Category archive
Scam alerts
Track the latest scam alerts, fake support incidents, delivery fraud, payment scams and rapid verification guidance in one archive.
This landing page groups scam alerts into one indexable archive so users and Google can navigate the incident stream by topic instead of only by date, with stronger internal links into the right tools and recovery paths.
Filter the alert archive
Narrow the archive by category and risk level to review phishing alerts, data breach alerts, malware coverage, vulnerability updates and ransomware incidents faster.
Full alert archive
Showing 12 of 241 matching alerts.
Each alert card surfaces the threat type, documented summary and best next step so the listing itself can answer intent around latest cybersecurity alerts, phishing alerts, breach alerts and incident response without forcing every visitor to click through immediately.
Older alerts from 2021-2025 are still available, but stronger, documented and more recent reporting is ranked first so the archive stays aligned with current Google quality expectations.
Prompt Injection Flaws in Microsoft Copilot and Salesforce Agentforce Enable Data Exfiltration via Form Inputs
Human review: Marcin Pocztowski | Source date: Apr 15, 2026 | Sources: 1Security researchers have identified critical prompt injection vulnerabilities in Microsoft Copilot Studio and Salesforce Agentforce that allow attackers to embed mali... Documented alert summary. Focus: affected products, exploit urgency and remediation guidance.
Best next step: Identity Theft Recovery Planner
13 Critical Questions to Mitigate Third-Party Cybersecurity Risks
Human review: Artur Ślesik | Source date: Apr 15, 2026 | Sources: 1As organizations increasingly rely on third-party IT providers and software, their exposure to cyber threats expands significantly. This article consolidates expert in... Documented alert summary. Focus: lure pattern, spoofing signals and account-protection next steps.
Best next step: Identity Theft Recovery Planner
UK’s NCSC Declares Passkeys the Default Authentication Standard, Phasing Out Passwords
Human review: Artur Ślesik | Source date: Apr 23, 2026 | Sources: 2The UK’s National Cyber Security Centre (NCSC) has officially recommended passkeys as the default authentication method for businesses and consumers, citing passwords... Verified across 2 sources. Focus: lure pattern, spoofing signals and account-protection next steps.
Best next step: Crypto Scam Checker for Fake Investments and Recovery Fraud
Hackers Exploit Vercel’s Trust in AI Integration to Breach Internal Systems
Human review: Artur Ślesik | Source date: Apr 20, 2026 | Sources: 1In April 2026, a sophisticated cyberattack compromised Vercel’s internal systems through a third-party AI application, Context.ai, abusing OAuth permissions. The breac... Documented alert summary. Focus: exposed data, who may be affected and breach-response priorities.
Best next step: Crypto Scam Checker for Fake Investments and Recovery Fraud
CISA Alerts on Multiple Actively Exploited SimpleHelp Vulnerabilities in Remote Support Software
Human review: Marcin Pocztowski | Source date: Apr 25, 2026 | Sources: 3The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning about two actively exploited vulnerabilities in SimpleHelp remote support sof... Verified across 3 sources. Focus: extortion context, containment timing and recovery options.
Best next step: Identity Theft Recovery Planner
CISA Alerts on Actively Exploited CVE-2026-1340 Code Injection Vulnerability in Ivanti Endpoint Manager Mobile
Human review: Marcin Pocztowski | Source date: Apr 08, 2026 | Sources: 3CISA has confirmed active exploitation of CVE-2026-1340, a critical code injection flaw in Ivanti Endpoint Manager Mobile. Organizations using this software must apply... Verified across 3 sources. Focus: affected products, exploit urgency and remediation guidance.
Best next step: Identity Theft Recovery Planner
Firefox and Tor Browser IndexedDB Vulnerability Exposed Hidden User Identifiers
Human review: Marcin Pocztowski | Source date: Apr 27, 2026 | Sources: 2A medium-risk vulnerability affecting Firefox and Tor Browser allowed malicious actors to access hidden identifiers stored via IndexedDB, potentially compromising user... Verified across 2 sources. Focus: exposed data, who may be affected and breach-response priorities.
Best next step: Identity Theft Recovery Planner
Anthropic’s MCP Vulnerability Exposes Critical Risks in AI Agentic Infrastructure
Human review: Marcin Pocztowski | Source date: Apr 22, 2026 | Sources: 1A critical vulnerability in Anthropic’s Model Context Protocol (MCP) SDK has exposed millions of systems to remote code execution attacks, compromising sensitive data... Documented alert summary. Focus: affected products, exploit urgency and remediation guidance.
Best next step: Identity Theft Recovery Planner
LucidRook Malware Targets Taiwanese NGOs and Universities via Spear-Phishing
Human review: Marcin Pocztowski | Source date: Apr 09, 2026 | Sources: 2LucidRook, a Lua-based malware, has been identified in targeted spear-phishing attacks against NGOs and universities in Taiwan, raising alarms over potential data brea... Verified across 2 sources. Focus: lure pattern, spoofing signals and account-protection next steps.
Best next step: Identity Theft Recovery Planner
Apple Fixes iOS Vulnerability Exploited by FBI to Access Deleted Signal Messages
Human review: Artur Ślesik | Source date: Apr 23, 2026 | Sources: 12Apple's iOS 26.4.2 update patches a critical vulnerability that allowed the FBI to retrieve deleted messages from the Signal app. This article details the flaw, its ex... Verified across 12 sources. Focus: exposed data, who may be affected and breach-response priorities.
Best next step: Identity Theft Recovery Planner
Global Cyber Threats Surge with Identity Breaches and Supply Chain Attacks Escalating
Human review: Artur Ślesik | Source date: May 01, 2026 | Sources: 6Cybersecurity firms report a surge in coordinated attacks targeting identity data and supply chains, marking a shift toward organized, multi-stage cybercrime campaigns... Verified across 6 sources. Focus: lure pattern, spoofing signals and account-protection next steps.
Best next step: Crypto Scam Checker for Fake Investments and Recovery Fraud
Hackers Exploit Trojanized NFC Tap-to-Pay App to Clone Cards and Drain Accounts
Human review: Artur Ślesik | Source date: Apr 22, 2026 | Sources: 3A sophisticated cybercrime campaign targeting Android users in Brazil has been uncovered, where hackers trojanize a legitimate NFC-relay payment app, HandyPay, to stea... Verified across 3 sources. Focus: infection path, likely payload impact and containment priorities.
Best next step: Identity Theft Recovery Planner
Alerts archive SEO topics
Archive maintenance and remediation tracking. HackWatch does not treat alerts as one-time posts. We continue checking whether vendors have issued patches, workarounds or final remediation updates, then refresh the article with the latest incident status so readers can see whether a threat is still active, mitigated or already resolved.