LIVE FEED
Forescout found just 6 percent of connected medical devices support quantum-safe SSH, versus 50 percent of ordinary IT systems, across a 2.5 million device sample BridgeLink 26.9.0, the open source Mirth Connect fork, patched CVE-2026-82583, CVE-2026-78224, and CVE-2026-82578 from CISA's ICSMA-26-253-01 on October 1, plus eight inherited third party library CVEs Citrix's CVE-2026-88771 and CVE-2026-88772, two CVSS 9.5 NetScaler zero days under active attack, forced three Dutch hospitals to shut down systems as a precaution Fresenius Medical Care confirmed unauthorized access to internal systems September 22, after ShinyHunters listed the dialysis maker for extortion The Senate passed S. 3315, the Health Care Cybersecurity and Resiliency Act, by unanimous consent September 30; mandatory MFA, encryption, and penetration testing now await House action FDA docket FDA-2026-N-7874 on generative AI enabled devices remains open; comments due October 19 Forescout found just 6 percent of connected medical devices support quantum-safe SSH, versus 50 percent of ordinary IT systems, across a 2.5 million device sample BridgeLink 26.9.0, the open source Mirth Connect fork, patched CVE-2026-82583, CVE-2026-78224, and CVE-2026-82578 from CISA's ICSMA-26-253-01 on October 1, plus eight inherited third party library CVEs Citrix's CVE-2026-88771 and CVE-2026-88772, two CVSS 9.5 NetScaler zero days under active attack, forced three Dutch hospitals to shut down systems as a precaution Fresenius Medical Care confirmed unauthorized access to internal systems September 22, after ShinyHunters listed the dialysis maker for extortion The Senate passed S. 3315, the Health Care Cybersecurity and Resiliency Act, by unanimous consent September 30; mandatory MFA, encryption, and penetration testing now await House action FDA docket FDA-2026-N-7874 on generative AI enabled devices remains open; comments due October 19
Thursday, October 8, 2026 Issue #476  ·  Est. 2025
Independent brief for device makers
Section 05 // Academia · Labs · Disclosures

Research

Academic studies, lab findings, and coordinated disclosures shaping how the industry measures device risk.

Latest Filings

5 stories on file
01
Quantum Risk

Forescout finds just 6 percent of connected medical devices ready for quantum-safe encryption

A Forescout Vedere Labs analysis of 2.5 million healthcare devices found only 6 percent of connected medical devices support quantum-safe SSH, against 50 percent of ordinary IT systems. Ransomware claims against healthcare providers hit 461 through August, up 47 percent year over year.

Forescout Vedere Labsjust now3 min read
02
Research

We checked 100+ top device makers for public security advisories. Most have nothing

About 25 of 110 publish real advisory listings. Thirty more post a policy page and an inbox. The rest, over 40 companies, have no public disclosure surface at all.

MedDevice CyberAug 114 min read
03
AI Threat

AI collapsed the cost of finding vulnerabilities. Triage is where it breaks

Published CVEs hit roughly 40,000 in 2024, the largest single-year jump on record, and AI-assisted discovery is pushing the curve steeper. For device makers, the bottleneck moved from finding flaws to dispositioning them.

MedDevice CyberMay 194 min read
04
AI Threat

ECRI ranked AI chatbot misuse the number one health tech hazard for 2026

ECRI's annual hazard list put misuse of AI chatbots at number one for 2026 and legacy medical device cybersecurity at number eight, tying both directly to patient harm.

ECRIJan 212 min read
05
AI Threat

A JAMA study steered medical LLMs into dangerous advice with prompt injection

A JAMA Network Open study found commercial large language models showed substantial vulnerability to prompt injection that pushed them into clinically dangerous medication and treatment recommendations.

JAMA Network OpenDec 193 min read