Vercel Breach Linked to Context.ai, ShinyHunters Says It’s Not Involved
2026-04-21T08:51:43Z•f772624a4f6c85d11a31ccec0b859b4131e7bca2bb3cf8870f2d3d463cbdb07e
Android malwareAstrinoxCVE-2025-0520Chrome extensionsContext.aiDDoS-for-hireEuropolMassivMicrosoft EdgeOperation PowerOFFRCERecruitRatSaferRatScattered SpiderShinyHuntersShowDocTikTokTyler BuchananVercelbanking appscryptocurrency thefts (crypto theft)device fingerprintingprotobuf.jsserver takeoverweb shells
What happened
Feed of security news (Apr 2026) covering multiple high-impact incidents: Vercel confirms a breach linked to Context.ai with a hacker listing data for sale (ShinyHunters denies involvement); fake TikTok downloader extensions on Chrome and Edge are spying on ~130,000 users and exfiltrating browser data; a critical RCE vulnerability in protobuf.js (library with ~52M downloads) enables remote code execution via malicious schemas; an older ShowDoc flaw (CVE-2025-0520) patched in 2020 is being actively exploited to deploy web shells and enable full server takeovers; Zimperium reports new Android‑or
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- f772624a4f6c85d11a31ccec0b859b4131e7bca2bb3cf8870f2d3d463cbdb07e
- Enrichment time
- 2026-04-21T08:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.