CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (1 May 2026)

Published: Loading…

At a Glance

  • CVE-2026-31431 Copy Fail Linux kernel flaw allows unprivileged users to gain root via page cache manipulation across major distributions since 2017.
  • CVE-2026-41940 cPanel and WHM authentication bypass vulnerability enables remote attackers to gain administrative access and has been actively exploited as a zero-day.
  • Compromised PyPI lightning versions 2.6.2 and 2.6.3 deployed credential-stealing malware that propagates through npm and GitHub repositories in Mini Shai-Hulud attacks.
  • GitHub Enterprise Server vulnerability CVE-2026-3854 allows remote code execution via git push injection, risking full compromise of repositories and internal secrets.
  • Deep#Door Python backdoor uses tunnelling services and evasion techniques to steal browser, cloud, and SSH credentials while maintaining persistent Windows access.

Summary

Critical vulnerabilities affecting widely deployed infrastructure dominated activity, including the Copy Fail Linux kernel flaw CVE-2026-31431 enabling root access through page cache manipulation across distributions. The issue impacts kernels since 2017 and allows container escape scenarios due to shared memory behaviour. A separate cPanel & WHM vulnerability CVE-2026-41940 enables authentication bypass via CRLF injection, granting remote administrative access and seeing active exploitation as a zero-day.

Additional high-impact flaws affected development and enterprise platforms, including GitHub Enterprise Server CVE-2026-3854, which permits remote code execution through crafted git push requests targeting backend systems. Google addressed a critical CVSS 10 vulnerability in Gemini CLI that allowed malicious configuration injection and arbitrary command execution in CI/CD workflows. EnOcean SmartServer vulnerabilities also exposed building management systems to remote code execution and security bypass risks.

Software supply chain attacks expanded significantly through the Mini Shai-Hulud campaign, compromising the PyPI lightning package and propagating across npm and Packagist ecosystems. Malicious versions introduced credential-stealing payloads that spread via dependency chains, including the intercom-client and intercom-php packages used in backend and CI/CD environments. SAP-related npm packages were also targeted, extending the campaign’s reach across enterprise development pipelines.

Malware activity included deployment of the Deep#Door Python backdoor, which establishes persistence on Windows systems and exfiltrates browser, cloud, and SSH credentials using tunnelling services. The Silver Fox group conducted phishing campaigns delivering ValleyRAT and a new ABCDoor backdoor to organisations in India and Russia. EtherRAT campaigns targeted privileged enterprise users by impersonating administrative tools distributed through GitHub-based lures.

Ransomware and data breach incidents affected multiple sectors, with Sandhills Medical disclosing a ransomware attack impacting 170,000 individuals following delayed notification. Moldova’s health insurance agency reported a potential data leak after a cyberattack, while a spyware incident exposed tens of thousands of private smartphone screenshots online. The UK education sector also recorded a sharp increase in cyber breaches over the past year.

Law enforcement actions targeted large-scale cybercrime operations, including dismantling Albanian call centres linked to €50 million investment fraud and arrests of 276 suspects in cryptocurrency scam networks. Authorities also disrupted a campaign involving over 610,000 stolen Roblox accounts monetised through malware distribution and illicit marketplaces. Additional actions included sentencing of a swatting ring leader and ongoing investigations into breaches involving national identity systems.

Highlights of the Day

Linux Copy Fail Flaw Enables Universal Root Privilege Escalation

CVE-2026-31431 is a Linux kernel logic flaw in the authencesn crypto component that allows unprivileged local users to perform a controlled 4-byte page cache overwrite via AF_ALG and splice(). A 732-byte Python exploit modifies setuid binaries in memory without altering on-disk files, enabling root access across major distributions including Ubuntu, RHEL, Amazon Linux, and SUSE. The vulnerability affects kernels shipped since 2017 and can also enable container escapes because the shared page cache allows cross-container manipulation on the same host.

cPanel Authentication Bypass Bug Grants Remote Root Access

CVE-2026-41940 is a critical authentication bypass vulnerability in cPanel & WHM and WP Squared, caused by a CRLF injection flaw in session handling that enables unauthenticated remote attackers to gain administrative access. The issue allows manipulation of the whostmgrsession cookie and injection of arbitrary session properties, such as setting user=root, by writing unsanitised data into session files via crafted requests. The flaw affects versions released after 11.40, with approximately 1.5 million internet-exposed instances potentially vulnerable and active exploitation reported prior to public disclosure.

Source: Rapid7

Malicious PyPI Lightning Package Steals Credentials and Spreads Worm

Attackers compromised the widely used PyPI lightning package by publishing versions 2.6.2 and 2.6.3 containing malicious code that executes automatically on import and deploys an obfuscated JavaScript payload. The malware harvests credentials including GitHub, npm, and cloud tokens, abuses GitHub APIs to inject backdoors into repositories, and modifies local npm packages to propagate via postinstall scripts. Evidence suggests a compromised maintainer account enabled the attack, with suspicious GitHub activity and attempted lateral movement across related repositories observed during the incident.

Source: Socket

Malicious Intercom PHP Package Spreads Mini Shai-Hulud Attack

Attackers compromised the intercom/intercom-php package on Packagist by altering version 5.0.2 to include a Composer plugin that executes a malicious script during installation and downloads an obfuscated credential-stealing payload. The malware harvests secrets including GitHub, npm, cloud, Kubernetes, and Vault credentials, encrypts the data, and exfiltrates it to a remote endpoint or via abused GitHub repositories. The incident is linked to a broader Mini Shai-Hulud campaign spanning PyPI and npm ecosystems, with the compromise traced to a transitive dependency chain involving the lightning package.

Source: Socket

Deep#Door Python Backdoor Enables Stealthy Credential Theft

Securonix analysed a Python-based backdoor named Deep#Door delivered via an obfuscated batch script that disables Windows security controls, extracts an embedded payload, and establishes persistence through registry keys, startup scripts, scheduled tasks, and WMI subscriptions. The malware uses a public tunnelling service (bore.pub) for command-and-control, enabling remote execution, keylogging, screenshot capture, webcam and microphone access, and theft of browser, cloud, and SSH credentials. It incorporates defence evasion techniques including AMSI and ETW patching, sandbox detection, log clearing, and in-memory execution, allowing long-term surveillance and data exfiltration from compromised Windows systems.

Source: Securonix

Daily Coverage

Developments
Copy Fail FlawCpanel Zero-DayLightning CompromiseGithub Rce
Vulnerabilities
CVE-2026-41940Cpanel 11.110.0 (Critical)CVE-2026-31431Linux 72548B093Ee38A6D4F2A19E6Ef1948Ae05C181F7 (High)CVE-2026-3854CVE-2026-41265Flowise < 3.1.0 (Critical)