THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Vercel breach tied to third-party AI OAuth abuse exposes customer credentials

Cloud platform Vercel disclosed a breach traced to a compromised third-party AI tool that had been granted broad Google Workspace OAuth access, leading to unauthorized access and theft of some Vercel credentials. The company warned a “limited subset of customers” to rotate secrets, and the incident spotlights a growing blind spot: unmonitored OAuth grants from employee-installed AI tools. Security teams should inventory and restrict third‑party OAuth scopes and default environment variables to non-readable “sensitive.”

Source: Recorded Future News (The Record)


CISA adds new Cisco Catalyst SD‑WAN Manager flaw to KEV amid active exploitation (CVE-2026-20133)

US CISA added CVE‑2026‑20133 to its Known Exploited Vulnerabilities catalog, joining two other Cisco Catalyst SD‑WAN Manager bugs already under attack. Federal agencies have just days to patch; enterprises should urgently restrict management interfaces, review exposed controllers, and apply all available updates to break ongoing exploit chains.

Source: Help Net Security


NGate Android malware hides in trojanized NFC HandyPay app to skim cards and PINs

ESET uncovered a new NGate variant targeting Android users by embedding malicious code in a trojanized copy of HandyPay, an NFC relay tool. The campaign, active since late 2025 and likely leveraging AI-generated code, exfiltrates NFC transaction data and PINs, with Brazil in scope. Organizations should block sideloaded apps, enforce mobile device management, and monitor for anomalous NFC transactions.

Source: ESET Research


‘Lotus’ wiper hits Venezuela energy and utilities with destructive attacks

Researchers detailed a previously undocumented data wiper, dubbed Lotus, used against Venezuelan energy and utility firms. Operators staged the environment by disabling defenses via scripts before irreversibly erasing data, underscoring persistent risks to OT/ICS networks and the need for immutable backups and segmentation between IT and operational domains.

Source: BleepingComputer


Apple Intelligence token flaw let attackers reuse stolen tokens on other devices

Ohio State University researchers found design weaknesses in Apple Intelligence’s two‑stage authentication, showing that tokens stolen on macOS could be reused on different devices. The attack, demonstrated on macOS 26.0 (Tahoe), raises concerns about GenAI service authentication and token binding; Apple has positioned Private Cloud Compute as privacy‑preserving, but implementations must strictly enforce device-scoped tokens.

Source: Help Net Security


Lazarus blamed for $290M Kelp DAO heist via LayerZero cross‑chain infrastructure

Security investigators attribute a $290M theft from Kelp DAO to North Korea’s Lazarus Group, which targeted LayerZero’s DVN by compromising RPCs and DDoSing others to force failover to attacker‑controlled infrastructure. The operation highlights systemic risks in cross‑chain bridges, emphasizing the need for independent quorum validation, RPC integrity checks, and real‑time anomaly detection on validator behavior.

Source: SecurityWeek


Talos IR Q1 2026: Phishing resurges as top initial access; public administration remains a prime target

Cisco Talos incident response data shows phishing reemerged as the leading initial access vector, accounting for over one‑third of engagements with known entry points—the first time since Q2 2025. Persistent targeting of public administration underscores the urgency of modern email defenses, phishing‑resistant MFA, and rapid credential hygiene when compromise is suspected.

Source: Cisco Talos


You May Also Be Interested In...

Oracle Patches 450 Vulnerabilities With April 2026 CPU
22 BRIDGE:BREAK Flaws Expose 20,000 Lantronix and Silex Serial‑to‑IP Converters
North Korean Hackers Use AppleScript, ClickFix in Fresh macOS Attacks

Cybersecurity — April 22, 2026 | Briefing24