Bluekit phishing kit enables automated phishing with 40+ templates and AI tools

2026-05-04T08:51:47Z75cae7c46586266ce87e23797c0828c28688f0b1d7c2dba144bdbcec80a56e02
AI-assistedBluekitCISACVE-2026-41940Deep#DoorGoogleIBMRATSalt TyphoonTrellixbug-bountycPanelcargo-theftcybercrimeknown-exploited-vulnerabilitymalwarenation-statephishingphishing-kitsource-code-breachspoofingsupply-chain-breachvoice-cloning

What happened

This feed highlights multiple high-risk developments: Bluekit, a new phishing kit with an AI assistant, automated domain registration, spoofing and voice‑cloning capabilities and 40+ templates that can streamline large-scale phishing campaigns; a late‑April 2026 breach at IBM Italy subsidiary Sistemi Informativi attributed to Chinese-linked Salt Typhoon, raising supply‑chain and nation‑state intrusion concerns in Europe; the U.S. CISA added a critical cPanel flaw (CVE-2026-41940, CVSS 9.3) to its Known Exploited Vulnerabilities catalog; and several other incidents including Trellix source-code

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
75cae7c46586266ce87e23797c0828c28688f0b1d7c2dba144bdbcec80a56e02
Enrichment time
2026-05-04T08:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Bluekit phishing kit enables automated phishing with 40+ templates and AI tools · Baitaphish