Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsChecklistsAI RankingsNewsletterStatusTagsAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Checklists
AI Rankings
Newsletter
Status
Tags
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1158+ Articles
126+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos
Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos
NEWS

Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos

This week's security roundup covers Linux privilege escalation zero-days, actively exploited Windows Defender vulnerabilities, router botnets hijacking DNS, and a sweeping new supply chain attack campaign called TrapDoor hitting npm, PyPI, and Crates.io.

Dylan H.

News Desk

May 25, 2026
5 min read

Overview

Another week, another cascade of active exploits and supply chain compromises. This Monday recap covers the most impactful cybersecurity stories from May 18–25, 2026 — from Linux kernel privilege escalation bugs to Windows Defender zero-days being weaponized in the wild, a coordinated DNS hijacking campaign targeting Microsoft 365 accounts via router botnets, and a freshly named cross-ecosystem supply chain attack making the rounds across npm, PyPI, and Crates.io.


Linux Kernel Flaws: Root Access at Risk

Dirty Frag Zero-Day

Researchers disclosed Dirty Frag, a new Linux kernel zero-day vulnerability that achieves local root privilege escalation on all major Linux distributions. The flaw leverages a race condition in the kernel's memory fragmentation handling and requires no special capabilities to trigger.

Proof-of-concept code circulated quickly, and CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog following confirmed in-the-wild exploitation. All major Linux vendors issued emergency patches within 24 hours of the PoC becoming public.

Affected systems: Linux kernel 5.15 through 6.x across Ubuntu, RHEL, Debian, Fedora, and derivatives.

Pack2TheRoot

A separate Linux privilege escalation technique dubbed Pack2TheRoot emerged this week, targeting a flaw in the kernel's network packet handling subsystem. Unlike Dirty Frag, Pack2TheRoot requires an initial foothold on the target system but enables reliable root escalation from a standard user context.

Patch status: Kernel patch merged upstream; distribution backports underway.


Windows Defender Zero-Days Under Active Exploitation

Two Defender Vulnerabilities Weaponized

Microsoft confirmed that two actively exploited Windows Defender vulnerabilities are being used in targeted attacks. The flaws allow attackers with local access to escalate privileges and disable security monitoring — effectively blinding endpoint detection systems before deploying secondary payloads.

Microsoft released out-of-band updates for both issues. Security teams should prioritize these patches over standard Patch Tuesday scheduling.

YellowKey and GreenPlasma

A researcher known for responsible (and sometimes not-so-responsible) disclosure dropped YellowKey and GreenPlasma — two Windows zero-day exploit chains targeting Bitlocker bypass and CTFMon privilege escalation respectively. Neither had patches at time of release.

MiniPlasma, a related Windows system-level privilege escalation exploit with a working PoC, was also publicly released. Microsoft acknowledged all three and is working on fixes.


Router Botnet DNS Hijacking Campaign

Authorities disrupted an ongoing campaign where threat actors compromised SOHO routers to modify DNS settings and redirect traffic from unsuspecting users to attacker-controlled infrastructure. The primary objective was stealing Microsoft 365 login credentials.

The campaign followed a well-worn playbook:

  1. Exploit weak or default credentials on consumer routers
  2. Modify DNS resolver settings to point to rogue servers
  3. Intercept authentication requests and harvest valid session cookies
  4. Use stolen credentials for follow-on BEC (Business Email Compromise) attacks

Law enforcement in multiple countries coordinated to sinkhole botnet infrastructure and notify affected ISPs.


Supply Chain Chaos: TrapDoor Campaign

The week's most far-reaching story came from researchers who named and documented TrapDoor — a coordinated cross-ecosystem supply chain attack campaign that has been running since at least May 22, 2026.

MetricDetail
Malicious packages34 packages confirmed
Poisoned versions384+ package versions
Ecosystems targetednpm, PyPI, Crates.io
Primary payloadCredential-stealing malware

The campaign targets developer credentials, CI/CD pipeline tokens, cloud provider access keys, and SSH credentials. Malicious code executes via post-install hooks, making it difficult to detect without specialized supply chain scanning tools.

Full coverage: TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and Crates.io


Law Enforcement Wins

First VPN Seized in Global Ransomware Crackdown

Europol and partner agencies announced the seizure and takedown of "First VPN", a commercial VPN service widely used by ransomware operators to anonymize infrastructure. The operator was arrested and the service — allegedly used by at least 25 ransomware groups — was dismantled.

KimWolf Botnet Admin Arrested

Canadian authorities charged the alleged administrator of the KimWolf DDoS botnet, a service-for-hire operation responsible for attacks against critical infrastructure including I2P network disruptions. The arrest came through joint cooperation between the FBI and RCMP.


Other Notable Stories

  • GitHub breach follow-up: Grafana confirmed source code theft via unrotated TanStack attack token (full story)
  • Drupal critical SQL injection actively exploited; added to CISA KEV — patch immediately
  • Cisco SD-WAN sixth zero-day of 2026 exploited in the wild; patch released
  • Microsoft Exchange zero-day under active attack — no patch available at time of writing
  • SonicWall VPN MFA bypass due to incomplete patching discovered in the wild

This Week's Patch Priority List

PriorityProductIssue
CriticalLinux kernelDirty Frag zero-day (root privesc)
CriticalWindows DefenderTwo actively exploited vulns
CriticalMicrosoft ExchangeZero-day under active attack
HighCisco SD-WANSixth exploited zero-day of 2026
HighDrupalSQL injection in KEV
HighSonicWall VPNMFA bypass via incomplete patch

Sources

  • The Hacker News — Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos

Related Reading

  • TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware
  • GitHub Confirms Breach via TanStack npm Supply Chain Attack
  • First VPN Dismantled in Global Takedown
#Zero-Day#Supply Chain#Linux#AWS#The Hacker News

Related Articles

ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories

This week's threat intelligence bulletin covers Linux rootkit campaigns, an actively exploited router zero-day, AI-assisted intrusions, new scam kit...

6 min read

Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More

This week's cybersecurity landscape opened with a critical Microsoft Exchange spoofing zero-day under active exploitation, a coordinated npm/PyPI supply...

5 min read

Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems

Anthropic's new Project Glasswing initiative uses a preview of its frontier model Claude Mythos to autonomously discover thousands of previously unknown...

6 min read
Back to all News