Edizione del 05.07.2026
Linux Kernel Flaws Expose Systems to Local Root Escalation
Researchers disclosed two separate Linux kernel privilege-escalation flaws that can give local attackers root access across a wide range of systems, including servers, desktops, and Android devices. One bug,
A second flaw,
CVE-2026-46242 or Bad Epoll, is a use-after-free race in the kernel's epoll subsystem that was reportedly exploited through Google's kernelCTF program and shown to be broadly reachable because epoll is a core component that cannot be disabled. The flaw was introduced by a 2023 kernel change, and reporting said an initial patch attempt was insufficient before a correct fix was merged weeks later, leaving defenders dependent on upstream fixes and vendor backports.A second flaw,
CVE-2026-43456, affects the kernel's net/bonding subsystem and stems from a type-confusion condition dating back to 2007. Researchers said the bug can be exploited with high reliability for local root by abusing incompatible headerops handling in bonded network devices, enabling controlled memory corruption and eventual code execution. The issue reportedly affects Linux versions 2.6.24 through 6.12.77 and requires CAPNET_ADMIN privileges; mitigations include applying the March 2026 patch, or temporarily disabling unprivileged user namespaces or the bonding module where feasible.Medtronic Data Breach Exposed Personal and Health Information in ShinyHunters Attack
Medtronic disclosed that unauthorized actors accessed certain corporate IT systems between April 13 and April 19, exposing personal and health-related information tied to 3,834,294 individuals. The company said the incident was detected after unusual activity on April 15 and attributed in public reporting to the ShinyHunters extortion group, which claimed to have stolen about 9 million records and briefly listed Medtronic on its Tor-based leak site before the post disappeared. Exposed data may include names, contact details, dates of birth, Social Security numbers, and other health-related information.
Medtronic said it found no impact on medical devices, patient safety, hospital customer networks, manufacturing and distribution operations, financial systems, or care delivery, and added that it has no evidence the stolen data was publicly released online. The company has engaged external cybersecurity experts, notified law enforcement and regulators, and is warning affected people to watch for phishing, social engineering, and unauthorized account activity while offering 24 months of credit monitoring, dark web monitoring, and identity theft recovery services.
Medtronic said it found no impact on medical devices, patient safety, hospital customer networks, manufacturing and distribution operations, financial systems, or care delivery, and added that it has no evidence the stolen data was publicly released online. The company has engaged external cybersecurity experts, notified law enforcement and regulators, and is warning affected people to watch for phishing, social engineering, and unauthorized account activity while offering 24 months of credit monitoring, dark web monitoring, and identity theft recovery services.
PolinRider Supply Chain Campaign Hijacks Developer Packages and Uses Blockchain Dead Drops
Researchers reported a broad software supply chain campaign targeting developers and cryptocurrency users through hijacked packages, browser extensions, and compromised maintainer accounts across ecosystems including npm, Go, Chrome, and Packagist. Socket linked the activity to North Korean actors associated with the Contagious Interview operation and identified 108 malicious packages and extensions spanning 162 release artifacts, while JFrog separately analyzed hijacked npm packages
The malware chain used unusual delivery and evasion techniques aimed at developer workstations, including a VS Code folder-open task instead of standard npm lifecycle scripts, JavaScript hidden in a fake font file, and encrypted payload retrieval from blockchain transaction data on TRON, Aptos, and BNB Smart Chain. Researchers said the campaign deployed components including BeaverTail, DEV#POPPER RAT, OmniStealer, a
html-to-gutenberg 4.2.11 and fetch-page-assets 1.2.9 that were uploaded with malicious code. The activity appears to rely on account hijacking rather than compromise of GitHub itself, and some attacker infrastructure reportedly remains active even after certain packages were removed.The malware chain used unusual delivery and evasion techniques aimed at developer workstations, including a VS Code folder-open task instead of standard npm lifecycle scripts, JavaScript hidden in a fake font file, and encrypted payload retrieval from blockchain transaction data on TRON, Aptos, and BNB Smart Chain. Researchers said the campaign deployed components including BeaverTail, DEV#POPPER RAT, OmniStealer, a
socket.io backdoor, and a Python infostealer to steal browser credentials, password-manager contents, cryptocurrency wallet data, developer secrets, and operating system credential-store material across Windows, macOS, and Linux. Security firms warned that affected developer systems and credentials should be treated as fully compromised.