Connect with us

Tech

US government warns of severe CopyFail bug affecting major versions of Linux

A severe security vulnerability affecting almost every version of the Linux operating system has caught defenders off-guard and scrambling to patch after security researchers publicly released exploit code that allows attackers to take complete control of vulnerable systems.

The U.S. government says the bug, dubbed “CopyFail,” is now being exploited in the wild, meaning it’s being actively used in malicious hacking campaigns.

The bug, officially tracked as CVE-2026-31431 and discovered in Linux kernel versions 7.0 and earlier, was disclosed to the Linux kernel security team in late March, and patched after about a week. But the patches have yet to fully trickle down to the many Linux distributions that rely on the vulnerable kernel, leaving any system running an affected Linux version at risk of compromise.

Linux is widely used in enterprise settings, running the computers that operate much of the world’s data centers. 

The CopyFail website says that the same short Python script “roots every Linux distribution shipped since 2017.” According to security firm Theori, which discovered CopyFail, the vulnerability was verified in several widely used versions of Linux including Red Hat Enterprise Linux 10.1, Ubuntu 24.04 (LTS), Amazon Linux 2023, as well as SUSE 16. 

DevOps engineer and developer Jorijn Schrijvershof wrote in a blog post that the exploit works on Debian and Fedora versions, as well as Kubernetes, which relies on the Linux kernel. Schrijvershof described the bug as having an “unusually big blast radius” as it works on “nearly every modern distribution” of Linux.

The bug is called CopyFail because the affected component in the Linux kernel, the core of the operating system that has virtually complete access to the entire device, does not copy certain data when it should. This corrupts sensitive data within the kernel, allowing the attacker to piggyback the kernel’s access to the rest of the system, including its data.

If exploited, the bug is particularly problematic because it allows a regular, limited-access user to gain full-administrator access on an affected Linux system. A successful compromise of a server in a data center could allow an attacker to gain access to every application, server, and database of numerous corporate customers, and potentially gain access to other systems on the same network or data center.

The CopyFail bug cannot be exploited over the internet on its own, but can be weaponized if used in conjunction with an exploit that works over the internet. Per Microsoft, if the CopyFail bug is chained together with another vulnerability that can be delivered over the internet, an attacker could use the flaw to gain root access to an affected server. A user operating a Linux computer with a vulnerable kernel could also be tricked into opening a malicious link or attachment that triggers the vulnerability.

The bug could also be injected by way of supply chain attacks, in which malicious actors hack into an open source developer’s account and plant the malware in their code in order to compromise a large number of devices in one go.

Given the risk to the federal enterprise network, U.S. cybersecurity agency CISA has ordered all civilian federal agencies to patch any affected systems by May 15.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

source

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Tech

Lucid Motors doesn’t know how many EVs it will build this year

Lucid Motors said Tuesday that it’s no longer sure how many EVs it will build or sell this year, as it navigates a transition to a new CEO and a company-wide cost-cutting push.

The company said in February that it planned to build between 25,000 and 27,000 vehicles this year. That’s far from the hundreds of thousands of vehicles that Lucid Motors estimated it would build and sell this year when it went public back in 2021. But it would have represented a significant bump from last year’s figure of around 18,000.

The change to Lucid’s guidance was announced during the company’s first-quarter earnings call by chief financial officer Taoufiq Boussaid. It comes just a few months after the company laid off 12% of its workforce, which TechCrunch first reported in February. Lucid Motors said in a filing Tuesday that those layoffs will cost the company around $40 million in the near term, though it believes the cuts will ultimately save as much as $500 million over the next few years.

Boussaid said the decision to pull Lucid Motors’ guidance for the year was a “governance decision,” and that incoming CEO Silvio Napoli is conducting a review of the business. Boussaid said Lucid Motors expects to provide a “full updated outlook” during the second-quarter earnings call in a few months.

“It’s clear that realizing Lucid’s full potential will require sharper focus and consistent execution, particularly around simplification, prioritization and speed,” Napoli said during the call.

Lucid Motors also shared Tuesday that it had a worse-than-expected first quarter, largely due to a production disruption and a temporary stop-sale that affected Gravity SUV deliveries for 29 days due to problems with a seat supplier.

These problems wound up inflating Lucid Motors’ inventory, and the company said it will have to carefully manage production volume in the near term in order to reduce that glut.

Techcrunch event

San Francisco, CA
|
October 13-15, 2026

“We are not constrained on capacity. We are constrained by our own discipline not to build inventory ahead of demand. As market conditions develop, we will scale production accordingly,” Boussaid said.

This all comes as Lucid Motors is supposed to start building its first high-volume vehicle this year, priced at under $50,000. The company has said it would begin producing the first EV on this mid-size platform by the end of 2026. On Tuesday, the company kept the focus on next year, saying it “remain[s] on track for production ramp-up of the mid size in 2027.”

Lucid Motors is also planning to launch a robotaxi service with Uber and Nuro by the end of this year, using autonomous versions of its Gravity SUV. Lucid confirmed Tuesday that it remains on track to start building the road-ready versions of those vehicles in the fourth quarter.

Update: This article was updated to clarify that deliveries were disrupted for 29 days.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

source

Continue Reading

Tech

Altara secures $7M to bridge the data gap that’s slowing down physical sciences

Companies working on batteries, semiconductors, and medical devices generate vast amounts of data — and much of it ends up scattered across spreadsheets and legacy systems, making it hard to use to improve products or understand failures.

