Researchers disclosed a new Linux kernel local privilege escalation dubbed Dirty Frag (CVE-2026-43284), with publicly available exploit code and broad impact across major distributions. Wiz’s technical analysis ties the bug to ESP and AF_RXRPC paths, meaning local attackers can escalate to root rapidly. Temporary mitigations include disabling AF_RXRPC and IPsec ESP where feasible and tightening unprivileged namespace use, while teams await upstream kernel patches.
Source: Wiz
Apache fixes critical HTTP/2 double-free (CVE-2026-23918) enabling RCE
Apache shipped patches for a critical double-free in its HTTP/2 implementation (CVSS 8.8) that can lead to remote code execution under certain conditions. Internet-facing servers should be updated immediately and restarted, with added monitoring for anomalous HTTP/2 crashes or memory errors that could signal exploitation attempts.
Source: SCMagazine
CISA orders 3-day fix for actively exploited Ivanti EPMM zero-day
US federal agencies have been directed to patch an actively exploited Ivanti Endpoint Manager Mobile flaw within 72 hours due to the risk of authenticated admin remote code execution. Organizations should update to fixed versions, restrict admin exposure to the internet, and review logs for suspicious administrator activity.
Source: SCMagazine
Canvas LMS cyberattack disrupts final exams across universities
A cyberattack against Instructure’s Canvas platform caused widespread outages just as students prepared for finals, forcing multiple schools to delay or reschedule exams. With threat actors attempting defacements and pressure tactics, institutions should enforce credential resets, monitor for SSO token misuse, and ramp up phishing defenses targeting students and faculty.
Source: SecurityWeek
RansomHouse claims breach of Trellix, shares internal system screenshots
The RansomHouse group published images purporting to show access to internal Trellix services, raising supply chain and trust concerns around a prominent security vendor’s environment. While the full scope remains unclear, defenders should prepare for potential phishing or impersonation activity leveraging alleged internal data.
Source: SecurityWeek
Poland confirms ICS breaches at five water plants; operational parameters at risk
Poland’s security agency reported intrusions at five water treatment facilities where attackers gained the ability to modify equipment operational parameters, posing direct risk to the public water supply. The case underscores rising OT/ICS targeting and the need for strict network segmentation, robust OT monitoring, and incident response playbooks that bridge IT and operations teams.
Source: SecurityWeek
AI startup Braintrust breached; customers told to rotate API keys
Hackers accessed one of Braintrust’s AWS accounts and compromised secrets used to connect to cloud-based AI providers, prompting the company to urge API key rotation. The incident highlights growing AI supply chain risk, where third-party observability and orchestration tools can become pivot points to model endpoints and sensitive data.
Source: SecurityWeek
You May Also Be Interested In...
‘PCPJack’ worm removes TeamPCP infections, steals credentials
Flaw in Claude’s Chrome extension allowed any other plugin to hijack victims’ AI
Microsoft says Edge’s plaintext password behavior is “by design”