Cloud Provider

Industry

Cloud App Host Vercel Suffers Cyberattack

April 19, 2026

Cloud app host Vercel Inc. suffered a cyberattack in April involving unauthorized access to its systems, affecting “a limited subset of customers.”
“We’ve identified a security incident that involved unauthorized access to certain internal Vercel systems,” the company said in an advisory. “We are actively investigating, and we have engaged incident response experts to help investigate and remediate. We have notified law enforcement and will update this page as the investigation progresses.
Vercel is a cloud application company. It created and maintains the Next.js web development framework. Vercel provides developer tools, frameworks, and cloud infrastructure to build and maintain websites.

read more

Ingram Micro Cyberattack Triggers Multi-Day IT Outage and Major Revenue Losses

July 3, 2025

Ingram Micro, a global technology distributor and IT services company, suffered a cyberattack resulting in global outage and employees working from home. The attack knocked key IT systems offline — including ordering platforms like Xvantage and license management tools — which meant that customers and partners could not place, track or manage orders for IT products and services during the outage. The company restored many of the internal systems and platforms impacted by the attack within days and performed a company-wide password and Multi-Factor Authentication (MFA) reset to restore operations.

The SafePay ransomware gang threatened to leak 3.5TB of data on July 30, 2025.

read more

Widespread Attacks Target Microsoft SharePoint Zero-day Vulnerability

July 18, 2025

Several hacking groups with ties to the Chinese government have been linked to a recent wave of widespread attacks targeting a Microsoft SharePoint zero-day vulnerability chain. They used this exploit chain (dubbed “ToolShell”) to breach dozens of organizations worldwide after hacking into their on-premise SharePoint servers.

Dutch cybersecurity firm Eye Security first spotted zero-day attacks exploiting the CVE-2025-49706 and CVE-2025-49704 vulnerabilities (first demoed during the Berlin Pwn2Own hacking contest by Viettel Cyber Security researchers). The company told BleepingComputer that at least 54 organizations had already been compromised, including several multinational companies and national government entities.

read more

Massive Cyberattack Hits Salesforce Affecting 760 Companies

August 8, 2025

Extortion groups claim to have stolen over 1.5 billion Salesforce records from 760 companies. The breach led to unauthorized access to customer data stored within Salesforce instances integrated with the Salesloft Drift app. Customers who had integrated with the Salesloft Drift app and shared data with it were directly impacted.

The attacks were claimed by threat actors stating they are part of the ShinyHunters, Scattered Spider, and Lapsus$ extortion groups, now calling themselves “Scattered Lapsus$ Hunters.” Google tracks this activity as UNC6040 and UNC6395.

read more

CLickFix Compromises Websites of over 100 US Auto Dealerships

March 17, 2025

Websites of over 100 auto dealerships were found serving malicious ClickFix code in a supply chain compromise. A threat actor infected LES Automotive, a shared video service unique to dealerships. Websites using the video service would serve a ClickFix webpage to their visitors. The attack was using the fake reCAPTCHA variation of ClickFix, relying on PowerShell commands to deploy payloads on the victim’s machine, and ultimately infect them with the remote access trojan.

read more

Ransomware Attack at Oracle

April 2, 2025

Oracle Corporation confirmed a hacker broke into a computer system and stole old client log-in credentials. An unidentified person began attempting to sell data online that was stolen from Oracle’s cloud servers.

It is the second cybersecurity breach that the software company has acknowledged to clients in the last month. Oracle told customers that the data breach is separate from the hacking incident that it flagged to some healthcare customers last month.

read more

Ransomware Attack Disrupts Hitachi Vantara Operations

April 26, 2025

Hitachi Vantara experienced a ransomware incident on April 26. BleepingComputer reports that, while the company’s cloud services are not impacted, Hitachi Vantara systems and Hitachi Vantara Manufacturing were disrupted as part of the containment effort. Additionally, while Hitachi Vantara’s remote and support operations are down, customers with self-hosted environments can still access their data as usual. The attack has also affected multiple projects owned by government entities.

read more

Cyberattack Destroys Infrastructure of Russian Internet Provider Nodex

January 7, 2025

Russian internet provider Nodex’s network was destroyed in a cyberattack claimed by the Ukrainian Cyber Alliance. The attack resulted in significant service disruptions and data theft. Nodex confirmed the attack and began working on restoring services. The Ukrainian Cyber Alliance shared screenshots of hacked systems and data they allegedly stole.

read more

Volt Typhoon Compromises US Internet Companies

June 12, 2024

A Chinese hacking group exploited a software bug to compromise several internet companies in the United States and abroad, a cybersecurity firm said on Tuesday. The hackers took advantage of a previously unknown vulnerability in Versa Director – a software platform used to manage services for customers of Santa Clara, California-based Versa Networks. Reportedly four U.S. victims and one Indian victim had been identified, although they were not identified.

Lumen researcher Ryan English said that the internet companies were targeted for the attackers to surveil their customers. The hacking campaign kicked off as early as June 12, 2024. Reportedly Volt Typhoon hacked Singapore Telecommunications early that month as test run for further hacks against US communications companies.

read more