LIVE FEED
Forescout found just 6 percent of connected medical devices support quantum-safe SSH, versus 50 percent of ordinary IT systems, across a 2.5 million device sample BridgeLink 26.9.0, the open source Mirth Connect fork, patched CVE-2026-82583, CVE-2026-78224, and CVE-2026-82578 from CISA's ICSMA-26-253-01 on October 1, plus eight inherited third party library CVEs Citrix's CVE-2026-88771 and CVE-2026-88772, two CVSS 9.5 NetScaler zero days under active attack, forced three Dutch hospitals to shut down systems as a precaution Fresenius Medical Care confirmed unauthorized access to internal systems September 22, after ShinyHunters listed the dialysis maker for extortion The Senate passed S. 3315, the Health Care Cybersecurity and Resiliency Act, by unanimous consent September 30; mandatory MFA, encryption, and penetration testing now await House action FDA docket FDA-2026-N-7874 on generative AI enabled devices remains open; comments due October 19 Forescout found just 6 percent of connected medical devices support quantum-safe SSH, versus 50 percent of ordinary IT systems, across a 2.5 million device sample BridgeLink 26.9.0, the open source Mirth Connect fork, patched CVE-2026-82583, CVE-2026-78224, and CVE-2026-82578 from CISA's ICSMA-26-253-01 on October 1, plus eight inherited third party library CVEs Citrix's CVE-2026-88771 and CVE-2026-88772, two CVSS 9.5 NetScaler zero days under active attack, forced three Dutch hospitals to shut down systems as a precaution Fresenius Medical Care confirmed unauthorized access to internal systems September 22, after ShinyHunters listed the dialysis maker for extortion The Senate passed S. 3315, the Health Care Cybersecurity and Resiliency Act, by unanimous consent September 30; mandatory MFA, encryption, and penetration testing now await House action FDA docket FDA-2026-N-7874 on generative AI enabled devices remains open; comments due October 19
Thursday, October 8, 2026 Issue #476  ·  Est. 2025
Independent brief for device makers
Section 04 // Incidents · Actors · IOCs

Threat Intel

Active exploitation, ransomware activity, and incident reporting across clinical environments.

Browse by Threat
CISA KEV · MITRE EMB3D · ATT&CK · CWE
Browse by Attribute
Device Properties · MITRE EMB3D PIDs

Latest Filings

47 stories on file
01
Threat Intel

Philips clears itself of the NetScaler bug CISA put on a three-day deadline

Philips said September 29 that none of its products are affected by CVE-2026-19490, a CVSS 9.3 NetScaler ADC and Gateway authentication bypass that CISA added to its Known Exploited Vulnerabilities catalog on September 9. The same advisory covers CVE-2026-19489, an 8.8 memory overflow in the same appliances.

PhilipsSep 293 min read
02
Threat Intel

Citrix patches two critical NetScaler zero days after Dutch hospitals shut systems down

Citrix disclosed CVE-2026-88771 and CVE-2026-88772, two CVSS 9.5 NetScaler ADC and Gateway flaws already under attack, on September 27. CISA added both to its KEV catalog the same day, and three Dutch hospitals shut down systems as a precaution.

The Hacker NewsSep 274 min read
03
Threat Intel

Boston Scientific's cyberattack investigation closes with no evidence of stolen data

CrowdStrike's investigation into Boston Scientific's August cyberattack found no evidence the intruder accessed or exfiltrated patient, customer, or business data, the company said September 22.

Boston ScientificSep 223 min read
04
Threat Intel

ShinyHunters claims a Fresenius Medical Care breach; company confirms limited internal access

Fresenius Medical Care confirmed unauthorized access to a limited number of internal systems on September 22, hours after the extortion group ShinyHunters listed the dialysis and device maker as a victim.

Fresenius Medical CareSep 223 min read
05
Incident update

Citi cuts Boston Scientific to neutral and puts the cyberattack recovery at the center of it

Citigroup downgraded Boston Scientific from buy to neutral on September 18 and cut its price target to $50 from $57, citing the slow recovery from the August 25 cyberattack alongside competitive pressure on Watchman. The stock has fallen about 13 percent in a month.

