CISA issues guidance on Linux kernel Dirty Frag privilege escalation
Dirty Frag affects Linux kernel 4.10+ by chaining xfrm-ESP and RxRPC page-cache flaws, enabling privilege escalation.
Records are individual enterprise-technology developments, captured as they happen: product launches, funding, partnerships, executive moves, vulnerabilities, and announcements across cloud infrastructure, networking, security, and AI. Looking for the synthesis? See Briefs
Decision Insights Threat Desk • May 20, 2026
Dirty Frag affects Linux kernel 4.10+ by chaining xfrm-ESP and RxRPC page-cache flaws, enabling privilege escalation.
Decision Insights Record • May 19, 2026
Acronis paired with Rimouski Océanic through MicroAge Rimouski to deliver email security, Microsoft 365 backup, and XDR via one platform.
Decision Insights Threat Desk • May 18, 2026
SGLang has two unauthenticated RCE issues and one unauthenticated path traversal tied to specific configs and endpoints.
Decision Insights Coverage • May 15, 2026
Netskope adds AI risk attributes to Cloud Confidence Index and describes prompt/response guardrails for SaaS apps with AI agents.
Decision Insights Record • May 13, 2026
JupiterOne launched AI Attack Surface Management (AI ASM) and Unified Vulnerability Management (UVM) to provide relationship-aware asset and vulnerability context.
Decision Insights Record • May 12, 2026
Arctic Wolf launched Aurora Mobile Threat Defense for iOS and Android, adding real-time mobile phishing and unsafe network detection plus Threat Intelligence Plus and Concierge enhancements.
Decision Insights Coverage • May 11, 2026
Vendor blog highlights a governance gap for AI used via MCP, APIs, and CLI, citing a report that 92% of orgs lack MCP policies.
Decision Insights Threat Desk • May 8, 2026
A local privilege escalation flaw in Linux kernel versions 4.17+ can let an unprivileged user gain root access.
Decision Insights Record • May 5, 2026
Infoblox completed its acquisition of Axur and will add DRPS URL scanning with AI, feeding DNS blocking and takedowns into Infoblox Threat Defense.
Decision Insights Record • May 5, 2026
Synack made Sara AI Pentesting generally available, pairing agentic AI with human validation for continuous security testing.
Decision Insights Record • May 4, 2026
Tencent’s Weixin 2025 Brand Protection Report cites AI detection, user reports, and brand partnership outcomes, including $430M+ recovered enforcement value.
Decision Insights Coverage • April 30, 2026
Intercom [email protected] used a preinstall flow to download Bun, harvest GitHub credentials, and use them for npm spread.
Decision Insights Record • April 29, 2026
Huawei launched Xinghe AI Network Security Agentic SOC with Sensing, Analysis and Enforcement agents for automated detection and response.
Decision Insights Record • April 29, 2026
Fortinet will return to the World Economic Forum Annual Meeting on Cybersecurity 2026 in Geneva, citing participation in public-private cyber initiatives.
Decision Insights Coverage • April 28, 2026
NSS Labs publishes two AI security white papers and a new AIPS test methodology focused on runtime guardrails like prompt injection and unauthorized output prevention.
Decision Insights Record • April 28, 2026
Fortinet’s 2026 Global Cybersecurity Skills Gap Report links talent shortages, board AI risk gaps, and breach costs to ongoing cybersecurity breaches.
Decision Insights Threat Desk • April 23, 2026
Unauthenticated access to DRC INSIGHT COS /v0/configuration lets same-network users modify config, enabling data exfiltration or disruption (CVE-2026-5756).
Decision Insights Record • April 23, 2026
Censys added integrations with AI, SIEM, and SOAR platforms, including Cisco Splunk SOAR and ES, Microsoft Sentinel, and Google SecOps.
Decision Insights Threat Desk • April 22, 2026
Ollama’s model quantization engine has an unauthenticated remote information disclosure flaw in CVE-2026-5757 that can let an attacker with model upload access read and exfiltrate server heap memory.
Decision Insights Threat Desk • April 20, 2026
Overview A remote code execution vulnerability has been discovered in the SGLang project, specifically in the reranking endpoint (/v1/rerank).
A synthesis of what changed across the vendors, projects and technologies tracked here. Published every two weeks. Subscribing creates a free Decision Insights account.