>samit_hota

Security News

Breach & incident coverage

Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.

286 stories published

SN-2026-274InformationalOpen

OpenAI Previews Astra AI Model After Breakthroughs in Math and Lattice Cryptography

OpenAI has teased Astra, a multi-agent AI model family built for long-running reasoning, demonstrating major advances in math and lattice cryptography.

Aug 2, 2026
SN-2026-273MediumOpen

Google Chrome Moving to Block Local Policy Extension Hijackers

Google is testing a Chrome update that blocks local policy force-installs from hijacking default search engines and new tab pages on unmanaged devices.

Aug 2, 2026
SN-2026-272MediumOpen

Google Chrome Moving to Block Policy-Installed Extension Hijackers

Google is enabling a feature in Chrome to block forced policy extension installs that hijack search engines and New Tab pages on unmanaged devices.

Aug 2, 2026
SN-2026-271CriticalMitigated

Coldcard Hardware Wallet Seed Flaw Exploited in $70M Bitcoin Theft

A firmware integration error in Coinkite Coldcard hardware wallets allowed attackers to brute-force weak seeds and drain $70.2 million in Bitcoin.

Aug 1, 2026
SN-2026-270CriticalOpen

Critical Rails Active Storage Vulnerability CVE-2026-66066 Allows Server RCE

A critical Rails Active Storage vulnerability (CVE-2026-66066) allows remote file reads and code execution. Patches and workarounds are now available.

Aug 1, 2026
SN-2026-269CriticalMitigated

Ruby on Rails Patches Critical RCE Flaw CVE-2026-66066 in Active Storage

Ruby on Rails patched a critical 9.5 CVSS flaw in Active Storage (CVE-2026-66066) that allows file reads and unauthenticated remote code execution.

Aug 1, 2026
SN-2026-268InformationalResolved

Balance Theory Secures $19 Million Series A to Rationalize Enterprise Cyber Spending

Balance Theory has raised $19 million in Series A funding led by SYN Ventures to expand its cybersecurity investment management platform.

Aug 1, 2026
SN-2026-267CriticalMitigated

Ruby on Rails Patches Critical File Read and RCE Flaw in Active Storage

A critical vulnerability (CVE-2026-66066) in Ruby on Rails Active Storage allows unauthenticated arbitrary file reads and RCE. Patch and rotate secrets now.

Aug 1, 2026
SN-2026-266CriticalResolved

Adobe Patches Maximum-Severity CVSS 10.0 Zero-Click Flaw in Campaign Classic

Adobe has patched a maximum-severity CVSS 10.0 zero-click code execution vulnerability in Campaign Classic alongside fixes for SQL injection and Adobe Bridge.

Aug 1, 2026
SN-2026-265HighMitigated

Adform Supply-Chain Attack Poisons Script to Swap Crypto Wallet Addresses

Attackers compromised Adform's trackpoint-async.js script, inserting client-side clipper code to rewrite cryptocurrency wallet addresses on visiting browser…

Aug 1, 2026
SN-2026-264HighMitigated

Arch Linux Disables AUR Package Adoption Following Supply-Chain Malware Attacks

Arch Linux has suspended package adoption in the AUR after attackers hijacked unmaintained packages to distribute a Rust-based infostealer and SSH worm.

Jul 31, 2026
SN-2026-263HighOpen

Amgen Discloses Cloud Data Breach Exposing Patient Health Data

Biotech giant Amgen filed an SEC Form 8-K following a cloud breach that exposed patient protected health information and proprietary data.

Jul 31, 2026