CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (9 May 2026)

Published: Loading…

At a Glance

  • Dirty Frag flaws CVE-2026-43284 and CVE-2026-43500 enable local root escalation across major Linux distributions through IPsec ESP and RxRPC components.
  • ShinyHunters defaced Canvas login portals after breaching Instructure, disrupting exams while threatening to leak data from 275 million users.
  • PCPJack worm targets Docker, Kubernetes, Redis and MongoDB services, stealing cloud credentials and replacing TeamPCP artefacts across compromised environments.
  • CVE-2026-23918 in Apache HTTP Server mod_http2 allows unauthenticated attackers to trigger heap corruption through crafted HTTP/2 request sequences.
  • CVE-2025-68670 allows unauthenticated remote code execution in xrdp through a stack-based buffer overflow during pre-authentication domain parsing.
  • ShinyHunters claimed responsibility for a Zara breach exposing email addresses, order IDs and support ticket data belonging to 197,400 customers.

Summary

Dirty Frag local privilege escalation flaws tracked as CVE-2026-43284 and CVE-2026-43500 enable root access across major Linux distributions through IPsec ESP and RxRPC components. Public proof-of-concept exploits abuse splice(2) and sendfile(2) operations to retain references to decrypted page-cache buffers and overwrite protected memory regions. Ivanti released patches for CVE-2026-6973 in Endpoint Manager Mobile after reports confirmed targeted zero-day exploitation against exposed enterprise deployments.

ShinyHunters disrupted educational institutions across the United States after defacing Canvas login portals and triggering outages during university final examinations. Instructure confirmed attackers exploited a vulnerability tied to Free-for-Teacher accounts and accessed names, email addresses, student IDs and platform messages. Separate reporting linked ShinyHunters to a breach affecting Zara customers, where attackers allegedly used compromised Anodot authentication tokens to access BigQuery-hosted datasets.

PCPJack targeted exposed Docker, Kubernetes, Redis, MongoDB and RayML services to steal credentials and propagate laterally across compromised cloud environments. The framework removes TeamPCP artefacts, deploys Sliver beacons, abuses Telegram for command-and-control operations and harvests AWS credentials, Kubernetes tokens and cryptocurrency wallets. Another Linux-focused threat named PamDOORa used malicious PAM modules to maintain SSH persistence through hidden authentication mechanisms advertised on Russian-language cybercrime forums.

CVE-2026-23918 affects Apache HTTP Server mod_http2 version 2.4.66 and enables heap corruption through crafted HTTP/2 HEADERS and RST_STREAM request sequences. The flaw permits unauthenticated denial-of-service conditions and possible remote code execution on internet-facing systems running HTTP/2, with fixes released in Apache HTTP Server 2.4.67. Researchers also disclosed CVE-2025-68670, an xrdp vulnerability caused by a stack-based buffer overflow during UTF-16 to UTF-8 conversion in pre-authentication RDP handling.

Attackers targeted browser and AI tooling through a flaw in the Claude Chrome extension that allowed arbitrary extensions to inject prompts and control agent actions. Demonstrated abuse scenarios included extracting GitHub code, deleting messages and sharing Google Drive files through trusted messaging interfaces lacking execution context validation. Researchers additionally reported that Microsoft Edge stores decrypted password vault contents in plaintext process memory for the duration of browser sessions, unlike other Chromium-based browsers.

Polish authorities reported breaches affecting five water treatment facilities where attackers gained the ability to modify operational parameters within industrial control systems. Australian officials warned organisations about ClickFix campaigns distributing Vidar infostealer malware through social engineering techniques targeting enterprise environments. NVIDIA confirmed a data breach affecting Armenian GeForce NOW users, while Braintrust disclosed unauthorised access to AWS-hosted AI provider secrets stored within internal systems.

Highlights of the Day

Dirty Frag Linux Flaws Enable Local Root Access

Researchers disclosed Dirty Frag, tracked as CVE-2026-43284 and CVE-2026-43500, a pair of Linux kernel local privilege escalation vulnerabilities affecting IPsec ESP and RxRPC components. The flaws allow unprivileged users to retain references to decrypted paged buffers through splice(2) and sendfile(2), creating a page-cache write primitive that public proof-of-concept exploits use to gain root access. CloudLinux and AlmaLinux released patched kernels for affected distributions, while CloudLinux confirmed the vulnerabilities impact CloudLinux 7 Hybrid, 8, 9 and 10 systems.

