>samit_hota

Security News

Breach & incident coverage

Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.

500 stories published

SN-2026-200InformationalMitigated

GitHub and PyPI Introduce New Rules to Counter Open Source Supply Chain Attacks

GitHub Dependabot adds a three-day cooldown on dependency PRs, while PyPI limits uploads to releases older than 14 days to curb software supply chain risk.

Jul 27, 2026
SN-2026-199HighOpen

ShinyHunters Claims Extortion of Ernst & Young Following ITSM Breach

The ShinyHunters extortion group claims it breached Ernst & Young via a supply-chain attack that compromised client tax files and internal systems.

Jul 27, 2026
SN-2026-198InformationalResolved

Beelzebub Secures $3.4 Million to Scale AI-Native Deception Platform

Beelzebub raises $3.4M in seed funding to expand its LLM-powered runtime deception and continuous adversary emulation security platform.

Jul 27, 2026
SN-2026-197HighOpen

Coca-Cola Confirms Data Breach Following Fairlife Ransomware Attack

Coca-Cola confirmed a data breach at dairy subsidiary Fairlife after an attack by the Anubis ransomware group forced production suspensions.

Jul 27, 2026
SN-2026-196HighOpen

Hacked Public Wi-Fi Gateways Exploited to Steal Corporate M365 Credentials

Threat actors are compromising public Wi-Fi gateway appliances to target traveling corporate personnel and steal Microsoft 365 credentials.

Jul 27, 2026
SN-2026-195HighOpen

TELESHIM Malware Abuses Telegram C2 in Middle East Government Attacks

Cyber-espionage actors linked to East Asia are targeting Middle Eastern government organizations using TELESHIM and custom malware controlled via Telegram.

Jul 27, 2026
SN-2026-194InformationalResolved

GitHub and PyPI Add Time-Based Defenses Against Supply Chain Attacks

GitHub Dependabot and PyPI introduce delayed update features to prevent automated pipelines from pulling newly published malicious package versions.

Jul 26, 2026
SN-2026-193MediumOpen

Steam Forum ClickFix Attacks Infect Gamers With XMRig Cryptominers

Attackers are abusing Steam discussion forums with ClickFix social engineering tricks, prompting gamers to execute PowerShell commands that drop XMRig.

Jul 25, 2026
SN-2026-192MediumOpen

ShinyHunters Data Breach Leaks Fuel $2,000 Sextortion Bitcoin Scam

Extortionists are using email addresses exposed in historical ShinyHunters data breaches to send personalized sextortion emails demanding $2,000 in Bitcoin.

Jul 25, 2026
SN-2026-191HighOpen

Malvertising Campaign Assembles Malware in Browser Memory via JavaScript

A malvertising campaign uses JavaScript on spoofed crypto and trading sites to assemble malware directly inside browser memory to bypass security filters.

Jul 25, 2026
SN-2026-190CriticalOpen

Unpatched Fastjson 1.x RCE Vulnerability Under Active Attack

Attackers are actively exploiting an unpatched remote code execution flaw in Fastjson 1.x (CVE-2026-16723) targeting Java Spring Boot deployments.

Jul 25, 2026
SN-2026-189HighMitigated

Rockwell Patches Code Execution Flaws in Arena Simulation Software

Rockwell Automation issued fixes for code execution vulnerabilities in its Arena simulation suite used across industrial environments.

Jul 25, 2026