Federal agents in Atlanta stopped a guy at the airport, forced him to unlock his phone, and it self-wiped using GrapheneOS's built-in duress feature
The DOJ is now charging him with destroying evidence
🚨| BREAKING: FIFA World Cup’s official X account messaged Speed, confirming that his World Cup song “Champions” has been listed on the FIFA World Cup 2026 Official Album 🤯🤯🔥
This week in cybersecurity:
- cPanel auth bypass
- CopyFail linux privesc
- 89 vulnerabilities in XAPI / Citrix XenServer: https://t.co/xSk2oanqQN
- 17 vulnerabilities in Omi: https://t.co/anw75KngxH
- Thousands of vibe coded apps have their DBs publicly readable: https://t.co/R4yzkeQmxx
- Someone triggered the whole cybersecurity community by dropping that vuln for the sobriety app on X
Time for a new week, buckle up!
VERCEL GOT HACKED
ShinyHunters - the group behind the Ticketmaster breach - is selling Vercel's internal database for $2M on BreachForums
here's why every developer should care:
- they have NPM tokens and GitHub tokens
- Vercel owns Next.js - 6 million weekly downloads
- one malicious push = global supply chain attack
- Vercel confirmed the breach today, April 19
- they literally DMed the hackers on Telegram asking them to stop
rotate your env variables RIGHT NOW
Vercel was breached. Here’s what you need to know.
TLDR: The hacker group ShinyHunters says they are selling Vercel’s source code, database access, and API keys, including NPM and GitHub tokens for $2M. If this is true, millions of developers could be affected. Vercel has confirmed the breach. Change your secrets now.
What happened?
On Sunday, April 19, 2026, ShinyHunters posted on BreachForums, a popular site for stolen data, offering access to Vercel’s internal systems. This includes source code, database access, API keys, NPM tokens, and GitHub tokens.
ShinyHunters have carried out some of the biggest breaches in recent years. When they post something, it should be taken seriously.
A few hours later, Vercel released an official notice confirming that someone had accessed some of their internal systems without permission. They have brought in security experts, notified law enforcement, and say their services are still running for now.
Why should you care even if you don't use Vercel?
This matters because Vercel owns Next.js, a React framework with over 6 million weekly downloads. The attacker claimed that if they push a malicious update to Next.js, it could reach every developer who installs or updates the package.
This is not an exaggeration. It would be a supply chain attack, similar to what happened with SolarWinds in 2020 and 3CX in 2023. You do not have to be a Vercel customer to be affected. If your stack uses Next.js, you could be at risk.
What was allegedly taken
- Source code repositories
- Database access credentials
- Internal API keys
- NPM publish tokens
- GitHub access tokens
What Vercel is saying
Vercel’s incident page is cautious and vague, which is normal during an active investigation. They say only a limited group of customers was affected and are contacting them directly. They have not confirmed what was taken or denied the BreachForums claims.
In other words, Vercel likely knows more than they are sharing right now, which is normal in the first 24 hours after an incident.
What you should do right now
Go to your Vercel activity log and look for anything suspicious
Rotate every environment variable in your Vercel projects
Check any GitHub tokens or NPM tokens you've granted Vercel access to and revoke them
Pin your next package to a specific known-good version until this blows over
Bottom line
This situation is still unfolding. We do not yet know the full scope, what has been independently verified, or if a supply chain attack is actually happening. However, the threat is real, and if the attacker’s claims are true, this is a serious risk for a platform so important to the JS ecosystem.
Keep checking Vercel’s incident page and prepare for the worst until there is more information. This is not being paranoid; it is the safest approach in 2026.
This page will be updated as more information becomes available.
Why did Kraken list $M (Memecore) on July 3, 2025 for spot and how did it pass due diligence?
$7.9M in suspicious Kraken withdrawals to 18 newly created addresses with 11.7 $M sitting total (valued at $39.8M now).
Insiders have manipulated the price to $6B market cap ($18B FDV) and Kraken is one of the few venues that supports $M spot.
In recent posts the only achievement the team has shared is $66M total volume on a launchpad and thousands of “users” from its incentivized InfoFi campaigns.
Suspected Memecore team address 0x6f1f0a1ccc76d2d292249b19c19e401f0e843ba9 (received 200M M at TGE) sent 5.3M $M to Kraken deposit addresses on July 3, 2025 0xaa1f9fa46177aca98f5f433d88fe6d21d029c4a6 & 0x0ca854724259770a62dd623b6e9bce0151c79fa7
Kraken withdrawal addresses
0x4207e505c0dbab1e0d80a76a9ed42ef7b12bea17
0xba64b15f8afb9316b656ebdc19463786f33792d2
0x71dc4397b40055432be9f0e904681b151bec6eb0
0xacd7ec923efc5ff10ba1ddbe521b1a5536a1d70a
0x75ac45467d7df5bff47139af3887e408005ef637
0xfe28d786f007a5d5abd46e447e5758a20916a7d6
0x81475797b4b5d930a115ecd85a2c36cbc956a4f0
0x79d4411bba21289bb728f35221478e1b4eda1c96
0xdb0b0ab84b7e688db809379e8e8e70c020f7d0b2
0x94044c87aee7433725c13798816ab751ef6db9d7
0x7ca8c28c5e4e61c54ecf2631a43e37f88c589d61
0x067c40852576438c81b3649d8fec3d8d7ab27208
0xe2ef6d412a60a91af4e4f37db3efb6971099d98b
0x2c0365ef67c20cc9177e004b43a2d51ace28b5cb
0xaeee0e6b84e24431c1cf1424322e318debc67974
0x45039d2c98a3c7c1e2593dda1e77360e335c5aca
0x0b38bb1558f63c2b36382edd2385674b07697c59
0xff4cd9c291379a72e9efa3ee0f8e10ab51601575
Circle has resulted in $240M+ directly funding North Korea across multiple hacks when you had hours to act for a clear cut case.
How is that compliance for USDC?
Stop acting as if you represent permission-less values you are a centralized stablecoin issuer and publicly traded company with an admin button to freeze.
Do not forget the times US law enforcement sent you the same request as Paxos, Tether, Techteryx in relation to Lazarus Group and took 5 months longer to respond.
No law says you could not freeze and your terms of service say you can freeze.
“Internet-native financial activity” moves in minutes for incidents while the ask of a court order takes days.
Instead you freeze 16 business hot wallet for a US civil case due to TRO that had incorrect tracing.
Your blog post contradicts itself in many ways and it’s clear you a leadership problem.
Kenya 🇰🇪 - AfyaRekod has allegedly been breached, compromising the personally identifiable information of over 258k patients. Attackers are demanding a $150k ransom to prevent the sale of sensitive medical data. https://t.co/dGPFGZL07l