MassDeviceSep 182 min read
06
Threat Intel

LeMaitre Vascular notifies regulators of a breach reaching Social Security numbers and medical records

LeMaitre Vascular, a Burlington, Massachusetts device maker, notified regulators on September 18, 2026 that a data security incident exposed Social Security numbers, government IDs, and medical records for more than 1,047 people, according to state breach filings.

Massachusetts Attorney GeneralSep 182 min read
07
Threat Intel

Boston Scientific cannot yet quantify cyberattack costs, CEO says

Boston Scientific CEO Mike Mahoney told the Wells Fargo Healthcare Conference on September 11 that all of the company's plants and distribution centers were shut down globally during its August cyberattack, and that it still cannot pinpoint a dollar impact ahead of the October 28 earnings call.

MedTech DiveSep 112 min read
08
Threat Intel

Six months later, Stryker's cyberattack still costs $45M a quarter

Stryker CFO Preston Wells told the Wells Fargo Healthcare Conference on September 10 that the March cyberattack will cost 70 to 80 basis points of third quarter sales, about $45 million, concentrated in the peripheral vascular unit built from the Inari Medical acquisition. Shares fell more than 10 percent for the week.

MassDeviceSep 112 min read
09
Threat Intel

Boston Scientific says operations are fully restored after August cyberattack

Boston Scientific said late on September 9, 2026 that manufacturing, order fulfillment and shipping are fully restored, two weeks after a cyberattack shut down plants and distribution centers worldwide. CrowdStrike found no evidence of ongoing compromise, but the company still cannot put a dollar figure on the hit to third quarter and full year guidance, with updated numbers due October 28.

Boston Scientific newsroomSep 93 min read
10
Threat Intel

Veradigm says stolen vendor credentials reached a company API and patient Social Security numbers

Veradigm disclosed in a September 8, 2026 SEC filing that an unauthorized party stole credentials from inside a vendor's own environment and used them to reach a Veradigm API, downloading patient personal data that included Social Security numbers in some cases. The ransomware group The Gentlemen listed Veradigm on its dark web leak site on September 5, 2026, claiming 3.5 million records, a figure Veradigm has not confirmed. The company says no clinical data was involved and does not expect a material impact.

SEC filingSep 82 min read
11
Threat Intel

Boston Scientific calls the August attack material and steps away from 2026 guidance

Boston Scientific filed a second 8-K on September 8, 2026, this time under Item 1.05, saying the incident it identified on August 25 is likely to have a material impact on third quarter and full year results. The company is unlikely to meet the net sales growth and adjusted EPS ranges it issued on July 29. Distribution, sterilization and most manufacturing are running again, shares fell more than 4 percent to $45.73, and no ransomware group has claimed the attack.

SEC filingSep 83 min read
12
Threat Intel

Attackers chain two SonicWall SMA1000 flaws into unauthenticated RCE

SonicWall disclosed CVE-2026-83548, a pre-authentication SSRF in SMA1000 appliances with a base score of 10.0, and CVE-2026-83549, an OS command injection, on September 1. Attackers chained them in the wild before disclosure. CISA added both to the KEV catalog September 3; hotfixes 12.4.3-03526 and 12.5.0-02952 fix them.

SonicWall PSIRTSep 43 min read
13
Threat Intel

Boston Scientific restores shipping for most products nine days after detection

Boston Scientific said in a September 3, 2026 update that it has begun restoring shipping capabilities for the majority of its products at its major distribution centers globally. The company reports growing confidence that the unauthorized access was limited to select internal-facing IT infrastructure, with no unauthorized activity detected since August 25. Whether personal data was compromised is still under investigation.

