Vercel confirmed a security incident stemming from a compromise at third-party AI tool Context.ai, which was used by a Vercel employee. Attackers leveraged that access to take over the employee’s Google Workspace account and access certain internal Vercel systems, exposing a limited set of customer credentials. The case spotlights OAuth supply-chain risk: overly broad third-party app permissions can become a high-impact pivot point.
Source: The Hacker News
FakeWallet crypto stealer slips into Apple’s App Store via lookalike wallet apps
Researchers uncovered more than twenty phishing apps on the Apple App Store masquerading as popular crypto wallets. The apps trick users into entering seed phrases and credentials, enabling theft of funds from legitimate wallets. Crypto users should verify publisher identities, avoid entering seed phrases into new apps, and migrate assets if exposure is suspected.
Source: Securelist
NIST scales back CVSS scoring for lower-priority CVEs amid volume surge
NIST will stop assigning severity scores to non-priority vulnerabilities due to the growing workload from surging CVE submissions. The change could increase triage pressure on defenders who rely on NVD scoring, pushing teams to lean more on vendor advisories, CISA KEV, EPSS, and threat intelligence to prioritize patches.
Source: BleepingComputer
Microsoft ships emergency fixes for Windows Server issues after April updates
Microsoft released out-of-band updates to resolve problems affecting Windows Server systems that emerged after the April 2026 Patch Tuesday. Administrators should review Microsoft’s guidance and deploy the OOB updates to affected servers to restore stability and functionality.
Source: BleepingComputer
Nearly 9.8B credential records exposed via misconfigured public Elasticsearch
SOCRadar identified three publicly accessible Elasticsearch servers leaking a combined 9,879,060,029 credential-related records spanning enterprise, cloud, and AI ecosystems. Such exposures supercharge credential stuffing, account takeover, and supply-chain attacks. Organizations should immediately inventory internet-facing search clusters, enable authentication, restrict access, and rotate any exposed secrets.
Source: SOCRadar
ZionSiphon malware targets Israeli water and desalination OT networks
Darktrace researchers detailed a new malware, ZionSiphon, designed to persist on hosts, tamper with local configs, and scan for OT-relevant services on local subnets used in water and desalination operations. The campaign underscores escalating IT/OT convergence risk. Utilities should tighten network segmentation, enhance east-west monitoring, and limit remote management pathways.
Source: The Hacker News
Cisco ISE flaws could allow remote code execution on critical NAC infrastructure
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) may enable remote code execution on a platform central to network access control and policy enforcement. A successful compromise could provide wide lateral movement and policy manipulation. Security teams should apply Cisco’s guidance promptly and minimize exposure of ISE management interfaces.
Source: The Cyber Express
You May Also Be Interested In...
EU pushes for stronger cloud sovereignty, awards €180 million to four providersHow to spot a North Korean fake in a job interview
Apple account change alerts abused to send phishing emails