Daily Recap, the week featured high-profile data breaches at Vercel and ANTS, a Seiko USA Shopify data claim, and misconfigured Perforce servers exposing sensitive data from major organizations. Ransomware, crypto threats, platform abuse, and regulation dominated headlines, including BlackCat/ALPHV and Scattered Spider activity, The Gentlemen using SystemBC, Lazarus/TraderTraitorβs KelpDAO heist, FakeWallet/SparkKitty on the Apple App Store, notable CVEs like SGLang CVE-2026-5760, Google Antigravity RCE risks, BridgeBreak flaws in Silex and Lantronix, and regulatory actions by the FTC and Italyβs data-protection authority.
#Vercel #LummaStealer #Mandiant #ANTS #SeikoUSA #Shopify #Perforce #BlackCat #ALPHV #AngeloMartino #ScatteredSpider #TheGentlemen #SystemBC #Lazarus #TraderTraitor #KelpDAO #rsETH #TornadoCash #FakeWallet #SparkKitty #AppleAppStore #Cisco #Zimbra #TeamCity #ActiveMQ #SGLang #CVE-2026-5760 #GGUF #GoogleAntigravity #BridgeBreak #Silex #Lantronix #Bluesky #Ofcom #Telegram #TeenChat #ChatAvenue #X #Athr #FTC #TakeItDownAct #Grok #PosteItaliane #Postepay #ItalyDataProtectionAuthority
#Vercel #LummaStealer #Mandiant #ANTS #SeikoUSA #Shopify #Perforce #BlackCat #ALPHV #AngeloMartino #ScatteredSpider #TheGentlemen #SystemBC #Lazarus #TraderTraitor #KelpDAO #rsETH #TornadoCash #FakeWallet #SparkKitty #AppleAppStore #Cisco #Zimbra #TeamCity #ActiveMQ #SGLang #CVE-2026-5760 #GGUF #GoogleAntigravity #BridgeBreak #Silex #Lantronix #Bluesky #Ofcom #Telegram #TeenChat #ChatAvenue #X #Athr #FTC #TakeItDownAct #Grok #PosteItaliane #Postepay #ItalyDataProtectionAuthority
Data Breaches
- Vercel was breached via a compromised third-party AI tool and Lumma Stealer, with attackers accessing internal environments and a limited set of customer secrets before the company notified users and brought in Mandiant and other experts β Vercel Breach, Lumma Attack, Weekly Recap
- French authorities said the ANTS portal breach may have exposed personal data from user accounts, increasing phishing and identity theft risk while investigations continue β ANTS Breach, French Agency
- Seiko USA was hit by a website defacement and extortion claim alleging theft of customer data from its Shopify backend, including names, emails, and shipping details β Seiko Deface
- Unsecured Perforce servers were found exposing sensitive data from major organizations, underscoring the risk of misconfigured code repositories and file sync systems β Perforce Leak
Ransomware & Cybercrime
- Former incident response negotiator Angelo Martino pleaded guilty to helping BlackCat/ALPHV operators extort U.S. companies by sharing victim leverage points and insurance limits β BlackCat Guilty
- Tyler Robert Buchanan pleaded guilty in the U.S. for roles in Scattered Spider attacks that used SMS phishing, SIM swapping, and Telegram exfiltration to steal cryptocurrency β Spider Plea
- The Gentlemen ransomware was reported using SystemBC to support bot-powered attacks and persistence β Gentlemen Ransomware
Crypto Threats
- Lazarus/TraderTraitor-linked attackers stole about $290 million from KelpDAO and related rsETH flows by abusing cross-chain infrastructure, with funds laundered through Tornado Cash and multiple partners investigating β Kelp Theft, KelpDAO Heist
- More than two dozen fake crypto apps in the Apple App Store were tied to FakeWallet/SparkKitty, stealing seed phrases and private keys through typosquatting and phishing β FakeWallet Apps, Apple Wallet Apps
Exploited Vulnerabilities
- CISA added 8 actively exploited vulnerabilities affecting Cisco, Zimbra, and TeamCity to its known exploited catalog β CISA KEV
- An actively exploited Apache ActiveMQ flaw was reported to impact about 6,400 servers, highlighting ongoing internet-wide exposure β ActiveMQ Flaw
- SGLang CVE-2026-5760 with a CVSS 9.8 score can enable remote code execution through malicious GGUF model files and prompt-injection payloads β SGLang RCE
- Researchers disclosed a sandbox-escape bug in Google Antigravity that could turn prompt injection into RCE by abusing file creation and native search tools β Antigravity Flaw
- BRIDGE:BREAK flaws in Silex and Lantronix serial-to-IP converters exposed OT and healthcare systems to unauthenticated RCE, firmware tampering, and device takeover β BridgeBreak Flaws
Platform Abuse & Outages
- Bluesky said a sophisticated DDoS attack disrupted feeds, notifications, threads, and search, though service stabilized and no user-data compromise was found β Bluesky Outage, Bluesky Attack
- Telegram, Teen Chat, Chat Avenue, and X are being probed by Ofcom over CSAM, grooming, and AI-generated explicit content concerns, with fines up to Β£18 million or 10% of global revenue possible β Ofcom Probe
- Athr markets an automated voice-phishing platform that can run callback scams for $4,000 plus a cut of proceeds, using spoofed alerts and AI voice agents to steal credentials and verification codes β ATHR Scam
AI, Fraud & Regulation
- The FTC is expanding enforcement of the Take It Down Act to target AI-enabled harms like nonconsensual deepfakes and voice-cloning scams, with Grok among potential scrutiny targets β FTC AI Action
- Poste Italiane and Postepay were fined more than β¬12.5 million by Italyβs data protection authority for unlawful processing of millions of usersβ data through intrusive app monitoring β Italian Fine, Privacy Penalty
- Coverage on stopping fraud at each stage of the customer journey emphasized reducing friction while improving identity and transaction controls β Fraud Controls
- AI deployment guidance stressed that successful production rollouts require real-world testing, integration, governance, and performance measurement beyond demos β AI Deployment