LIVE FEED
Boston Scientific CEO Mike Mahoney told investors September 11 the company still cannot quantify its cyberattack costs; hospitals placed contingent orders elsewhere while plants and distribution centers were shut down globally Boston Scientific's September 8 Item 1.05 8-K: the August 25 incident is likely material to Q3 and full year 2026 results, guidance update due October 28 CISA advisory ICSMA-26-253-01: three high severity flaws in NextGen Healthcare's Mirth Connect, patched in version 4.7.2 CISA advisory ICSMA-26-253-02: integer overflow in Orthanc DICOM Server, CVE-2026-87020, fixed in version 1.13.0 CRA Article 14 reporting obligations took effect September 11; ENISA's Single Reporting Platform still has no API and no Article 15 voluntary track FDA docket FDA-2026-N-7874 on generative AI enabled devices remains open; comments due October 19 Boston Scientific CEO Mike Mahoney told investors September 11 the company still cannot quantify its cyberattack costs; hospitals placed contingent orders elsewhere while plants and distribution centers were shut down globally Boston Scientific's September 8 Item 1.05 8-K: the August 25 incident is likely material to Q3 and full year 2026 results, guidance update due October 28 CISA advisory ICSMA-26-253-01: three high severity flaws in NextGen Healthcare's Mirth Connect, patched in version 4.7.2 CISA advisory ICSMA-26-253-02: integer overflow in Orthanc DICOM Server, CVE-2026-87020, fixed in version 1.13.0 CRA Article 14 reporting obligations took effect September 11; ENISA's Single Reporting Platform still has no API and no Article 15 voluntary track FDA docket FDA-2026-N-7874 on generative AI enabled devices remains open; comments due October 19
Wednesday, September 16, 2026 Issue #454  ·  Est. 2025
Independent brief for device makers
Boston Scientific cannot yet quantify cyberattack costs, CEO says
VULNERABILITY ANALYSIS // MEDDEVICE CYBER
Threat Intel

Boston Scientific cannot yet quantify cyberattack costs, CEO says

Boston Scientific CEO Mike Mahoney told the Wells Fargo Healthcare Conference on September 11 that all of the company's plants and distribution centers were shut down globally during its August cyberattack, and that it still cannot pinpoint a dollar impact ahead of the October 28 earnings call.

02
Threat Intel
Six months later, Stryker's cyberattack still costs $45M a quarter

Stryker CFO Preston Wells told the Wells Fargo Healthcare Conference on September 10 that the March cyberattack will cost 70 to 80 basis points of third quarter sales, about $45 million, concentrated in the peripheral vascular unit built from the Inari Medical acquisition. Shares fell more than 10 percent for the week.

5 days ago  ·  2 min read  ·  Via MassDevice
THREAT
PULSE
Sep 11
CRA Reporting Begins
24h
Exploited Vuln Early Warning
4
DICOM Stack Advisories 2026
455
Healthcare Ransomware 2025
Browse by Threat
CISA KEV · MITRE EMB3D · ATT&CK · CWE

Latest Intelligence

Updated 5 days ago
Policy
ENISA named the coordinating CSIRTs a week before CRA reporting starts

ENISA updated its list of CSIRTs designated as coordinators on September 4, 2026, covering all 27 member states, one week before Article 14 reporting obligations apply on September 11. The Single Reporting Platform launches with no API and no support for voluntary reporting under Article 15. Registration runs through EU Login with multi factor authentication, and platform downtime does not pause the 24 hour clock.

ENISASep 43 min read
Vulnerability
Philips reports no product impact from Next.js flaw CVE-2026-75604

Philips published a September 4 advisory for CVE-2026-75604, a Next.js path traversal scored 9.0 that lets remote requests read private build data on Windows hosts and reach remote code execution. Versions 13.4.0 through 15.5.23 and 16.0.0 through 16.3.2 are affected, and Vercel fixed it in 15.5.24 and 16.3.3. Philips says no Philips products are known to be impacted at this time.

Philips Product SecuritySep 43 min read
Threat Intel
Attackers chain two SonicWall SMA1000 flaws into unauthenticated RCE

SonicWall disclosed CVE-2026-83548, a pre-authentication SSRF in SMA1000 appliances with a base score of 10.0, and CVE-2026-83549, an OS command injection, on September 1. Attackers chained them in the wild before disclosure. CISA added both to the KEV catalog September 3; hotfixes 12.4.3-03526 and 12.5.0-02952 fix them.

SonicWall PSIRTSep 43 min read
Threat Intel
Boston Scientific restores shipping for most products nine days after detection

Boston Scientific said in a September 3, 2026 update that it has begun restoring shipping capabilities for the majority of its products at its major distribution centers globally. The company reports growing confidence that the unauthorized access was limited to select internal-facing IT infrastructure, with no unauthorized activity detected since August 25. Whether personal data was compromised is still under investigation.

Boston ScientificSep 33 min read
Threat Intel
Novocure says attackers entered through a subsidiary and reached patient IDs

Novocure disclosed in a September 1, 2026 SEC filing that attackers accessed some of its information systems in mid-August after entering through a subsidiary. Internal ID numbers for more than 1,400 US patients were exposed, along with identifying information for fewer than 50 patients in the western United States. The company filed under Item 8.01, says no medical treatment devices were reached, and reports all systems fully functional.

SEC filingSep 13 min read
Enforcement
DaVita agrees to pay up to $15 million over the Interlock ransomware attack

A federal court in Colorado granted preliminary approval on August 21, 2026 to a settlement of up to $15 million in Jenkins et al. v. DaVita Inc., resolving class litigation over the April 12, 2025 Interlock ransomware attack that compromised data on 2,689,826 dialysis patients. Class members can claim up to $2,500 in documented losses plus a cash payment expected near $50.

HIPAA JournalSep 12 min read
Vendor & Market
Sponsored

AI-Native Medical Device Pentesting and Vulnerability Management.

From the directory

Armis  ·  Asimily  ·  Blue Goat Cyber  ·  Claroty (Team82)  ·  Cybellum  ·  Finite State  ·  MedCrypt  ·  MedSec  ·  Ordr  ·  Promenade Software  ·  Sequoia (GDT)

Browse the vendor directory →