CVE-2026-0073, CVE-2026-0300, CVE-2026-1281, CVE-2026-1340, CVE-2026-23631, CVE-2026-25243, CVE-2026-25592, CVE-2026-26030, CVE-2026-26164, CVE-2026-31431, CVE-2026-33109, CVE-2026-40379, CVE-2026-5786, CVE-2026-5787, CVE-2026-5788, CVE-2026-6973, CVE-2026-7821, CVE-2026-7973, CVE-2026-7982, CVE-2026-7988, CVE-2026-7995, CVE-2026-8013, CVE-2026-8016, CVE-2026-8017, CVE-2026-8019, CVE-2026-8021, CVE-2026-8022
IP Addresses:
12.6.1.1, 12.7.0.1, 12.8.0.1
Get tomorrow's brief in your inbox
Today: Ivanti ships its third EPMM zero-day patch of 2026 (CVE-2026-6973, active exploitation confirmed), Palo Alto Networks warns of month-long state-sponsored firewall attacks (CVE-2026-0300, patches May 13), and a new Linux kernel zero-day called Dirty Frag grants instant root on all major distributions with no patch available.
Ivanti EPMM Zero-Day (CVE-2026-6973)
Ivanti disclosed another actively exploited zero-day in Endpoint Manager Mobile (EPMM), the third EPMM zero-day in 2026. CVE-2026-6973 is a high-severity remote code execution flaw (CVSS 7.2) that allows authenticated attackers with administrative privileges to execute arbitrary code. CISA added it to the KEV catalog with a May 10 remediation deadline. Ivanti confirmed "very limited" exploitation in the wild. The vulnerability requires admin access to exploit, which is why customers who rotated EPMM credentials after January's CVE-2026-1281 and CVE-2026-1340 zero-days are at significantly reduced risk. Evidence suggests CVE-2026-6973 was chained with the earlier vulnerabilities to maintain persistence after initial compromise. Shadowserver tracks over 850 EPMM instances exposed online, concentrated in Europe (508) and North America (182). This is Ivanti's 34th KEV entry since 2021, with 22 exploited flaws in the past two years alone.
Palo Alto Networks Firewall Zero-Day (CVE-2026-0300)
Palo Alto Networks confirmed that suspected state-sponsored hackers exploited a critical PAN-OS firewall zero-day for nearly a month before disclosure. CVE-2026-0300 is a buffer overflow in the PAN-OS User-ID Authentication Portal that allows unauthenticated remote code execution with root privileges on Internet-exposed PA-Series and VM-Series firewalls. The first unsuccessful exploitation attempts began April 9, followed by successful RCE and shellcode injection on April 16. Attackers deployed Earthworm and ReverseSocks5 tunneling tools, conducted Active Directory enumeration using firewall service account credentials, and performed extensive log cleanup to evade detection. Unit 42 tracks the campaign as CL-STA-1132, a likely state-sponsored cluster with operational tradecraft matching Chinese APT groups (Volt Typhoon, APT41). Shadowserver tracks over 5,400 exposed PAN-OS firewalls, concentrated in Asia (2,466) and North America (1,998). CISA added CVE-2026-0300 to the KEV catalog with a May 9 deadline. Patches are expected May 13 and May 28.
Linux Dirty Frag Zero-Day (No CVE Assigned)
A new Linux kernel privilege escalation vulnerability called Dirty Frag allows local attackers to gain root privileges on all major distributions with a single command. Security researcher Hyunwoo Kim disclosed the flaw after an embargo breach when an unrelated third party published the exploit publicly. Dirty Frag chains two kernel vulnerabilities (xfrm-ESP Page-Cache Write and RxRPC Page-Cache Write) to modify protected system files in memory and escalate to root. The vulnerabilities were introduced in January 2017 (xfrm-ESP) and June 2023 (RxRPC). Dirty Frag belongs to the same vulnerability class as Dirty Pipe and Copy Fail (CVE-2026-31431, added to CISA KEV last week with active exploitation). The exploit has a very high success rate because it relies on deterministic logic bugs with no race conditions required. Working proof-of-concept code is publicly available. Affected distributions include Ubuntu, RHEL, CentOS Stream, AlmaLinux, openSUSE, and Fedora. No CVE identifier has been assigned and no patches are available yet.
