Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach
2026-04-26T08:51:44Z•9beccd498bab48df375073dba021cf715c47a7ee86b7fd2cbcfbcad6f61fa7e3
Android privacyCI/CD securityChina threat actorsCisco FirepowerFirefox vulnerabilitiesFirestarterLLM securityMeta AccountNFC malwareOpenAI GPT-5.5SmokedMeatUbuntu 26.04Vercel breachauthenticationbotnetsfirewall backdoormemory-safepasskeysprompt injectionrouters
What happened
Weekly intelligence roundup: multiple high-impact items including a persistent state‑sponsored backdoor (“Firestarter”) observed on Cisco Firepower/Secure Firewall appliances that in some cases can only be removed by powering the device off; the UK NCSC advising consumers to replace passwords with passkeys; growing real‑world abuse of indirect prompt injection against LLM agents; China‑linked espionage shifting to large botnets of compromised routers and edge devices; reports of 271 Firefox flaws (Claude Mythos) and a Vercel breach; new offensive/defensive tooling (SmokedMeat) for CI/CD attack
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 9beccd498bab48df375073dba021cf715c47a7ee86b7fd2cbcfbcad6f61fa7e3
- Enrichment time
- 2026-04-26T08:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.