A Dozen Allied Agencies Say China Is Building Covert Hacker Networks Out of Everyday Routers

A coalition of U.S. and international government agencies has issued a warning about a significant shift in Chinese hacker tactics, highlighting the use of large-scale covert networks composed of compromised everyday routers and Internet of Things devices to conduct cyberattacks. These networks enable malicious activities such as reconnaissance, malware delivery, and espionage while disguising attackers' origins, prompting recommendations for organizations, especially large and critical infrastructure entities, to adopt enhanced cybersecurity measures and active threat hunting.

https://cyberscoop.com/china-nexus-covert-networks-advisory/

Phishing — Sometimes with AI’s Help — Topped Initial-Access Methods in Q1, Cisco Says

In the first quarter of 2026, phishing—sometimes aided by AI tools like the Softr platform—was the most common method hackers used to gain initial access, according to Cisco’s Talos threat intelligence report. Attackers leveraged AI to quickly create fake login pages for credential harvesting without coding, targeting mainly government and health-care sectors, with deficient multifactor authentication being the leading security weakness exploited.

https://www.cybersecuritydive.com/news/phishing-initial-access-ai-cisco/818185/

We Found a Stable Firefox Identifier Linking All Your Private Tor Identities

Researchers discovered a privacy vulnerability in Firefox-based browsers whereby the order of IndexedDB databases returned by the indexedDB.databases() API serves as a stable, process-scoped identifier. This allows unrelated websites to link user activity across origins and defeats privacy features in Firefox Private Browsing and Tor Browser, including Tor's “New Identity” function, by exposing a deterministic fingerprint until the browser process restarts. Mozilla has released a fix that canonicalizes the database order to eliminate this leakage and restore expected privacy guarantees.

https://fingerprint.com/blog/firefox-tor-indexeddb-privacy-vulnerability/

“Hackers Can Now Launch Massive 2Tbps Attacks”: Report Reveals Staggering 10x Growth in Botnet Size with Record-Breaking DDoS Incidents Peaking for 40 Minutes as Multi-Vector Attacks Grow in Complexity and Become Harder to Dismantle

Security researchers report a massive 10-fold growth in the size of the largest botnet, which expanded from 1.33 million to 13.5 million infected devices within a year, enabling hackers to launch unprecedented sustained DDoS attacks exceeding 2 Tbps and lasting over 40 minutes. These increasingly complex multi-vector attacks, often commanded via blockchain-based systems, pose greater challenges for mitigation as traffic now originates worldwide, rendering traditional defenses less effective.

https://www.techradar.com/pro/hackers-can-now-launch-massive-2tbps-attacks-report-reveals-staggering-10x-growth-in-botnet-size-with-record-breaking-ddos-incidents-peaking-for-40-minutes-as-multi-vector-attacks-grow-in-complexity-and-become-harder-to-dismantle

Bissa Scanner, An AI-Assisted Credential Harvesting Factory

An exposed server revealed a criminal operation exploiting the React2Shell vulnerability (CVE-2025-55182) to harvest credentials. The “Bissa scanner” operation used AI tools like Claude Code and OpenClaw to automate target scanning, credential extraction, and victim triage. The operation targeted credentials from various cloud providers, payment platforms, and databases, highlighting the risks of storing secrets in .env files.

https://thecyberexpress.com/bissa-scanner-ai-assisted-credential-factory/

UK Government Says 100 Countries Have Spyware That Can Hack People’s Phones

According to U.K. intelligence, over 100 countries now have access to commercial spyware capable of hacking phones and computers to steal sensitive data, increasing from 80 countries in 2023. The U.K. National Cyber Security Centre warns this expanded access lowers barriers for foreign governments and hackers to target U.K. citizens, companies, and critical infrastructure, with victims now including bankers and wealthy businesspeople, and highlights ongoing threats from state-backed intrusions and leaked hacking tools.

https://techcrunch.com/2026/04/22/uk-government-says-100-countries-have-spyware-that-can-hack-peoples-phones/

How a Roblox Cheat and One AI Tool Brought Down Vercel’s Entire Platform

In early 2026, a security breach at Vercel was triggered by an employee at Context.ai downloading a Roblox cheat bundled with Lumma Stealer malware, which compromised internal systems and enabled attackers to access non-sensitive environment variables stored by Vercel. This incident exposed the risks posed by broad OAuth permissions granted to third-party AI tools and highlighted how non-sensitive environment variables were less protected, prompting Vercel to change its default encryption settings; the breach has led to widespread credential rotations and raised concerns over the security trade-offs in AI tooling and developer convenience.

https://webmatrices.com/post/how-a-roblox-cheat-and-one-ai-tool-brought-down-vercel-s-entire-platform

