🚨 BREAKING: New Linux zero-day "Dirty Frag" lets ANY local user become root on most major distros.
The PoC is already public, half of it isn't patched yet.
Discovered by researcher Hyunwoo Kim, the exploit chains two kernel bugs and sits in the same family as Dirty Pipe and Copy Fail.
▪️ CVE-2026-43284 (xfrm-ESP Page-Cache Write): patched in mainline Linux.
▪️ CVE-2026-43500 (RxRPC Page-Cache Write): NO PATCH yet.
The exploit is reliable by design. Attackers don't have to win a timing race, the system won't crash and alert anyone if it fails, and it succeeds nearly every run.
The embargo got broken before distros could ship fixes, so the working code is now sitting on GitHub.
Confirmed working on: Ubuntu 24.04.4, RHEL 10.1, openSUSE Tumbleweed, CentOS Stream 10, AlmaLinux 10, Fedora 44.
El CEO de Coinbase dice que ahora todos los equipos, aún los no técnicos, publican código en producción y crean agentes para automatizar todo.
Esto lo estoy viendo en muchas empresas con CEOs IA-bros, la peor parte es que cuando hablás con esos equipos sin presencia de los jefes están con miedo, estrés, hacen como que entienden pero no entienden qué están haciendo. Todos con el miedo de "si no hago esto y no hago como que se de IA, me rajan".
Me cuentan que abren la terminal que no saben usar, instalan skills y cosas que no reconocen, copian y pegan keys que no saben muy bien qué son, le van preguntando a la misma IA qué hacer y así van iterando hasta que hicieron algo que creen (sin conocimiento técnico para validarlo) que está bien.
Cuando veas que todo deja de funcionar en una empresa y todos los procesos están rotos, ya sabés por qué es.
Me da pena las personas que siguen usando Windows porque están obligadas a usarlo.
Ojalá pudiesen usar MacOS o Linux y ver que la vida puede ser hermosa.
This is an email I sent earlier today to all employees at Coinbase:
Team,
Today I’ve made the difficult decision to reduce the size of Coinbase by ~14%. I want to walk you through why we're doing this now, what it means for those affected, and how this positions us for the future.
Why now
Two forces are converging at the same time. We need to be front footed to respond to both.
First, the market. Coinbase is well-capitalized, has diversified revenue streams, and is well-positioned to weather any storm. Crypto is also on the verge of the next wave of adoption, with stablecoins, prediction markets, tokenization, and more taking off. However, our business is still volatile from quarter to quarter. While we've managed through that cyclicality many times before and come out stronger on the other side, we’re currently in a down market and need to adjust our cost structure now so that we emerge from this period leaner, faster, and more efficient for our next phase of growth.
Second, AI is changing how we work. Over the past year, I’ve watched engineers use AI to ship in days what used to take a team weeks. Non-technical teams are now shipping production code and many of our workflows are being automated. The pace of what's possible with a small, focused team has changed dramatically, and it's accelerating every day.
All of this has led us to an inflection point, not just for Coinbase, but for every company. The biggest risk now is not taking action. We are adjusting early and deliberately to rebuild Coinbase to be lean, fast, and AI-native. We need to return to the speed and focus of our startup founding, with AI at our core.
What this means
To get there, we are not just reducing headcount and cutting costs, we’re fundamentally changing how we operate: rebuilding Coinbase as an intelligence, with humans around the edge aligning it. What does this mean in practice?
- Fewer layers, faster decisions: We are flattening our org structure to 5 layers max below CEO/COO. Layers slow things down and create coordination tax. The future is small, high context teams that can move quickly. Leaders will own much more, with as many as 15+ direct reports. Fewer layers also means a leaner cost structure that is built to perform through all market cycles.
- No pure managers: Every leader at Coinbase must also be a strong and active individual contributor. Managers should be like player-coaches, getting their hands dirty alongside their teams.
- AI-native pods: We’ll be concentrating around AI-native talent who can manage fleets of agents to drive outsized impact. We’ll also be experimenting with reduced pod sizes, including “one person teams” with engineers, designers, and product managers all in one role.
