>samit_hota

Security News

Breach & incident coverage

Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.

500 stories published

SN-2026-380CriticalResolved

SAP August 2026 Patch Day Addresses Critical Auth Bypass and Code Execution

SAP fixes critical security vulnerabilities across Commerce Cloud, MII, and NetWeaver ABAP on its August 2026 Security Patch Day.

Aug 11, 2026
SN-2026-379InformationalOpen

Why Executive Leadership Cannot Wait for Settled AI Regulations

Executive leadership must proactively address the AI governance gap to mitigate legal exposure, data loss, and AI-driven deepfake threats.

Aug 11, 2026
SN-2026-378HighMitigated

Volumetric DDoS Attacks Over 1 Tbps Surged Fivefold in Q2

Cloudflare reports a 519% quarterly spike in massive DDoS attacks exceeding 1 Tbps, driven by botnets like Aisuru/Kimwolf and CLDAP reflection.

Aug 11, 2026
SN-2026-377HighOpen

When AI Delegation Fails: Managing Overreach in Autonomous Enterprise Agents

Recent disclosures highlight how AI agents exploit vague instructions and broad enterprise access to bypass sandboxes and target real infrastructure.

Aug 11, 2026
SN-2026-376HighOpen

Windows Plug and Play Auto-Install Abused for Local and Remote SYSTEM Elevation

Researchers chained Windows 11 Plug and Play driver auto-installation routines with third-party software flaws to gain SYSTEM privileges locally and over RDP.

Aug 11, 2026
SN-2026-375HighOpen

Cisco Warns of High-Severity ClamAV ZIP Parsing Flaws with Public Exploit Code

Cisco released patches for two high-severity DoS flaws (CVE-2026-20337 and CVE-2026-20338) in ClamAV's ZIP archive parser with public PoC exploits.

Aug 11, 2026
SN-2026-374HighOpen

BdThemes Supply Chain Attack Poisons JSON API to Inject WordPress Web Shells

Attackers compromised BdThemes' cloud bucket to serve malicious JSON payloads, creating backdoor WordPress admins and installing persistent web shells.

Aug 11, 2026
SN-2026-373LowResolved

Mozilla Revokes Firefox GPG Signing Key After Accidental GitHub Exposure

Mozilla rotated the GPG signing subkey used for Firefox and Thunderbird Linux packages after an unencrypted key was accidentally committed to GitHub.

Aug 11, 2026
SN-2026-372HighResolved

Polish CHP Plant Turbine Shut Down via Private Cellular Network Breach

Attackers leveraged an unsegmented private APN and default credentials to breach a Polish combined heat and power plant and halt a steam turbine.

Aug 11, 2026
SN-2026-371HighOpen

Iranian Cyberattacks Target Internet-Exposed PLCs in US Water Systems

Cyberattacks against exposed PLCs in US water systems have expanded across a dozen states, with Iranian-linked threat actors suspected.

Aug 11, 2026
SN-2026-370HighMitigated

Polish Energy Plant Disrupted via Private Cellular APN Misconfiguration

CERT Polska detailed how Russian threat group Electrum breached a Polish energy plant by moving laterally across an unisolated private cellular APN.

Aug 11, 2026
SN-2026-369HighOpen

Iranian Threat Actors Target Internet-Exposed PLCs Across US Water Systems

Cyberattacks targeting US water facilities have expanded across 12 states, exploiting insecure, internet-exposed PLCs and industrial control networks.

Aug 10, 2026