惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Commits to openclaw:main
Recent Commits to openclaw:main
Simon Willison's Weblog
Simon Willison's Weblog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
S
Schneier on Security
Cyberwarzone
Cyberwarzone
NISL@THU
NISL@THU
The Last Watchdog
The Last Watchdog
Security Archives - TechRepublic
Security Archives - TechRepublic
The Hacker News
The Hacker News
Schneier on Security
Schneier on Security
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
Help Net Security
Help Net Security
Scott Helme
Scott Helme
SecWiki News
SecWiki News
Security Latest
Security Latest
T
Threat Research - Cisco Blogs
L
LINUX DO - 最新话题
L
Lohrmann on Cybersecurity
TaoSecurity Blog
TaoSecurity Blog
K
Kaspersky official blog
Attack and Defense Labs
Attack and Defense Labs
P
Privacy & Cybersecurity Law Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
L
LINUX DO - 热门话题
N
News and Events Feed by Topic
Know Your Adversary
Know Your Adversary
Forbes - Security
Forbes - Security
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Google DeepMind News
Google DeepMind News
T
Tor Project blog
P
Palo Alto Networks Blog
Cisco Talos Blog
Cisco Talos Blog
A
Arctic Wolf
O
OpenAI News
T
The Exploit Database - CXSecurity.com
C
CXSECURITY Database RSS Feed - CXSecurity.com
AI
AI
N
News and Events Feed by Topic
博客园 - Franky
T
Threatpost
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Engineering at Meta
Engineering at Meta
S
SegmentFault 最新的问题
C
Cyber Attacks, Cyber Crime and Cyber Security
N
Netflix TechBlog - Medium
V2EX - 技术
V2EX - 技术
B
Blog RSS Feed
Hacker News: Ask HN
Hacker News: Ask HN
D
Docker
博客园 - 三生石上(FineUI控件)

