US federal agencies have until Sunday to patch CVE-2026-41940, a critical cPanel/WHM vulnerability already under active exploitation. Rapid7 warns successful compromise can hand attackers control of the cPanel host, its configs and databases, and all managed websites—reports of takeovers and extortion have already surfaced. Organizations should patch immediately, restrict admin interfaces, and review logs for unauthorized access.
Source: Recorded Future News
‘Copy Fail’ Linux flaw enables easy local root on systems built since 2017
A newly disclosed Linux kernel bug, CVE-2026-31431 (“Copy Fail”), allows local privilege escalation to root across most Linux distributions from the last decade. Researchers and EU officials are urging urgent patching as exploit code and a Metasploit module are already available, dramatically lowering the bar for post-compromise elevation on servers and endpoints.
Source: Recorded Future News
Systemic MCP design issue exposes AI agent servers to command execution
Research finds the Model Context Protocol’s default STDIO transport executes arbitrary OS commands, enabling command injection across AI agent stacks; 7,000 internet-exposed servers were observed with an estimated 200,000 vulnerable instances. Multiple popular tools received CVEs, and while Anthropic characterized the behavior as “expected,” CISOs are advised to treat STDIO as a privileged execution surface, sandbox processes, and audit configs across IDEs and servers.
Source: VentureBeat
US and Five Eyes publish guidance for safely deploying AI agents
New joint guidance from the US and allies warns that AI agents capable of real-world actions are already operating inside critical infrastructure, often with excessive permissions beyond what organizations can monitor or control. The document outlines secure design, least-privilege access, monitoring, and supply chain controls to reduce blast radius and prevent autonomous agents from making unreviewed changes.
Source: CyberScoop
DDoS knocks Ubuntu/Canonical services offline, disrupting updates
Hacktivists claimed responsibility for sustained DDoS attacks that took down several Ubuntu and Canonical web services, impeding users’ ability to fetch updates. Prolonged outages during an active Linux kernel vulnerability cycle raise operational and security risk, underscoring the need for mirrored repos, offline caches, and contingency distribution channels.
Source: TechCrunch
Sleeper Ruby gems and Go modules poison CI for credential theft and persistence
A new software supply chain campaign using the “BufferZoneCorp” GitHub account seeded sleeper packages that later pulled malicious payloads to steal credentials, tamper with GitHub Actions, and establish SSH persistence. The incident highlights growing abuse of developer ecosystems and CI/CD pipelines; defenders should enforce signed dependencies, pin versions, and monitor build logs and tokens.
Source: The Hacker News
SonicWall patches three SonicOS flaws amid fears of fast ransomware exploitation
SonicWall released firmware updates fixing three vulnerabilities affecting Gen 6, 7, and 8 firewalls, with experts warning threat actors may move quickly against unpatched edge devices. Organizations should prioritize upgrades, restrict management plane exposure, and validate that hot spares and HA peers are also remediated.
Source: SC Media
You May Also Be Interested In...
Preparing for a ‘vulnerability patch wave’
Federal zero trust guidelines for OT environments unveiled
Trellix confirms source code breach with unauthorized repo access