Cybersecurity
204 articles RSS
ADT Confirms Breach of 5.5 Million Customers After ShinyHunters Vish an Okta SSO Account and Loot Salesforce
Home security giant ADT says attackers detected on April 20 stole names, phone numbers and addresses for 5.5 million customers after voice-phishing an employee's Okta single sign-on. ShinyHunters published an 11GB archive when the company refused to pay.
Vercel Breach Traces Back to a Roblox Cheat: How a Lumma Stealer Infection at Context.ai Became an OAuth Pivot Into a Cloud Provider
A Lumma Stealer infection at AI startup Context.ai escalated into a cross-tenant OAuth attack on Vercel, exposing employee accounts, environment variables, and customer credentials, with attackers reportedly demanding a $2 million ransom in Telegram messages with the company.
Bitwarden CLI Npm Package Backdoored for 90 Minutes as Shai-Hulud Worm Resurfaces Through Checkmarx Breach
A malicious build of @bitwarden/cli@2026.4.0 was live on npm for roughly 93 minutes on April 22 after attackers used credentials stolen from Checkmarx to push a self-propagating worm that harvests cloud, Git, and AI tooling credentials.
Windows Defender's Own Engine Weaponized: Three Zero-Days Put SYSTEM Privileges in Attacker Hands
A researcher's protest disclosure turned Microsoft Defender's remediation engine into an attack vector, with two of three zero-days remaining unpatched as ransomware actors move in.
France Titres Breach Exposes Up to 12 Million Government ID Records as Hacker Claims 19 Million Stolen
France's national identity document agency confirmed hackers breached its portal and stole data on up to 12 million citizens, while the threat actor claims 19 million records are for sale.
Microsoft's Own Patch Tuesday Update Introduced a Critical ASP.NET Core Flaw, Forcing an Emergency 10.0.7 Release
A regression shipped in .NET 10.0.6 broke HMAC validation and exposed cookie-forging attacks. Microsoft released out-of-band .NET 10.0.7 on April 21 to patch CVE-2026-40372, rated 9.1 CVSS.
MCPwn Flaw in Nginx UI Becomes the First Major MCP Vulnerability Exploited in the Wild
A missing authentication check on a Model Context Protocol endpoint in nginx-ui exposes roughly 2,600 servers to full takeover, and unauthenticated exploitation is practical when paired with a second flaw that leaks a required node secret.
Firefox 150 Ships With 271 AI-Found Vulnerabilities Patched, as Mozilla Declares Defenders Can Finally Win
Mozilla released Firefox 150 on April 21, 2026, fixing 271 vulnerabilities surfaced by Anthropic's Claude Mythos Preview in a security sweep Mozilla's CTO calls a turning point for defender-side AI.
FBI's 2025 Internet Crime Report Creates Its First AI Category, Logging 22,364 Complaints and $893 Million in Losses
For the first time in 25 years, the FBI's IC3 annual report carves out a standalone artificial intelligence section, formally recognizing AI-enabled fraud as a distinct policy concern.
Adobe Rushes Out Acrobat Reader Patch for Zero-Day Exploited Since December
Adobe says CVE-2026-34621 is under active exploitation in Acrobat and Reader; the flaw can lead to arbitrary code execution and prompted a CISA KEV deadline.
CISA Adds 13-Year-Old Apache ActiveMQ RCE to KEV Catalog, Giving Federal Agencies Two Weeks to Patch a Bug Found by Claude in Ten Minutes
CISA added CVE-2026-34197, a 13-year-old remote code execution flaw in Apache ActiveMQ Classic, to its Known Exploited Vulnerabilities catalog on April 16 as Horizon3.ai's Naveen Sunkavally described finding the chain with Anthropic's Claude in about ten minutes.
Operation Atlantic Freezes $12 Million in Crypto Scam Proceeds and Identifies 20,000 Approval Phishing Victims Across Three Continents
A week-long NCA-led operation with the US Secret Service and Canadian police disrupted approval phishing scams, freezing millions while identifying fraud wallets across more than 30 countries.