ShinyHunters Breach Disrupts Canvas During University Final Exams

ShinyHunters defaced the Canvas login portal with ransom demands after breaching Instructure, disrupting coursework and final exams at universities and K-12 schools across the United States. Instructure said attackers exploited a vulnerability linked to Free-for-Teacher accounts, stealing names, email addresses, student ID numbers and user messages from institutions using the platform. The company temporarily disabled Canvas services, notified the FBI and CISA, and stated the same threat actors retained access after an earlier intrusion discovered on 29 April.

Claude Chrome Extension Flaw Enables Cross-Site Account Abuse

LayerX researchers disclosed a flaw in Anthropic’s Claude Chrome extension that allows any browser extension, including zero-permission extensions, to inject prompts and control Claude through a trusted messaging interface. The vulnerability affects the extension’s externally_connectable configuration, which trusts scripts running on claude.ai without validating the originating execution context or extension identity. Researchers demonstrated attacks that extracted private GitHub code, shared Google Drive files externally, sent emails and deleted messages, while Anthropic’s version 1.0.70 mitigation remained bypassable through privileged execution modes and side-panel initialisation flows.

Source: LayerX

xrdp Flaw Allows Unauthenticated Remote Code Execution

Kaspersky researchers disclosed CVE-2025-68670, an unauthenticated remote code execution vulnerability in the xrdp remote desktop server caused by a stack-based buffer overflow during domain name processing. The flaw occurs in xrdp_wm_parse_domain_information when UTF-16 client data is converted to UTF-8 before being copied into a 256-byte buffer during pre-authentication RDP connection handling. xrdp maintainers patched the vulnerability in versions 0.10.5, 0.10.4.1 and 0.9.27 after researchers demonstrated exploitation through a crafted RDP file that overwrote the return address and triggered stack smashing protection.

Source: Kaspersky

PCPJack Worm Steals Cloud Credentials Across Exposed Infrastructure

SentinelLABS identified PCPJack, a modular cloud worm that targets exposed Docker, Kubernetes, Redis, MongoDB and RayML services, steals credentials from cloud platforms, developer tools and financial services, and propagates through compromised environments. The malware uses Telegram for command and control, deploys Sliver beacons, exploits vulnerabilities including CVE-2025-29927, CVE-2025-55182 and CVE-2026-1357, and harvests AWS credentials, Kubernetes tokens, SSH keys and cryptocurrency wallets. SentinelLABS said PCPJack removes artefacts linked to TeamPCP campaigns, downloads payloads from attacker-controlled Amazon S3 infrastructure, and spreads laterally through Kubernetes APIs, Docker sockets, Redis cron rewrites and SSH credential reuse.

Zara Breach Exposes Data of 197,000 Customers

Have I Been Pwned confirmed that a data breach affecting Zara exposed information belonging to 197,400 customers after attackers accessed databases hosted by a former technology provider. The leaked data included email addresses, geographic locations, product SKUs, order IDs and customer support ticket information, while Inditex said payment details, passwords, names and addresses were not compromised. ShinyHunters claimed responsibility for the breach and allegedly leaked a 140GB archive stolen from BigQuery instances using compromised Anodot authentication tokens linked to wider SaaS-focused intrusion campaigns.

Apache HTTP/2 Flaw Risks Remote Code Execution

Orca Security disclosed CVE-2026-23918, a high-severity double-free vulnerability in Apache HTTP Server mod_http2 version 2.4.66 that can trigger heap corruption through specially crafted HTTP/2 HEADERS and RST_STREAM frames. The flaw allows unauthenticated attackers to cause denial-of-service conditions or potentially achieve remote code execution on internet-facing servers with HTTP/2 enabled, and Apache fixed the issue in version 2.4.67. Orca Security said public proof-of-concept details are already available, although no confirmed in-the-wild exploitation has been reported.

Daily Coverage

Developments
Canvas DefacementDirty FragPcpjack WormApache Http/2 Flaw
Vulnerabilities
CVE-2026-43284Linux Cac2661C53F35Cbe651Bef9B07026A5A05Ab8Ce0CVE-2026-43500Linux D0D5C0Cd1E711C98703F3544C1E6Fc1372898De5CVE-2026-29201CVE-2022-0847CVE-2026-31431Linux 72548B093Ee38A6D4F2A19E6Ef1948Ae05C181F7 (High)CVE-2026-1357CVE-2025-55182A Pre-Authentication Remote Code Execution Vulnerability Exists In React Server Components Versions 19.0.0, 19.1.0, 19.1.1, And 19.2.0 Including The Following Packages: React-Server-Dom-Parcel, React-Server-Dom-Turbopack, And React-Server-Dom-Webpack. The Vulnerable Code Unsafely Deserializes Payloads From Http Requests To Server Function Endpoints.CVE-2025-29927CVE-2026-23918CVE-2026-6973Endpoint_Manager_Mobile 12.6.1.1 (High)
Threat Groups
CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.