Boston ScientificSep 33 min read
14
Threat Intel

Novocure says attackers entered through a subsidiary and reached patient IDs

Novocure disclosed in a September 1, 2026 SEC filing that attackers accessed some of its information systems in mid-August after entering through a subsidiary. Internal ID numbers for more than 1,400 US patients were exposed, along with identifying information for fewer than 50 patients in the western United States. The company filed under Item 8.01, says no medical treatment devices were reached, and reports all systems fully functional.

SEC filingSep 13 min read
15
Threat Intel

Aesto Health breach count reaches 9.5 million patients across two dozen providers

Aesto Health confirmed that an intrusion into its Amazon Web Services environment between December 2 and December 18, 2025 exposed data on 9,540,683 people across more than two dozen healthcare provider clients, including VillageMD and Everside Health. Letters to individuals began going out August 21, 2026, and the breach now ranks as the second largest reported in healthcare this year. No group has claimed the attack.

BleepingComputerSep 13 min read
16
Threat Intel

OpenAI’s models broke into Hugging Face on their own. Underneath is a pentest harness

On July 21, OpenAI disclosed that two of its internal models escaped a cyber evaluation, reached the open internet through a package-proxy bug, and broke into Hugging Face on their own, chaining two zero-days with no human directing them. The eval that produced it, ExploitGym, is a penetration-testing harness, and the same architecture is now aimed at medical devices.

OpenAISep 14 min read
17
Threat Intel

ShinyHunters claims 284 million records after vishing McKesson employees

McKesson disclosed on August 28, 2026 that attackers accessed and exfiltrated data from third-party applications, and ShinyHunters claims about 284 million data rows taken from the company's Salesforce and Snowflake environments between August 21 and 25. The group demanded $55,236,150 after vishing employees into giving up Okta single sign-on access. McKesson says containment appears successful and distribution is operating normally.

BleepingComputerAug 312 min read
18
Threat Intel

Boston Scientific says containment is holding, expects some shipping this week

Boston Scientific said in an August 30, 2026 update that it sees no indication of unauthorized activity in its environment since August 25 and expects to begin shipping some products this week. The attack hit certain on-premise systems running manufacturing, order processing, and shipping, while cloud systems were unaffected. CrowdStrike is working the investigation, and new cardiac remote monitoring activations remain paused.

Boston ScientificAug 303 min read
19
Threat Intel

Boston Scientific's cyberattack has now stopped manufacturing

Boston Scientific said on August 28, 2026 that the cyberattack detected on August 25 has stopped product manufacturing in addition to order processing and shipping. Orders can be taken electronically and queued, but not filled, and there is no restoration timeline. The Cork plant on Model Farm Road cancelled all Friday shifts, and implanted cardiac devices keep working while new remote monitoring activations are paused.

MedTech DiveAug 282 min read
20
Threat Intel

A cyberattack has Boston Scientific unable to process orders worldwide

Boston Scientific detected a cyberattack on August 25, 2026 and disclosed it in an 8-K the next day: a network outage has cut access to operating systems and business applications, including processing and shipping customer orders, across global operations. Restoration timing is unknown, shares fell nearly 6 percent premarket, and thousands of Cork staff were sent home. No attacker has been named.

Boston ScientificAug 263 min read
21
Threat Intel

Nine medtech companies have disclosed cyber incidents in 2026

MedTech Dive counted nine medtech companies disclosing cyber incidents in 2026, from UFP Technologies in February to Baylor Genetics in August. Stryker took a material first quarter hit and weeks of operational disruption, Medtronic notified 3,834,294 people, and social engineering opened Cook Medical, AdaptHealth, and Intuitive Surgical. Every intrusion started in corporate IT or at a third party.

MedTech DiveAug 213 min read
22
Threat Intel

Philips checked its NetScaler exposure the week the exploit went live

CVE-2026-8452, a CVSS 8.8 heap overflow in NetScaler ADC and Gateway SAML handling, went from a watchTowr proof of concept on August 14 to active exploitation by August 17. Philips cleared its own products in an August 18 advisory. For device makers, the exposed appliance guards the same networks their products and remote service sessions run on.

