>samit_hota

Security News

Breach & incident coverage

Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.

500 stories published

SN-2026-296InformationalOpen

CISO Conversation: Ping Identity's Russ Kirby on Leadership, Passion, and Pragmatism

Ping Identity CISO Russ Kirby shares insights on career progression, pragmatic incident response, and hiring enthusiastic security talent over certifications.

Aug 4, 2026
SN-2026-295HighOpen

Decades-Old IPMI Vulnerability Exposes Over 24,000 BMC Interfaces Online

A 20-year-old flaw in IPMI 2.0 (CVE-2013-4786) allows remote attackers to extract password hashes from internet-exposed server management interfaces.

Aug 4, 2026
SN-2026-294HighResolved

Google ADK Vulnerabilities Allowed Agent-to-Agent Prompt Injection and RCE

Security researchers discovered agent-to-agent prompt injection flaws in Google’s Agent Development Kit for Python, enabling remote code execution.

Aug 4, 2026
SN-2026-293InformationalMitigated

Microsoft Bug Bounty Program Payouts Top $20 Million as AI Research Accelerates

Microsoft paid over $20 million to security researchers between July 2025 and June 2026, driven by AI-assisted vulnerability research and supply chain bounties.

Aug 4, 2026
SN-2026-292HighOpen

Russian Hackers Hijack Hotel Wi-Fi Networks to Steal Microsoft 365 Accounts

Microsoft links the CaptiveCrunch campaign targeting hotel Wi-Fi to Midnight Blizzard, using custom Go and PowerShell malware to compromise M365 accounts.

Aug 4, 2026
SN-2026-291HighOpen

New York Allocates $9M for Water Sector Security Following Multi-State OT Attacks

New York awards $9 million to 153 water and wastewater utilities after a coordinated campaign targeted internet-exposed PLCs across multiple states.

Aug 4, 2026
SN-2026-290HighMitigated

Anthropic Claude Attacks Driven by System Over-Permissioning, Not Model Vulnerabilities

Anthropic reports recent security incidents involving Claude AI models were caused by over-permissioning and network access gaps rather than model flaws.

Aug 3, 2026
SN-2026-289CriticalOpen

N-able RMM Vulnerability Exploited to Grant Admin Privileges

Threat actors are actively exploiting a patch bypass flaw (CVE-2026-18577) in N-able RMM servers to gain unauthorized administrative access.

Aug 3, 2026
SN-2026-288InformationalOpen

Researchers Launch Tool to Trace AI-Generated Videos Back to Source

Security researchers have introduced a new detection tool aimed at tracing AI-generated video back to its source model and architecture.

Aug 3, 2026
SN-2026-287CriticalOpen

N-able RMM Servers Targeted via CVE-2026-18577 Authentication Bypass

Attackers are actively exploiting CVE-2026-18577, an authentication bypass flaw in N-able RMM servers, to gain administrative control.

Aug 3, 2026
SN-2026-286HighOpen

Fake Roblox Xeno Script Launcher Delivers Multi-Stage Java RAT and Infostealer

Threat actors are distributing a trojanized Roblox Xeno script executor that drops a Java-based RAT capable of webcam spying and credential theft.

Aug 3, 2026
SN-2026-285HighOpen

DOUBLECUP ClickFix Service Hides Malware in Browser Cache Steganography

The DOUBLECUP ClickFix service uses browser cache steganography to infect Windows and macOS systems with CountLoader and DeviceManager RAT.

Aug 3, 2026