Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials

Web infrastructure provider Vercel disclosed a security breach caused by the compromise of Context.ai, a third-party AI tool used by a Vercel employee, which allowed attackers to access some internal systems and limited customer credentials. The breach involved unauthorized access to non-sensitive environment variables, with no evidence of sensitive data being accessed, and Vercel is working with cybersecurity firms and law enforcement while urging affected customers to rotate credentials and adopt enhanced security measures.

https://thehackernews.com/2026/04/vercel-breach-tied-to-context-ai-hack.html

NIST Is Cataloging so Many Vulnerabilities It Can Only Assign Severity Scores to the Highest Priority Threats

The National Institute of Standards and Technology (NIST) is overwhelmed by a 263% increase in vulnerability submissions since 2020, leading it to prioritize adding detailed analysis and severity scoring only for the highest priority threats, such as those listed in CISA’s Known Exploited Vulnerabilities catalog and software used by the federal government. Other vulnerabilities are considered “lowest priority,” though users can request further enrichment from NIST via email if needed.

https://www.techradar.com/pro/security/nist-is-cataloging-so-many-vulnerabilities-it-can-only-assign-severity-scores-to-the-highest-priority-threats

Claude Code, Gemini CLI, GitHub Copilot Agents Vulnerable to Prompt Injection Via Comments

Aonan Guan and colleagues disclosed a prompt injection attack called ‘Comment and Control’ affecting popular AI code security and automation tools like Anthropic’s Claude Code, Google’s Gemini CLI, and GitHub Copilot Agent. This attack uses crafted GitHub comments to hijack AI agents, allowing execution of arbitrary commands and exfiltration of credentials, highlighting a critical architectural flaw where AI agents process untrusted input alongside sensitive credentials and execution capabilities.

https://www.securityweek.com/claude-code-gemini-cli-github-copilot-agents-vulnerable-to-prompt-injection-via-comments/

European Police Email 75,000 People Asking Them to Stop DDoS Attacks

Europol and global law enforcement agencies have launched Operation PowerOFF, sending warning emails to over 75,000 individuals suspected of using DDoS-for-hire services that enable cyberattacks without technical skills. The operation resulted in four arrests, seizure of 53 domains, and 24 executed search warrants, targeting the disruption caused by these easily accessible cyberattacks.

https://techcrunch.com/2026/04/16/european-police-email-75000-people-asking-them-to-stop-ddos-attacks/

The Silent “Storm”: New Infostealer Hijacks Sessions, Decrypts Server-Side

A new infostealer named Storm, emerging in early 2026, steals browser credentials, session cookies, crypto wallets, and more by sending encrypted data to attackers' servers for decryption instead of decrypting locally, evading endpoint security detection. Storm automates session hijacking by restoring authenticated sessions remotely, enabling attackers to access SaaS platforms and cloud environments without triggering password alerts, and it is sold via tiered subscriptions on cybercrime forums.

https://www.bleepingcomputer.com/news/security/the-silent-storm-new-infostealer-hijacks-sessions-decrypts-server-side/

OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident

OpenAI disclosed that a GitHub Actions workflow used for signing its macOS apps unintentionally downloaded a malicious version of the Axios npm package as part of a supply chain attack linked to North Korean hackers, but affirmed no user data or internal systems were compromised. In response, OpenAI revoked and rotated the affected signing certificate, blocking older app versions and coordinating with Apple to prevent further notarizations with the compromised certificate, highlighting the growing threat and complexity of software supply chain attacks.

https://thehackernews.com/2026/04/openai-revokes-macos-app-certificate.html

GTA 6 Developer Rockstar Reportedly Hacked, Data Being Ransomed

Hacker group ShinyHunters claims to have breached Rockstar Games' secured cloud servers via a security flaw in a third-party service, Anodot, demanding a ransom by April 14 or threatening to leak corporate data. Rockstar confirmed a data breach occurred but stated that only a limited amount of non-material company information was accessed, with no impact on their organization or players.

https://kotaku.com/rockstar-games-reportedly-hacked-massive-data-leak-ransom-gta-6-shinyhunters-2000686858

