A critical local privilege escalation vulnerability dubbed “Copy Fail” (CVE-2026-31431) has been discovered in the Linux kernel’s cryptographic subsystem. Currently, a highly reliable public proof-of-concept exploit is actively circulating, allowing unprivileged users to gain root access on almost all major Linux distributions released since 2017.
Vulnerability Details
Affected Product: Linux Kernel (Ubuntu, Amazon Linux, RHEL, SUSE) built since 2017
Identifier: CVE-2026-31431
CVSS Score: 7.8 (High)
Exploitation Status: Public PoC Available / Actively Exploited
Risk & Impact
Triage: Critical urgency for multi-tenant environments, shared-kernel containers, and CI/CD runners.
Attack Vector: An unprivileged local user chains an AF_ALG socket operation with splice() to perform a controlled 4-byte write into the page cache of a setuid binary.
Ease of Exploit: Highly reliable and deterministic; requires no race conditions or per-kernel offsets.
Action Plan
Immediate Action: Apply vendor kernel updates immediately as they become available (mainline fix committed April 1, 2026).
Workaround: Disable the algif_aead kernel module to block exploitation.
Detection: Monitor for anomalous AF_ALG socket activity and unexpected in-memory modifications to setuid binaries.
Relevant professional terms
Local Privilege Escalation (LPE)
An attack technique where a user with limited access rights exploits a vulnerability to gain higher-level permissions, such as root or administrator access, on a system they already have access to.
Page Cache
A component of the operating system’s memory management that stores copies of data from disk in RAM to speed up subsequent read and write operations.
cPanel has released emergency updates to address CVE-2026-41940, a critical zero-day authentication bypass vulnerability in cPanel, WHM, and WP Squared that allows unauthenticated remote attackers to gain root administrative access. The flaw is currently actively exploited in the wild, with targeted attacks observed since late February 2026.
Vulnerability Details
Affected Product: cPanel & WHM (versions after 11.40, prior to patched builds like 11.136.0.5) and WP Squared (prior to 136.1.7)
Identifier: CVE-2026-41940
CVSS Score: 9.8 (Critical)
Exploitation Status: Actively Exploited
Risk & Impact
Triage: Immediate patching is required due to the risk of full server and hosted website compromise.
Attack Vector: Unauthenticated remote attackers inject Carriage Return Line Feed (CRLF) characters into a malicious basic authorization header, manipulating the session cookie to write arbitrary properties (e.g., user=root) into the pre-authentication session file.
Ease of Exploit: Low complexity; requires no privileges or user interaction, and a Proof-of-Concept (PoC) is publicly available.
Action Plan
Immediate Action: Upgrade cPanel & WHM to patched builds (e.g., Version 11.136.0.5, 11.134.0.20, etc.) and WP Squared to Version 136.1.7.
Workaround: Restrict access to cPanel/WHM management ports (2082, 2083, 2086, 2087, 2095, 2096) to trusted IP ranges via firewall rules.
Detection: Review authentication logs for anomalous session file creation or CRLF injection attempts, and utilize the cPanel-provided detection script or Nuclei templates to hunt for vulnerable instances.
Relevant professional terms
CRLF Injection
A software vulnerability that occurs when an attacker injects a Carriage Return (CR) and Line Feed (LF) character sequence into an HTTP stream, allowing them to manipulate headers, logs, or session files.
Zero-Day Vulnerability
A software flaw that is exploited by attackers before the vendor has become aware of it or released a patch to fix it.
The Quick Page/Post Redirect plugin, installed on over 70,000 WordPress sites, contains a dormant backdoor introduced five years ago that allows for arbitrary code injection. Currently, no CVE-ID has been assigned to this supply chain compromise, but its status remains a significant threat due to a hidden self-update mechanism.
An AI-powered security analysis uncovered 38 previously undisclosed vulnerabilities in the OpenEMR electronic health record platform, including maximum-severity zero-days such as CVE-2026-24908 and CVE-2026-24898. These critical flaws, which could lead to full database compromise and remote code execution, are currently patched by the vendor.
Vulnerability Details
Affected Product: OpenEMR versions prior to 8.0.0
Identifier: CVE-2026-24908, CVE-2026-24898, CVE-2026-23627 (among 38 total CVEs)
CVSS Score: 10.0 (Critical)
Exploitation Status: Patched (Discovered via AI audit; no active exploitation reported)
Risk & Impact
Triage: Critical - Immediate patching is required for all internet-facing instances to protect sensitive patient health information (PHI).
