Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials

2026-04-20T07:24:09Z5f790b62f21aa3026694b25afb279990d26d48cee959f94411b9ddf091c9df1a
active-exploitationai-toolbotnetcloud-infrastructurecredential-theftcritical-vulnerabilitiesdata-breachknown-exploited-vulnerabilitymirain8npatchingphishingratsupply-chainthird-party-compromise

What happened

The Hacker News digest reports a range of high-impact incidents and vulnerabilities: Vercel disclosed a breach stemming from a compromise of the third‑party AI tool Context.ai that allowed takeover of an employee's Vercel Google Workspace account and exposure of limited customer credentials. Multiple high‑severity, actively exploited vulnerabilities are highlighted — including Apache ActiveMQ (CVE-2026-34197) added to CISA KEV and nginx-ui authentication bypass (CVE-2026-33032) under active exploitation — alongside Microsoft Defender zero‑days, critical Cisco and SAP flaws, and PHP Composer RE

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
5f790b62f21aa3026694b25afb279990d26d48cee959f94411b9ddf091c9df1a
Enrichment time
2026-04-20T07:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.