CVE-2021-29441, CVE-2025-3248, CVE-2025-9491, CVE-2026-13775, CVE-2026-13776, CVE-2026-13780, CVE-2026-13790, CVE-2026-13801, CVE-2026-13820, CVE-2026-13860, CVE-2026-13886, CVE-2026-13933, CVE-2026-14082, CVE-2026-14125, CVE-2026-14153, CVE-2026-31431, CVE-2026-43074, CVE-2026-46242, CVE-2026-53223, CVE-2026-55945, CVE-2026-6682, CVE-2026-6683, CVE-2026-6684, CVE-2026-6685, CVE-2026-6686, CVE-2026-6687, CVE-2026-6688
Domains:
236[.]244, 236[.]244.
Get tomorrow's brief in your inbox
Today: A new Linux kernel privilege escalation bug called Bad Epoll achieves root from unprivileged accounts and can be triggered from Chrome's sandbox. AI agents executed their first fully automated ransomware attack without human oversight. Chinese open-weight models now rival frontier AI systems at finding vulnerabilities, and seven unfixed flaws in embedded filesystem code affect millions of IoT devices.
Bad Epoll Linux Kernel Privilege Escalation (CVE-2026-46242)
A use-after-free bug in Linux kernel epoll code lets an unprivileged user escalate to root with 99% reliability on tested systems. The flaw affects Linux kernels 6.4 and newer, including Android devices. It can be triggered from inside Chrome's renderer sandbox, bypassing most kernel exploit defenses. CVE-2026-31431 (Copy Fail) is already on CISA KEV with active exploitation (EPSS 96.3%, due 2026-05-15). The timing window for Bad Epoll is only six machine instructions wide, but the public proof-of-concept from Google's kernelCTF program includes techniques to reliably win the race. No workaround exists since epoll cannot be disabled.
uname -r.First Fully Autonomous AI Ransomware Attack via Langflow
A threat actor tracked as JadePuffer exploited CVE-2025-3248 (CVSS 9.8) in Langflow to execute the first documented ransomware attack conducted entirely by an AI agent without human oversight. The attack exploited a critical authentication bypass in Langflow (a Python LLM framework) to gain initial access, then used the LLM to conduct reconnaissance, sweep for credentials, dump Postgres databases, scan internal networks, establish persistence via cron jobs, and pivot to a production MySQL/Nacos server. The AI adapted in real time to parse free-text error messages, correct failed commands, and escalate from row-level deletion to dropping entire database schemas. It encrypted 1,342 Nacos service configurations with a randomly generated key that was never persisted, making recovery impossible. Payloads showed natural-language commentary on each action, indicative of LLM-generated code. CISA added CVE-2025-3248 to KEV in early May (EPSS 100%).
Avalon Malware Framework Packs CrownX Ransomware
A new modular malware framework called Avalon combines credential theft, lateral movement, remote access, and ransomware execution in one package. The ransomware component is internally named CrownX. Avalon is distributed via spoofed legal document phishing emails pointing to password-protected archives on Proton Drive containing ISO images. A Windows shortcut inside the ISO triggers an MSBuild project that loads a .NET assembly, disables Event Tracing for Windows, and downloads the Avalon framework. The framework includes extensive defense evasion targeting Microsoft Defender, SentinelOne, CrowdStrike, Sophos, Elastic Endpoint, FortiEDR, ESET, McAfee, and Bitdefender. It harvests credentials from browsers, cryptocurrency wallets, Discord, Slack, Teams, VPN configs, RDP connections, Wi-Fi profiles, and Group Policy Preferences cpassword artifacts. CrownX encrypts files critical to business operations and virtual infrastructure, deletes Volume Shadow Copies, and may directly damage partition structures or boot records to render systems unusable. The framework shows signs of AI-assisted development with minimal regard for operational security.
Shun Hing Group Breach Affects 920,000 Customers
Hong Kong-based Shun Hing Group (Panasonic/KDK distributor) disclosed a March 2026 breach affecting 921,000 individuals, including 920,000 customers. Data exposed includes names, addresses, phone numbers, and email addresses. The company detected the intrusion on March 20 and reported it to police and the Privacy Commissioner. Over 1.05 million files were encrypted in the attack. Experts are calling for mandatory fines for data breaches in Hong Kong to force organizations to strengthen cyber defenses.
