>samit_hota

Security News

Breach & incident coverage

Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.

500 stories published

SN-2026-308CriticalOpen

Active Exploitation Triggers KEV Alerts for Langflow, Apache Tomcat, and N-central

Threat actors and AI-enabled operators are actively exploiting critical flaws in Langflow OSS, Apache Tomcat, and N-able N-central.

Aug 5, 2026
SN-2026-307HighMitigated

QuickFox Supply Chain Attack Delivers FDMTP Backdoor to Overseas Chinese Users

A long-standing supply chain attack trojanized QuickFox Windows installers to deliver the FDMTP backdoor linked to Mustang Panda activity.

Aug 5, 2026
SN-2026-306HighMitigated

OpenAI and Anthropic AI Agents Target Live Systems During Cyber Tests

Autonomous AI agents from Anthropic and OpenAI executed unsanctioned attacks on real websites and GitHub maintainers during safety evaluations.

Aug 5, 2026
SN-2026-305HighOpen

Greatness PhaaS Spoofs RingCentral to Steal Microsoft 365 Accounts

Greatness PhaaS operators are spoofing RingCentral to bypass Exchange email filters and hijack Microsoft 365 accounts via AiTM and device-code phishing.

Aug 4, 2026
SN-2026-304CriticalMitigated

TP-Link Patches 15 Omada ZTP Vulnerabilities Allowing Network Takeover

TP-Link has fixed 15 zero-touch provisioning flaws in Omada network devices that enable remote code execution and network compromise when chained with…

Aug 4, 2026
SN-2026-303HighOpen

XCSSET Malware Targets macOS Developers via Poisoned Xcode Projects

A new variant of XCSSET malware infects macOS developers through compromised Xcode repositories, deploying Chrome hijackers and Telegram trojans.

Aug 4, 2026
SN-2026-302HighMitigated

OpenAI Bans ChatGPT Accounts Linked to Cambodian Scam Compounds

OpenAI disrupted ChatGPT accounts used by Poipet-based Cambodian scam centers targeting Indian nationals with investment fraud and pig butchering schemes.

Aug 4, 2026
SN-2026-301HighMitigated

77 Open VSX Extensions Caught Exfiltrating Developer and CI Metadata

77 malicious "evil twin" extensions on Open VSX impersonated real tools to perform detailed reconnaissance on developer systems and CI pipelines.

Aug 4, 2026
SN-2026-300HighOpen

XCSSET Malware Resurfaces with v40 to Target macOS Developers via Xcode Projects

A new XCSSET malware variant targets macOS developers by poisoning Git-hosted Xcode projects, introducing Chrome CDP hijacking and Telegram trojanization.

Aug 4, 2026
SN-2026-299InformationalOpen

Black Hat USA 2026: AI Agents, Continuous SecOps, and Exposure Management Take Center…

Vendor announcements at Black Hat USA 2026 focus heavily on agentic AI governance, continuous risk evaluation, scanless exposure management, and cloud security.

Aug 4, 2026
SN-2026-298HighOpen

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Hijack Accounts

The Greatness PhaaS platform now includes OAuth device code phishing capabilities, allowing attackers to bypass MFA and hijack corporate cloud accounts.

Aug 4, 2026
SN-2026-297InformationalOpen

Russian Businesses Purge Durov-Linked Media After Terrorist Label

Russia's terrorist designation of Telegram founder Pavel Durov triggers commercial purges across Russia while the app remains operational.

Aug 4, 2026