THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Vercel breached via third‑party AI tool, exposes some customer credentials

Cloud platform Vercel confirmed attackers accessed internal systems and compromised a limited subset of customer credentials after a Context.ai OAuth token tied to a Vercel employee was abused to take over their Google Workspace account. The incident underscores growing supply‑chain risk from agentic AI tools granted overly broad scopes—teams should rotate Vercel tokens, audit and restrict OAuth permissions, monitor SaaS integrations, and enforce least‑privilege access to AI apps.

Source: Help Net Security


$290M Kelp DAO crypto heist blamed on North Korea after cross‑chain failover poisoning

Investigators attribute the theft to North Korean actors who targeted LayerZero’s DVN by compromising some RPC endpoints and DDoS’ing others, forcing failover to attacker‑controlled infrastructure. The operation highlights systemic risks in cross‑chain bridges—operators should harden validator/DVN trust, use diverse RPC providers with health attestation, validate failover paths, and add anomaly detection for bridge flow manipulation.

Source: SecurityWeek


“The Gentlemen” RaaS surges to #2 by victim count, targets edge devices and moves fast

Check Point reports The Gentlemen ransomware‑as‑a‑service has claimed 320+ victims since mid‑2025 (240 in 2026), with researchers finding a SystemBC‑powered botnet of 1,570 likely corporate hosts tied to an affiliate. The group favors internet‑facing VPNs and firewalls for entry and can encrypt enterprise networks within hours; manufacturers, tech firms, and increasingly healthcare are most impacted—prioritize patching on edge gear, enforce MFA, and monitor egress C2 via SOCKS/proxy beacons.

Source: Check Point Blog


Critical RCE in widely used protobuf.js; exploit code published

A remote code execution flaw (GHSA-xq3m-2v4x-88gg) tied to unsafe dynamic code generation in protobuf.js exposes millions of projects to attack, with public exploit code now available. Teams should urgently inventory where protobuf.js appears (including transitive deps), upgrade to the latest patched release, and review build/runtime defenses against malicious schema input.

Source: SC Media


Leaked “Nightmare‑Eclipse” tooling now seen in real intrusions

Huntress observed in‑the‑wild use of the BlueHammer, RedSun, and UnDefend tooling—originally released as PoCs following a dispute with Microsoft—in an intrusion that began with FortiGate VPN compromise. The toolset focuses on Defender tamper/disable and evasion; defenders should harden VPN access, enable Defender Tamper Protection, monitor for security service manipulation, and rapidly deploy fixes when available.

Source: Huntress


CISA adds 8 actively exploited bugs to KEV, sets near‑term federal deadlines

CISA’s KEV update includes flaws in Cisco Catalyst SD‑WAN Manager and PaperCut, among others, with remediation deadlines spanning April–May 2026 for U.S. federal agencies. Private organizations should treat KEV listings as prioritized patch queues, validate exposure paths, and apply compensating controls where immediate patching isn’t possible.

Source: The Hacker News


Crypto‑stealing “FakeWallet” apps slipped into Apple’s App Store

Kaspersky found 20+ iOS apps impersonating major crypto wallets to phish seed phrases and drain funds, illustrating that mobile walled gardens remain vulnerable to well‑crafted financial malware. Affected users should immediately remove suspect apps, move assets to new wallets with fresh seed phrases, and enterprises should enforce MDM restrictions on unapproved finance apps.

Source: Securelist (Kaspersky)


You May Also Be Interested In...

AI platform ATHR makes voice phishing a one‑person job

Void Dokkaebi spreads malware via poisoned developer repositories

“Background noise” spikes may predict the next big edge‑device vuln

Cybersecurity — April 21, 2026 | Briefing24