Vercel confirms breach as hackers claim to be selling stolen data

2026-04-20T01:23:27Zd52b1010a526e21363b8e0acc9d788294f05adc650b62faa5356cc8e3e85ce63
active-exploitationapache-activemqapple-notifications-abusebackup-softwarebreachcryptocurrency-exchange-hackdDoSdata-theftmicrosoft-patch-issuesnakivooperation-poweroffpayouts-kingphishingprotobuf.jsqemu-emu-vm-bypassransomwarercereboot-loopsremote-code-executionwindows-zero-days

What happened

Multiple high-impact incidents and trends were reported: Vercel confirmed a breach with stolen data being offered for sale; Apple account-change notifications are being abused to deliver phishing via legitimate Apple-sent emails; a critical remote-code-execution flaw in protobuf.js (PoC published) and an actively exploited high-severity Apache ActiveMQ vulnerability were highlighted; three recently leaked Windows zero-days are now being exploited and some Windows servers are experiencing reboot loops after April patches. Additional noteworthy items: Payouts King ransomware uses hidden QEMU VMs

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
d52b1010a526e21363b8e0acc9d788294f05adc650b62faa5356cc8e3e85ce63
Enrichment time
2026-04-20T01:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.