Forbes - Consumer Tech

This Unhackable Quantum Navigation System Is The Size Of A Loaf Of Bread Apple At 50 — A Leadership Shift And An AR Future We Are Under-Investing In Robotics ... 90% Of Humanoid Robots Are Made In China Ditch The Apple White: Beats Expands Colorful Cable Line-Up With New 10-Foot Option Satechi’s New ChargeView 140W Desktop GaN Charger With Real-Time Display The Hasselblad In Your Pocket: Oppo’s Find X9 Ultra Challenges The Galaxy S26 Ultra There's No Such Thing As Brain Honey How AI Agents Could Rebuild Fashion’s Visual Production Layer QClaw Goes Global. The Agent Built Itself In 5 Days Apple’s Tim Cook Exit Hides A $4 Trillion Agentic AI Power Move EZQuest Reveals A New Line Of Pro Series USB-C Hubs For MacBook Neo Samsung Galaxy Z TriFold 2 Already In The Works, Report Claims Apple Revealed New Siri Release Date For iPhone, Latest Report Claims How Arcani’s HARK Is Designed For Modern Battlefield Acoustics The Newest Trend In Tech Embraces Femininity And Fun Samsung’s 75R95H Ushers In A New World Of LCD TVs New Apple iPhone Fold Design Pushes Smartphone Rivals To Go Wider And Taller iPhone 18 Pro Report: Four New Colors Leak As Apple Cancels Popular Shade Nothing’s Design-Led Strategy: Carl Pei Reveals The Tech Brand’s Philosophy iOS 26.5 Release Date: When To Expect Your iPhone Messaging Upgrade Google Pixel And Highsnobiety Build A Talent Pipeline For Fashion Android Circuit: Samsung Raises Galaxy Prices, Oppo Pad Mini Teased, Microsoft Closing Outlook App Apple Loop: iPhone Fold Launch Dates, iPad Air Upgrade, iPhone 18 Pro Specs Comcast $117.5 Million Breach Settlement — Are You Eligible? Amazfit Cheetah 2 Pro Takes Aim At The Garmin Audience Disney’s Launches ‘Infinity Vision’ Certification For Premium Theaters SoundPeats Reveals New Air6 HS Semi-Open Wireless Earbuds Amazon’s $11.57 Billion Leap Into Space: A Challenge To Starlink Meta Quest 3 Hit With $100 Price Increase Backblaze Stops Backing Up Dropbox And Others—Calls It An Improvement ‘Technically Hard To Do’: Why Samsung’s Galaxy S26 Ultra Privacy Display Is A Global First Ulanzi Launches D200X Creative Deck To Challenge Logitech And Elgato Plugable’s New 10-In-1 USB-C Hub Has Most Of The Ports You’ll Need AI Solved A Mathematical Problem That Had Stumped The World’s Best Minds For Decades RØDE Announces A Slew Of New Podcasting Innovations At NAB 2026 Samsung SmartThings Gets Smarter, Safer And More Personal Apple Announces Events In Run-Up To TCS London Marathon Apple Now Largest Smartphone Maker. Also, Samsung Now Largest Universal Announces 8-Movie ‘Steven Spielberg: The Spotlight Collection’ 4K Blu-Ray Boxset Denon Unveils Versatile New Living Room AV Receiver Google Android PIN Hackers Target 800 Apps During Attack Surge Canva AI 2.0 Launches With New Features And Conversational AI Govee’s New $450 Lightwall Brings RGBIC Effects Indoors And Out New Garmin Watch Is One Of The Most Expensive Yet The One Catch To Samsung’s New AirDrop-Style Sharing On Galaxy S26 World-First: Humanoid Robot On Live Industrial-Scale Electronics Production Line Cadence Teams With Nvidia And Google To Redefine AI System Engineering Dolby Files Lawsuit Against Barco Over HDR Patents Apple To Bring Major Upgrade To iPad Air In Months, Report Claims iPhone Setting Update—Stop FBI From Accessing Deleted Signal Messages GoPro Mission 1 Levels Up Action Cameras But One Mystery Remains Adobe Brings Chat To Firefly AI Assistant Across Creative Cloud Apps Sky Eyes Up Ring With Standalone Smart Home Launch Orico’s New X50 Thunderbolt 5 Compatible Enclosure Offers High-Speed Fanless Storage How 2,000 Tons Of Sand Stores 100 Megawatt-Hours And Slashes Carbon Emissions 70% iPhone’s Hidden Strength In The Rush To Wide Foldable Smartphones New Samsung Galaxy Price Shock Is Bad News For 2026 Buyers Can The Power Of AI Help You To Chat With Your Cat? Inside China’s Push To Build Birdlike Drones Sky Glass Air All-In-One Budget TV With Seamless Access To Sky Channels Booking.com Confirms Data Breach, Reservation PIN Codes Changed Google, DressX And The New Fashion AI Virtual Try-On Stack Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Humanoid Robots’ 88% Fail Rate: Completing Home Tasks Why Your Next Smartphone Could Have Lower Specs And A Higher Price Apple iPhone Fold: Striking Design Revealed In Leaked Photos Here’s The Most Affordable Humanoid Robot You Can Buy Now Samsung’s Disappointing Price Update For Galaxy Phone Buyers Is It Time For Apple To Forget About The MacBook Air Oura Has Designed A Solution To A Big Smart Ring Problem Apple iPhone Fold: Striking Design Revealed In Leaked Photos Adobe Attacks Underway—Windows And Mac Users Given 72 Hours To Update iOS 26.4.1 Release: Crucial iPhone Feature Update Arrives, But No Security Fix Can’t Stand Liquid Glass? This New Hidden iPhone Setting Is A Game-Changer Android Circuit: Galaxy S27 Pro Emerges, Honor 600 Pre-Order Offers, Pixel 11 Display Leaks Apple Loop: iPhone 18 Pro Leak, Urgent iOS Update, MacBook Neo Issues The Costly Dream Of Space-Based AI Infrastructure Adobe Attacks Underway—Windows And Mac Users Given 72 Hours To Update New Google Security Warning For Android 14, 15 And 16 Users—Update Now Fosi Launches CD Player With Built-In DAC And Headphone Amplifier The Shift From Place To Performance In Workplace Design Dyson Just Launched A $99 Gadget: Meet The HushJet Mini Cool Fan Apple iOS 26.4.1 Unexpected New iPhone Software: Should You Upgrade? LG Announces All U.K. And Some U.S. Pricing For Its 2026 TV Range Google Brings New 2FA Bypass Protection To Chrome For Windows Users iOS 26.4.1 Release: Crucial iPhone Feature Update Arrives, But No Security Fix SiFive's $400M Round Signals A RISC-V Moment In AI Data Centers Google Issues Critical Update Alert For 3.5 Billion Chrome Users Apple Vision Pro Gets A Major Gaming Upgrade Disney Announces ‘Alice In Wonderland’ 4K Blu-Ray, Featuring An All-New 4K Restoration Surprise Galaxy S27 Leak Gives Samsung New Options Aqara Thermostat Hub W200: Matter Controller With Smart Heating Skills Now On Sale AI Transformation: No-One’s At The Wheel, Says 500-Company Study Insta360 Launches Screen For Taking Selfies With A Phone’s Rear Camera Apple iPhone Fold Gets New Release And Screen Confirmation Angry Hacker Drops Microsoft Zero-Day Exploit, 1 Billion Users Warned Artemis II Just Dropped Stunning Wallpapers For Your Phone Or PC New Amazon Hack Attack—Alert For 300 Million Users Apple’s 2026 Shake-Up: iPhone 18 Pro Leaks While iPhone Fold Steals The Show
Critical New Linux Zero-Day Leaked—What Admins Need To Do Now
Davey Winder · 2026-05-10 · via Forbes - Consumer Tech
Linux penguin with glasses holding a red megaphone.

