Interconnected blue nodes representing the latest critical cybersecurity vulnerabilities.

Daily Cybersecurity News - May 8, 2026

Dirty Frag Linux Kernel Hands Out Root

Linux kernel chain gives unprivileged users root on every major distro. Researchers call it Dirty Frag, a page-cache overwrite like Copy Fail.

Chain hits CVE-2026-43284 in ESP IPsec and CVE-2026-43500 in RxRPC. Local users splice shared pages into skbs, then decrypt in place for 4-byte writes to su or passwd. Public PoC available, CVSS 7.8.

Strikes kernels since 4.11 for ESP, 6.5 for RxRPC across Ubuntu 24.04, RHEL 8-10, Fedora, AlmaLinux, openSUSE, CentOS Stream. Unpatched in distro kernels.

Mainline patched ESP via commit f4c50a4034e6, RxRPC fix pending.

Source: Wiz Blog

xrdp Pre-Auth RCE Buffer Overflow

xrdp just patched a pre-auth RCE that lets anyone crash or potentially root Linux RDP servers with a crafted connection.

CVE-2025-68670 hides in xrdp_wm_parse_domain_information during Secure Settings Exchange. Attackers send a 512-byte UTF-16 domain starting with "_" and containing "__"; UTF-8 conversion overflows a 256-byte stack buffer, smashing the return address. CVSS 9.1.

Hits xrdp before 0.10.5 on any Linux setup, including Debian, SUSE, RHEL if installed. Stack canaries block simple exploits unless leaked.

Kaspersky team found it auditing their own USB Redirector module for xrdp.

Source: Securelist

RansomHouse Claims Trellix Source Code Theft

RansomHouse hackers claim they stole source code from Trellix's repository.

The group disclosed the breach last week and posted images as proof. Trellix builds endpoint security tools used by enterprises everywhere.

Source code leaks like this hand attackers the blueprint for finding flaws in security products. RansomHouse sticks to straightforward ransomware grabs.

Trellix first revealed the repository breach on May 1.

Polish Agency Exposes Russian ICS Water Hacks

Poland’s Internal Security Agency reports hackers breached ICS at five water treatment plants. In 2025, attackers hit facilities in Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko, and Sierakowo. ABW blames hacktivists backed by Russian APT28, APT29, and Belarusian UNC1151. Hackers gained control to alter equipment parameters. State actors now push for physical disruption over data theft. Hacktivists serve as fronts for intelligence ops. Breaches span 2024-2025 with rising OT focus.

Source: SecurityWeek

ShinyHunters Defaces School Canvas Logins for Ransom

ShinyHunters escalates their Instructure breach by defacing Canvas login portals at schools worldwide.

They exploit a vulnerability in Instructure's systems to inject HTML ransom messages on web logins and the Canvas app. This hits approximately 330 educational institutions just days after the initial data theft.

Visible defacement ramps up pressure on victims during finals week. It's classic ShinyHunters: data exfil first, then public shaming when ignored.

Ransom deadline runs to May 12, 2026, with threats to leak 275 million user records from nearly 9,000 schools.

Source: Malwarebytes

Chinese Hackers Hit Palo Alto Firewalls with Zero-Day

CL-STA-1132 exploits a zero-day in Palo Alto firewalls for root access, showing clear Chinese state hallmarks.

They hit the User-ID portal for unauthenticated RCE, inject shellcode into nginx, then wipe logs by clearing crash dumps and kernel messages. Attackers follow with AD enumeration using stolen service account creds and drop Earthworm for tunneling.

Tradecraft mixes familiar Chinese tools like Earthworm and ReverseSocks5 with tight opsec through intermittent sessions over weeks. Overlaps Volt Typhoon and APT41 toolsets but sticks to proven living-off-the-land moves.

Attempts started April 9, success a week later with tools deployed four days after compromise.

Source: SecurityWeek

Anthropic Mythos Finds 271 Vulns in Firefox

Anthropic gave Mozilla early access to Mythos Preview. It scanned Firefox and flagged 271 security bugs for fixes in version 150.

Mozilla built an agent on their fuzzing setup. Mythos generates reproducible test cases, verifies hypotheses across VMs, and catches latent issues like 15-year-old HTML bugs.

Scale crushes prior art. Earlier Opus 4.6 model found just 22 bugs; Mythos delivers near-zero false positives, shifting advantage to defenders.

Mozilla fixed 423 security bugs in April 2026 releases.

Source: TechCrunch