16 January 2026 — This morning HotCRP.com experienced a security breach. An attacker exploited an API vulnerability to download documents submitted by other authors to CCS 2026. The attacker was able to download submitted PDFs and attachments for approximately 500 papers before they were stopped.