Vercel confirms breach as hackers claim to be selling stolen data

2026-04-19T19:23:26Z06bdc876cf5492f38ef1f039bacf9db7686673718dd7c247776b9cc83b125083
CISADDoSactive-exploitationapache-activemqbreachcloud-securitycredential-theftcrypto-exchangedata-theftendpoint-evasionincident-responsepatchingphishingprotobuf-jsqemuransomwareremote-code-executionunderground-marketsvulnerability-managementwindows-zero-day

What happened

Multiple high-risk incidents and active exploitations were reported: Vercel confirmed a breach with threat actors attempting to sell stolen data; a critical remote code execution flaw in protobuf.js has public PoC; CISA warned of active exploitation of a high-severity Apache ActiveMQ vulnerability; recently leaked Windows zero-days are being used to gain elevated privileges. Attackers continue to innovate (Payouts King using QEMU VMs to evade endpoint security) and phishing is being amplified via abused Apple account-change emails. Organizations should urgently review exposures tied to cloud/S

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
06bdc876cf5492f38ef1f039bacf9db7686673718dd7c247776b9cc83b125083
Enrichment time
2026-04-19T19:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Vercel confirms breach as hackers claim to be selling stolen data · Baitaphish