Attack Vector: Unauthenticated attackers can exploit REST API endpoints via SQL injection and missing authorization checks to access patient data or execute arbitrary code.
Ease of Exploit: High - No authentication or login credentials are required to exploit the maximum severity flaws.
Action Plan
Immediate Action: Upgrade to OpenEMR Version 8.0.0 and apply all subsequent security patches released in March 2026.
Workaround: Restrict public internet access to the OpenEMR instance and place it behind a secure Virtual Private Network (VPN) or Web Application Firewall (WAF).
Detection: Monitor web access logs for anomalous POST requests to the MedEx recall/reminder endpoint and unusual SQL syntax in the _sort query parameter.
Relevant professional terms
Remote Code Execution (RCE)
A severe vulnerability that allows an attacker to execute arbitrary commands or malicious code on a target machine or server over a network.
SQL Injection (SQLi)
A common attack vector that uses malicious SQL code for backend database manipulation to access, modify, or delete information that was not intended to be displayed.
Threat actor TeamPCP compromised official SAP npm packages in a supply chain attack dubbed “Mini Shai Hulud.” The campaign targets developers and CI/CD pipelines to harvest cloud credentials, GitHub tokens, and browser passwords.
Key TTPs
Initial Access: Malicious preinstall scripts injected into legitimate SAP npm packages.
Execution: Downloads the Bun JavaScript runtime to execute an obfuscated payload.
Defense Evasion: Terminates execution if Russian locale settings are detected.
Campaign Analysis
This campaign marks an evolution for TeamPCP, introducing browser credential theft and weaponizing AI coding agents. It leverages victim-owned GitHub repositories as its primary exfiltration channel.
Targeting & Infrastructure
Target Profile: SAP developers, CI/CD environments, and cloud infrastructure.
Infrastructure: Exfiltrates encrypted secrets to newly created public GitHub repositories on victims’ accounts.
US Cyber-Sabotage Framework Corrupts Iranian Engineering
Executive Summary
Discovered by SentinelOne, Fast16 is a 2005 state-sponsored cyber-sabotage framework linked to the US. Predating Stuxnet, it was designed to silently corrupt high-precision engineering calculations in Iranian nuclear research facilities.
Key TTPs
Initial Access: Self-propagating network worm exploiting weak admin passwords on Windows file shares.
Execution: Utilizes an embedded Lua 5.0 virtual machine to deploy a malicious kernel driver.
Defense Evasion: Employs environmental awareness checks to avoid security software and operates as a rootkit to intercept filesystem I/O.
Campaign Analysis
Fast16 represents a paradigm shift in cyber warfare, moving from espionage to strategic physical sabotage. By subtly altering floating-point arithmetic in simulation software, it aimed to cause catastrophic real-world engineering failures.
Targeting & Infrastructure
Target Profile: Iranian nuclear research programs utilizing high-precision simulation suites like LS-DYNA.
Infrastructure: Deployed as a carrier module capable of delivering multiple payloads across targeted Windows 2000/XP networks.
Relevant Terms
Rootkit: Malicious software designed to gain unauthorized, highly privileged access to a system while hiding its presence.
Lua Virtual Machine: A lightweight, embeddable scripting engine used to execute the malware’s core logic dynamically within a host process.
A threat actor compromised Huge Networks, a Brazilian DDoS mitigation firm, to orchestrate a massive botnet. The attackers leveraged the firm’s infrastructure to launch sustained DDoS attacks against regional ISPs.
Key TTPs
Initial Access: Mass-scanning for insecure routers and unmanaged DNS servers, alongside exploiting exposed SSH keys.
Execution: Deployment of Portuguese-language malicious scripts written in Python.
Defense Evasion: Hijacking a legitimate DDoS mitigation provider’s infrastructure to mask malicious traffic.
Campaign Analysis
This ironic supply-chain abuse allowed attackers to launch digital sieges using the very infrastructure designed to protect networks. The threat actor maintained root access to build a highly disruptive regional botnet.
Targeting & Infrastructure
Target Profile: Brazilian Internet Service Providers (ISPs) and network operators.
Infrastructure: Botnet built from compromised routers and unmanaged DNS servers, orchestrated via root access to Huge Networks.
Relevant Terms
DDoS: A malicious attempt to disrupt normal traffic of a targeted network by overwhelming it with a flood of data.
DNS Reflection: An amplification attack technique where attackers spoof a target’s IP and send requests to open DNS servers, causing massive responses.