Cloud platform Vercel disclosed a breach traced to a compromised third-party AI tool that had been granted broad Google Workspace OAuth access, leading to unauthorized access and theft of some Vercel credentials. The company warned a “limited subset of customers” to rotate secrets, and the incident spotlights a growing blind spot: unmonitored OAuth grants from employee-installed AI tools. Security teams should inventory and restrict third‑party OAuth scopes and default environment variables to non-readable “sensitive.”
Source: Recorded Future News (The Record)
CISA adds new Cisco Catalyst SD‑WAN Manager flaw to KEV amid active exploitation (CVE-2026-20133)
US CISA added CVE‑2026‑20133 to its Known Exploited Vulnerabilities catalog, joining two other Cisco Catalyst SD‑WAN Manager bugs already under attack. Federal agencies have just days to patch; enterprises should urgently restrict management interfaces, review exposed controllers, and apply all available updates to break ongoing exploit chains.
Source: Help Net Security
NGate Android malware hides in trojanized NFC HandyPay app to skim cards and PINs
ESET uncovered a new NGate variant targeting Android users by embedding malicious code in a trojanized copy of HandyPay, an NFC relay tool. The campaign, active since late 2025 and likely leveraging AI-generated code, exfiltrates NFC transaction data and PINs, with Brazil in scope. Organizations should block sideloaded apps, enforce mobile device management, and monitor for anomalous NFC transactions.
Source: ESET Research
‘Lotus’ wiper hits Venezuela energy and utilities with destructive attacks
Researchers detailed a previously undocumented data wiper, dubbed Lotus, used against Venezuelan energy and utility firms. Operators staged the environment by disabling defenses via scripts before irreversibly erasing data, underscoring persistent risks to OT/ICS networks and the need for immutable backups and segmentation between IT and operational domains.
Source: BleepingComputer
Apple Intelligence token flaw let attackers reuse stolen tokens on other devices
Ohio State University researchers found design weaknesses in Apple Intelligence’s two‑stage authentication, showing that tokens stolen on macOS could be reused on different devices. The attack, demonstrated on macOS 26.0 (Tahoe), raises concerns about GenAI service authentication and token binding; Apple has positioned Private Cloud Compute as privacy‑preserving, but implementations must strictly enforce device-scoped tokens.
Source: Help Net Security
Lazarus blamed for $290M Kelp DAO heist via LayerZero cross‑chain infrastructure
Security investigators attribute a $290M theft from Kelp DAO to North Korea’s Lazarus Group, which targeted LayerZero’s DVN by compromising RPCs and DDoSing others to force failover to attacker‑controlled infrastructure. The operation highlights systemic risks in cross‑chain bridges, emphasizing the need for independent quorum validation, RPC integrity checks, and real‑time anomaly detection on validator behavior.
Source: SecurityWeek
Talos IR Q1 2026: Phishing resurges as top initial access; public administration remains a prime target
Cisco Talos incident response data shows phishing reemerged as the leading initial access vector, accounting for over one‑third of engagements with known entry points—the first time since Q2 2025. Persistent targeting of public administration underscores the urgency of modern email defenses, phishing‑resistant MFA, and rapid credential hygiene when compromise is suspected.
Source: Cisco Talos
You May Also Be Interested In...
Oracle Patches 450 Vulnerabilities With April 2026 CPU
22 BRIDGE:BREAK Flaws Expose 20,000 Lantronix and Silex Serial‑to‑IP Converters
North Korean Hackers Use AppleScript, ClickFix in Fresh macOS Attacks