Latest Internet & Cybersecurity News

đź“…April 26, 2026 at 1:00 PM
Major cybersecurity incidents include Vercel breach via AI tool, CISA KEV updates on Cisco flaws, China botnets, Scattered Spider guilty pleas, and rising AI-driven exploits.Source 1Source 2
1

Vercel Breached via Compromised Third-Party AI Tool

Cloud platform Vercel suffered a security breach where attackers accessed internal systems and compromised credentials of a limited subset of customers through a third-party AI tool.Source 2 This incident highlights supply chain risks in AI integrations.Source 1

2

CISA Adds Multiple Flaws to Known Exploited Vulnerabilities Catalog

U.S. CISA added vulnerabilities in SimpleHelp, Samsung, D-Link, Cisco Catalyst, Kentico Xperience, and others to its KEV catalog, including Cisco Catalyst SD-WAN Manager bug CVE-2026-20133.Source 1Source 2 Federal agencies must patch within strict timelines.Source 1

3

Over 400,000 Sites at Risk from Breeze Cache Plugin Flaw

Hackers are exploiting CVE-2026-3844 in the Breeze Cache WordPress plugin, putting over 400,000 sites at risk of takeover.Source 1 No patch is available yet, urging immediate deactivation.Source 1

4

China-Linked Actors Use Consumer Device Botnets for Espionage

China-aligned threat actors build botnets from compromised routers and edge devices to evade detection in cyber espionage, warned by UK NCSC and partners.Source 1Source 2 They shifted to large-scale covert networks.Source 2

5

Scattered Spider Member Pleads Guilty to $8M Crypto Theft

British national Tyler Buchanan, tied to Scattered Spider, pleaded guilty to SMS phishing hacks stealing over $8 million in cryptocurrency from US victims.Source 1Source 2 This follows similar guilty pleas in the group.Source 2

6

Ransomware Negotiator Admits Assisting BlackCat Attacks

A Florida ransomware negotiator pleaded guilty to secretly aiding BlackCat extortion schemes while hired to resolve them against US companies.Source 1Source 2 He conspired in the attacks.Source 2

7

Bluesky Hit by 24-Hour DDoS Attack by Pro-Iran Group

Social platform Bluesky endured a 24-hour DDoS attack claimed by a pro-Iran group, disrupting service amid rising geopolitical tensions.Source 1 This reflects digital warfare trends.Source 6

8

North Korea’s Lazarus APT Steals $290M from Kelp DAO

Lazarus Group stole $290 million from cryptocurrency platform Kelp DAO in a major heist.Source 1 This continues North Korea's crypto theft campaigns funding operations.Source 1

9

Progress Software Fixes WAF Bypass Vulnerability

Progress Software patched high-severity flaws in MOVEit WAF and LoadMaster, including CVE-2026-21876 allowing firewall bypass detection evasion.Source 2 Updates urged for all users.Source 2

10

AI Model Claude Mythos Discovers 271 Firefox Flaws

Anthropic’s Claude Mythos AI identified 271 vulnerabilities in Firefox, showcasing AI's power in vulnerability discovery.Source 2 Meanwhile, it turns bugs into exploits for low cost.Source 1Source 7

11

French Hacker 'HexDex' Arrested for Sports Institution Breaches

A 20-year-old French hacker alias HexDex was arrested for data breaches targeting sports organizations.Source 2 Authorities link him to multiple incidents.Source 2

12

Supply Chain Risks Escalate in Cyber Sovereignty Focus

Hidden dependencies and long-tail vendors heighten supply chain risks, prompting calls for SBOM transparency and trust-driven sourcing amid Volt Typhoon-like threats.Source 4 This affects critical infrastructure.Source 4

Latest Internet & Cybersecurity News | DeckBook AI