TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

WIRED

Dangerous New Linux Exploit Gives Attackers Root Access to Countless Computers

Dan Goodin, Ars Technica · 4 days ago · Read original ↗

ATT&CK techniques detected

3 predictions
T1068Exploitation for Privilege Escalation
95%
“dangerous new linux exploit gives attackers root access to countless computers publicly released exploit code for an effectively unpatched vulnerability that gives root access to virtually all releases of linux is setting off alarm bells as defenders scramble to ward off severe c…”
T1068Exploitation for Privilege Escalation
62%
“, and sometimes even on the same machine. because the code released for copyfail exploits a logic flaw, “ reliability isn ’ t probabilistic, and the same script works across distributions, researchers from bugcrowd wrote. “ no race window, no kernel offset. ” copyfail gets its na…”
T1588.006Vulnerabilities
42%
“of those vulnerabilities were actively exploited in the wild. linux distributors frequently stick with older kernel versions and backport fixes into them. there ’ s no indication in the disclosure deadline that theori ever contacted the distributors. with the exploit available be…”

Summary

The exploit, dubbed CopyFail and tracked as CVE-2026-31431, allows hackers to take over PCs and data center servers. The Linux vulnerabilities have been patched—but many machines remain at risk.