>samit_hota

Security News

Breach & incident coverage

Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.

500 stories published

SN-2026-044CriticalOpen

Critical Authentication Bypass Actively Exploited in Gitea Docker Image

Attackers are leveraging a critical authentication bypass vulnerability within the official Gitea Docker image to hijack instances and impersonate users.

Jul 11, 2026
SN-2026-043CriticalResolved

Critical Linux Kernel FUSE Page Cache Overflow (CVE-2026-31694) Enables Root Access

A critical local privilege escalation (LPE) vulnerability in the Linux kernel's FUSE subsystem allows unprivileged local attackers to gain root privileges.

Jul 11, 2026
SN-2026-042HighOpen

Novo Nordisk Confirms Breach, AI/ML Asset Theft Claimed by FulcrumSec

Novo Nordisk confirmed a breach and data exfiltration, with FulcrumSec claiming theft of proprietary AI models and research assets.

Jul 11, 2026
SN-2026-041CriticalOpen

Critical Unauthenticated RCE (CVE-2026-46817) in Oracle EBS Payments Actively Exploited

A critical unauthenticated Remote Code Execution (RCE) vulnerability in Oracle E-Business Suite Payments module is under active exploitation.

Jul 11, 2026
SN-2026-040HighOpen

U.S. DHS Homeland Security Information Network (HSIN) Compromised

The U.S. Department of Homeland Security's HSIN, a platform for interagency coordination, was compromised by an unidentified threat actor.

Jul 11, 2026
SN-2026-039HighOpen

Instructure Suffers Data Breach by ShinyHunters, Affecting Millions of Users

Edtech giant Instructure, behind the Canvas LMS, experienced a data breach with ShinyHunters accessing user data and defacing pages.

Jul 11, 2026
SN-2026-038HighOpen

CISA Adds Actively Exploited iCagenda and Balbooa Forms Vulnerabilities to KEV Catalog

CISA has added two new unrestricted file upload vulnerabilities in iCagenda and Balbooa Forms to its Known Exploited Vulnerabilities Catalog due to active…

Jul 11, 2026
SN-2026-037HighOpen

SR Bancorp Vendor Mercadien Suffers Data Breach Exposing Somerset Regal Bank Customer Data

SR Bancorp's vendor, Mercadien, P.C. CPAs, experienced a data breach exposing sensitive Somerset Regal Bank customer information including SSNs and account…

Jul 11, 2026
SN-2026-036HighOpen

Argentine Football Association Suffers Database Breach Triggered by Infostealer Malware

The Argentine Football Association experienced a significant cyberattack leading to database leaks and unauthorized communications, likely due to infostealer…

Jul 11, 2026
SN-2026-035HighOpen

Frontier Airlines Discloses Data Breach Exposing Customer Social Security Numbers

Frontier Airlines confirmed a data breach on or about July 9, 2026, affecting customers with potentially exposed Social Security numbers.

Jul 11, 2026
SN-2026-034CriticalOpen

Progress Software Urges ShareFile Customers to Shut Down Storage Zone Controllers Over…

Progress Software issued an urgent advisory for ShareFile customers to shut down on-premises Storage Zone Controllers due to a credible security threat.

Jul 11, 2026
SN-2026-033HighResolved

CISA Discloses Internal AWS GovCloud Credential Leak and Lack of Incident Response Plan

CISA revealed a contractor exposed AWS GovCloud credentials on GitHub, highlighting the agency's unpreparedness with its own incident response playbook.

Jul 11, 2026