Daily Security Intel

Archives
Log in
Subscribe
July 4, 2026

[SecurityIntel] 04 Jul | Critical Bad Epoll Linux Kernel Vulnerability Patched

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Saturday, July 04, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Critical Bad Epoll Linux Kernel Vulnerability Patched

CRITICAL

5

C2 IPs

42

OTX IOCs

17

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by the critical "Bad Epoll" Linux kernel privilege escalation vulnerability (CVE-2026-46242) and unpatched flaws in the widely used FatFs embedded filesystem library. Additionally, threat actors are leveraging advanced techniques, including Agentic AI via Langflow for automated ransomware attacks, and targeting developers through malicious npm packages and critical Cursor AI code editor vulnerabilities. State-sponsored activity remains high, with Pegasus spyware targeting European politicians and North Korean actors distributing malicious packages.

■ CRITICAL STORIES

CRITICAL#1

New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android

This local privilege escalation vulnerability (CVE-2026-46242) affects desktops, servers, and Android devices, allowing attackers with low-privilege access to gain full root control.

HIGH#2

Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices

RunZero has disclosed seven vulnerabilities in the FatFs filesystem library, which is widely integrated into millions of embedded systems, consumer electronics, and IoT devices, posing a massive supply chain risk.

CRITICAL#3

Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution

The DuneSlide vulnerabilities in the Cursor AI code editor allow zero-click prompt injection attacks to escape the sandbox and execute arbitrary code on the host operating system.

HIGH#4

Agentic AI Used to Conduct Ransomware Attack via Langflow

This attack marks a significant shift as threat actors use LLM agents to orchestrate and automate complex, multi-stage ransomware intrusions by combining known exploits with real-time reasoning.

■ CVEs IDENTIFIED

CVE-2026-46242

Linux Kernel — Local Privilege Escalation to Root

Critical

[CVE-TBD]

ChaN FatFs — Denial of Service and potential Code Execution in embedded devices

High

[CVE-TBD]

Anysphere Cursor AI Code Editor — OS-level Remote Code Execution via DuneSlide prompt injection

Critical

■ THREAT ACTORS

Lazarus Group

Nation-State

Distributed malicious npm packages mimicking Rollup polyfills to steal developer secrets

Armored Likho

APT / Cyberespionage

Targeted government and power sectors in Russia, Brazil, and Kazakhstan with BusySnake stealer

ShinyHunters

Cybercrime / Ransomware

Breached Medtronic IT systems, stealing personal and medical data of 3.8 million people

■ ATT&CK TTPs

T1068
Exploitation for Privilege Escalation | Used via Bad Epoll (CVE-2026-46242) to gain root on Linux and Android
T1195.002
Software Supply Chain Compromise | Malicious npm packages mimicking Rollup polyfills to compromise developers
T1566.002
Spearphishing Link | Avalon malware framework and ARToken PhaaS campaigns targeting credentials
T1056.001
Keylogging/Credential API Hooking | PamStealer using fake PAM checks to steal macOS login passwords
T1204.002
Malicious File | BusySnake stealer and PamStealer distributed via social engineering and fake sites
T1090.003
Multi-hop Proxy | NetNut residential proxy network using compromised Android devices to mask traffic

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Linux Kernel — Local privilege escalation to root (CVE-2026-46242) — [THN]

[P1 PATCH NOW]≤24h

Cursor AI Code Editor — DuneSlide zero-click prompt injection leading to OS-level RCE — [SW]

[P2 PATCH NOW]≤72h

Android OS — Impacted by "Bad Epoll" kernel vulnerability (CVE-2026-46242) — [THN]

[P3 PATCH NOW]≤1 week

ChaN FatFs — Seven unpatched filesystem vulnerabilities in embedded devices — [THN]

■ RECOMMENDED ACTIONS TODAY

1[P1] Apply the official Linux kernel security updates immediately to patch the "Bad Epoll" local privilege escalation vulnerability (CVE-2026-46242) across all Linux desktops, servers, and Android deployments.
2[P1] Update Cursor AI Code Editor to the latest version to mitigate the DuneSlide zero-click prompt injection sandbox escape vulnerabilities.
3[P2] Audit software development environments for malicious npm packages, specifically blocking and removing "rollup-packages-polyfill-core" and related unauthorized Rollup polyfills.
4[P2] Implement strict application controls and monitor PAM (Pluggable Authentication Modules) configurations on macOS endpoints to detect unauthorized modifications by PamStealer.
5[P3] Review embedded device inventories for the integration of the FatFs filesystem library and coordinate with device manufacturers for upcoming firmware patches.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 05 Jul | AI-Driven JadePuffer Ransomware Automates Entire Attack Lifecycle Older → [SecurityIntel] 02 Jul | Active Exploitation of Kemp LoadMaster and Oracle EBS
Powered by Buttondown, the easiest way to start and grow your newsletter.