>samit_hota

Security News

Breach & incident coverage

Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.

290 stories published

SN-2026-050CriticalMitigated

Dell BIOS Flaw (CVE-2026-40639) Exposes Admin Passwords

A critical vulnerability in Dell BIOS allows attackers to recover administrator and user passwords from SPI flash in milliseconds due to a broken encryption…

Jul 12, 2026
SN-2026-049HighOpen

Exposed Hacker Server Reveals WP SHELLSTORM Backdooring Thousands of WordPress Sites

An exposed cybercrime server linked to WP SHELLSTORM has revealed the compromise of thousands of WordPress sites through outdated plugins and injected…

Jul 11, 2026
SN-2026-048CriticalMitigated

Malicious JScrambler npm Package Release Drops Rust Infostealer During Install

Version 8.14.0 of the JScrambler npm package was compromised to silently deploy a native Rust-based infostealer during installation across Windows, macOS, and…

Jul 11, 2026
SN-2026-047HighOpen

Sophos Flags New Vect-TeamPCP Cybercriminal Alliance for Ransomware Attacks

Sophos X-Ops has uncovered a new alliance between the ransomware group Vect and cybercriminal outfit TeamPCP, combining their expertise for efficient…

Jul 11, 2026
SN-2026-046HighOpen

Exposed Hacker Server Reveals WP SHELLSTORM Backdooring Thousands of WordPress Sites

An exposed cybercrime server linked to WP SHELLSTORM has revealed the compromise of thousands of WordPress sites through outdated plugins and injected…

Jul 11, 2026
SN-2026-045HighOpen

WeedHack Malware Offered as Service, Targets Minecraft Users with Info-Stealing…

A new malware-as-a-service, "WeedHack," is being distributed disguised as Minecraft clients or mods to steal system information, passwords, and other…

Jul 11, 2026
SN-2026-044CriticalOpen

Critical Authentication Bypass Actively Exploited in Gitea Docker Image

Attackers are leveraging a critical authentication bypass vulnerability within the official Gitea Docker image to hijack instances and impersonate users.

Jul 11, 2026
SN-2026-043CriticalResolved

Critical Linux Kernel FUSE Page Cache Overflow (CVE-2026-31694) Enables Root Access

A critical local privilege escalation (LPE) vulnerability in the Linux kernel's FUSE subsystem allows unprivileged local attackers to gain root privileges.

Jul 11, 2026
SN-2026-042HighOpen

Novo Nordisk Confirms Breach, AI/ML Asset Theft Claimed by FulcrumSec

Novo Nordisk confirmed a breach and data exfiltration, with FulcrumSec claiming theft of proprietary AI models and research assets.

Jul 11, 2026
SN-2026-041CriticalOpen

Critical Unauthenticated RCE (CVE-2026-46817) in Oracle EBS Payments Actively Exploited

A critical unauthenticated Remote Code Execution (RCE) vulnerability in Oracle E-Business Suite Payments module is under active exploitation.

Jul 11, 2026
SN-2026-040HighOpen

U.S. DHS Homeland Security Information Network (HSIN) Compromised

The U.S. Department of Homeland Security's HSIN, a platform for interagency coordination, was compromised by an unidentified threat actor.

Jul 11, 2026
SN-2026-039HighOpen

Instructure Suffers Data Breach by ShinyHunters, Affecting Millions of Users

Edtech giant Instructure, behind the Canvas LMS, experienced a data breach with ShinyHunters accessing user data and defacing pages.

Jul 11, 2026