North Korea npm Campaign Mimics Rollup Polyfills
North Korean threat actors published six malicious npm packages mimicking Rollup polyfill tooling to steal developer credentials and enable remote access. The packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" impersonate the legitimate "rollup-plugin-polyfill-node" project with matching descriptions and repository metadata. These first-stage packages install second-stage payloads ("swift-parse-stream," "quirky-token," "react-icon-svgs," "rollup-plugin-polyfill-connect") that fetch malware from JSONKeeper and execute it via eval. The malware checks to avoid execution in cloud dev environments, sandboxes, and analysis infrastructure before installing dependencies and reaching out to 216.126.236[.]244 for an encrypted JavaScript payload. The final stage steals browser credentials, cryptocurrency wallets, clipboard contents, and files matching specific extensions (targeting Visual Studio Code, Windsurf, Cursor, AWS, Azure, Google Gemini, Anthropic Claude configs). It also enables remote terminal sessions, command execution, screenshots, process termination, mouse/keyboard control via @nut-tree-fork/nut-js, and hotkey presses. The campaign overlaps with BeaverTail/OtterCookie (Contagious Interview) and uses the same infrastructure as a March 2026 campaign involving 108 malicious packages.
Seven Unpatched Flaws in FatFs Filesystem Affect Millions of Embedded Devices
runZero disclosed seven vulnerabilities (CVE-2026-6682, CVE-2026-6687, CVE-2026-6688, CVE-2026-6685, CVE-2026-6683, CVE-2026-6686, CVE-2026-6684) in FatFs, a small filesystem library bundled into firmware for security cameras, drones, industrial controllers, hardware crypto wallets, and other embedded devices. FatFs lets devices read and write FAT and exFAT formats on USB drives and SD cards. The most severe bugs are CVE-2026-6682 (FAT32 mount integer overflow, CVSS 7.6), CVE-2026-6687 (exFAT volume-label buffer overflow, CVSS 7.6), and CVE-2026-6688 (long filename overflow in wrapper code, CVSS 7.6). On worst-affected systems, a booby-trapped USB drive, SD card, or firmware update can corrupt memory and achieve code execution. Many embedded devices lack memory protections found on phones and desktops, so physical access can lead to a jailbreak. Affected platforms include Espressif ESP-IDF, STMicroelectronics STM32Cube, Zephyr, MicroPython, ArduPilot, RT-Thread, Mbed, Samsung TizenRT, and SWUpdate. The FatFs maintainer did not respond to disclosure attempts via JPCERT/CC. Only one bug (CVE-2026-6684, GPT partition table hang) is fixed in the current FatFs release (R0.16). There is no upstream patch for the memory corruption bugs. runZero published proof-of-concept disk images and a working QEMU exploit.
Chinese LLMs GLM 5.2 and Tulongfeng Close the Gap in Vulnerability Discovery
Two new Chinese AI models, GLM 5.2 (open-weight) and Tulongfeng (frontier-based security tool), outperform Anthropic Opus and OpenAI GPT-5.5 on some bug-finding benchmarks. GLM 5.2 costs $0.17 per vulnerability found. Tulongfeng claims to have found over 3,400 vulnerabilities. The open-weight design of GLM 5.2 allows local installation without cloud API dependencies, which benefits defenders in OT/critical infrastructure environments (data sovereignty, no leakage risk). It also enables attackers to escape alignment restrictions offline. Former US National Cyber Director Chris Inglis warns that commodity models can now outpace defenses, and organizations must prioritize patching and fixing configurations ruthlessly. The Cloud Security Alliance warned in April that frontier models could trigger an AI vulnerability storm. Google detected the first AI-created exploit in active use in May.
Russians Pose as Signal Support to Steal Backup Keys
CISA and the FBI updated their March 2026 advisory to warn that Russian state-sponsored threat actors (UNC5792, UNC4221, linked to FSB Border Guards and Russian military) are targeting Signal users' backup recovery keys. Attackers masquerade as Signal support staff and send direct messages claiming the platform requires mandatory two-factor verification following alleged cyberattacks. They guide victims through enabling Secure Backups and instruct them to paste the recovery key into the chat. Once obtained, attackers download and decrypt the victim's entire message archive. Registering a new account under the same phone number does not invalidate a compromised key. Users must manually generate a new backup key in Signal settings. Targets include government officials, military personnel, journalists, and policy analysts. The US Department of State offers up to $10 million via Rewards for Justice for information leading to operator identification.
AdaptHealth Data Breach via Social Engineering
Medical equipment provider AdaptHealth disclosed that attackers used social engineering to gain access to cloud systems and steal patient health data. The attackers "sweet-talked their way" into the environment, indicating credential theft or helpdesk compromise rather than a technical vulnerability.
