad39aad7a352d431232e10e2819f5a8f4
ai-driven-attackandroidargocdcisa-kevcredential-theftcursor-sandbox-escapeembedded-devicesfatfsfortibleedkuberneteslangflow-rcelinux-kernelmalware-frameworknetnutnorth-koreanpm-malwareprivilege-escalationransomwaresharepoint-rcesupply-chain
What happened
A batch of The Hacker News stories (July 1–4, 2026) covering multiple high-impact vulnerabilities, active exploitation, malware campaigns, and supply-chain abuse. Notable items: a U.S. government entity paid ~$1M in a data‑theft extortion incident attributed to a group calling itself Kairos; Linux “Bad Epoll” local privilege‑escalation (CVE-2026-46242) affecting Linux and Android; Microsoft SharePoint RCE (CVE-2026-45659) added to CISA KEV for active exploitation; two Cursor sandbox‑escape vulnerabilities (CVE-2026-50548, CVE-2026-50549) rated near‑critical; and Adobe fixes for multiple CVSS 9
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 802d7121b399418ddc93259ebc49bf0ad39aad7a352d431232e10e2819f5a8f4
- Enrichment time
- 2026-07-06T01:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.