Geometric network nodes illustrating critical system vulnerabilities and data breaches.

Daily Cybersecurity News - May 14, 2026

Linux Fragnesia Flaw Spawns Root Exploits

Linux kernels just got hit with Fragnesia, another local root bug in the IPsec code. Unprivileged users splice file data into sockets then trigger bad decryption to corrupt page cache on su.

CVE-2026-46300 scores CVSS 7.8. Attackers build keystream tables via AF_ALG, flip bytes in read-only pages like /usr/bin/su for instant root. Public PoC available from V12 Security.

Hits all major distros on kernels before May 13 patches from Ubuntu, RHEL, AlmaLinux. Works inside containers or CI if AppArmor allows unprivileged namespaces.

Third kernel root bug in two weeks after Copy Fail and Dirty Frag.

Exim Mailer UAF Gives Remote Root

Exim mail servers just got hit with a remote code execution bug that lets unauthenticated attackers run code over SMTP.

CVE-2026-45185 is a user-after-free in TLS shutdown during BDAT chunked transfers on GnuTLS builds. Attackers trigger it with crafted SMTP traffic to corrupt memory and execute code. Patch lands in Exim 4.99.3.

Hits Exim 4.97 to 4.99.2 compiled with GnuTLS that advertise STARTTLS and CHUNKING. Targets Debian, Ubuntu servers, shared hosting, enterprise MTAs; OpenSSL builds dodge it.

PoC built in seven-day AI-vs-human exploit challenge targeting Exim's allocator.

Windows BitLocker Zero-Days Unlock Protected Drives

Windows BitLocker zero-days let attackers bypass encryption and escalate privileges with public PoCs out now.

YellowKey tricks WinRE NTFS transactions via crafted FsTx files on USB or EFI partition, reboot, CTRL key for shell on unlocked volumes. GreenPlasma lets unprivileged users craft memory sections in SYSTEM dirs via CTFMON. Both zero-day, unpatched, confirmed working by researchers.

YellowKey hits Windows 11, Server 2022/2025 in TPM-only setups with physical access. GreenPlasma works against unprivileged users on recent Windows builds.

Chaotic Eclipse dropped them on github[.]com/Nightmare-Eclipse after Microsoft disputes.

AI Poop App Tries Selling 150K User Stools

An AI app that analyzes user-submitted poop photos offered to sell its entire database to a reporter.

The app hoarded 150k stool images from users tracking their health. A seller contacted 404 Media directly with access to the full trove of graphic photos.

This tops the list of dumb data grabs. Users shared intimate pics expecting privacy, not a black market flip.

Seller pitched the database as "something valuable just not what you expect."

Source: 404 Media

KongTuke Hijacks Teams for Five-Minute Breaches

KongTuke initial access brokers now hijack Microsoft Teams accounts to breach corporate networks in minutes.

They pose as IT support in Teams chats, hide payloads with Unicode tricks, and dupe employees into pasting PowerShell that grabs a ZIP from Dropbox[.]com. This deploys ModeloRAT for screenshots, exfil, and multiple persistence hooks like scheduled tasks.

Teams marks a fresh social engineering vector after web lures like ClickFix and CrashFix. They rotate five Microsoft 365 tenants to dodge blocks.

Tracked since early 2025, with clusters overlapping LandUpdate808 and TAG-124.

iPhone Thieves Unlock Then Phishing Your Contacts

Criminals steal iPhones and turn them into phishing machines against your own contacts.

They buy underground tools to bypass passcodes and biometric locks, then send fake messages from your device to friends and family. Victims hand over bank logins, crypto wallets, and more, thinking the pleas come from you.

This setup thrives on a bustling black market selling unlock kits and phishing templates. Nothing novel technically, but the speed from theft to fraud stands out.

Underground shops offer full kits for under $100, with tutorials for non-tech thieves.

Source: Wired

Anthropic Withholds Mythos AI Over Vuln-Hunting Power

Anthropic launched Claude Mythos Preview, an AI that crushes software vulnerability hunting.

It finds zero-days across every major OS and browser, including a 27-year-old OpenBSD bug. Red team tests show it crafts exploits from simple prompts, chaining multiple flaws for RCE.

Not public due to insane compute costs; cheaper open models match some feats. Pushes defender tooling ahead of attackers, but dual-use risks loom.

Available only to 12 companies via Project Glasswing.