SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefSaturday, July 04, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Critical Bad Epoll Linux Kernel Vulnerability Patched | CRITICAL |
|
5 C2 IPs | 42 OTX IOCs | 17 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by the critical "Bad Epoll" Linux kernel privilege escalation vulnerability (CVE-2026-46242) and unpatched flaws in the widely used FatFs embedded filesystem library. Additionally, threat actors are leveraging advanced techniques, including Agentic AI via Langflow for automated ransomware attacks, and targeting developers through malicious npm packages and critical Cursor AI code editor vulnerabilities. State-sponsored activity remains high, with Pegasus spyware targeting European politicians and North Korean actors distributing malicious packages. |
|
■ CRITICAL STORIES New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android This local privilege escalation vulnerability (CVE-2026-46242) affects desktops, servers, and Android devices, allowing attackers with low-privilege access to gain full root control. |
Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices RunZero has disclosed seven vulnerabilities in the FatFs filesystem library, which is widely integrated into millions of embedded systems, consumer electronics, and IoT devices, posing a massive supply chain risk. |
Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution The DuneSlide vulnerabilities in the Cursor AI code editor allow zero-click prompt injection attacks to escape the sandbox and execute arbitrary code on the host operating system. |
Agentic AI Used to Conduct Ransomware Attack via Langflow This attack marks a significant shift as threat actors use LLM agents to orchestrate and automate complex, multi-stage ransomware intrusions by combining known exploits with real-time reasoning. |
|
■ CVEs IDENTIFIED CVE-2026-46242 Linux Kernel — Local Privilege Escalation to Root |
[CVE-TBD] ChaN FatFs — Denial of Service and potential Code Execution in embedded devices |
[CVE-TBD] Anysphere Cursor AI Code Editor — OS-level Remote Code Execution via DuneSlide prompt injection |
|
■ THREAT ACTORS Lazarus Group | Nation-State |
Distributed malicious npm packages mimicking Rollup polyfills to steal developer secrets |
Armored Likho | APT / Cyberespionage |
Targeted government and power sectors in Russia, Brazil, and Kazakhstan with BusySnake stealer |
ShinyHunters | Cybercrime / Ransomware |
Breached Medtronic IT systems, stealing personal and medical data of 3.8 million people |
|
|
|
■ ATT&CK TTPs | T1068 | | Exploitation for Privilege Escalation | Used via Bad Epoll (CVE-2026-46242) to gain root on Linux and Android |
| T1195.002 | | Software Supply Chain Compromise | Malicious npm packages mimicking Rollup polyfills to compromise developers |
| T1566.002 | | Spearphishing Link | Avalon malware framework and ARToken PhaaS campaigns targeting credentials |
| T1056.001 | | Keylogging/Credential API Hooking | PamStealer using fake PAM checks to steal macOS login passwords |
| T1204.002 | | Malicious File | BusySnake stealer and PamStealer distributed via social engineering and fake sites |
| T1090.003 | | Multi-hop Proxy | NetNut residential proxy network using compromised Android devices to mask traffic |
|
■ PATCH PRIORITY Linux Kernel — Local privilege escalation to root (CVE-2026-46242) — [THN] |
Cursor AI Code Editor — DuneSlide zero-click prompt injection leading to OS-level RCE — [SW] |
Android OS — Impacted by "Bad Epoll" kernel vulnerability (CVE-2026-46242) — [THN] |
ChaN FatFs — Seven unpatched filesystem vulnerabilities in embedded devices — [THN] |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Apply the official Linux kernel security updates immediately to patch the "Bad Epoll" local privilege escalation vulnerability (CVE-2026-46242) across all Linux desktops, servers, and Android deployments. |
| 2 | [P1] Update Cursor AI Code Editor to the latest version to mitigate the DuneSlide zero-click prompt injection sandbox escape vulnerabilities. |
| 3 | [P2] Audit software development environments for malicious npm packages, specifically blocking and removing "rollup-packages-polyfill-core" and related unauthorized Rollup polyfills. |
| 4 | [P2] Implement strict application controls and monitor PAM (Pluggable Authentication Modules) configurations on macOS endpoints to detect unauthorized modifications by PamStealer. |
| 5 | [P3] Review embedded device inventories for the integration of the FatFs filesystem library and coordinate with device manufacturers for upcoming firmware patches. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |