Progress warns of critical MOVEit Automation auth bypass flaw
2026-05-04T13:23:33Z•594ab42716e187117cd42f24775dc798f51cb5bcc46da5cd8929bfcb4e21e39c
Android malwareCISACVE-2026-41940ConsentFix v3Copy FailDigiCert false positivesInstructureLinux privilege escalationMFTMOVEit AutomationMicrosoft April 2026 updatesOAuth abuseProgress SoftwareShinyHuntersSorry ransomwareTelegram Mini Appsauthentication bypassbackup failurescPanelpsmounterex.sys
What happened
Multiple high-risk security incidents and vulnerabilities were reported: Progress warned of a critical authentication-bypass bug in MOVEit Automation and urged customers to patch; CISA warned that the newly disclosed “Copy Fail” Linux vulnerability is being exploited in the wild to gain root; a critical cPanel flaw (CVE-2026-41940) is being mass-exploited in "Sorry" ransomware attacks; Microsoft confirmed April 2026 updates are breaking third‑party backups using psmounterex.sys; and attackers are abusing Telegram Mini Apps for crypto scams and Android malware distribution. Other notable items:
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 594ab42716e187117cd42f24775dc798f51cb5bcc46da5cd8929bfcb4e21e39c
- Enrichment time
- 2026-05-04T13:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.