sudo sh -c "printf 'install esp4 /bin/false\ninstall esp6 /bin/false\ninstall rxrpc /bin/false\n' > /etc/modprobe.d/dirtyfrag.conf; rmmod esp4 esp6 rxrpc 2>/dev/null; true". This will break IPsec VPNs and AFS distributed file systems. Monitor for patches from your distribution maintainer. Given the public PoC and high success rate, treat this as an immediate priority for any Internet-facing Linux systems.Ivanti patched four additional high-severity EPMM vulnerabilities alongside CVE-2026-6973, with no evidence of in-the-wild exploitation. CVE-2026-5786 (CVSS 8.8) is an improper access control flaw allowing authenticated attackers to gain admin access. CVE-2026-5787 (CVSS 8.9) is an improper certificate validation vulnerability that allows unauthenticated attackers to impersonate registered Sentry hosts and obtain valid CA-signed client certificates. CVE-2026-5788 (CVSS 7.0) allows unauthenticated attackers to invoke arbitrary methods. CVE-2026-7821 (CVSS 7.4) is a certificate validation flaw that allows unauthenticated attackers to enroll devices and disclose EPMM appliance information, but only affects customers using Apple Device Enrollment.
RansomHouse Claims Trellix Breach
RansomHouse ransomware group claimed responsibility for the recent attack on cybersecurity firm Trellix. The company confirmed this week that part of its source code repository was breached, but stated that it found no evidence that the source code release or distribution process was affected or that the code has been exploited. RansomHouse published screenshots on its leak site showing access to internal services and management dashboards, but has not specified how much data was stolen or what type of data is involved. The timing of the attack suggests a potential connection to the recent supply chain campaign linked to TeamPCP and Lapsus$ that has impacted Checkmarx, Aqua Security, and Bitwarden, though this connection has not been confirmed. RansomHouse emerged in 2022 and operates as a RaaS provider targeting large enterprises. The group's leak site currently lists more than 170 victims.
TCLBanker Malware Spreads via WhatsApp and Outlook
A new banking trojan named TCLBanker targets 59 banking, fintech, and cryptocurrency platforms using a trojanized Logitech AI Prompt Builder MSI installer. The malware includes self-spreading worm modules for WhatsApp and Outlook that automatically infect new victims. TCLBanker is a major evolution of the Maverick/Sorvepotel malware family and currently focuses on Brazil, though LATAM malware has historically expanded targeting scope. The malware uses DLL side-loading within a legitimate Logitech application to evade detection and includes heavy anti-analysis protections (environment-dependent decryption, watchdog threads hunting for analysis tools). It monitors browser address bars for 59 targeted platforms and establishes WebSocket C2 sessions for remote control when victims access them. Capabilities include live screen streaming, keylogging, clipboard hijacking, shell execution, and fake overlay systems (credential prompts, PIN keypads, fake Windows Update screens). The WhatsApp worm searches for authenticated WhatsApp Web sessions in Chromium browser profiles, hijacks the victim's account, harvests Brazilian contacts, and sends spam messages. The Outlook worm uses COM automation to harvest contacts and send phishing emails.
Microsoft Expands Passkey Support
Microsoft announced expanded passkey support across its ecosystem on World Passkey Day. The company eliminated weaker authentication methods and rolled out phishing-resistant authentication covering 99.6% of users and devices in its internal environment. Key updates include synced passkeys and passkey profiles in Microsoft Entra ID, Entra passkeys on Windows using Windows Hello (GA late May 2026), passkeys for Microsoft Entra External ID (GA late May 2026), and passkey-preferred authentication in Entra ID (preview). Microsoft Password Manager now saves and syncs passkeys across devices signed in with Microsoft accounts, with iOS and Android support rolling out soon. FIDO Alliance estimates 5 billion passkeys are already in use worldwide. Sign-in success rates with passkeys are significantly higher than with passwords, and exposure to credential-based attacks is significantly lower. AI-powered phishing campaigns drive click-through rates as high as 54%.
