CVE-2026-53359 (Januscape), a 16-year-old Linux KVM flaw enabling VM-to-host escape, landed patches July 4 while the North Korean PolinRider supply chain campaign hit 100+ legitimate packages through stolen maintainer credentials, graduating beyond typosquatting into a method that subverts the trust signals defenders rely on.
ShinyHunters expanded Monday's identity breach wave to 275 million education users via Canvas and pivoted to cloud data warehouse infrastructure at Vimeo; separately, an unpatched PAN-OS RCE zero-day leaves internet-facing firewalls exposed until at least May 13.
CVE-2026-31431 is a deterministic local privilege escalation in the Linux kernel's authencesn crypto template, with a public exploit and no race condition, making it the most reliable Linux LPE since Dirty Pipe.