Threat Brief — 2026-07-04 — Kernel root, embedded FS flaws, Chromium patch wave
Executive summary
A new Linux kernel privilege-escalation flaw ("Bad Epoll," CVE-2026-46242) dominates today's feed, enabling unprivileged users to gain root across Linux desktops, servers, and Android — a fix is available but uptake will lag. runZero disclosed seven unpatched vulnerabilities in the FatFs filesystem library, which is bundled into millions of embedded devices that read FAT/exFAT from USB and SD cards. Google helped disrupt the NetNut residential proxy network, cutting off roughly 2 million compromised Android devices, while a new modular malware framework called Avalon with ransomware capabilities surfaced alongside a fresh wave of developer-targeting npm packages linked to North Korea. A large Chromium/Edge CVE batch (~20 flaws) and several Linux kernel and library patches round out a patch-heavy day.
Top items
- Bad Epoll — Linux kernel local privilege escalation (CVE-2026-46242): A newly disclosed kernel flaw lets any unprivileged user escalate to root; affects Linux desktops, servers, and Android. A fix is already available — prioritise patching kernel and Android fleet images. Source
- Seven unpatched FatFs filesystem vulnerabilities: runZero disclosed flaws in FatFs, a small FAT/exFAT library bundled into millions of embedded devices that handle USB drives and SD cards. No patches exist yet; assess exposure in IoT/embedded product lines, especially any that accept untrusted media. Source
- Avalon malware framework with CrownX ransomware: A previously undocumented modular malware framework distributed via multi-stage phishing that bypasses traditional controls; combines stealer/spy capabilities with ransomware. Review email-gateway and endpoint detection coverage for novel loader chains. Source
- North Korea-linked malicious npm packages masquerading as Rollup polyfills: Packages like "rollup-packages-polyf…" facilitate remote access and secret theft from developer machines. Audit npm dependencies and CI/CD secrets for exposure; this fits the ongoing DPRK supply-chain pattern. Source
- Pegasus spyware confirmed on European Parliament member: Citizen Lab reports former MEP Stelios Kouloglou was repeatedly hacked with Pegasus while serving on a spyware investigative committee. Reinforces nation-state mobile surveillance risk for high-profile individuals. Source
- NetNut residential proxy network disrupted: Google-partnered operation cut off ~2 million compromised Android devices (smart TVs, streaming boxes) from the NetNut proxy service. Operational win; expect residual botnet nodes to re-emerge under new infrastructure. Source
- PamStealer — macOS credential theft via fake Maccy sites: Jamf Threat Labs identified a new macOS information stealer distributed through fraudulent Maccy app sites that abuses PAM checks to capture login passwords. Update Mac endpoint blocks and user awareness messaging. Source
- ARToken PhaaS — Microsoft 365 phishing toolkit exposed: New phishing-as-a-service platform operating as an EvilTokens affiliate, offering extensive M365 credential-theft capabilities. Tune mail-flow and identity-protection rules for associated indicators. Source
- Armored Likho APT targets government and power sector: Previously undocumented actor blending financially motivated and espionage operations against government agencies and electric power sector in Russia, Brazil, and Kazakhstan; deploys "BusySnake" stealer. Relevant to OT/energy-sector defenders. Source
- Chromium/Edge batch — ~20 CVEs: Microsoft Edge ingests a large Chromium patch set covering WebAppInstalls, Chromecast (incl. heap buffer overflow CVE-2026-13798 and integer overflow CVE-2026-13796), DevTools, GuestView, Updater use-after-free (CVE-2026-14018), USB policy bypass (CVE-2026-13951), and others. Source
- libexpat vulnerabilities (CVE-2026-56405, CVE-2026-56412): Integer overflow in
getAttributeIdand a use-after-free from incomplete fix for CVE-2026-50219 in versions before 2.8.2. Update any systems parsing untrusted XML with libexpat. Source
- Container/runtime CVEs — Kubevirt DoS (CVE-2026-13322) and Podman env-var leak (CVE-2026-57231): Kubevirt virt-handler has an unbounded virtio-serial readline causing OOM DoS; Podman can leak host environment variables into containers via malformed images. Patch container platform components accordingly. Source
Themes
- Patch-wave day: A single Chromium update drives ~20 CVEs, alongside multiple Linux kernel fixes (nilfs2, mailbox, tty, ocfs2, f2fs, drm) and library patches (libexpat, libnfs, ws). Funnel these through standard patch pipelines and prioritise kernel and browser updates.
- Supply-chain and developer-targeting convergence: DPRK-linked npm packages, the FatFs embedded-library disclosure, and the ARToken PhaaS platform all highlight continued attacker focus on upstream dependencies and developer tooling — a persistent theme worth sustained investment in dependency hygiene and secrets management.
- Mobile and embedded under pressure: Bad Epoll hits Android, NetNut was built on compromised Android TVs/boxes, Pegasus targeted a senior official's mobile, and FatFs exposes embedded devices — mobile and IoT/OT edge assets remain a broadening attack surface.
