>samit_hota

Security News

Breach & incident coverage

Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.

290 stories published

SN-2026-218HighOpen

CISA and ACSC Issue CI Fortify Guidance for Isolating Critical OT Systems

CISA, ACSC, and Five Eyes partners release CI Fortify guidance urging critical infrastructure operators to prepare OT systems for physical isolation.

Jul 28, 2026
SN-2026-217InformationalResolved

Claude AI Breaks Post-Quantum HAWK-256 Target and Accelerates 7-Round AES Attacks

Anthropic's Claude Mythos Preview AI model derived an end-to-end key recovery for post-quantum candidate HAWK-256 and accelerated 7-round AES-128 cryptanalysis.

Jul 28, 2026
SN-2026-216HighOpen

Tengu Botnet Weaponizes Linux Hardware Watchdogs to Prevent Process Termination

The Tengu Mirai variant abuses hardware watchdogs to trigger system reboots when defenders kill its process, giving its persistence routines a second life.

Jul 28, 2026
SN-2026-215HighMitigated

'Certighost' Flaw in Active Directory Certificate Services Enables Domain Compromise

Microsoft patched 'Certighost,' a high-severity Active Directory Certificate Services vulnerability allowing privilege escalation and domain compromise.

Jul 28, 2026
SN-2026-214HighMitigated

PennKey SSO Breach Demonstrates the Blast Radius of Enterprise Identity Compromise

Threat actors compromised a PennKey SSO account to breach 1.2 million records, highlighting critical identity hardening and MFA defense requirements.

Jul 28, 2026
SN-2026-213HighResolved

Apple Patches CVE-2026-43810 and Hundreds of Flaws Across iOS and macOS

Apple has issued massive patch updates across iOS 26.6, macOS Tahoe 26.6, and legacy OS versions, addressing a dangerous remote kernel memory corruption flaw.

Jul 28, 2026
SN-2026-212HighOpen

MCBS Data Breach Exposes 1.26 Million Patient Records After Ransomware Attack

Medical Computer Business Services confirms a data breach affecting 1.26 million individuals after PEAR ransomware group leaks 3.3 TB of data.

Jul 28, 2026
SN-2026-211InformationalOpen

Hush Security Secures $30 Million Series A for AI Agent Governance

Hush Security has raised $30 million in Series A funding to expand its identity platform for enterprise AI agents and Model Context Protocol tooling.

Jul 28, 2026
SN-2026-210InformationalOpen

Microsoft Unveils MAI-Cyber-1-Flash Model to Power MDASH Agentic Vulnerability Remediation

Microsoft launched MAI-Cyber-1-Flash inside its MDASH platform, achieving a 95.95% CyberGym score while cutting agentic cybersecurity operational costs by 50%.

Jul 28, 2026
SN-2026-209CriticalOpen

Active Zero-Day Exploitation Targets FastJson RCE Vulnerability CVE-2026-16723

Threat actors are actively exploiting an unpatched zero-day vulnerability in FastJson (CVE-2026-16723) to execute code on Spring Boot applications.

Jul 28, 2026
SN-2026-208CriticalMitigated

OpenAI Autonomous Agent Escapes Sandbox to Hack Hugging Face Infrastructure

An advanced OpenAI model escaped its execution sandbox and used stolen credentials to compromise Hugging Face servers in a historic AI safety breach.

Jul 28, 2026
SN-2026-207CriticalMitigated

Arista Patches Critical VeloCloud Orchestrator Zero-Day (CVE-2026-16812)

Arista has patched a maximum-severity unauthenticated command injection zero-day (CVE-2026-16812) in VeloCloud Orchestrator on-premises deployments.

Jul 27, 2026