Researchers Spot Uptick in Use of Vercel for Phishing Campaigns
2026-05-07T08:52:18Z•efdac76a51eb933bfef5b03cafbb88eeefbb2c36ffcefa7d62adf6425889ed3c
API key exposureCloudZIran-linked APTMedtronicMicrosoft Phone LinkNorth Korea / BlueNoroffPhenoRATSMS OTP interceptionTrellix breachUK BiobankVect wiperVenomous#Helper RMM phishing attacksVercelbrowser extension vulnerabilitycredential theftdata breachinfo-stealerinsider riskmalicious npmmass-phishingphishingransomwaresupply-chain compromisetrojanized software
What happened
A cluster of high-impact cyber incidents and trends was reported: a surge in phishing campaigns (notably abusing Vercel and large-scale fake compliance emails targeting ~35,000 users), advanced malware and interception techniques (CloudZ RAT with Pheno plugin abusing Microsoft Phone Link to steal SMS OTPs; Deep#Door and other info‑stealers), and multiple supply‑chain and insider-risk problems (trojanized gaming platform, malicious npm dependency, browser extension flaw exposing API keys, employees selling credentials). Nation‑state and ransomware activity remains active (Iran‑linked APT false‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- efdac76a51eb933bfef5b03cafbb88eeefbb2c36ffcefa7d62adf6425889ed3c
- Enrichment time
- 2026-05-07T08:52:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.