114Articles
8Categories
2026-04-20Date
🐛
Security Researcher Goes To War Against Microsoft
🐛
NIST Adopts Risk-Based NVD Model as CVE Submissions Jump 263% Since 2020
🐛
Copilot & Agentforce offen für Prompt-Injection-Tricks
🐛
Claude Mythos – ist der Hype gerechtfertigt?
🐛
TBK DVR Vulnerability CVE-2024-3721 Exploited to Spread Nexcorium DDoS Malware
🐛
VU#915947: SGLang is vulnerable to remote code execution when rendering chat templates from a model file
🐛
Attackers Exploit DVR Command Injection Flaw to Deploy Mirai-Based Botnet
🐛
CVE-2023-33538 under attack for a year, but exploitation still unsuccessful
🐛
National Vulnerability Database (NVD) Shifts to Selective Enrichment as CVE Volume Surges | Flashpoint
🐛
SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files
⚠️
deleteduser.com - a $15 Personally Identifiable Information (PII) Magnet
⚠️
Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials
⚠️
Vercel Reports Data Breach Amid Claims of Compromised Internal Infrastructure
⚠️
QEMU Hijacked as Stealth Backdoor for Credential Theft, Ransomware
⚠️
Critical Gardyn Flaws Open Smart Garden Devices to Remote Hijacking
⚠️
Handling the CVE Flood With EPSS, (Mon, Apr 20th)
⚠️
Ungepatchte Windows-Zero-Days RedSun, UnDefend und BlueHammer werden attackiert
⚠️
AI Model Claude Opus turns bugs into exploits for just $2,283
⚠️
Angriff auf Next.js-Hersteller Vercel: Kundendaten abgegriffen
⚠️
Making AI actually work in the enterprise and more RSAC Conference 2026 interviews - A... - ESW #455
⚠️
Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain
⚠️
CISOs reshape their roles as business risk strategists
⚠️
Network ‘background noise’ may predict the next big edge-device vulnerability
⚠️
Fracturing Software Security With Frontier AI Models
⚠️
Third-party AI hack triggers Vercel breach, internal environments accessed
⚠️
Anthropic MCP Hit by Critical Vulnerability Enabling Remote Code Execution
⚠️
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
KEV
⚠️
Attackers abuse Microsoft Teams to impersonate the IT helpdesk in a new enterprise intrusion playbook
⚠️
Hackers exploit Vercel’s trust in AI integration
⚠️
CISA flags Apache ActiveMQ flaw as actively exploited in attacks
KEV
⚠️
Vercel confirms breach as hackers claim to be selling stolen data
⚠️
Gh0st RAT, CloverPlus Hit Victims in Dual-Malware Campaign
⚠️
ShowDoc Vulnerability Patched in 2020 Now Used in Active Server Takeovers
⚠️
⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More
⚠️
App host Vercel says it was hacked and customer data stolen
⚠️
AI Agents Are Insider Risk
⚠️
Fireside Chat: PKI has carried digital trust through every tech advance—now comes the hardest one
⚠️
Vulnerability exploitation surges often precede disclosure, offering possible early warnings
⚠️
Vercel systems targeted after third-party tool compromised
⚠️
Cloud development platform Vercel confirms breach.
⚠️
2026’s Breach List So Far: FBI Hacked, 1B Androids at Risk, 270M iPhones Vulnerable
⚠️
Vercel Confirms Major Security Incident as Hacker Claims $2M Ransom Demand
⚠️
Survey: Security Leaders Emphasize Need for Workforce Education
⚠️
Microsoft Defender Flaws Exploited on Windows, Two Left Unpatched
⚠️
The MCP Disclosure Is the AI Era’s ‘Open Redirect’ Moment
⚠️
When one weak link is enough.
