>samit_hota

Security News

Breach & incident coverage

Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.

500 stories published

SN-2026-488CriticalOpen

Active Exploitation Targets WSO2 API Manager via Forged Admin JWT Tokens

Attackers are actively exploiting CVE-2026-5430 in WSO2 API Manager to bypass JWT signature verification and gain full administrative control.

Sep 16, 2026
SN-2026-487HighResolved

Google Patches Actively Exploited Pixel Modem Zero-Day CVE-2026-58704

Google releases September 2026 security updates for Pixel devices, patching active zero-day CVE-2026-58704 alongside 109 other vulnerabilities.

Sep 16, 2026
SN-2026-486HighOpen

CenterPoint Energy Confirms Breach After Threat Actor Leaks 7.5M Records

Texas utility CenterPoint Energy confirmed a breach of its external systems after a threat actor leaked customer data and threatened critical infrastructure.

Sep 16, 2026
SN-2026-485HighMitigated

CenterPoint Energy Confirms Data Breach After Hacker Leaks 7.5M Records

CenterPoint Energy confirmed a breach compromising customer data after a threat actor scraped 7.49 million records through an unprotected public API.

Sep 16, 2026
SN-2026-484CriticalMitigated

Cisco Secure Email Gateway Zero-Day Exploited to Execute Root Commands

Cisco has patched a critical AsyncOS zero-day (CVE-2026-76461) in Secure Email Gateway being actively exploited to execute arbitrary root commands.

Sep 15, 2026
SN-2026-483CriticalMitigated

Cisco Patches Actively Exploited Secure Email Gateway Zero-Day (CVE-2026-76461)

Cisco has patched CVE-2026-76461, an actively exploited SQL injection zero-day in Secure Email Gateway allowing root-level remote code execution.

Sep 15, 2026
SN-2026-482HighMitigated

Revolut Data Breach Exposes Passport Copies and Financial Records to Fake Agency

Fintech giant Revolut suffered a targeted data breach after compliance staff fulfilled fraudulent data requests sent from a government domain.

Sep 15, 2026
SN-2026-481HighMitigated

Revolut Tricked into Handing Sensitive Crypto Customer Data to Extortionists

Fraudsters exploited compromised government email accounts to file fake emergency data requests, stealing sensitive identity and financial data from Revolut.

Sep 15, 2026
SN-2026-480InformationalOpen

AWS Deception Benchmark Reveals Massive False-Positive Rates in AI Security Models

AWS released its public Deception Benchmark for AI vulnerability detection, revealing top LLMs fail production accuracy standards due to high false positives.

Sep 14, 2026
SN-2026-479InformationalResolved

Post-Breach Urgency Fades Within Months Despite High Risk Acceptance

A ManageEngine survey of 700 IT leaders reveals cybersecurity attention sharply recedes months after a breach, compounding systemic governance risks.

Sep 14, 2026
SN-2026-478HighOpen

Anthropic CEO Warns AI Agent Swarms Could Compromise Internet Infrastructure Within Months

Anthropic CEO Dario Amodei warns frontier AI models could orchestrate autonomous agent swarms capable of widespread network disruption within 6 to 12 months.

Sep 14, 2026
SN-2026-477CriticalMitigated

Tencent Patches Critical Sogou Input Method RCE Flaw Exploited by UNC3569

Threat actors are actively exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method to deploy GrayRabbit malware.

Sep 14, 2026