Attackers are cashing in on fresh 'CopyFail' Linux flaw

2026-05-05T19:24:08Z4055027dda7b743b6cd94a7c9b72f84b7f1c01f96fad9b4f105e8fc2284df607
CopyFailagentic-aiai-enabled-phishingcisacpanelcvss-10.0data-leakexploit-in-the-wildfive-eyesgemini-cligithublinux-kernellocal-privilege-escalationnpmopenaipatch-tsunamiphishingpypiransomwareremote-code-executionshinyhunterssupply-chain-attackvishingwhmzero-day

What happened

A large set of active, high-impact incidents and warnings: CISA warns that a newly disclosed Linux kernel bug dubbed “CopyFail” is being exploited in the wild with a released reliable root exploit. A critical cPanel/WHM vulnerability is confirmed as exploited (CISA known-exploited), with emergency patches and at least one ransomware report. Google patched a CVSS 10.0 RCE in Gemini CLI that may break CI/CD workflows. Ongoing supply-chain attacks hit npm/PyPI packages (including SAP/Intercom), and ShinyHunters posted a Vimeo-derived 119K email dump. Other notable items: Cushman & Wakefield vish/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
4055027dda7b743b6cd94a7c9b72f84b7f1c01f96fad9b4f105e8fc2284df607
Enrichment time
2026-05-05T19:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.