LIVE FEED
CISA: every Flow Neuroscience FL-100 tDCS headset shares one hardcoded BLE credential, CVE-2026-18164 rated 8.1 Coalition for Health AI convenes 100 member cyber work group, AI attack and defense playbooks due by year end CRA Article 14 reporting obligations take effect September 11 EU MDR revision proposal adds a 30 day exploited-vulnerability reporting clock via Eudamed Mira hormone monitor cloud API handed session tokens to any password, CVE-2026-68067 rated 9.8 Pulsetto vagus nerve stimulator ships hidden BLE commands: no patch, no vendor response CISA: every Flow Neuroscience FL-100 tDCS headset shares one hardcoded BLE credential, CVE-2026-18164 rated 8.1 Coalition for Health AI convenes 100 member cyber work group, AI attack and defense playbooks due by year end CRA Article 14 reporting obligations take effect September 11 EU MDR revision proposal adds a 30 day exploited-vulnerability reporting clock via Eudamed Mira hormone monitor cloud API handed session tokens to any password, CVE-2026-68067 rated 9.8 Pulsetto vagus nerve stimulator ships hidden BLE commands: no patch, no vendor response
Sunday, August 16, 2026 Issue #1  ·  Est. 2025
Independent brief for device makers
Section 06 // Products · Funding · Deals

Vendors

Product launches, funding rounds, and market moves across the medical device security vendor landscape.

Vendor Directory

Medical device cybersecurity

AI-Native

Platforms built AI-first for medical device vulnerability discovery and verification.

Consulting Firms

Services teams doing pentesting, regulatory and product-security work for device makers.

Blue Goat Cyber

Penetration testing and FDA-focused cybersecurity services for medical device makers, including premarket testing and documentation support.

bluegoatcyber.com ↗
MedCrypt

Device cybersecurity built for manufacturers, spanning advisory services and product tooling for vulnerability management, SBOM and premarket submission evidence.

www.medcrypt.com ↗
MedSec

Medical device security consulting: penetration testing, premarket and postmarket program support, and regulatory documentation for manufacturers and health systems.

medsec.com ↗
Promenade Software

Medical device software development and cybersecurity services with an IEC 62304 and FDA regulatory focus.

promenadesoftware.com ↗
Sequoia (GDT)

Regulatory and quality consulting for medtech, including cybersecurity documentation aligned to FDA and EU MDR expectations.

www.sequoia-consulting.com ↗

Tool Vendors

Product-security, SBOM, and connected-device monitoring tooling.

Armis

Asset intelligence and security platform covering unmanaged and IoMT devices across clinical networks.

www.armis.com ↗
Asimily

IoMT risk management platform focused on vulnerability prioritization and remediation for connected medical devices.

asimily.com ↗
Claroty (Team82)

Connected-device security across healthcare and OT, with the Team82 research group publishing vulnerability findings in medical and industrial systems.

claroty.com ↗
Cybellum

Product security and SBOM platform for device makers, covering vulnerability management and compliance across the product lifecycle.

cybellum.com ↗
Finite State

Product security platform centered on firmware analysis and SBOM management, used to generate premarket submission evidence for connected devices.

finitestate.io ↗
Ordr

Connected-device visibility and security for healthcare environments, discovering and classifying IoMT assets and their exposure.

ordr.net ↗

Listing is editorial and does not imply endorsement. To be considered, submit a tip.

Vendor News

0 stories on file

Nothing on file for this desk yet. Know something we should cover? Submit a tip.