>samit_hota

Security News

Breach & incident coverage

Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.

500 stories published

SN-2026-344CriticalMitigated

Metabase Zero-Day Exploited in Wild Grants Unauthenticated Admin Access

Metabase has patched a CVSS 10.0 zero-day SQL injection flaw impacting version 1.58+ that allows unauthenticated remote administrative access.

Aug 8, 2026
SN-2026-343MediumOpen

Water Utilities Partner with DEF CON Franklin to Launch Water Watch Center

The National Rural Water Association and DEF CON Franklin launched the Water Watch Center to provide free MDR and threat intelligence to rural utilities.

Aug 7, 2026
SN-2026-342CriticalMitigated

Metabase SQL Injection Zero-Day Exploited in Customer Data Theft Attacks

A critical unauthenticated Metabase SQL injection zero-day with a 10.0 CVSS score was exploited to steal customer data from Framework, Tally, and LexisNexis.

Aug 7, 2026
SN-2026-341CriticalMitigated

Nearly 800 Malicious npm Packages Deliver Cross-Platform RATs and Infostealers

A massive npm supply chain campaign uses AI-generated typosquatting packages to deploy cross-platform malware and Sliver C2 across dev environments.

Aug 7, 2026
SN-2026-340HighOpen

Meta Ordered to Pay $567M and Restrict Youth Usage in Landmark New Mexico Decision

A New Mexico judge ordered Meta to pay $567 million and enforce strict platform limits over harms to youth on Instagram and Facebook.

Aug 7, 2026
SN-2026-339HighMitigated

QuickFox VPN Supply Chain Compromise Delivers FDMTP Implant to Windows Users

Threat actors modified QuickFox VPN installers to profile Windows systems, skipping casual gamers to drop the FDMTP implant on dev and crypto hosts.

Aug 7, 2026
SN-2026-338HighOpen

Irregular AI Misconfigurations Exposed Internet Targets to Autonomous Hacking Models

Cybersecurity evaluation firm Irregular misconfigured testing sandboxes, allowing AI agents from Anthropic, OpenAI, and Meta to compromise real systems.

Aug 7, 2026
SN-2026-337HighMitigated

North Carolina Ports Cyberattack Disrupts Logistics at Wilmington and Inland Hubs

A major North Carolina Ports cyberattack caused systems-wide outages, delaying container gates and operations across Wilmington and Morehead City facilities.

Aug 7, 2026
SN-2026-336MediumMitigated

Levi Strauss Discloses Data Exfiltration Following Social Engineering Attack

Levi Strauss & Co. has disclosed a corporate data breach after social engineering attackers compromised three employee laptops to exfiltrate company files.

Aug 7, 2026
SN-2026-335HighOpen

Microsoft 365 AitM Phishing Campaign Targets Payroll and Finance Emails

Arctic Wolf details an M365 AitM phishing campaign using multi-stage redirects, residential proxies, and Graph API abuse to harvest payroll emails.

Aug 7, 2026
SN-2026-334HighOpen

UNC6671 Rebrands Vishing Extortion Operation After $10 Million Ransom Spree

Vishing group UNC6671 has rebranded from BlackFile to Redact, Pink, Helix, and Falcon, targeting M365 and Okta with AiTM MFA-bypass attacks.

Aug 7, 2026
SN-2026-333CriticalMitigated

Microsoft and Apple Patch Critical Cloud, Active Directory, and macOS Flaws

Microsoft patched multiple CVSS 10.0 flaws across Azure, Entra, and Teams, while Apple issued fixes for a macOS Screen Sharing authentication bypass.

Aug 7, 2026