LIVE FEED
Forescout found just 6 percent of connected medical devices support quantum-safe SSH, versus 50 percent of ordinary IT systems, across a 2.5 million device sample BridgeLink 26.9.0, the open source Mirth Connect fork, patched CVE-2026-82583, CVE-2026-78224, and CVE-2026-82578 from CISA's ICSMA-26-253-01 on October 1, plus eight inherited third party library CVEs Citrix's CVE-2026-88771 and CVE-2026-88772, two CVSS 9.5 NetScaler zero days under active attack, forced three Dutch hospitals to shut down systems as a precaution Fresenius Medical Care confirmed unauthorized access to internal systems September 22, after ShinyHunters listed the dialysis maker for extortion The Senate passed S. 3315, the Health Care Cybersecurity and Resiliency Act, by unanimous consent September 30; mandatory MFA, encryption, and penetration testing now await House action FDA docket FDA-2026-N-7874 on generative AI enabled devices remains open; comments due October 19 Forescout found just 6 percent of connected medical devices support quantum-safe SSH, versus 50 percent of ordinary IT systems, across a 2.5 million device sample BridgeLink 26.9.0, the open source Mirth Connect fork, patched CVE-2026-82583, CVE-2026-78224, and CVE-2026-82578 from CISA's ICSMA-26-253-01 on October 1, plus eight inherited third party library CVEs Citrix's CVE-2026-88771 and CVE-2026-88772, two CVSS 9.5 NetScaler zero days under active attack, forced three Dutch hospitals to shut down systems as a precaution Fresenius Medical Care confirmed unauthorized access to internal systems September 22, after ShinyHunters listed the dialysis maker for extortion The Senate passed S. 3315, the Health Care Cybersecurity and Resiliency Act, by unanimous consent September 30; mandatory MFA, encryption, and penetration testing now await House action FDA docket FDA-2026-N-7874 on generative AI enabled devices remains open; comments due October 19
Thursday, October 8, 2026 Issue #476  ·  Est. 2025
Independent brief for device makers
Section 06 // Products · Funding · Deals

Vendors

Product launches, funding rounds, and market moves across the medical device security vendor landscape.

Vendor Directory

Medical device cybersecurity

Consulting Firms

Services teams doing pentesting, regulatory and product-security work for device makers.

Blue Goat Cyber

Penetration testing and FDA-focused cybersecurity services for medical device makers, including premarket testing and documentation support.

bluegoatcyber.com ↗
MedCrypt

Device cybersecurity built for manufacturers, spanning advisory services and product tooling for vulnerability management, SBOM and premarket submission evidence.

www.medcrypt.com ↗
MedSec

Medical device security consulting: penetration testing, premarket and postmarket program support, and regulatory documentation for manufacturers and health systems.

medsec.com ↗
Promenade Software

Medical device software development and cybersecurity services with an IEC 62304 and FDA regulatory focus.

promenadesoftware.com ↗
Sequoia (GDT)

Regulatory and quality consulting for medtech, including cybersecurity documentation aligned to FDA and EU MDR expectations.

www.sequoia-consulting.com ↗

Tool Vendors

Product-security, SBOM, and connected-device monitoring tooling.

Armis

Asset intelligence and security platform covering unmanaged and IoMT devices across clinical networks.

www.armis.com ↗
Asimily

IoMT risk management platform focused on vulnerability prioritization and remediation for connected medical devices.

asimily.com ↗
Claroty (Team82)

Connected-device security across healthcare and OT, with the Team82 research group publishing vulnerability findings in medical and industrial systems.

claroty.com ↗
Cybellum

Product security and SBOM platform for device makers, covering vulnerability management and compliance across the product lifecycle.

cybellum.com ↗
Finite State

Product security platform centered on firmware analysis and SBOM management, used to generate premarket submission evidence for connected devices.

finitestate.io ↗
Ordr

Connected-device visibility and security for healthcare environments, discovering and classifying IoMT assets and their exposure.

ordr.net ↗

Listing is editorial and does not imply endorsement. To be considered, submit a tip.

Vendor News

0 stories on file

Nothing on file for this desk yet. Know something we should cover? Submit a tip.