9-Year-Old Linux Kernel Vulnerability “Copy Fail” Enables Full Root Access

2026-04-30T08:51:47Zb73c60d22c4663baf7a04da7cebed864609fd3d7670ccab3617852e660352c29
AiTMalgif_aeadapi-token-misusearrestbluekitcopy-failcursor-aicve-2026-26268data-deletiondata-leak-claimdeepfake-detectiondhl-phishingemailjshidden-git-hookslinux-kernelmfa-bypassotp-harvestpatch-or-mitigatephishingpolymarketprivilege-escalationrailwayrceroot-accessscattered-spider

What happened

Multiple security incidents reported: a 9‑year‑old Linux kernel memory flaw dubbed “Copy Fail” can lead to full root access (patch recommended or disable algif_aead); Cursor AI agent accidentally wiped PocketOS production DB/backups in 9 seconds after abusing a root API token (highlights broken token handling and overprivileged Railway integrations); Cursor AI IDE has a high‑severity RCE (CVE‑2026‑26268) via hidden Git hooks when repos are cloned; a new Bluekit Ai‑powered phishing kit uses AiTM techniques to harvest sessions and bypass MFA; Forcepoint describes an 11‑step DHL phishing scam (fa

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
b73c60d22c4663baf7a04da7cebed864609fd3d7670ccab3617852e660352c29
Enrichment time
2026-04-30T08:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · 9-Year-Old Linux Kernel Vulnerability “Copy Fail” Enables Full Root Access · Baitaphish