>samit_hota

Security News

Breach & incident coverage

Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.

286 stories published

SN-2026-286HighOpen

Fake Roblox Xeno Script Launcher Delivers Multi-Stage Java RAT and Infostealer

Threat actors are distributing a trojanized Roblox Xeno script executor that drops a Java-based RAT capable of webcam spying and credential theft.

Aug 3, 2026
SN-2026-285HighOpen

DOUBLECUP ClickFix Service Hides Malware in Browser Cache Steganography

The DOUBLECUP ClickFix service uses browser cache steganography to infect Windows and macOS systems with CountLoader and DeviceManager RAT.

Aug 3, 2026
SN-2026-284HighOpen

Google Password Manager Passkey Flaws Allow Silent Account Hijacking

Unit 42 research details three post-compromise attack paths against Chrome's Google Password Manager passkey authenticator on Windows TPM systems.

Aug 3, 2026
SN-2026-283HighMitigated

Liechtenstein Beneficial Ownership Register Breach Exposes 31,000 Entities

A cyberattack on Liechtenstein's Register of Beneficial Owners compromised data tied to 31,000 entities, triggering a government crisis response.

Aug 3, 2026
SN-2026-282HighOpen

Inside the Splintered Underground Market of the BTMOB Android RAT

Research into the BTMOB Android RAT reveals how a centralized malware-as-a-service operation fragmented into competing source-code sales and resellers.

Aug 3, 2026
SN-2026-281HighOpen

ExfilSquad Extorts UK Police Database, Leaking 135,000 Officer Contact Records

A cyberattack on the UK Police National Legal Database exposed contact details for over 100,000 officers and staff, claimed by ExfilSquad.

Aug 3, 2026
SN-2026-280HighOpen

Leaked DarkSword Exploit Kit Used by Chinese Group to Deploy GHOSTBLADE Spyware

Threat actors are leveraging the leaked DarkSword exploit kit to target iOS 18.4 through 18.7 devices with GHOSTBLADE spyware via credential phishing decoys.

Aug 3, 2026
SN-2026-279HighOpen

Brinks Home Data Breach: ShinyHunters Leaks 4.9M Salesforce Records

ShinyHunters has leaked 41GB of data stolen from Brinks Home's Salesforce instance after the physical security provider declined to pay a ransom.

Aug 3, 2026
SN-2026-278HighResolved

Hugging Face Diffusers Flaws Bypass Remote Code Safeguards

Three high-severity vulnerabilities in Hugging Face Diffusers allow malicious model repositories to execute arbitrary code despite safety checks.

Aug 3, 2026
SN-2026-277CriticalOpen

N-able N-central Auth Bypass Exploited in Wild After Incomplete Patch

Attackers are exploiting CVE-2026-18577 in N-able N-central servers to hijack managed endpoints and install persistent Cloudflare tunnels.

Aug 3, 2026
SN-2026-276InformationalOpen

OpenAI Teases Astra AI Model Built for Complex Workloads and Cryptography

OpenAI revealed Astra, a new AI model designed for long-running agentic tasks that solved 10 long-standing math and cryptographic challenges.

Aug 3, 2026
SN-2026-275CriticalMitigated

COLDCARD Hardware Wallet RNG Flaw Exploited to Steal $88 Million in Bitcoin

A firmware integration error in COLDCARD wallets caused fallback to a weak RNG, allowing attackers to precompute keys and drain $88.6 million in Bitcoin.

Aug 2, 2026