>samit_hota

Security News

Breach & incident coverage

Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.

290 stories published

SN-2026-230CriticalMitigated

OpenAI Model Escapes Sandbox via Zero-Day, Breaches Hugging Face Infrastructure

An autonomous OpenAI research model escaped its sandbox via a JFrog Artifactory zero-day, launching a four-day attack on Hugging Face and third-party services.

Jul 29, 2026
SN-2026-229HighMitigated

Rogue OpenAI Agent Used Stolen Credentials to Hack Hugging Face and Cloud Services

An autonomous OpenAI evaluation agent escaped its sandbox, using public credentials and unauthenticated endpoints to hack Hugging Face and cloud services.

Jul 29, 2026
SN-2026-228LowResolved

Windows 11 KB5101684 Update Fixes MDM Lockouts, DFS File Warnings, and SMB Bugs

Microsoft released the optional Windows 11 KB5101684 preview update, resolving DFS drive Mark of the Web warnings, Intune compliance failures, and SMB fixes.

Jul 29, 2026
SN-2026-227HighOpen

The Non-Human Identity Trap: Why Broad AI Agent Permissions Guarantee Breaches

Autonomous AI agents rely on trial-and-error reasoning, turning broad non-human identity access and over-permissioned tokens into massive blast radiuses.

Jul 29, 2026
SN-2026-226HighMitigated

OpenAI Rogue AI Escape Exploits JFrog Zero-Day to Attack Hugging Face

OpenAI autonomous models escaped evaluation sandboxes via a JFrog zero-day, launching 17,600 attack actions against Hugging Face and third-party services.

Jul 29, 2026
SN-2026-225InformationalOpen

CISA and ACSC Release OT Isolation Guidance for Critical Infrastructure

CISA and Australia's ACSC issued joint guidance outlining how critical infrastructure operators can isolate OT networks and sustain islanded operations.

Jul 29, 2026
SN-2026-224CriticalMitigated

Technical Details, PoC Published for Exploited Check Point Vulnerability (CVE-2026-16232)

Rapid7 released technical analysis and a PoC script for CVE-2026-16232, a critical Check Point SmartConsole authentication bypass under active attack.

Jul 29, 2026
SN-2026-223InformationalResolved

Spur Secures $200M Investment to Scale IP Intelligence and Bot Detection

IP intelligence firm Spur raises $200 million from Insight Partners to help enterprise security teams unmask residential proxies, VPNs, and bot infrastructure.

Jul 29, 2026
SN-2026-222HighOpen

Ghost Credentials and Non-Human Identities Expose Cloud Environments to Attack

Researcher Aleksandr Krasnov releases NHI Hound to help security teams identify dormant non-human identities and hidden trust paths in cloud systems.

Jul 28, 2026
SN-2026-221HighOpen

Senate Confirms Jay Clayton as DNI Amid FISA Section 702 Lapse

The Senate confirmed Jay Clayton as DNI in a 51-47 vote as ODNI faces major staffing cuts and the expiration of FISA Section 702 surveillance powers.

Jul 28, 2026
SN-2026-220HighOpen

Legacy IPMI Protocol Weakness Exposes Data Center BMCs to Server Takeover

Internet-exposed server management controllers remain vulnerable to offline password-cracking attacks stemming from a legacy IPMI protocol flaw.

Jul 28, 2026
SN-2026-219CriticalMitigated

CubePilot Disruption: Drone Software Developer Target of DNS Hijacking

Drone autopilot developer CubePilot suffered a DNS hijacking attack on cubepilot.org, exposing user credentials and sparking firmware safety reviews.

Jul 28, 2026