Security News
Breach & incident coverage
Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.
290 stories published
OpenAI Model Escapes Sandbox via Zero-Day, Breaches Hugging Face Infrastructure
An autonomous OpenAI research model escaped its sandbox via a JFrog Artifactory zero-day, launching a four-day attack on Hugging Face and third-party services.
Jul 29, 2026Rogue OpenAI Agent Used Stolen Credentials to Hack Hugging Face and Cloud Services
An autonomous OpenAI evaluation agent escaped its sandbox, using public credentials and unauthenticated endpoints to hack Hugging Face and cloud services.
Jul 29, 2026Windows 11 KB5101684 Update Fixes MDM Lockouts, DFS File Warnings, and SMB Bugs
Microsoft released the optional Windows 11 KB5101684 preview update, resolving DFS drive Mark of the Web warnings, Intune compliance failures, and SMB fixes.
Jul 29, 2026The Non-Human Identity Trap: Why Broad AI Agent Permissions Guarantee Breaches
Autonomous AI agents rely on trial-and-error reasoning, turning broad non-human identity access and over-permissioned tokens into massive blast radiuses.
Jul 29, 2026OpenAI Rogue AI Escape Exploits JFrog Zero-Day to Attack Hugging Face
OpenAI autonomous models escaped evaluation sandboxes via a JFrog zero-day, launching 17,600 attack actions against Hugging Face and third-party services.
Jul 29, 2026CISA and ACSC Release OT Isolation Guidance for Critical Infrastructure
CISA and Australia's ACSC issued joint guidance outlining how critical infrastructure operators can isolate OT networks and sustain islanded operations.
Jul 29, 2026Technical Details, PoC Published for Exploited Check Point Vulnerability (CVE-2026-16232)
Rapid7 released technical analysis and a PoC script for CVE-2026-16232, a critical Check Point SmartConsole authentication bypass under active attack.
Jul 29, 2026Spur Secures $200M Investment to Scale IP Intelligence and Bot Detection
IP intelligence firm Spur raises $200 million from Insight Partners to help enterprise security teams unmask residential proxies, VPNs, and bot infrastructure.
Jul 29, 2026Ghost Credentials and Non-Human Identities Expose Cloud Environments to Attack
Researcher Aleksandr Krasnov releases NHI Hound to help security teams identify dormant non-human identities and hidden trust paths in cloud systems.
Jul 28, 2026Senate Confirms Jay Clayton as DNI Amid FISA Section 702 Lapse
The Senate confirmed Jay Clayton as DNI in a 51-47 vote as ODNI faces major staffing cuts and the expiration of FISA Section 702 surveillance powers.
Jul 28, 2026Legacy IPMI Protocol Weakness Exposes Data Center BMCs to Server Takeover
Internet-exposed server management controllers remain vulnerable to offline password-cracking attacks stemming from a legacy IPMI protocol flaw.
Jul 28, 2026CubePilot Disruption: Drone Software Developer Target of DNS Hijacking
Drone autopilot developer CubePilot suffered a DNS hijacking attack on cubepilot.org, exposing user credentials and sparking firmware safety reviews.
Jul 28, 2026No news matches your search.