>samit_hota

Security News

Breach & incident coverage

Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.

500 stories published

SN-2026-416InformationalResolved

Frontier AI Models Favor Offense Over Defense in New Cyber Benchmark

Benchmark tests show frontier AI models achieve an 85% attack success rate while detecting only 19% of intrusions, highlighting a critical defensive gap.

Aug 16, 2026
SN-2026-415HighMitigated

Framework Customer Data Exposed in Metabase Zero-Day Exploit

Laptop maker Framework notified customers of a data breach after attackers exploited a zero-day vulnerability in its Metabase reporting software.

Aug 16, 2026
SN-2026-414HighOpen

Evooo1Bot Linux Botnet Converts Edge Routers into SOCKS5 Proxy Relays

Fortinet discovered Evooo1Bot, a modular Mirai variant targeting edge routers to build SOCKS5 proxy networks and launch DDoS attacks.

Aug 16, 2026
SN-2026-413CriticalMitigated

ChainDrop Worm Infects 444 npm Packages via Tarball Manipulation

A new variant of the Shai-Hulud npm worm, dubbed ChainDrop, poisoned 444 packages by altering tarballs and abusing VS Code and Claude Code workspace hooks.

Aug 16, 2026
SN-2026-412CriticalMitigated

ChainDrop npm Worm Weaponizes Dev Tools and Tarballs in Massive Supply Chain Attack

A new Shai-Hulud variant named ChainDrop infected 444 npm packages, exploiting IDE execution hooks and direct tarball modification to evade repository scanning.

Aug 15, 2026
SN-2026-411InformationalOpen

Anthropic Outlines Plan for Invisible Claude AI Text Watermarking

Anthropic is rolling out invisible text watermarking across Claude LLM outputs globally to comply with EU AI Act content transparency requirements.

Aug 15, 2026
SN-2026-410CriticalOpen

Clop Targets Shell, GE, and Philips in Mass PTC Windchill Exploitation

Clop ransomware exploits CVE-2026-12569 in PTC Windchill and FlexPLM, targeting Shell, GE, and Philips to steal sensitive engineering data via webshells.

Aug 15, 2026
SN-2026-409HighOpen

ShinyHunters Leaks Personal Data of 1.6 Million RingCentral Accounts

RingCentral suffered a data breach exposing 1.6 million account records after ShinyHunters leaked stolen user details following a failed ransom demand.

Aug 15, 2026
SN-2026-408HighMitigated

Key Takeaways From Black Hat 2026: AI Supply Chains, NatJack, and Telemetry

Black Hat USA 2026 highlighted emerging risks in AI skills marketplaces, the NatJack NAT connection tracking attack, and modern supply chain telemetry.

Aug 14, 2026
SN-2026-407InformationalOpen

Weekly Infosec Roundup: New AI Security Gateways and Threat Exposure Tools

Overview of new security tools from A10 Networks, Searchlight Cyber, ScienceLogic, and DataGrout focusing on AI governance and threat exposure.

Aug 14, 2026
SN-2026-406HighMitigated

Trezor Data Breach Exposes Customer Details via ShipMonk Hack

A zero-day SQL injection in Metabase compromised logistics provider ShipMonk, exposing PII for nearly 14,000 Trezor crypto hardware wallet buyers.

Aug 14, 2026
SN-2026-405HighResolved

Microsoft Patches LegacyHive Windows Zero-Day Vulnerability CVE-2026-62832

Microsoft has patched CVE-2026-62832, a Windows User Profile Service zero-day known as LegacyHive that allowed local privilege escalation.

Aug 14, 2026