Hundreds of Orgs Compromised Daily in Microsoft Device Code Phishing Attacks

A widespread Microsoft device-code phishing campaign has been compromising hundreds of organizations daily since mid-March 2026, using AI and automation to bypass multi-factor authentication and gain access to corporate Microsoft 365 accounts. The attackers generate dynamic device codes to trick victims into authorizing access, enabling them to steal sensitive financial emails and data, with the phishing infrastructure leveraging legitimate cloud services to evade detection. Microsoft recommends limiting the use of device code authentication and training employees to recognize phishing attempts to mitigate such attacks.

https://www.theregister.com/2026/04/07/microsoft_device_code_phishing/

Over 20,000 Crypto Fraud Victims Identified in International Crackdown

An international law enforcement effort called Operation Atlantic, led by the UK's National Crime Agency (NCA) and involving agencies from Canada, the UK, and the US, has identified over 20,000 victims of cryptocurrency fraud and frozen more than $12 million in criminal proceeds. This joint operation disrupted multiple fraud networks globally, highlighting the effectiveness of public-private partnerships in combating crypto scams and supporting victims.

https://www.bleepingcomputer.com/news/security/police-identifies-20-000-victims-in-international-crypto-fraud-crackdown/

New VENOM Phishing Attacks Steal Senior Executives’ Microsoft Logins

Threat actors using a new phishing-as-a-service platform called VENOM have been targeting Microsoft logins of senior executives since at least last November. The attacks impersonate Microsoft SharePoint notifications with highly personalized emails and QR codes leading victims to sophisticated credential-harvesting pages that bypass traditional protections like MFA, highlighting the need for stronger authentication measures such as FIDO2 and stricter access policies.

https://www.bleepingcomputer.com/news/security/new-venom-phishing-attacks-steal-senior-executives-microsoft-logins/

Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621

Adobe has released emergency updates to address a critical security vulnerability (CVE-2026-34621) in Acrobat Reader that is actively being exploited in the wild. The flaw, related to prototype pollution, could enable attackers to execute arbitrary malicious code on affected versions of Acrobat DC, Acrobat Reader DC, and Acrobat 2024 for both Windows and macOS, with Adobe confirming awareness of ongoing exploitation.

https://thehackernews.com/2026/04/adobe-patches-actively-exploited.html

Has Mythos Just Broken the Deal That Kept the Internet Safe?

Martin Alderson discusses the potential cybersecurity crisis posed by Anthropic's new AI model, Mythos, which can generate working exploits against browser sandboxes 72.4% of the time, a dramatic increase from under 1% with previous models. This threatens the foundational security of the internet and cloud computing, as sandboxes that isolate code execution may no longer be effective defenses, raising concerns about widespread device compromise and disruption.

https://martinalderson.com/posts/has-mythos-just-broken-the-deal-that-kept-the-internet-safe/

Claude Mixes up Who Said What, and That’s Not OK

AI model Claude exhibits a significant bug where it confuses its own generated messages as if they were user inputs, leading it to attribute internal instructions to the user mistakenly. This issue, distinct from hallucinations or permission errors, appears related to the message handling system rather than the model itself and has been observed repeatedly by different users, including scenarios where Claude takes destructive actions based on its own false assumptions about user commands.

https://dwyer.co.za/static/claude-mixes-up-who-said-what-and-thats-not-ok.html

Number Usage in Passwords: Take Two

An analysis of nearly 500,000 unique passwords submitted to honeypots from April 2024 to March 2026 reveals common use of numbers, especially years, in passwords. The study finds that years typically appear in passwords during or just before the corresponding year, with “1234” and the previous year's numbers being frequent; many passwords also contain date-like 8-digit numbers, often representing birthdates or recent dates, mostly appended at the end of the password. The report highlights the persistence of predictable numeric patterns and advises against using current years or dates in passwords to enhance security.

https://isc.sans.edu/diary/rss/32866

How Teenage Hacking Gangs Hijack the Internet

Teenage hacking gangs are reshaping cybercrime by causing chaos and seeking attention rather than financial gain, according to cyber correspondent Joe Tidy. He highlights notorious cases like Finnish hacker Julius Kivimäki, who executed devastating hacks including a traumatic breach of a digital psychotherapy chain’s patient records, illustrating how these young hackers wield power over governments, corporations, and individuals with little regard for the damage caused.

https://www.rnz.co.nz/life/books/how-teenage-hackers-hijack-the-internet

Scroll to Top