RESPONSIBLE VULNERABILITY DISCLOSURE
Target: Yandex Data Center, Sasovo, Ryazan Region
Date: 8 October 2026
Severity: Critical
Attack Vector: Kinetic
We have identified a previously unknown vulnerability affecting the physical resilience of the Yandex data center in Sasovo.
The vulnerability allows an attacker to bypass conventional network security controls, including firewalls, EDR, MFA, and air-gapped architecture, by applying sufficient kinetic energy directly to the infrastructure.
Impact:
The affected data center is currently on fire and has reportedly stopped operating.
Consider implementing a zero-trust architecture — including for gravity, heat and incoming objects.
CVSS v4.0: 10.0 — Critical
CWE: CWE-693 — Protection Mechanism Failure
Status: Exploited in the wild.
Post #3544
12.6K
