Bluekit phishing kit enables automated phishing with 40+ templates and AI tools
2026-05-04T08:51:47Z•75cae7c46586266ce87e23797c0828c28688f0b1d7c2dba144bdbcec80a56e02
AI-assistedBluekitCISACVE-2026-41940Deep#DoorGoogleIBMRATSalt TyphoonTrellixbug-bountycPanelcargo-theftcybercrimeknown-exploited-vulnerabilitymalwarenation-statephishingphishing-kitsource-code-breachspoofingsupply-chain-breachvoice-cloning
What happened
This feed highlights multiple high-risk developments: Bluekit, a new phishing kit with an AI assistant, automated domain registration, spoofing and voice‑cloning capabilities and 40+ templates that can streamline large-scale phishing campaigns; a late‑April 2026 breach at IBM Italy subsidiary Sistemi Informativi attributed to Chinese-linked Salt Typhoon, raising supply‑chain and nation‑state intrusion concerns in Europe; the U.S. CISA added a critical cPanel flaw (CVE-2026-41940, CVSS 9.3) to its Known Exploited Vulnerabilities catalog; and several other incidents including Trellix source-code
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 75cae7c46586266ce87e23797c0828c28688f0b1d7c2dba144bdbcec80a56e02
- Enrichment time
- 2026-05-04T08:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.