IP Addresses:
2.52.0.0, 2.55.255.255, 79.176.0.0, 79.191.255.255, 212.150.0.0, 212.150.255.255
Get tomorrow's brief in your inbox
Today: Microsoft pushes emergency updates to stop Windows Server domain controllers from crashing in restart loops. Vercel confirms breach after Context.ai compromise exposed customer credentials. ZionSiphon malware targets Israeli water infrastructure but fails due to buggy geolocation code.
Microsoft releases emergency updates to fix Windows Server issues
Microsoft released out-of-band updates to address two critical issues affecting Windows Server systems after the April 2026 Patch Tuesday. Some servers with domain controller roles are entering restart loops due to LSASS crashes, and Windows Server 2025 devices are experiencing installation failures with KB5082063. The LSASS issue affects authentication processing during early startup and impacts existing domain controllers and new setups. Additionally, some Windows Server 2025 devices boot into BitLocker recovery after installing KB5082063.
Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials
Web infrastructure provider Vercel disclosed a breach originating from a compromised employee account at Context.ai, a third-party AI tool. The attacker leveraged this access to take over a Vercel employee's Google Workspace account, gaining access to environment variables that were not marked as "sensitive." Vercel stores sensitive environment variables encrypted, but non-sensitive variables were accessible. A threat actor using the ShinyHunters persona claimed responsibility and is selling stolen data for $2 million. Hudson Rock identified that a Context.ai employee was infected with Lumma Stealer in February 2026 after downloading Roblox game exploits. The malware harvested Google Workspace credentials and keys for Supabase, Datadog, and Authkit, including the [email protected] account.
Apple account change alerts abused to send phishing emails
Attackers are exploiting Apple's account notification system to send legitimate-looking phishing emails from Apple's own infrastructure. Threat actors create Apple IDs and insert phishing messages into the first and last name fields, then trigger security alerts by modifying shipping information. These emails originate from [email protected], pass SPF, DKIM, and DMARC checks, and include callback numbers for fake purchase scams. The phishing lure claims an $899 iPhone purchase via PayPal and pressures victims to call a scammer-controlled number.
Microsoft pulls service update causing Teams launch failures
Microsoft reverted a service update that caused Teams desktop client launch failures across a subset of users. Affected clients showed a "We're having trouble loading your message" error and remained stuck on the loading screen. The issue stemmed from a regression in the Teams client build caching system that caused older desktop builds to enter an unhealthy state. Microsoft flagged this as an incident, indicating critical service issues and significant user impact.
NIST to stop rating non-priority flaws due to volume increase
The National Institute of Standards and Technology will stop assigning severity scores to lower-priority vulnerabilities due to rising submission volumes, which grew 263% recently. Starting April 15, NIST will only provide enrichment (severity ratings, product lists, analyses) for CVEs in CISA's KEV catalog, affecting U.S. federal government software, or involving critical software per Executive Order 14028. NIST enriched 42,000 CVEs in 2025 but can no longer keep pace. All CVEs will still be listed in the NVD, but non-priority vulnerabilities will only have CNA-assigned severity ratings.
FakeWallet crypto stealer spreading through iOS apps in the App Store
Kaspersky identified over 20 phishing apps in the Apple App Store masquerading as popular crypto wallets including MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken, and Bitpie. The apps redirect users to browser pages distributing trojanized wallet versions designed to steal recovery phrases and private keys. The campaign leverages iOS provisioning profiles to install malware and has been active since at least fall 2025. The apps use typosquatting and fake promotional banners claiming official wallets are unavailable in the App Store. Kaspersky reported findings to Apple, and several malicious apps have been removed.
Half of the 6 Million Internet-Facing FTP Servers Lack Encryption
SecurityWeek reports that approximately 3 million of the 6 million internet-facing FTP servers lack encryption, exposing organizations to man-in-the-middle attacks, credential theft, and data interception. The continued use of the 50-year-old FTP protocol without encryption (FTPS or SFTP) creates unnecessary risk for file transfers.
Qilin's 2024 attack on NHS vendor continues to impact patient care for one NHS Trust
South London and Maudsley NHS Foundation Trust (SLaM) remains impacted by the June 2024 Qilin ransomware attack on Synnovis, with pathology systems still not restored as of April 2026. The trust operates in business continuity mode without electronic requesting or reporting, relying on paper processes and manual uploads. As of early January 2026, 161,560 pathology reports remained delayed for manual entry. Critical results are communicated by phone, with full reports delivered as paper or PDFs and manually uploaded into patient records. No pathology reports for SLaM patients are available in the London Care Record shared system.
ZionSiphon Malware Targets Israeli Water, Desalination OT Systems
Darktrace identified ZionSiphon, a new malware strain designed to target Israeli water treatment and desalination systems. The malware checks for Israeli IP ranges (2.52.0.0-2.55.255.255, 79.176.0.0-79.191.255.255, 212.150.0.0-212.150.255.255) and scans for OT-relevant services using Modbus, DNP3, and S7comm protocols. It attempts to modify chlorine doses and pressure parameters in water management systems. The malware contains politically motivated strings supporting Iran, Palestine, and Yemen and threatens to poison Tel Aviv and Haifa populations. However, the current sample contains a bug in the IP geolocation function that causes it to self-delete even on Israeli networks, preventing activation. The sample appeared on VirusTotal on June 29, 2025, after the Twelve-Day War between Iran and Israel.
AI vendors shrug off responsibility for vulnerabilities
Security researchers disclosed vulnerabilities in AI agents from Anthropic, Google, and Microsoft that integrate with GitHub Actions, allowing attackers to steal API keys and access tokens. All three vendors paid bug bounties (Anthropic $100, Google $1,337, GitHub $500) but did not assign CVEs or publish security advisories. Separately, researchers identified a design flaw in Anthropic's Model Context Protocol (MCP) affecting 200,000 servers, but Anthropic declined to patch the root issue, calling it "expected behavior." The flaw impacts 150 million downloads across software packages using MCP, with 10 high and critical CVEs issued for individual tools.
RoadK1ll Implant: Node.js-based reverse tunneling backdoor
Blackpoint Cyber identified RoadK1ll, a Node.js-based reverse tunneling implant that establishes outbound WebSocket connections to attacker infrastructure. Unlike traditional RATs, it carries no command set and requires no inbound listener. Its sole function is to convert a compromised machine into a controllable relay point for pivoting to internal systems and network segments unreachable from outside the perimeter.
Vercel discloses data breach following Context.ai compromise
Multiple cryptocurrency platforms suffered significant breaches. Kelp DAO was hacked for $292 million, the largest crypto heist of 2026 so far, through exploitation of a withdrawal vulnerability. Rhea Finance lost $18.4 million via vulnerabilities in its margin trading feature, with attackers preparing the attack days in advance by creating fake token pools.
April 2026 continues the pattern of supply chain compromise driving major breaches, with the Vercel incident demonstrating how third-party AI tools with broad OAuth permissions can become initial access vectors. The Context.ai compromise via Lumma Stealer, delivered through game exploit downloads, highlights the risk of employees using corporate credentials on untrusted software. Meanwhile, NIST's decision to stop enriching lower-priority CVEs reflects the 263% growth in vulnerability submissions, forcing organizations to adopt probabilistic scoring (EPSS) alongside CVSS. The ZionSiphon malware, though non-functional, signals increasing adversary interest in OT/ICS sabotage targeting critical infrastructure, following the pattern established by Stuxnet and NotPetya.