Fragnesia CVE-2026-46300 Gives Linux Attackers Root Access
Fragnesia is a separate Linux kernel flaw in the Dirty Frag class. It can turn local access into root on unpatched systems, but the mitigation has real IPsec and AFS tradeoffs.
News desk
Security incidents, exploited vulnerabilities, breach reports, malware campaigns, and urgent patch notes arranged for fast daily scanning.
October 4, 2026
Fragnesia is a separate Linux kernel flaw in the Dirty Frag class. It can turn local access into root on unpatched systems, but the mitigation has real IPsec and AFS tradeoffs.
September findings explain RubyDoc code execution, public-data retrieval and API-key attempts in the May RubyGems attack. Signups reopened May 16.
Exim 4.99.3 fixes CVE-2026-45185 Dead.Letter, a GnuTLS/BDAT use-after-free that can expose internet-facing mail servers to potential remote code execution.
Mini Shai-Hulud abused trusted publishing to ship malicious TanStack npm packages with valid provenance, turning package installs into a token-exposure incident for CI and…
TrickMo.C moves Android banking malware control to TON/.adnl and adds proxy/pivot features, turning infected phones into traffic-exit nodes for fraud.
A rogue Checkmarx AST Scanner Jenkins plugin release put CI/CD source code and secrets at risk. Teams should verify plugin versions, mirrors, caches, and…
Attackers are exploiting cPanel & WHM CVE-2026-41940 to deploy a Filemanager backdoor, steal credentials, and maintain access on hosting servers.
Operation HookedWing used GitHub Pages, compromised servers, and staged redirects to target more than 500 organizations with credential phishing.
Dirty Frag chains Linux kernel bugs into local root escalation. The practical risk is post-compromise: a low-privilege foothold can become full host control.