We checked 100+ top device makers for public security advisories. Most have nothing
About 25 of 110 publish real advisory listings. Thirty more post a policy page and an inbox. The rest, over 40 companies, have no public disclosure surface at all.
Academic studies, lab findings, and coordinated disclosures shaping how the industry measures device risk.
About 25 of 110 publish real advisory listings. Thirty more post a policy page and an inbox. The rest, over 40 companies, have no public disclosure surface at all.
Published CVEs hit roughly 40,000 in 2024, the largest single-year jump on record, and AI-assisted discovery is pushing the curve steeper. For device makers, the bottleneck moved from finding flaws to dispositioning them.
ECRI's annual hazard list put misuse of AI chatbots at number one for 2026 and legacy medical device cybersecurity at number eight, tying both directly to patient harm.
A JAMA Network Open study found commercial large language models showed substantial vulnerability to prompt injection that pushed them into clinically dangerous medication and treatment recommendations.