New Bluekit phishing service includes an AI assistant, 40 templates

2026-05-01T07:23:32Z7edf5a83f76983e7b7a7f62ce52faf20ae12f10ae641cf5f2b9885c3b160c0ca
ai-assistantauthentication-bypasscargo-theftcpanelcredential-theftcryptomininglinux-lpelocal-privilege-escalationnpm-compromiseoauth-sprawlphishing-kitproof-of-conceptremote-code-executionsupply-chainswattingwindows-update-issuewordpress-backdoorzero-day

What happened

Multiple high-impact threats reported: a new Bluekit phishing-as-a-service offers >40 templates and an AI assistant to speed campaign creation; a critical authentication-bypass in cPanel/WHM (CVE-2026-41940) is being actively exploited with PoC available and emergency updates issued; a widespread Linux local privilege escalation (‘Copy Fail’) allows unprivileged users to gain root on kernels since 2017 (exploit published); Qinglong task scheduler authentication-bypass/RCE is being abused to deploy cryptominers; official SAP npm packages were trojanized (TeamPCP supply-chain credential theft);

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
7edf5a83f76983e7b7a7f62ce52faf20ae12f10ae641cf5f2b9885c3b160c0ca
Enrichment time
2026-05-01T07:23:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.