Vercel Breach Shows How Shadow AI and OAuth Sprawl Bypass Every Perimeter Control
The Vercel April 2026 breach, traced to a Context.ai OAuth compromise, exposes how shadow AI integrations silently hand attackers keys to enterprise environments.
The Vercel April 2026 breach, traced to a Context.ai OAuth compromise, exposes how shadow AI integrations silently hand attackers keys to enterprise environments.
ShinyHunters breached ADT via an Okta SSO vishing attack and stole data on 5.5 million customers. ADT refused to pay; 11GB of data
New Lotus Wiper malware used LotL techniques to irreversibly destroy disk sectors at Venezuelan energy and utility firms. No CVE — purely destructive.
Forescout's 2026 report identifies tens of thousands of exposed RDP and VNC servers directly mapped to ICS/OT environments across critical industries.
Medtronic confirmed unauthorized access to corporate IT systems after ShinyHunters claimed 9M records stolen. Patient safety and medical devices unaffected.
CISA advisory AA26-097A: Iranian IRGC-linked CyberAv3ngers exploit internet-exposed Rockwell Allen-Bradley PLCs using legitimate Studio 5000 software. 5,219 devices at risk.
Iran-linked Handala hacker group targeted US service members in Bahrain via WhatsApp threats, claiming to have leaked personal data of over 2,379 Marines.
A cybercrime group of Brazilian origin has resurfaced after more than three years to orchestrate a campaign that targets Minecraft players with a
Chrome 147 and Firefox 150 address critical and high-severity arbitrary code execution vulnerabilities. Firefox 150 also patches 271 AI-found bugs. Update both browsers
DoD signs AI integration agreements with Google, Microsoft, AWS, Nvidia, OpenAI, Reflection, and SpaceX to deploy AI on classified systems via GenAI.mil. Anthropic