New Bluekit phishing service includes an AI assistant, 40 templates

2026-05-01T01:23:33Zc37572491157c3bd87dfcff06dd0298cc902d0b11583d9e48bd96d3da867944b
AI-assistantBluekitCVE-2026-41940Copy-FailFBIKB5083769LinuxOAuth-vulnerabilityQinglongRCESAPWHMWindows-11WordPress-backdoorbackup-failurecPanelcargo-theftcrypto-fraudlocal-privilege-escalationnpmphishingphishing-kitrobloxsupply-chainzero-day

What happened

A batch of Bleeping Computer reports highlights multiple high-impact threats and incidents: a new Bluekit phishing service bundles an AI assistant and 40+ templates for credential theft; a critical cPanel/WHM authentication-bypass (CVE-2026-41940) is being actively exploited with PoCs and prompted an emergency update; a widespread Linux local privilege-escalation dubbed “Copy Fail” (affecting kernels since 2017) now has a published exploit enabling local root; and Qinglong task-scheduler auth bypass/RCE flaws are being used to deploy cryptominers. Additional notable stories include official‑s‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
c37572491157c3bd87dfcff06dd0298cc902d0b11583d9e48bd96d3da867944b
Enrichment time
2026-05-01T01:23:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.