Vercel confirms breach as hackers claim to be selling stolen data
2026-04-20T01:23:27Z•d52b1010a526e21363b8e0acc9d788294f05adc650b62faa5356cc8e3e85ce63
active-exploitationapache-activemqapple-notifications-abusebackup-softwarebreachcryptocurrency-exchange-hackdDoSdata-theftmicrosoft-patch-issuesnakivooperation-poweroffpayouts-kingphishingprotobuf.jsqemu-emu-vm-bypassransomwarercereboot-loopsremote-code-executionwindows-zero-days
What happened
Multiple high-impact incidents and trends were reported: Vercel confirmed a breach with stolen data being offered for sale; Apple account-change notifications are being abused to deliver phishing via legitimate Apple-sent emails; a critical remote-code-execution flaw in protobuf.js (PoC published) and an actively exploited high-severity Apache ActiveMQ vulnerability were highlighted; three recently leaked Windows zero-days are now being exploited and some Windows servers are experiencing reboot loops after April patches. Additional noteworthy items: Payouts King ransomware uses hidden QEMU VMs
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- d52b1010a526e21363b8e0acc9d788294f05adc650b62faa5356cc8e3e85ce63
- Enrichment time
- 2026-04-20T01:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.