Dirty Frag Linux zero-day confirmed.

getty

Updated May 10: This article regarding the critical Dirty Frag Linux kernel zero-day vulnerability that gives attackers root access with no patch available has been updated to include comments from security experts at Black Duck, Bugcrowd and Sectigo.

If you thought that Linux was somehow the safe and secure choice of operating system, you might want to think again. Hot on the heels of the Copy Fail access vulnerability that had remained hidden for 9 years comes news that a new zero-day, with no patch available and granting hackers root, has been confirmed. On Friday, May 8, 2026, the Dirty Frag vulnerability was publicly disclosed after a strict embargo tregarding the vulnerability was broken. As such, and with a proof of concept exploit known, it’s now only a matter of time before threat actors use this in the wild to attack systems. Here’s what we know about CVE-2026-43284 and the workaround you can employ to mitigate against attacks.

ForbesMicrosoft Says Edge Password Security Vulnerability Is ‘By Design’—Is It Time To Switch To Chrome?By Davey Winder

What We Know About CVE-2026-43284, The Linux Dirty Frag Zero-Day

Why is it always a Friday? Just as security teams and end users alike look forward to the weekend, a security issue rears its ugly head, putting a stop to all that. With the major Linux distributions still rolling out patches for the Copy Fail vulnerability, which the U.S. Cybersecurity and Infrastructure Security Agency has confirmed is now being exploited by attackers, comes news that an even worse issue is out there. Dirty Frag, officially now tracked by the Common Vulnerabilities and Exposures database as CVE-2026-43284, has been confirmed and publicly disclosed, all before a patch is ready to roll.

The reason for the May 8 public disclosure, according to the security researcher responsible, Hyunwoo Kim, was someone breaking the embargo that was in place. “Because the embargo has now been broken, no patches or CVEs exist for
these vulnerabilities,” Kim said. After consulting with the Linux Distros Openwall maintainers, and at their request, Kim confirmed, “I am publicly releasing this Dirty Frag document.”

MORE FOR YOU

Amazingly, just like Copy Fail before it in terms of age, the Dirty Frag privilege escalation flaw has been present in the Linux kernel, specifically its algif_aead cryptographic algorithm interface, for around nine years.

Also, like Copy Fail, Kim said, “Dirty Frag likewise allows immediate root privilege escalation on all major distributions, and it chains two separate vulnerabilities.”

Here’s what leading security experts have to say about the Dirty Frag Linux kernel vulnerability.

“This vulnerability is like both Copy Fail and Dirty Pipe in that they attack page caches in the system, where in-place crypto operations take place,” Ben Ronallo, principal cybersecurity engineer at Black Duck, told me, “but Dirty Frag is not limited to a single Linux subsystem.” With full code exploit now published, Ronallo said, echoing my earlier warning, “it’s only a matter of hours or days before this is weaponized.”

David Brumley, chief AI and science officer at Bugcrowd, meanwhile, said that while Dirty Frag is in the same vulnerability class as Copy Fail, “virtually every Linux distribution is vulnerable, and the fix for Copy Fail alone is insufficient.” That Copy Fail was uncovered using advanced AI analysis, yet Dirty Frag was missed, is cause for some concern. “It is a reminder that vulnerability classes are rarely exhausted by a single pass,” Brumley said, “even a very good one. Independent researchers still matter because they bring different intuitions, different workflows, and different failure modes.”

Jason Soroko, senior fellow at Sectigo, warned that the threat significance of Dirty Frag “is amplified by its highly deterministic nature,” explaining that “because the exploit does not rely on a timing window or race conditions, attackers can achieve immediate root access with an exceptionally high success rate without risking a kernel panic.”

ForbesCritical New Google Security Update—127 Chrome Security Vulnerabilities ConfirmedBy Davey Winder

How To Mitigate The Linux Dirty Frag Attack Risk Before A Patch Arrives

To mitigate Linux attacks now that the zero-day has been publicly disclosed, and before a patch is ready to roll out, users are advised by Kim to remove the modules in which the vulnerabilities occur as follows:

sh -c "printf 'install esp4 /bin/false\ninstall esp6 /bin/false\ninstall rxrpc /bin/false\n' > /etc/modprobe.d/dirtyfrag.conf; rmmod esp4 esp6 rxrpc 2>/dev/null; true"

Dirty Frag has been tested as being applicable to the following Linux distribution versions:

  • Ubuntu 24.04.4: 6.17.0-23-generic
  • RHEL 10.1: 6.12.0-124.49.1.el10_1.x86_64
  • openSUSE Tumbleweed: 7.0.2-1-default
  • CentOS Stream 10: 6.12.0-224.el10.x86_64
  • AlmaLinux 10: 6.12.0-124.52.3.el10_1.x86_64
  • Fedora 44: 6.19.14-300.fc44.x86_64_

You can read more technical details and keep up to date with developments related to the latest Linux kernel zero-day at the official Dirty Frag information site.