This cybersecurity brief for April 19, 2026, covers a series of high-impact incidents. A sophisticated supply chain attack compromised Vercel via a third-party AI tool, exposing customer credentials. A critical zero-day vulnerability in Microsoft Defender allowing full system takeover was disclosed with a public proof-of-concept. Meanwhile, ransomware activity remains intense, with groups like Shinyhunters claiming attacks on Zara and Aman Resorts, and law enforcement identifying key members of the defunct REvil and GandCrab gangs. These events underscore the persistent threats from supply chain vectors, unpatched vulnerabilities, and organized cybercrime.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.