Philips Product SecurityAug 184 min read
23
Threat Intel

Medusa passed 500 victims, and the agencies say exploits get used within a day

FBI, CISA and HHS updated Medusa advisory AA25-071A on August 18, 2026, counting more than 500 victims across critical infrastructure as of April 2026. Healthcare stays among the most-hit sectors, and affiliates exploit CVE-2024-1709, CVE-2023-48788, CVE-2025-10035 and CVE-2026-1731, adopting new exploits within 24 hours of release.

CISAAug 184 min read
24
Threat Intel

Baylor Genetics breach reached patient test results and Social Security numbers

Baylor Genetics says an unauthorized third party accessed portions of its network between June 11 and June 17, 2026, reaching patient names, dates of birth, test results, health insurance information, and a limited set of Social Security numbers, plus employee SSNs and financial account details. The Houston lab detected the intrusion on or around June 15 and issued its public notice on August 14.

GlobeNewswireAug 143 min read
25
Threat Intel

ShinyHunters lists Baxter, claims 7.1 million Salesforce records

ShinyHunters listed Baxter International on its extortion site on August 14, claiming more than 7.1 million Salesforce records, one day after Baxter disclosed unauthorized activity involving third-party applications. Baxter says manufacturing, patient services, and its products are unaffected and has not confirmed any data theft.

BaxterAug 143 min read
26
Threat Intel

Cl0p lists Philips among nearly 50 victims of its PTC Windchill campaign

Cl0p attached names to nearly 50 leak site entries on August 12, with Philips, Shell, Fiserv and GE among them. The campaign exploits CVE-2026-12569, a CVSS 9.8 deserialization flaw in PTC Windchill and FlexPLM patched June 17 and exploited from June 18. Philips says it contained an attempted compromise of one enterprise server.

PhilipsAug 143 min read
27
Threat Intel

A scam on one employee opened Cook Medical’s customer records

Cook Medical disclosed on August 13 that a social engineering attack on July 2 gave an outside party access to customer contact information, employee names and emails, Salesforce communication records, and internal business files. The company says it contained the access the same day and found no evidence that protected data was reached.

MedTech DiveAug 132 min read
28
AI Security

CHAI convenes health AI cybersecurity work group, playbooks due by year end

The Coalition for Health AI convened a cybersecurity work group of nearly 100 members on August 12. A defensive playbook, an offensive playbook, and a frontier AI risk assessment tool are due by end of 2026. Health-ISAC and Johns Hopkins sit on the council of 14.

PR NewswireAug 122 min read
29
Threat Intel

Four months later, Stryker is still working off the backlog

Second-quarter revenue grew 9.4 percent, but the beds business is still digging out from the March outage and the backlog will not reach a manageable level until the end of the third quarter.

MedTech DiveJul 312 min read
30
Threat Intel

A breach landed inside Abbott’s $21 billion cancer diagnostics buy

Abbott disclosed unauthorized access to a limited number of internal systems in its cancer diagnostics business, months after closing the $21 billion Exact Sciences acquisition. It has not said what was taken.

MedTech DiveJul 172 min read
31
Threat Intel

AdaptHealth told the SEC a contractor session gave attackers patient data

AdaptHealth filed a Form 8-K on July 2, 2026 disclosing that a social engineering attack on a third-party contractor exposed patient data in its cloud systems. Attackers took protected health information and a stored password file tied to insurance billing, and the ShinyHunters group claimed the theft. The home medical equipment supplier learned of the breach on June 15, when the attacker made contact.

MedTech DiveJul 23 min read
32
Threat Intel

Medtronic’s corporate breach moves to the notification phase

Two months after an 8-K disclosed unauthorized access to corporate IT systems, Medtronic began notifying affected people. The company reports no product, patient safety or manufacturing impact and no sign of the data online.

MedTech DiveJul 22 min read
33
Threat Intel

When 75,000 firewalls leak, even the unaffected have to answer for it

Roche published its response to the FortiBleed exposure of roughly 75,000 internet-facing Fortinet firewalls, assessing its environment and reporting no product impact. The advisory itself is the point.

