New Bluekit phishing service includes an AI assistant, 40 templates
2026-04-30T19:23:34Z•a7f6936b55323d9ced379ef4ed4844f13da32989c21deb17c01744ecdaf68876
AI-assistantCVE-2026-41940Copy-FailFBIKB5083769LinuxQinglongRCESAPTeamPCPWHMWindows-11WordPressbackdoorbackup-failurecPanelcargo-theftcrypto-fraudcryptomininglocal-privilege-escalationnpmphishingphishing-kitsupply-chainzero-day
What happened
Multiple high-impact threats and active exploits were reported: a new Bluekit phishing-as-a-service with an AI assistant and 40+ templates; a critical cPanel/WHM authentication-bypass actively exploited in the wild (CVE-2026-41940) with emergency updates available; a published exploit for a Linux local privilege-escalation (“Copy Fail”) that can yield root on many distributions; Qinglong task-scheduler authentication-bypass RCE used to deploy cryptominers; and an April Windows 11 update (KB5083769) causing third-party backup failures. In addition, supply-chain attacks and backdoors were found—
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- a7f6936b55323d9ced379ef4ed4844f13da32989c21deb17c01744ecdaf68876
- Enrichment time
- 2026-04-30T19:23:34Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.