San Francisco-based startup Altara, which just secured $7 million in seed funding, says it has built an AI layer designed to bridge these data gaps and bring fragmented technical information into a single platform. The round was led by Greylock, with participation from Neo, BoxGroup, Liquid 2 Ventures, and Jeff Dean.

Altara was founded in 2025 by Eva Tuecke (pictured right), who previously conducted particle physics research at Fermilab and worked at SpaceX; and Catherine Yeo (pictured left), a former AI engineer at Warp. The two met while studying computer science at Harvard University.

“Imagine if you’re a company building next-generation batteries, and a battery fails during the cell testing in the R&D process,” Yeo said. “A team of engineers has to go in and manually check a lot of different sources of data, anything from their sensor logs to their temperature data, moisture data. They cross-check historical failure reports.”

Scientists and engineers often spend weeks or months on this “scavenger hunt” across a multitude of data sources just to diagnose and resolve failures, she said.

Altara claims that its AI dramatically slashes the time required for this process, condensing weeks of manual data triaging into minutes.

Corinne Riley, a partner at Greylock, compares what Altara is doing in the physical sciences to the role of site reliability engineers in the software world. If a system fails, “an SRE will go in, and they’ll go look at the observability stack of the company,” she said. “Someone pushed a change to the code, and that’s what caused an outage.”

Techcrunch event

San Francisco, CA
|
October 13-15, 2026

For instance, Greylock-backed Resolve, which is valued at $1.5 billion, uses AI to diagnose software failures. Altara’s vision is to act as the hardware equivalent, determining exactly what went wrong when a battery or a semiconductor fails to perform.

Altara isn’t the only startup using AI to accelerate development in the physical sciences. Startups like Periodic Labs and Radical AI are also tackling scientific research from the ground up. 

Altara is taking a different, much less capital-intensive approach though. Rather than trying to replace decades-old research and manufacturing firms, Altara provides an intelligence layer that plugs into their existing data.

In fact, Greylock’s Riley views AI for physical science as the “next big frontier” and predicts an impending explosion of development in the sector.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

source

Continue Reading

Tech

Bumble’s paying users are slipping as it bets on an overhaul later this year

As Bumble gets ready for a big overhaul meant to win back Gen Z users (who are pretty over dating apps right now), its latest earnings still reports that paying users are declining. In the first quarter of 2026, total paying users fell 21.1% to 3.2 million, down from 4 million a year ago. 

This has been the story for a few quarters now. However, during the call to investors this afternoon, Bumble has framed this as a deliberate shift toward higher-quality, more intentional users.

So while total revenue dropped 14.1% to $212.4 million (though it did beat expectations), and Bumble app revenue fell to $172.7 million, its total average revenue per paying user increased nearly 9%. It also reported higher profits: Net earnings increased to $52.6 million compared to $19.8 million in the year-ago quarter (largely from cutting sales and marketing expenses).

On the company’s investor call, founder and CEO Whitney Wolfe Herd described the paid-user decline as part of an intentional reset. “This is a period of real transformation at Bumble over the past few quarters,” she said. “We have executed a deliberate reset of our member base. We made a clear choice to prioritize quality over quantity, focusing on well-intentioned, engaged members. That decision reduced overall scale, but meaningfully improved the health of our ecosystem.”

Still, even with that framing, a shrinking paying user base is hard to ignore. That’s why much of the conversation on the call was more about what comes next. Bumble is asking investors to look ahead to its massive overhaul, which it hopes will eventually reverse the trend.

“When do we start to see a rebound in the numbers you’re all looking for? Well, the answer is very simple. When our technology and our next-gen recommendation engine can actually help better connect people more compatibly and show people who they want to see and out on great dates. That’s where the magic happens,” Herd said.

The overhaul refers to replacing Bumble’s old technology platform with a cloud-native, AI-powered one so it can improve matches and roll out updates more quickly. This is already starting to roll out to some users and will expand over the next few months.

Techcrunch event

San Francisco, CA
|
October 13-15, 2026

The more noticeable changes, though, are coming later. Bumble said on Tuesday that its full “reimagined” experience for members is now expected to launch in Q4, with a broader rollout continuing into late this year and early next year. That’s a bit later than earlier expectations and shows this is going to be more of a phased rollout than a single big relaunch.

And the changes themselves sound pretty significant. The company is making a big bet that the swiping model is outdated and most matches never turn into actual dates. The company wants to fix that by redesigning profiles, changing how people interact, and focusing a lot more on getting users to meet in real life.

AI is a huge part of that plan. Earlier this year, Bumble introduced something called “Bee,” a built-in matchmaker that learns daters’ preferences, relationship goals, and communication style, then suggests matches based on those factors. In a feature called “Dates,” Bee may even explain why two people are a good fit before they connect. 

Profiles are changing too. Bumble has been experimenting with more detailed, “chapter-style” profiles that go beyond just photos and a short bio. 

Additionally, Bumble is seeing some momentum outside of dating. Its friend-focused app, Bumble BFF, added a Groups tab last year where users can join chats, plan hangouts, and organize events. According to Herd, engagement there is growing, especially among Gen Z women. Group joins nearly doubled between December and March, the company touts. 

For now, Bumble is kind of in wait-and-see mode. The hope is that by fixing how people go from matching to actually going on dates, it can bring users back. But until that new experience is fully out there, it’s still just a bet.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

source

Continue Reading