EPISODE · May 12, 2026 · 17 MIN
2026-05-12: Linux systems face a second privilege escalation exploit in two weeks with Dirty Frag working
from Cyber Threat Brief
Show Notes - 2026-05-12 Stories Covered: - Today: - Linux Dirty Frag Vulnerability (CVE-2026-43284, CVE-2026-43500) (https://arstechnica.com/security/2026/05/linux-bitten-by-second-severe-vulnerability-in-as-many-weeks/) - Active Directory Certificate Services Exploitation (https://unit42.paloaltonetworks.com/active-directory-certificate-services-exploitation/) - Instructure Pays Ransom to ShinyHunters (https://www.bleepingcomputer.com/news/security/instructure-reaches-agreement-with-shinyhunters-to-stop-data-leak/) - The Gentlemen Ransomware Group Suffers Data Breach (https://databreaches.net/2026/05/11/the-gentlemen-ransomware-group-becomes-a-victim/) - State of Ransomware in 2026 (https://securelist.com/state-of-ransomware-in-2026/119761/) - Checkmarx Jenkins Plugin Compromised by TeamPCP (https://www.bleepingcomputer.com/news/security/official-checkmarx-jenkins-package-compromised-with-infostealer/) - Mini Shai-Hulud Worm Spreads Across npm and PyPI (https://thehackernews.com/2026/05/mini-shai-hulud-worm-compromises.html) - GhostLock Tool Abuses Windows API for File Access Denial (https://www.bleepingcomputer.com/news/security/new-ghostlock-tool-abuses-windows-api-to-block-file-access/) - FleetWave Data Breach Confirmed (https://www.theregister.com/cyber-crime/2026/05/12/fleetwave-outage-takes-another-turn-chevin-confirms-crooks-accessed-customer-data/) - State-Sponsored Actors: Long-Term Covert Access (https://blog.talosintelligence.com/state-sponsored-actors-better-known-as-the-friends-you-dont-want/) - FCC Extends Foreign Router Support Deadline (https://www.darkreading.com/endpoint-security/fcc-softens-foreign-router-ban) - OpenAI Launches Daybreak AI Security Platform (https://thehackernews.com/2026/05/openai-launches-daybreak-for-ai-powered.html) - CrowdStrike Automated Leads: AI-Powered Threat Detection (https://www.crowdstrike.com/en-us/blog/ai-threat-detection-with-automated-leads/) - GM Settles California CCPA Violation for $12.75M (https://www.bleepingcomputer.com/news/legal/gm-agrees-to-1275m-california-settlement-over-sale-of-drivers-data/) - Apple and Google Launch Cross-Platform E2EE RCS (https://thehackernews.com/2026/05/ios-265-brings-default-end-to-end.html) - DOJ Charges Premium Home Service with Fake Review Scheme (https://www.justice.gov/opa/pr/department-justice-files-complaint-against-best-gdr-llc-doing-business-premium-home-service) - Fake Claude Code Installers Deliver Credential Stealers (https://www.theregister.com/security/2026/05/11/cookie-thieves-caught-stealing-dev-secrets/) CVEs Referenced: CVE-2022-26923, CVE-2026-43284, CVE-2026-43500, CVE-2026-45321 Full brief: https://carolinacleartech.com/brief/2026-05-12/
Embed this episode
What this episode covers
Show Notes - 2026-05-12 Stories Covered: - Today: - Linux Dirty Frag Vulnerability (CVE-2026-43284, CVE-2026-43500) (https://arstechnica.com/security/2026/05/linux-bitten-by-second-severe-vulnerability-in-as-many-weeks/) - Active Directory Certificate Services Exploitation (https://unit42.paloalton
NOW PLAYING
2026-05-12: Linux systems face a second privilege escalation exploit in two weeks with Dirty Frag working
No transcript for this episode yet
Similar Episodes
No similar episodes found.