>samit_hota

Security News

Breach & incident coverage

Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.

500 stories published

SN-2026-224CriticalMitigated

Technical Details, PoC Published for Exploited Check Point Vulnerability (CVE-2026-16232)

Rapid7 released technical analysis and a PoC script for CVE-2026-16232, a critical Check Point SmartConsole authentication bypass under active attack.

Jul 29, 2026
SN-2026-223InformationalResolved

Spur Secures $200M Investment to Scale IP Intelligence and Bot Detection

IP intelligence firm Spur raises $200 million from Insight Partners to help enterprise security teams unmask residential proxies, VPNs, and bot infrastructure.

Jul 29, 2026
SN-2026-222HighOpen

Ghost Credentials and Non-Human Identities Expose Cloud Environments to Attack

Researcher Aleksandr Krasnov releases NHI Hound to help security teams identify dormant non-human identities and hidden trust paths in cloud systems.

Jul 28, 2026
SN-2026-221HighOpen

Senate Confirms Jay Clayton as DNI Amid FISA Section 702 Lapse

The Senate confirmed Jay Clayton as DNI in a 51-47 vote as ODNI faces major staffing cuts and the expiration of FISA Section 702 surveillance powers.

Jul 28, 2026
SN-2026-220HighOpen

Legacy IPMI Protocol Weakness Exposes Data Center BMCs to Server Takeover

Internet-exposed server management controllers remain vulnerable to offline password-cracking attacks stemming from a legacy IPMI protocol flaw.

Jul 28, 2026
SN-2026-219CriticalMitigated

CubePilot Disruption: Drone Software Developer Target of DNS Hijacking

Drone autopilot developer CubePilot suffered a DNS hijacking attack on cubepilot.org, exposing user credentials and sparking firmware safety reviews.

Jul 28, 2026
SN-2026-218HighOpen

CISA and ACSC Issue CI Fortify Guidance for Isolating Critical OT Systems

CISA, ACSC, and Five Eyes partners release CI Fortify guidance urging critical infrastructure operators to prepare OT systems for physical isolation.

Jul 28, 2026
SN-2026-217InformationalResolved

Claude AI Breaks Post-Quantum HAWK-256 Target and Accelerates 7-Round AES Attacks

Anthropic's Claude Mythos Preview AI model derived an end-to-end key recovery for post-quantum candidate HAWK-256 and accelerated 7-round AES-128 cryptanalysis.

Jul 28, 2026
SN-2026-216HighOpen

Tengu Botnet Weaponizes Linux Hardware Watchdogs to Prevent Process Termination

The Tengu Mirai variant abuses hardware watchdogs to trigger system reboots when defenders kill its process, giving its persistence routines a second life.

Jul 28, 2026
SN-2026-215HighMitigated

'Certighost' Flaw in Active Directory Certificate Services Enables Domain Compromise

Microsoft patched 'Certighost,' a high-severity Active Directory Certificate Services vulnerability allowing privilege escalation and domain compromise.

Jul 28, 2026
SN-2026-214HighMitigated

PennKey SSO Breach Demonstrates the Blast Radius of Enterprise Identity Compromise

Threat actors compromised a PennKey SSO account to breach 1.2 million records, highlighting critical identity hardening and MFA defense requirements.

Jul 28, 2026
SN-2026-213HighResolved

Apple Patches CVE-2026-43810 and Hundreds of Flaws Across iOS and macOS

Apple has issued massive patch updates across iOS 26.6, macOS Tahoe 26.6, and legacy OS versions, addressing a dangerous remote kernel memory corruption flaw.

Jul 28, 2026