AI Agent Framework RCE Vulnerabilities
Microsoft disclosed two critical vulnerabilities in its Semantic Kernel AI agent framework that could turn prompt injection into host-level remote code execution. CVE-2026-25592 and CVE-2026-26030 have been fixed. The vulnerabilities allowed attackers with prompt injection vectors to achieve unauthorized code execution by influencing agent inputs. Exploitation of CVE-2026-26030 required the targeted agent to use the Search Plugin backed by In-Memory Vector Store functionality with default configuration. The research demonstrates that AI agents fundamentally change the threat model of AI applications because plugins grant agents the ability to read files, search databases, run scripts, and perform other active operations. When frameworks map AI model outputs to system tools without proper validation, prompt injection becomes a code execution primitive. Microsoft is launching a research series focused on identifying vulnerabilities in popular AI agent frameworks through responsible disclosure.
Android ADB Authentication Bypass (CVE-2026-0073)
Google patched a critical Android vulnerability that allows attackers to bypass authentication in the Android Debug Bridge (ADB) remote debugging service. CVE-2026-0073 is a logic error in the ADB authentication process that occurs when key types don't match (for example, private key is RSA and public key is Ed25519). The ADB service returns an error but still opens a remote Android shell. The bug only works if ADB was used at least once, so there's an initial private key on the host to compare against. Exploitation works over private networks and the Internet. The vulnerability impacts all devices running Android 11 or later (every Android version since September 2020). ADB is disabled by default in the standard Android OS release, but may be enabled and left exposed by OEMs during factory testing. Countless botnets have grown to massive sizes by exploiting Android devices with ADB ports left exposed over the Internet. This bug will likely lead to a surge in attacks from existing botnets and integration into targeted attacks and law enforcement device unlocking toolkits. The demonstrated primitive provides remote code execution as the Android 'shell' user in SELinux context 'u:r:shell:s0', which is the operating system's debugging interface.
Microsoft May 2026 Security Updates
Microsoft published May 2026 security updates addressing multiple vulnerabilities across Azure and Microsoft 365 products. CVE-2026-33109 is a remote code execution vulnerability in Azure Managed Instance for Apache Cassandra caused by improper access control. CVE-2026-40379 is a spoofing vulnerability in Microsoft Enterprise Security Token Service (ESTS) in Azure Entra ID caused by exposure of sensitive information to unauthorized actors. CVE-2026-26164 is an information disclosure vulnerability in M365 Copilot caused by improper neutralization of special elements in output (injection). Multiple Redis vulnerabilities affecting Microsoft's redis-server implementation include CVE-2026-25243 (RESTORE invalid memory access allowing RCE) and CVE-2026-23631 (Lua use-after-free allowing RCE). Chromium-based Edge patches include CVE-2026-8021 (script injection in UI), CVE-2026-8022 (inappropriate implementation in MHTML), CVE-2026-8019 (insufficient policy enforcement in WebApp), CVE-2026-8017 (side-channel information leakage in Media), CVE-2026-8016 (use-after-free in WebRTC), CVE-2026-8013 (insufficient validation in FedCM), CVE-2026-7995 (out-of-bounds read in AdFilter), CVE-2026-7988 (type confusion in WebRTC), CVE-2026-7982 (uninitialized use in WebCodecs), and CVE-2026-7973 (integer overflow in Dawn).
Three major zero-days dominate today's threat landscape, all with active exploitation confirmed. Ivanti's third EPMM zero-day this year underscores the vendor's persistent security challenges (34 KEV entries since 2021). Palo Alto's month-long compromise window before disclosure highlights the extended dwell time state-sponsored actors achieve against edge network devices with limited logging. The Dirty Frag Linux kernel vulnerability with public PoC and no available patches presents immediate risk to all Linux environments, particularly given the high success rate and trivial exploitation.