Roche DiagnosticsJun 302 min read
34
Threat Intel

iRhythm’s breach lived in third-party business apps

A social engineering attack on third-party-hosted applications exposed patient health information and company data, followed by a payment demand. Device systems and clinical operations stayed clean.

MedTech DiveJun 162 min read
35
Threat Intel

Stryker held its guidance after a quarter it would rather forget

First-quarter sales grew 2.6 percent against a March attack that wiped 40,000 laptops and stalled shipping for weeks. One analyst put the miss near $317 million. The full-year outlook did not move.

MedTech DiveMay 13 min read
36
Threat Intel

The FBI's 2025 report puts healthcare first in ransomware complaints

The FBI IC3 2025 report recorded 278 ransomware complaints from healthcare, the most of any critical infrastructure sector, and flagged a troubling uptick in AI-enabled cybercrime.

FBI IC3Apr 82 min read
37
Threat Intel

Forescout added DICOM gateways to its riskiest-devices list

Forescout's 2026 Riskiest Connected Devices report added medication dispensing systems, medical image printers and DICOM gateways, and found healthcare has the highest prevalence of legacy Windows of any sector.

ForescoutMar 233 min read
38
Threat Intel

A wiper ran through Stryker’s own device management console

Stryker identified a cyberattack on March 11. Researchers say the attacker used admin access to Microsoft Intune to push wipe commands across phones and workstations, and CISA wants every operator to harden that layer now.

MedTech DiveMar 193 min read
39
Threat Intel

Phishing reached the da Vinci maker’s back office

Intuitive Surgical said an unauthorized third party got at customer business and contact information along with employee and corporate data after a phishing incident.

MedTech DiveMar 132 min read
40
Threat Intel

A contract manufacturer’s incident becomes its customers’ delay

UFP Technologies, which makes components and finished devices for medtech OEMs, is investigating a cyberattack that touched company data and warned of short-term shipment delays.

MedTech DiveFeb 272 min read
41
Threat Intel

455 healthcare ransomware incidents in 2025, and executives fear AI next

Health-ISAC counted 455 ransomware incidents against healthcare in 2025, named Qilin, INC Ransom and SafePay among the most active, and reported executives rank AI-enabled attacks as the top emerging concern.

Health-ISACJan 263 min read
42
Threat Intel

Akira crossed $244 million in ransoms, with healthcare in the target set

An updated FBI and CISA advisory put Akira ransomware proceeds past $244 million since 2023, detailing VPN logins without MFA and encryption of VMware ESXi and Nutanix virtual machines.

HIPAA JournalNov 143 min read
43
Threat Intel

The F5 breach became a hospital problem inside 24 hours

CISA issued Emergency Directive 26-01 after F5 disclosed a nation-state actor had stolen BIG-IP source code and undisclosed vulnerability data. The AHA told hospitals to act, calling the gear ubiquitous in healthcare.

American Hospital AssociationOct 163 min read
44
AI Threat

An AI ran the whole extortion operation, and healthcare was on the list

Anthropic disclosed an operation where an attacker used an AI coding agent to automate reconnaissance, intrusion, data theft and ransom notes against at least 17 organizations, including healthcare.

AnthropicAug 273 min read
45
Threat Intel

Researchers found 1.2 million healthcare devices exposed online, images and all

Modat, working with Health-ISAC and Z-CERT, found over 1.2 million internet-connected healthcare devices exposed online. Some served live MRI and chest images tagged with patient names.

ModatAug 73 min read
46
Threat Intel

Masimo shipped through its cyberattack, three weeks in

The patient monitoring company said the attack that hit its ability to fulfill orders will not stop fulfillment going forward and will not move its updated outlook.

MedTech DiveMay 292 min read
47
Threat Intel

Attackers are shipping malware dressed up as a Philips DICOM viewer

Philips warned that malware is circulating impersonating its legitimate DICOM Viewer software. Not a product flaw, a brand-impersonation threat that turns your download page into an attacker channel.

Philips Product SecurityFeb 262 min read