>samit_hota

Security News

Breach & incident coverage

Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.

500 stories published

SN-2026-188HighOpen

Exploit Released for Unpatched GitLab RCE via Jupyter Notebook Diffs

A newly published PoC exploit allows low-privileged authenticated users to achieve Remote Code Execution as the git user on self-managed GitLab servers.

Jul 25, 2026
SN-2026-187MediumMitigated

OnTrac Parcel Delivery Discloses Customer Data Breach Following Network Hack

Regional parcel carrier OnTrac is notifying customers after an unauthorized network intrusion exposed personal delivery details.

Jul 24, 2026
SN-2026-186HighOpen

Hermes AI Agent Used to Automate Attack on Thai Ministry of Finance

Threat actors deployed the open-source Hermes AI agent in unattended mode to conduct automated post-exploitation activities against Thailand's Ministry of…

Jul 24, 2026
SN-2026-185HighOpen

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Prior to Malware Delivery

North Korean threat actor BlueNoroff is using fake Zoom and Teams platforms to profile victim crypto wallets before dropping malware payloads.

Jul 24, 2026
SN-2026-184HighOpen

Hackers Hijack Hotel Wi-Fi DNS Settings to Steal Microsoft 365 Credentials

Threat actors are altering DNS configurations on hotel Wi-Fi networks to redirect guests to fake Microsoft 365 authentication pages.

Jul 24, 2026
SN-2026-183CriticalOpen

Certighost Exploit Enables Domain Controller Impersonation via Misconfigured AD CS

A working Active Directory exploit named Certighost allows low-privileged users to request Domain Controller certificates and perform DCSync attacks.

Jul 24, 2026
SN-2026-182HighResolved

Network Maintenance Automation Bug Triggers Widespread Microsoft 365 Outage

A logic flaw in Microsoft's automated network maintenance system inadvertently stripped IP routes, causing widespread Azure and Microsoft 365 downtime.

Jul 24, 2026
SN-2026-181CriticalResolved

ChatGPT AgentForger Vulnerability Allowed Rogue AI Agent Deployment

Zenity Labs discovered a critical vulnerability in OpenAI ChatGPT Workspace Agents that permitted stealth deployment of rogue autonomous agents via a link.

Jul 24, 2026
SN-2026-180CriticalResolved

Crafted SVGs in Bing Image Search Allow SYSTEM Command Execution

A critical vulnerability in Microsoft Bing's image processing tier allowed crafted SVG uploads to execute arbitrary commands as SYSTEM and root.

Jul 24, 2026
SN-2026-179CriticalOpen

Clop Ransomware Group Targets PTC Windchill and FlexPLM Software

The Clop ransomware group is targeting Internet-exposed PTC Windchill and FlexPLM servers in a data exfiltration and extortion campaign.

Jul 24, 2026
SN-2026-178HighMitigated

NodeBB Patches Eight High-Severity Flaws Discovered by AI Agents

NodeBB released version 4.14.2 to fix eight high-severity vulnerabilities exposing admin privileges and private chats in versions prior to 4.14.0.

Jul 24, 2026
SN-2026-177HighMitigated

Australian Energy Provider Origin Confirms Customer Data Breach

Origin Energy has confirmed a data breach after an unauthorized party accessed and leaked sensitive customer PII online.

Jul 23, 2026