Saturday, July 4, 2026
Daily digest
New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
CVE-2026-46242, dubbed "Bad Epoll," is a Linux kernel privilege escalation flaw that allows any unprivileged local user to gain root access. It affects Linux servers, desktops, and Android devices. A patch has been released.
Why it matters: Nutanix AHV runs on Linux; an unprivileged guest-to-host or local-user-to-root escalation path on unpatched AHV nodes is a direct risk to your virtualization layer. Verify your AHV version against the patched kernel and prioritize updates.
ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit
A phishing-as-a-service platform called ARToken has been identified as an affiliate of the EvilTokens operation, which provides a specialized toolkit for compromising Microsoft 365 accounts. Researchers gained visibility into the toolkit's capabilities through the ARToken exposure. The platform is designed to bypass standard M365 authentication controls.
Why it matters: GCC High tenants are not immune to token-harvesting phishing attacks targeting M365; review your Conditional Access policies, ensure phishing-resistant MFA (FIDO2 or certificate-based) is enforced, and confirm anti-phishing policies in Defender for Office 365 are tuned.
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
North Korean threat actors tied to the Contagious Interview campaign have published 108 malicious packages across npm, Packagist, Go, and Chrome extensions in a campaign called PolinRider. The campaign is ongoing and new packages are expected to emerge as threat actors continue compromising maintainer accounts. The packages are designed for credential theft and remote access.
Why it matters: If your Ansible automation, CI/CD pipelines, or developer workstations pull from npm or Go module registries, a compromised dependency could introduce a backdoor into your build chain โ a supply-chain risk with direct CUI exposure implications under CMMC SC.3.177 and CM controls.
New Avalon Malware Framework Packs CrownX Ransomware Capabilities
Researchers have discovered Avalon, a previously undocumented modular malware framework distributed via multi-stage phishing that bypasses traditional security controls. The framework bundles credential harvesting, lateral movement, remote access, backup/recovery disruption, and ransomware (CrownX) into a single platform. Its modular design allows operators to deploy components selectively.
NetNut proxy network disrupted, 2 million infected devices cut off
A joint operation involving Google and the FBI disrupted NetNut, a residential proxy network built on approximately 2 million compromised Android devices including smart TVs and streaming boxes. The operation severed access to the botnet infrastructure. Other residential proxy services may rely on the same underlying compromised device pool.
Confidential computing's core trust mechanism is broken. The fix may not exist
Security researchers have identified fundamental weaknesses in attested TLS, the mechanism confidential computing relies on to prove the identity and integrity of a workload to a remote party. The flaw means the handshake cannot reliably establish who is on the other end of the connection. No architectural fix is currently available.
Why it matters: If you are evaluating or operating confidential computing enclaves in AWS GovCloud (e.g., Nitro Enclaves) for CUI workloads, this calls into question attestation-based trust assumptions you may be relying on for data-in-use protection claims in your SSP.
Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
runZero disclosed seven vulnerabilities in FatFs, a widely embedded FAT/exFAT filesystem library present in security cameras, industrial controllers, drones, hardware crypto wallets, and other firmware-based devices. The flaws remain unpatched. Because FatFs is embedded in firmware, there is no central patch mechanism โ each device vendor must independently issue an update.
AdaptHealth says attackers sweet-talked their way into cloud systems and stole patient data
AdaptHealth disclosed that attackers used social engineering against a third-party contractor to obtain credentials and gain access to cloud systems, exfiltrating patient health information and insurance billing passwords. The breach originated through a contractor account rather than a direct system vulnerability. Health information and financial credentials were confirmed stolen.
Why it matters: This is a direct illustration of the third-party/supplier risk that CMMC L2 addresses under AC and IA controls โ contractor accounts with cloud access to sensitive data are a top attack vector. Review whether your external contractors have appropriately scoped access to AWS GovCloud or M365 GCC High and whether their accounts are covered by your MFA and monitoring policies.
Staff shortages strain weapons programs, GAO says
A GAO report found that Pentagon workforce reductions and a federal hiring freeze have left major weapons acquisition programs significantly short-staffed. The shortfalls risk program delays and are eroding institutional acquisition expertise within DoD. GAO flagged the situation as a risk to both cost and schedule outcomes.
Chinese LLMs Broaden the Gap Between Attackers & Defenders
Two new large language models from Chinese firms are now competitive with top US frontier models and are being assessed for their impact on the offensive/defensive balance in cybersecurity. Analysts warn that unrestricted Chinese LLMs lower the barrier for threat actors to generate exploit code, phishing content, and attack tooling at scale. The models are accessible without the safety guardrails present in US commercial equivalents.