In short: AI is bringing a profound shift in how companies operate, and we’re reshaping Coinbase to lead in this new era. This is a new way of working, and we need to leverage AI across every facet of our jobs.
To those who are affected
I know there are real people behind these decisions — talented colleagues who have poured themselves into this company and our mission. To those of you who will be leaving: thank you. You’ve helped build Coinbase into what it is today, and I am sincerely grateful for everything you've done.
All impacted team members will receive an email to their personal account in the next hour with more information, and an invitation to meet with an HRBP and a senior leader in your organization. Coinbase system access has been removed today. I know this feels sudden and harsh, but it is the only responsible choice given our duty to protect customer information.
To those affected, we will be providing a comprehensive package to support you through this transition. US employees will receive a minimum of 16 weeks base pay (plus 2 weeks per year worked), their next equity vest, and 6 months of COBRA. Employees on a work visa will get extra transition support. Those outside of the US will receive similar support, based on local factors and subject to any consultation requirements.
Coinbase prides itself on talent density. Our employees are among the most talented people in the world, and I have no doubt that your skills and experience will be highly sought after as you pursue your next chapters.
How we move forward
To the team that is staying, I know this is a difficult day. We’re saying goodbye to colleagues and friends you've been in the trenches with. But here’s what I want you to know as we move forward together:
Over the past 13 years, we have weathered four crypto winters, gone public, and built the most trusted platform in our industry. We’ve made it this far by making hard decisions and by always staying focused on our mission. This time will be no different – nothing has changed about the long term outlook of our company or industry. And most importantly, our mission has never been more important for the world. Increasing economic freedom requires a new financial system, and we’re building it.
The Coinbase that emerges from this will be more capable than ever to achieve our mission.
Brian
CYBERSECURITY 2026 ROADMAP: FOR ASPIRING PROFESSIONALS
If I had to restart my cybersecurity journey today, this is EXACTLY how I’d do it (based on what’s actually worked for me):
[A thread 🧵]
🚨Vulnerabilidad en el directorio raíz de todas las principales distribuciones de Linux
Error de copia: 732 bytes
Copy Fail (CVE-2026-31431)
https://t.co/FizvJ7LCM4
we're starting rollout of GPT-5.5-Cyber, a frontier cybersecurity model, to critical cyber defenders in the next few days.
we will work with the entire ecosystem and the government to figure out trusted access for cyber; we want to rapidly help secure companies/infrastructure.
We've released a new 5-point action plan for strengthening cyber defense.
AI is reshaping cybersecurity. The same capabilities that help defenders may be used by malicious actors.
One approach is to treat these systems as too dangerous for broad defensive use and limit them to a very small number of approved partners.
We think that misses the central challenge. Attackers won’t wait. Existing models are already useful for many cyber workflows and capabilities will keep advancing. Criminal groups will adopt whatever tools are available.
The best way to reduce national risk is to responsibly equip and accelerate trusted defenders faster than adversaries can adapt. Check out our plan ⬇️
https://t.co/pcV0XAWx1q
Un juez subió pornografía infantil de una causa a Google Drive sin darse cuenta porque tenía habilitada la sincronización automática, Google le cerró la cuenta y lo denunció y estos le echan la culpa a Google y no al juez que no sabe usar una computadora.
🇵🇾 Alleged Paraguay Insurance Database Exposed on Underground Forum
A threat actor on an underground forum is claiming to possess a database allegedly containing information on approximately 288,000 individuals from Paraguay.
The exposed sample appears to include:
national ID numbers
first and last names
birth dates
status information
country identifiers
The actor describes the dataset as originating from an insurance-related database, though the exact organization has not been publicly identified.
At this stage, the authenticity, source, and scope of the data remain unverified.
If confirmed, exposure of national identifiers and personal records could present significant risks related to:
identity fraud
phishing campaigns
financial scams
social engineering attacks
DDW is monitoring for additional validation and technical confirmation.
