Vercel Supply Chain Breach & Microsoft SharePoint Zero-Day – Weekly News Roundup

https://gbhackers.com/sap-patch-day-fixes-critical-flaws/
Here is the most recent Cybersecurity news for the past week:

☁️ Vercel Discloses Supply Chain Breach via Context.ai

Web infrastructure platform Vercel reported a security incident where attackers gained access to internal systems by compromising Context.ai, a third-party AI tool.The attackers exploited a Vercel employee’s Google Workspace OAuth account, successfully extracting non-sensitive customer environment variables, though Vercel noted that encrypted “sensitive” variables remained secure.

https://thehackernews.com/2026/04/vercel-breach-tied-to-context-ai-hack.html

🛡️ Microsoft Patches 167 Flaws and SharePoint Zero-Day

Microsoft released its April 2026 Patch Tuesday update, addressing a massive 167 security vulnerabilities.The most critical fix was for CVE-2026-32201, an actively exploited spoofing zero-day flaw in Microsoft SharePoint Server that allows unauthenticated attackers to view and manipulate sensitive data, prompting CISA to issue a strict patching deadline.

https://krebsonsecurity.com/2026/04/patch-tuesday-april-2026-edition/
https://krebsonsecurity.com/2026/04/patch-tuesday-april-2026-edition/

💸 Ameriprise Financial Reports Second Data Breach in Six Months

Financial services firm Ameriprise Financial filed a data breach notification revealing its second cybersecurity incident in less than six months. The breach, which occurred in early March 2026, exposed the names and personal identifiers of nearly 50,000 individuals, leading to multiple class-action lawsuit investigations regarding the company’s data privacy practices.

https://www.advisorhub.com/ameriprise-discloses-second-data-breach-in-less-than-six-months/

🚨 CISA Warns of Active Exploitation in Cisco Networking Devices

The Cybersecurity and Infrastructure Security Agency (CISA) has added three previously disclosed Cisco networking device vulnerabilities to its Known Exploited Vulnerabilities catalog.The advisory highlights active, in-the-wild exploitation of flaws like CVE-2026-20133, urging organizations to patch immediately to prevent unauthorized access to sensitive network traffic and configurations.

https://www.cybersecuritydive.com/news/cisa-cisco-vulnerabilities-sd-wan-confirm-exploitation/818064/

📚 McGraw Hill Confirms Data Breach Involving Millions of Records

Education publishing giant McGraw Hill confirmed a significant data breach stemming from a misconfigured Salesforce environment. While the company stated that no financial data or social security numbers were compromised, the threat actor group ShinyHunters claimed responsibility, exposing approximately 13.5 million unique email addresses alongside names and phone numbers.

newsletter signup

Our goal? To deliver the best cybersecurity insights you can read in five minutes or less — straight to your inbox, once a week.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

newsletter signup

Our goal? To deliver the best cybersecurity insights you can read in five minutes or less — straight to your inbox, once a week.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.