Subject: [Action Required] Fix for Windows Server Restart Loop (April Update)
Hi all,
This is a security advisory regarding a critical issue with the April 2026 Windows Server updates.
■ Overview Microsoft has released an out-of-band update to address a critical bug in the April 2026 security update (KB5082063). In certain environments, specifically domain controllers (DCs) using Privileged Access Management (PAM) within multi-domain forests, the update causes LSASS crashes leading to continuous reboot loops.
■ Scope - Windows Server Domain Controllers (DCs) in multi-domain forests utilizing Privileged Access Management (PAM).
■ Recommended Actions 1. Identify if your current DC infrastructure meets the affected criteria. 2. Apply the out-of-band fix provided by Microsoft promptly. 3. It is strongly recommended to validate the update in a staging/test environment before deploying to production to avoid potential downtime.
■ Reference - Microsoft Official Security Update Guide / KB5082063
Priority: High (Prompt action is recommended as this can render the entire domain unavailable).
Subject: [Security Notice] Beware of Phishing and SIM-Swap Attacks
Hi everyone,
Our IT security team would like to alert you to the activities of cybercrime groups using sophisticated phishing and "SIM-swap" techniques to steal sensitive information and assets.
How you can help: 1. Be cautious of suspicious emails or SMS messages. Avoid clicking unknown links or entering your credentials on unfamiliar sites. 2. If you currently use SMS-based two-factor authentication (2FA), we recommend switching to an authenticator app or a physical security key for better protection.
Please prioritize these security practices to keep your accounts safe.
Subject: [FYI] Threat Intelligence: Scattered Spider SIM-Swap and Phishing Campaigns
Hi all,
This is a security advisory regarding the threat actor known as "Scattered Spider."
■ Overview Scattered Spider utilizes a combination of advanced social engineering, phishing, and SIM-swapping (hijacking a target's phone number via mobile carriers) to bypass multi-factor authentication (MFA) and steal cryptocurrency or sensitive corporate data.
■ Scope - All users relying on SMS-based MFA - Accounts dependent on mobile carrier identity verification
■ Recommended Actions 1. Transition users from SMS-based MFA to FIDO2-compliant physical security keys or authenticator apps (TOTP). 2. Conduct security awareness training focusing on the risks of SIM-swapping and sophisticated phishing. 3. Audit MFA configurations for all privileged accounts to ensure robust authentication.
■ Reference - Related reports on Scattered Spider (e.g., The Register)
Priority: High (Prompt implementation of countermeasures is recommended)
Subject: [Security Advisory] Customer Credential Compromise at Vercel
Hi all,
This is a security notification regarding a recent incident involving Vercel.
■ Overview Vercel has reported a security incident where unauthorized access to internal systems led to the compromise of credentials for a limited subset of customers. The breach originated from a compromise of a third-party AI tool, Context.ai, where attackers exploited an OAuth integration used by a Vercel employee.
■ Scope - Vercel customer accounts and associated internal systems. - A limited subset of customers (those affected have been contacted directly by Vercel).
■ Required Actions 1. Verify if any organizational accounts have received direct notifications from Vercel regarding this breach. 2. For any affected or high-risk accounts, promptly rotate all credentials, including API keys, passwords, and authentication tokens. 3. Review and audit OAuth permissions granted to third-party applications to ensure the principle of least privilege.