Mozilla: Anthropic’s Mythos Found 271 Zero-Day Vulnerabilities in Firefox 150

Mozilla reported that Anthropic’s AI model Mythos Preview identified 271 security vulnerabilities in the unreleased Firefox 150 source code, significantly more than previous AI models. Mozilla’s CTO stated that AI tools like Mythos could decisively shift cybersecurity defenses by making vulnerability detection faster and more efficient, potentially transforming how software security is maintained.

https://arstechnica.com/ai/2026/04/mozilla-anthropics-mythos-found-271-zero-day-vulnerabilities-in-firefox-150/

No Exploit Needed: How Attackers Walk Through the Front Door Via Identity-Based Attacks

The article highlights that despite advances in cybersecurity threats, stolen credentials remain the most common and effective method attackers use to gain unauthorized access. It emphasizes the growing role of AI in accelerating these identity-based attacks and advocates for a dynamic, iterative incident response approach—DAIR—to effectively detect, contain, and eradicate threats.

https://thehackernews.com/2026/04/no-exploit-needed-how-attackers-walk.html

All Vulnerabilities Are Exploitable: The New Reality of Software Risk

Javed Hasan, CEO and Cofounder of Lineaje, explains that rapid software evolution and AI-generated code have made all software vulnerabilities potentially exploitable, as automated tools can quickly create working exploits. He argues that traditional vulnerability management is outdated, urging organizations to adopt continuous security practices that assume every vulnerability can be weaponized, embedding security directly into development with automated governance to reduce risk in dynamic software environments.

https://www.cybersecurity-insiders.com/all-vulnerabilities-are-exploitable-the-new-reality-of-software-risk/

The Volunteer DDoS: Why AI Security Tools Are Breaking the Infrastructure They’re Meant to Protect

The article discusses how AI security tools, designed to identify vulnerabilities rapidly, are overwhelming open source software maintainers with excessive, low-quality reports, creating a “volunteer DDoS” effect that hinders real security work. It highlights the need for improved governance and trust frameworks—like those developed by the OpenSSF, including SAFE-MCP, OSS-CRS, and OMS—to filter AI findings, verify model provenance, enforce scoped permissions, and maintain human review, emphasizing that existing community-driven governance structures are crucial to managing AI-driven security challenges effectively.

https://hackernoon.com/the-volunteer-ddos-why-ai-security-tools-are-breaking-the-infrastructure-theyre-meant-to-protect

Fracturing Software Security With Frontier AI Models

Unit 42's research reveals that frontier AI models significantly enhance the ability to autonomously discover software vulnerabilities, accelerating the exploitation of zero-day and N-day flaws and enabling complex attack chains at unprecedented speed and scale. These advancements pose heightened risks to open-source software and software supply chains, as AI-driven attacks can rapidly identify and exploit vulnerabilities, necessitating stronger prevention, rapid patching, and automated incident response strategies for security teams.

https://unit42.paloaltonetworks.com/ai-software-security-risks/

Critical Anthropic’s MCP Vulnerability Enables Remote Code Execution Attacks

A critical architectural vulnerability in Anthropic’s Model Context Protocol (MCP) SDK exposes over 150 million downloads to remote code execution (RCE) attacks, potentially compromising up to 200,000 servers. Identified by OX Security, the flaw enables attackers to take full control of affected environments, gaining access to sensitive data and internal systems; despite recommendations, Anthropic has not applied a protocol-level fix, leaving several projects vulnerable.

https://cybersecuritynews.com/anthropics-mcp-vulnerability/

Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials

Web infrastructure provider Vercel disclosed a security breach caused by the compromise of Context.ai, a third-party AI tool used by a Vercel employee, which allowed attackers to access some internal systems and limited customer credentials. The breach involved unauthorized access to non-sensitive environment variables, with no evidence of sensitive data being accessed, and Vercel is working with cybersecurity firms and law enforcement while urging affected customers to rotate credentials and adopt enhanced security measures.

https://thehackernews.com/2026/04/vercel-breach-tied-to-context-ai-hack.html

NIST Is Cataloging so Many Vulnerabilities It Can Only Assign Severity Scores to the Highest Priority Threats

The National Institute of Standards and Technology (NIST) is overwhelmed by a 263% increase in vulnerability submissions since 2020, leading it to prioritize adding detailed analysis and severity scoring only for the highest priority threats, such as those listed in CISA’s Known Exploited Vulnerabilities catalog and software used by the federal government. Other vulnerabilities are considered “lowest priority,” though users can request further enrichment from NIST via email if needed.

https://www.techradar.com/pro/security/nist-is-cataloging-so-many-vulnerabilities-it-can-only-assign-severity-scores-to-the-highest-priority-threats

Scroll to Top