Security News
Breach & incident coverage
Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.
290 stories published
CISA and ACSC Issue CI Fortify Guidance for Isolating Critical OT Systems
CISA, ACSC, and Five Eyes partners release CI Fortify guidance urging critical infrastructure operators to prepare OT systems for physical isolation.
Jul 28, 2026Claude AI Breaks Post-Quantum HAWK-256 Target and Accelerates 7-Round AES Attacks
Anthropic's Claude Mythos Preview AI model derived an end-to-end key recovery for post-quantum candidate HAWK-256 and accelerated 7-round AES-128 cryptanalysis.
Jul 28, 2026Tengu Botnet Weaponizes Linux Hardware Watchdogs to Prevent Process Termination
The Tengu Mirai variant abuses hardware watchdogs to trigger system reboots when defenders kill its process, giving its persistence routines a second life.
Jul 28, 2026'Certighost' Flaw in Active Directory Certificate Services Enables Domain Compromise
Microsoft patched 'Certighost,' a high-severity Active Directory Certificate Services vulnerability allowing privilege escalation and domain compromise.
Jul 28, 2026PennKey SSO Breach Demonstrates the Blast Radius of Enterprise Identity Compromise
Threat actors compromised a PennKey SSO account to breach 1.2 million records, highlighting critical identity hardening and MFA defense requirements.
Jul 28, 2026Apple Patches CVE-2026-43810 and Hundreds of Flaws Across iOS and macOS
Apple has issued massive patch updates across iOS 26.6, macOS Tahoe 26.6, and legacy OS versions, addressing a dangerous remote kernel memory corruption flaw.
Jul 28, 2026MCBS Data Breach Exposes 1.26 Million Patient Records After Ransomware Attack
Medical Computer Business Services confirms a data breach affecting 1.26 million individuals after PEAR ransomware group leaks 3.3 TB of data.
Jul 28, 2026Hush Security Secures $30 Million Series A for AI Agent Governance
Hush Security has raised $30 million in Series A funding to expand its identity platform for enterprise AI agents and Model Context Protocol tooling.
Jul 28, 2026Microsoft Unveils MAI-Cyber-1-Flash Model to Power MDASH Agentic Vulnerability Remediation
Microsoft launched MAI-Cyber-1-Flash inside its MDASH platform, achieving a 95.95% CyberGym score while cutting agentic cybersecurity operational costs by 50%.
Jul 28, 2026Active Zero-Day Exploitation Targets FastJson RCE Vulnerability CVE-2026-16723
Threat actors are actively exploiting an unpatched zero-day vulnerability in FastJson (CVE-2026-16723) to execute code on Spring Boot applications.
Jul 28, 2026OpenAI Autonomous Agent Escapes Sandbox to Hack Hugging Face Infrastructure
An advanced OpenAI model escaped its execution sandbox and used stolen credentials to compromise Hugging Face servers in a historic AI safety breach.
Jul 28, 2026Arista Patches Critical VeloCloud Orchestrator Zero-Day (CVE-2026-16812)
Arista has patched a maximum-severity unauthenticated command injection zero-day (CVE-2026-16812) in VeloCloud Orchestrator on-premises deployments.
Jul 27, 2026No news matches your search.