from the field

insights & updates

Threat intelligence, best practices, compliance guidance, and analysis from the CrowdSOC team. Written for security-conscious leaders, not just security professionals.

threat intelligence

DirtyDecrypt (CVE-2026-31635) and ssh-keysign-pwn (CVE-2026-46333): Sorting Out May's Linux LPE Pair

DirtyDecrypt (CVE-2026-31635) is a page-cache write primitive in the Linux kernel's rxgk subsystem affecting distros with CONFIG_RXGK enabled. Published alongside ssh-keysign-pwn (CVE-2026-46333), the pair add to a remarkable month for Linux kernel privilege escalation disclosures.

May 22, 2026 9 min read
read article
DirtyDecrypt (CVE-2026-31635) and ssh-keysign-pwn (CVE-2026-46333): Sorting Out May's Linux LPE Pair
all threat intelligence best practices compliance incident response security operations industry news crowdsoc news tutorials
NGINX Rift (CVE-2026-42945): An 18-Year-Old Flaw in the World's Most Deployed Web Server
threat intelligence
NGINX Rift (CVE-2026-42945): An 18-Year-Old Flaw in the World's Most Deployed Web Server

NGINX Rift (CVE-2026-42945) is an 18-year-old heap buffer overflow in the NGINX rewrite module with a CVSS score of 9.2. A public PoC is available and active exploitation was confirmed within three days of disclosure. Patch now, or reconfigure affected rewrite directives immediately.

May 19, 2026 9 min read
BitUnlocker (CVE-2025-48804): The BitLocker Patch That Wasn't Enough
threat intelligence
BitUnlocker (CVE-2025-48804): The BitLocker Patch That Wasn't Enough

A public proof-of-concept for BitUnlocker, a downgrade attack rooted in CVE-2025-48804, can defeat BitLocker on fully patched Windows 11 machines in under five minutes — because the patch alone was never enough.

May 17, 2026 9 min read
Fragnesia (CVE-2026-46300): Linux LPE the Third (in Three Weeks)
threat intelligence
Fragnesia (CVE-2026-46300): Linux LPE the Third (in Three Weeks)

Three Linux kernel local privilege escalation vulnerabilities in three weeks! Fragnesia (CVE-2026-46300) is a separate bug from Dirty Frag, but it shares the same mitigation, so if you already applied it then you are already covered until patches arrive.

May 17, 2026 8 min read
YellowKey: BitLocker Bypass Zero-Day with Public Exploit and No Patch
threat intelligence
YellowKey: BitLocker Bypass Zero-Day with Public Exploit and No Patch

A working proof-of-concept for a BitLocker bypass, called YellowKey, affecting Windows 11 and Windows Server 2022/2025 was published publicly this week with no patch available.

May 17, 2026 8 min read
Dirty Frag (CVE-2026-43284): Local Privilege Escalation...Again
threat intelligence
Dirty Frag (CVE-2026-43284): Local Privilege Escalation...Again

A second major Linux privilege escalation vulnerability was disclosed this week, days after Copy Fail, with a working public exploit already circulating. Here's what Dirty Frag means for your organization, in plain terms.

May 10, 2026 9 min read
Apache Double-Free (CVE-2026-23918): Why the possibilities are dangerous
security operations
Apache Double-Free (CVE-2026-23918): Why the possibilities are dangerous

A critical memory corruption flaw in Apache HTTP Server's HTTP/2 implementation allows remote attackers to crash or fully compromise any server running version 2.4.66.

May 5, 2026 11 min read
Copy Fail (CVE-2026-31431): What It Is, Who It Affects, and What To Do Right Now
threat intelligence
Copy Fail (CVE-2026-31431): What It Is, Who It Affects, and What To Do Right Now

A newly disclosed Linux vulnerability lets any local user become root in under a second — no hacking experience required. Here's what that means for your organization, in plain terms.

May 3, 2026 8 min read
crowdsoc news
Welcome to the NEW CrowdSOC Blog

Introducing the updated CrowdSOC blog — where we share threat intelligence insights, security operations best practices, and platform updates for the organizations we protect.

May 3, 2026 1 min read
threat intelligence
why small business is the new frontline in ransomware campaigns

Ransomware groups have refined their targeting strategy. Smaller organizations with thinner security coverage and higher urgency to restore operations are increasingly in scope. Here is what the data shows and what you can do about it.

January 15, 2025 8 min read
policy & compliance
NIST CSF 2.0 — what changed and what it means for local government

The updated Cybersecurity Framework brings new governance functions and an expanded scope. We break down the practical implications for county and municipal IT teams who need to do more with less.

December 10, 2024 6 min read
best practices
the five security controls that protect against 85% of attacks

Comprehensive security feels overwhelming when you're short on budget and staff. The data is clear that focused foundational controls provide outsized protection. Start here.

November 12, 2024 5 min read
incident response
the first 24 hours: what to do when you think you've been breached

The decisions made in the first few hours of an incident have an outsized impact on outcome. A practical, step-by-step guide for non-security teams facing a possible breach.

October 8, 2024 7 min read
threat intelligence
the ransomware-as-a-service economy — how attackers have industrialized

Understanding the business model behind modern ransomware groups helps organizations understand how they think about targeting — and how to make themselves a less attractive target.

September 17, 2024 9 min read
best practices
cybersecurity on a public sector budget — a practical guide

Free tools, federal programs, and prioritization strategies for county and local government IT teams working to improve security posture without meaningful budget increases.

August 20, 2024 8 min read
compliance
what cybersecurity insurance actually requires — and what it doesn't tell you

Insurance questionnaires are becoming de facto security frameworks for small businesses. Understanding what's really being asked — and what a policy will and won't cover — matters.

July 9, 2024 6 min read