News Grower

Independent coverage of AI, startups, and technology.

Ars Technica Apr 30, 2026 at 20:20 Big Tech Stable Warm

The most severe Linux threat to surface in years catches the world flat-footed

CopyFail threatens multi-tenant servers, CI/CD work flows, Kubernetes containers, and more.

Signal weather

Stable

The story has moved beyond the first headline and now acts as a reliable context anchor.

By Dan Goodin Original source
The most severe Linux threat to surface in years catches the world flat-footed

Publicly released exploit code for an effectively unpatched vulnerability that gives root access to virtually all releases of Linux is setting off alarm bells as defenders scramble to ward off severe compromises inside data centers and on personal devices. The vulnerability and exploit code that exploits it were released Wednesday evening by researchers from security firm Theori, five weeks after privately disclosing it to the Linux kernel security team. The team patched the vulnerability in versions 7.0, 6.19.12, 6.18.12, 6.12.85, 6.6.137, 6.1.170, 5.15.204, and 5.10.254) but few of the Linux distributions had incorporated those fixes at the time the exploit was released. A single script hacks all distros The critical flaw, tracked as CVE-2026-31431 and the name CopyFail, is a local privilege escalation, a vulnerability class that allows unprivileged users to elevate themselves to administrators. CopyFail is particularly severe because it can be exploited with a single piece of exploit code—released in Wednesday’s disclosure—that works across all vulnerable distributions with no modification. With that, an attacker can, among other things, hack multi-tenant systems, break out of containers based on Kubernetes or other frameworks, and create malicious pull requests that pipe the exploit code through CI/CD work flows. Read full article Comments

Stay on the signal

Follow The most severe Linux threat to surface in years catches the world flat-footed

Follow this story beyond a single article: new follow-ups, adjacent sources, and the evolving storyline.

We send a confirmation link first, then only meaningful digests.

Story map

Understand this topic fast

A quick entry into the story: why it matters now, who is involved, and where to go next for context.

Why it matters now

This story is still moving and pulling follow-up coverage.
There are already 6 connected articles in the same storyline to continue from here.
The story keeps orbiting around Ars Technica, Containers, and Copyfail, so the entity pages are the fastest way to build context.
Ars Technica already has 4 follow-up stories on the same theme.

Topic constellation

Open the live map for this story

See which entities, story threads, sources, and follow-up articles shape this story right now.

Click nodes to continue

Entity Cluster Article Hub Source

Story timeline

Continue with this story

A short sequence of events and follow-up stories to understand the arc quickly.

Jun 14, 2026 at 16:02 Ars Technica

Did a medieval flying monk spot Halley's comet, twice? It's complicated

University of Leicester historian thinks Eilmer of Malmesbury saw two different comets: in 1018 and 1066

Jun 14, 2026 at 16:01 Hacker News

Linux 7.1

Comments

Jun 14, 2026 at 05:10 SecurityLab

В Arch Linux нашли вредонос-матрёшку: пакет внутри пакета, а на самом дне — похититель паролей

400 пакетов, одна старая лазейка — и доступ ко всему: от браузера до криптокошельков.

Jun 14, 2026 at 04:03 SecurityLab

MX Linux 25.2 — убежище для тех, кто устал от systemd и теперь ещё и от ИИ на рабочем столе

Новые ядра, починенные MX Tools и возможность выбрать systemd или sysvinit без головной боли...

Jun 13, 2026 at 17:17 Ars Technica

Review: Disclosure Day is big on action, light on ideas

There's nothing new or surprising, but it's still an entertaining film from one of our greatest directors.

Apr 30, 2026 at 20:20 Ars Technica

The most severe Linux threat to surface in years catches the world flat-footed

CopyFail threatens multi-tenant servers, CI/CD work flows, Kubernetes containers, and more.

How reliable this looks

Signal and trust for Ars Technica

This source works at a rapid pace: 100% of recent stories land in the hot window, and 0% carry visible search signal.

Trusted

Reliability

92

Freshness

100

Sources in storyline

3

Related articles

More stories that share tags, source, or category context.

SecurityLab Jun 14, 2026 at 05:10 Cybersecurity
Rising Hot

В Arch Linux нашли вредонос-матрёшку: пакет внутри пакета, а на самом дне — похититель паролей

400 пакетов, одна старая лазейка — и доступ ко всему: от браузера до криптокошельков.

Signal weather

Momentum is building quickly, so this card is a good early entry point into the topic.

Why now

Fresh coverage with immediate momentum.

SecurityLab Jun 14, 2026 at 04:03 Cybersecurity
Rising Hot

MX Linux 25.2 — убежище для тех, кто устал от systemd и теперь ещё и от ИИ на рабочем столе

Новые ядра, починенные MX Tools и возможность выбрать systemd или sysvinit без головной боли...

Signal weather

Momentum is building quickly, so this card is a good early entry point into the topic.

Why now

Fresh coverage with immediate momentum.

More from Ars Technica

Fresh reporting and follow-up coverage from the same newsroom.

Open source page