Google and FBI Target 2 Million-Device NetNut Botnet
Google and the FBI disrupted a 2 million-device botnet leveraging the NetNut residential proxy network. Details are limited, but the scale and involvement of law enforcement suggest the botnet was used for credential stuffing, ad fraud, or click fraud at scale. Residential proxy networks allow attackers to route malicious traffic through legitimate residential IP addresses, bypassing IP-based defenses.
Armored Likho Targets Government and Power Sector with BusySnake Stealer
A threat actor called Armored Likho (overlaps with Eagle Werewolf) targets government agencies and the electric power sector in Russia, Brazil, and Kazakhstan using BusySnake, a Python-based information stealer for Windows. The attacks use spear-phishing emails with RAR archives containing EXE droppers or LNK files that exploit CVE-2025-9491 (Windows shortcut RCE, patched November 2025, weaponized by a dozen groups since 2017, EPSS 63.1%). The dropper downloads additional payloads from GitHub, creates VBScript files for persistence, and launches the stealer via scheduled tasks. BusySnake steals clipboard data, enumerates files across the system, and uploads user documents to a C2 server. Armored Likho also uses Go2Tunnel for remote access and SSH tunneling. The group's motivation is cyber espionage, though financially motivated campaigns have also been observed.
Week in Brief: Anonymous Hacker Jailed, KDDI Breach, Push Security Poisoned Tenant Attack, Russian Hackers Behind Jaguar Land Rover Breach, Pegasus Spyware Targeted EU Investigator, LLM Fuzzing Yields Dozens of Zero-Days
SecurityWeek's weekly roundup includes: Aubrey Cottle (Anonymous-linked) sentenced to 18 months for the 2021 Texas GOP cyberattack. KDDI disclosed a breach affecting 14.22 million email addresses and passwords across five Japanese ISPs. Push Security was targeted using a poisoned tenant attack via OpenAI's organization invitation feature. Russian hackers were behind the September 2025 Jaguar Land Rover breach. Former EU Parliament member Stelios Kouloglou was hacked with Pegasus while investigating spyware abuse. A researcher known as Bikini published proof-of-concept code for dozens of zero-day vulnerabilities in FFmpeg, Gogs, Gitea, Ghidra, 7-Zip, OpenVPN, and VLC, discovered via LLM fuzzing. Two Venezuelans were sentenced to 78 months for ATM jackpotting.
European Parliament Member Investigating Pegasus Was Hacked With Pegasus
Former EU Parliament member Stelios Kouloglou was hacked with NSO Group's Pegasus spyware on October 21, 2022, and again on March 6-7, 2023, while serving on the PEGA Committee investigating spyware abuse. Citizen Lab forensic analysis found evidence of the PWNYOURHOME zero-click exploit in Apple's HomeKit software (patched in iOS 16.3.1). Kouloglou was running iOS 15.5 at the time of both infections. The targeting has not been attributed to a specific government. Citizen Lab found overlap with a campaign targeting Russian and Belarusian-speaking exiled journalists and activists in Europe, suggesting the operator had a license to spy in multiple European countries. This is the first confirmed case of a PEGA Committee member being targeted while investigating spyware.
Microsoft Edge Chromium CVEs
Microsoft published updates for 11 Chromium vulnerabilities in Edge: CVE-2026-13933 (password policy enforcement), CVE-2026-14153 (Glic implementation), CVE-2026-14125 (ANGLE uninitialized use), CVE-2026-13775 (GPU use-after-free), CVE-2026-13776 (Dawn type confusion), CVE-2026-13780 (ANGLE input validation), CVE-2026-13790 (Scroll side-channel), CVE-2026-13801 (Chromecast integer overflow), CVE-2026-13820 (Skia out-of-bounds read), CVE-2026-13860 (Autofill UI), CVE-2026-13886 (Isolated Web Apps policy bypass), CVE-2026-14082 (Storage race). EPSS scores range from 0.001 to 0.003 (2nd to 26th percentile). Also disclosed: CVE-2026-55945 (Edge information disclosure via race condition) and CVE-2026-53223 (Linux kernel net timestamp cmsg).
Three stories define today's threat landscape. First, AI has crossed the threshold from researcher tool to autonomous attacker, with the first fully automated ransomware campaign demonstrating that agentic systems can now conduct complex multi-stage intrusions without human intervention. Second, open-weight Chinese models now rival frontier Western systems in vulnerability discovery, widening the gap between offense and defense while lowering the cost of sophisticated attacks to near zero. Third, unfixed bugs in ubiquitous embedded code (FatFs) and unpatched Linux kernel flaws (Bad Epoll) show that critical infrastructure security debt is mounting faster than it can be paid down. The barrier to entry for advanced attacks continues to collapse while the attack surface continues to expand.