New Bluekit phishing service includes an AI assistant, 40 templates

2026-04-30T19:23:34Za7f6936b55323d9ced379ef4ed4844f13da32989c21deb17c01744ecdaf68876
AI-assistantCVE-2026-41940Copy-FailFBIKB5083769LinuxQinglongRCESAPTeamPCPWHMWindows-11WordPressbackdoorbackup-failurecPanelcargo-theftcrypto-fraudcryptomininglocal-privilege-escalationnpmphishingphishing-kitsupply-chainzero-day

What happened

Multiple high-impact threats and active exploits were reported: a new Bluekit phishing-as-a-service with an AI assistant and 40+ templates; a critical cPanel/WHM authentication-bypass actively exploited in the wild (CVE-2026-41940) with emergency updates available; a published exploit for a Linux local privilege-escalation (“Copy Fail”) that can yield root on many distributions; Qinglong task-scheduler authentication-bypass RCE used to deploy cryptominers; and an April Windows 11 update (KB5083769) causing third-party backup failures. In addition, supply-chain attacks and backdoors were found—

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
a7f6936b55323d9ced379ef4ed4844f13da32989c21deb17c01744ecdaf68876
Enrichment time
2026-04-30T19:23:34Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.