⚠️
The FTC’s AI portfolio is about to get bigger
⚠️
Vercel’s security breach started with malware disguised as Roblox cheats
⚠️
Small Banks at Risk of Collapse
⚠️
Vuln in Google’s Antigravity AI agent manager could escape sandbox, give attackers remote code execution
📢
NCSC Outlines Coordinated Plan to Boost NHS Cyber Resilience
📢
Iran’s MOIS Tied to Coordinated Cyber Campaign Using Multiple Hacker Personas
📢
Minister: Swedish heating plant targeted by pro-Russian cyberattack
📢
Cyberattack at French identity document agency may have exposed personal data
🔥
Fake Helpdesk Attack Uses Teams and Quick Assist to Breach Targets
🔥
British Hacker Admits Stealing Millions in Virtual Currency From Targeted Companies
🔥
JanaWare Ransomware Hits Turkish Users via Tailored Adwind RAT
🔥
DFIR Report – The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy
🔥
Bluesky blames app outage on ‘sophisticated’ DDoS attack
🔥
20th April – Threat Intelligence Report
🔥
Crypto infrastructure company blames $290 million theft on North Korean hackers
🔥
Scattered Spider member Tyler Buchanan pleads guilty to major crypto theft
🔥
Amtrak Data Breach Exposes 2.1M Records, Reports Suggest Larger Leak
🔥
France’s ANTS ID System website hit by cyberattack, possible data breach
🕵️
ISC Stormcast For Monday, April 20th, 2026 https://isc.sans.edu/podcastdetail/9898, (Mon, Apr 20th)
🕵️
Public Notion Pages Expose Editors’ Profile Photos and Email Addresses
🕵️
ZionSiphon Hits Israeli Water Systems With OT Sabotage Malware
🕵️
NSA Confirms Use of Anthropic’s Mythos Despite Pentagon Blacklist
🕵️
Top ERP Software Vendors in 2026
🕵️
Windows 11 Dev Build Introduces Improved Secure Boot Oversight and Storage Security
🕵️
iTerm2 Flaw Turns SSH Escape Sequences Into Arbitrary Code Execution
🕵️
Microsoft-Signed Malware Built With FUD Crypt Packs Persistence and C2
🕵️
MiningDropper Spreads Infostealers, RATs, Banking Malware on Android
🕵️
Is “Satoshi Nakamoto” Really Adam Back?
🕵️
North Korea-Linked UNC1069 Hacks Crypto Pros via Fake Meetings
🕵️
Notion pages have leaked user data via an unauthenticated API since 2022
🕵️
Intel Utility Hijacked in AppDomain Attack to Launch Malware
🕵️
New RecruitRat, SaferRat, Astrinox, Massiv Android Malware Found Targeting 800 Apps
🕵️
Critical sandbox bypass fixed in popular Thymeleaf Java template engine | CSO Online
🕵️
This $20 Career Prep Bundle Teaches Something Others Neglect
🕵️
Why the Axios attack proves AI is mandatory for supply chain security
🕵️
Meta Plans Up to 8,000 Job Cuts in New Round of Layoffs
🕵️
Anthropic secretly installs spyware when you install Claude Desktop
🕵️
Stellantis teams with Microsoft to strengthen digital capabilities
🕵️
Apple’s App Store found hosting ‘FakeWallet’ crypto-stealing apps
🕵️
North Korea hackers blamed for $290M crypto theft
🕵️
Chrome Privacy Concerns Rise as Expert Warns of Fingerprinting Risks
🕵️
Amazon Debuts ‘Slimmest Ever’ Fire TV Stick HD Starting at $34.99
🕵️
Italy fines national postal service $14.7M over invasive data collection
🕵️
Over 800 Android Apps Targeted in PIN-Stealing Trojan Campaign
🕵️
Bad Data Breaks AI Systems
🕵️
Mac Studio 2026: Apple’s New Desktop Faces a Delayed Timeline
🕵️
China’s Robot Half Marathon Was More Than a Stunt
🕵️
This VPN Lets You Verify Your Business Privacy For $130
🌐
A week in security (April 13 – April 19)
🌐
Researchers Detect ZionSiphon Malware Targeting Israeli Water, Desalination OT Systems
🌐
ZionSiphon Malware Targets Water Infrastructure Systems
🌐
Formbook Malware Campaign Uses Multiple Obfuscation Techniques to Avoid Detection
🎙️
Beyond IT: Cybersecurity is a strategic business risk
🎙️
Big Tech can stop scams. They just don’t (Lock and Code S07E08)
🎙️
Building a unified security ecosystem with Melissa K. Smith from SentinelOne
📡
Microsoft: Update außer der Reihe gegen ungewollte Server-Reboots
📡
Zahlreiche Attacken auf Dell PowerProtect Data Domain möglich
📡
FakeWallet crypto stealer spreading through iOS apps in the App Store
📡
FakeWallet crypto stealer spreading through iOS apps in the App Store
📡
The Weird, Twisting Tale of How China Spied on Alysa Liu and Her Dad
📡
Crypto Exchange Grinex Blames Western Spies for $13m Theft
📡
Why Most AI Deployments Stall After the Demo
📡
British hacker tied to Scattered Spider campaign pleads guilty in $8M scheme
📡
Mythos: An AI tool too powerful for public release
📡
How to clone an AWS CloudHSM cluster across Regions
📡
Elon Musk fails to appear for questioning by French police over sexualized AI images on X
📡
Mastodon says its flagship server was hit by a DDoS attack
📡
Italian regulator fines national postal service orgs $15 million for data privacy violations