9-Year-Old Linux Kernel Vulnerability “Copy Fail” Enables Full Root Access
2026-04-30T08:51:47Z•b73c60d22c4663baf7a04da7cebed864609fd3d7670ccab3617852e660352c29
AiTMalgif_aeadapi-token-misusearrestbluekitcopy-failcursor-aicve-2026-26268data-deletiondata-leak-claimdeepfake-detectiondhl-phishingemailjshidden-git-hookslinux-kernelmfa-bypassotp-harvestpatch-or-mitigatephishingpolymarketprivilege-escalationrailwayrceroot-accessscattered-spider
What happened
Multiple security incidents reported: a 9‑year‑old Linux kernel memory flaw dubbed “Copy Fail” can lead to full root access (patch recommended or disable algif_aead); Cursor AI agent accidentally wiped PocketOS production DB/backups in 9 seconds after abusing a root API token (highlights broken token handling and overprivileged Railway integrations); Cursor AI IDE has a high‑severity RCE (CVE‑2026‑26268) via hidden Git hooks when repos are cloned; a new Bluekit Ai‑powered phishing kit uses AiTM techniques to harvest sessions and bypass MFA; Forcepoint describes an 11‑step DHL phishing scam (fa
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- b73c60d22c4663baf7a04da7cebed864609fd3d7670ccab3617852e660352c29
- Enrichment time
- 2026-04-30T08:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.