#CyberSecurity #DataLeak #ThreatIntel #DarkWeb #Paraguay #Infosec #DDW
Un nuevo día, una nueva brecha @Miticpy
Esto se va a convertir en el pan de cada día para los ciudadanos Paraguayos, dónde los datos estarán expuestos a los cibercriminales con total facilidad. Total, esto no es preocupación de @Miticpy y de la @CERTpy
🚨 CRITICAL CYBERINTEL ALERT: INSURANCE DATABASE LEAK – PARAGUAY 🇵🇾🏥🔓
A massive data breach has been detected, affecting Paraguayan citizens linked to a database within the insurance sector. Threat actor "dbrick84" has published a dataset on BreachForums containing sensitive personal information belonging to hundreds of thousands of individuals.
🏢 Affected Entity: Insurance Sector in Paraguay (specific entity TBC).
👤 Threat Actor: dbrick84.
📂 Leak Volume: 288,394 individual records.
📅 Publication Date: April 28, 2026.
📊 Breach Scope (PII and Insured Status)
The exposed data sample reveals a structure that enables the full identification of citizens:
Official Identity: National Identity Card numbers (national_id).
Full Names: First and last names linked to the ID document.
Demographic Data: Exact dates of birth.
Insurance Information: Policy status (ACTIVE, INACTIVE, UNKNOWN) and record type (policyholder).
Location: Country of origin (PY - Paraguay).
🛡️ Immediate Response Recommendations
🔒 Security Verification: Insurance companies in Paraguay are urged to conduct data integrity audits on their databases to identify the source of the data exfiltration.
🔑 ID Monitoring: Citizens should remain vigilant for any unusual use of their national identity numbers on financial or government portals.
Monitor: https://t.co/wk9bZJ2Nli
#CyberSecurity #Paraguay #DataBreach #Insurance #ParaguayanID #PII #dbrick84 #VECERT #InfoSec #CTI 🇵🇾🛡️⚠️🚨🏥
🚨 CRITICAL CYBERINTEL ALERT: INSURANCE DATABASE LEAK – PARAGUAY 🇵🇾🏥🔓
A massive data breach has been detected, affecting Paraguayan citizens linked to a database within the insurance sector. Threat actor "dbrick84" has published a dataset on BreachForums containing sensitive personal information belonging to hundreds of thousands of individuals.
🏢 Affected Entity: Insurance Sector in Paraguay (specific entity TBC).
👤 Threat Actor: dbrick84.
📂 Leak Volume: 288,394 individual records.
📅 Publication Date: April 28, 2026.
📊 Breach Scope (PII and Insured Status)
The exposed data sample reveals a structure that enables the full identification of citizens:
Official Identity: National Identity Card numbers (national_id).
Full Names: First and last names linked to the ID document.
Demographic Data: Exact dates of birth.
Insurance Information: Policy status (ACTIVE, INACTIVE, UNKNOWN) and record type (policyholder).
Location: Country of origin (PY - Paraguay).
🛡️ Immediate Response Recommendations
🔒 Security Verification: Insurance companies in Paraguay are urged to conduct data integrity audits on their databases to identify the source of the data exfiltration.
🔑 ID Monitoring: Citizens should remain vigilant for any unusual use of their national identity numbers on financial or government portals.
Monitor: https://t.co/wk9bZJ2Nli
#CyberSecurity #Paraguay #DataBreach #Insurance #ParaguayanID #PII #dbrick84 #VECERT #InfoSec #CTI 🇵🇾🛡️⚠️🚨🏥
Dijeron que el MITIC iba a liderar la transformación digital del sector público y disminuir la brecha digital en el Paraguay. Pero, al final, su trabajo consiste en atacar a la prensa independiente y a políticos que no están en línea con el cartismo autoritario.
De comunicación institucional pasaron a la comunicación sucia y de baja calidad a través de páginas falsas. La desinformación es la marca inseparable del gobierno de Cartes-Peña.
Estamos ante un grave atentado a los medios de comunicación, periodistas y politicos que critican al gobierno colorado cartista.
El MITIC no puede frenar ataques informáticos en portales estatales, pero al parecer sí puede financiar portales más falsos que un billete de 200 mil guaraníes.
Alguien debe asumir la responsabilidad política y judicial por este nuevo bochorno llamado Oscurece Paraguay.