>samit_hota

Security News

Breach & incident coverage

Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.

500 stories published

SN-2026-284HighOpen

Google Password Manager Passkey Flaws Allow Silent Account Hijacking

Unit 42 research details three post-compromise attack paths against Chrome's Google Password Manager passkey authenticator on Windows TPM systems.

Aug 3, 2026
SN-2026-283HighMitigated

Liechtenstein Beneficial Ownership Register Breach Exposes 31,000 Entities

A cyberattack on Liechtenstein's Register of Beneficial Owners compromised data tied to 31,000 entities, triggering a government crisis response.

Aug 3, 2026
SN-2026-282HighOpen

Inside the Splintered Underground Market of the BTMOB Android RAT

Research into the BTMOB Android RAT reveals how a centralized malware-as-a-service operation fragmented into competing source-code sales and resellers.

Aug 3, 2026
SN-2026-281HighOpen

ExfilSquad Extorts UK Police Database, Leaking 135,000 Officer Contact Records

A cyberattack on the UK Police National Legal Database exposed contact details for over 100,000 officers and staff, claimed by ExfilSquad.

Aug 3, 2026
SN-2026-280HighOpen

Leaked DarkSword Exploit Kit Used by Chinese Group to Deploy GHOSTBLADE Spyware

Threat actors are leveraging the leaked DarkSword exploit kit to target iOS 18.4 through 18.7 devices with GHOSTBLADE spyware via credential phishing decoys.

Aug 3, 2026
SN-2026-279HighOpen

Brinks Home Data Breach: ShinyHunters Leaks 4.9M Salesforce Records

ShinyHunters has leaked 41GB of data stolen from Brinks Home's Salesforce instance after the physical security provider declined to pay a ransom.

Aug 3, 2026
SN-2026-278HighResolved

Hugging Face Diffusers Flaws Bypass Remote Code Safeguards

Three high-severity vulnerabilities in Hugging Face Diffusers allow malicious model repositories to execute arbitrary code despite safety checks.

Aug 3, 2026
SN-2026-277CriticalOpen

N-able N-central Auth Bypass Exploited in Wild After Incomplete Patch

Attackers are exploiting CVE-2026-18577 in N-able N-central servers to hijack managed endpoints and install persistent Cloudflare tunnels.

Aug 3, 2026
SN-2026-276InformationalOpen

OpenAI Teases Astra AI Model Built for Complex Workloads and Cryptography

OpenAI revealed Astra, a new AI model designed for long-running agentic tasks that solved 10 long-standing math and cryptographic challenges.

Aug 3, 2026
SN-2026-275CriticalMitigated

COLDCARD Hardware Wallet RNG Flaw Exploited to Steal $88 Million in Bitcoin

A firmware integration error in COLDCARD wallets caused fallback to a weak RNG, allowing attackers to precompute keys and drain $88.6 million in Bitcoin.

Aug 2, 2026
SN-2026-274InformationalOpen

OpenAI Previews Astra AI Model After Breakthroughs in Math and Lattice Cryptography

OpenAI has teased Astra, a multi-agent AI model family built for long-running reasoning, demonstrating major advances in math and lattice cryptography.

Aug 2, 2026
SN-2026-273MediumOpen

Google Chrome Moving to Block Local Policy Extension Hijackers

Google is testing a Chrome update that blocks local policy force-installs from hijacking default search engines and new tab pages on unmanaged devices.

Aug 2, 2026