<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><title>News Agent — Healthcare &amp; Life Sciences</title><link>/industries/healthcare/</link><description>Cyber threat intelligence for the Healthcare &amp; Life Sciences industry — daily-brief items tagged to this slice.</description><item><title>General Santos Doctors Hospital, a 280-bed tertiary hospital in the Philippines, listed on Rhysida&#x27;s leak site Sep 10. 🟥 Unverified DLS clai</title><link>/briefings/2026/09/12/2026-09-12/</link><guid isPermaLink="false">2026-09-12-General Santos Doctors Hospital, a 280-bed tertiary hospital</guid><pubDate>Sat, 12 Sep 2026 06:00:00 +0000</pubDate><description>General Santos Doctors Hospital, a 280-bed tertiary hospital in the Philippines, listed on Rhysida&#x27;s leak site Sep 10. 🟥 Unverified DLS claim — roughly 3.5M files (2.44TB) allegedly exfiltrated, including name-tagged diagnostic scans, cancer-center records with national health-insurance IDs, and a staff register with professional license numbers; no hospital confirmation yet, verify before treating as a breach. Ransomware.live [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>Veradigm confirms unauthorized access to patient data after The Gentlemen ransomware group asserts 3.5M records were taken</title><link>/briefings/2026/09/10/2026-09-10/</link><guid isPermaLink="false">2026-09-10-Veradigm confirms unauthorized access to patient data after </guid><pubDate>Thu, 10 Sep 2026 06:00:00 +0000</pubDate><description>Veradigm confirms unauthorized access to patient data after The Gentlemen ransomware group asserts 3.5M records were taken — attacker used compromised third-party vendor credentials to reach a single API, not a network-wide compromise. The Chicago-based EHR/e-prescribing vendor says Social Security numbers were exposed for a subset of customers via a narrow, credential-based access path; no clinical/medical data, servers or broader network were touched, and operations weren&#x27;t disrupted. The Gentlemen posted Veradigm to its data-leak site Sep 5 with a Sep 11 publication deadline absent a ransom negotiation. Veradigm confirms the access itself; the 3.5M-record scope is the attacker&#x27;s own figure. BleepingComputer [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>A Fortune-class healthcare vendor compromised through a single vendor credential and a narrow API scope, rather than a network-wide intrusio</title><link>/briefings/2026/09/10/2026-09-10/</link><guid isPermaLink="false">2026-09-10-A Fortune-class healthcare vendor compromised through a sing</guid><pubDate>Thu, 10 Sep 2026 06:00:00 +0000</pubDate><description>A Fortune-class healthcare vendor compromised through a single vendor credential and a narrow API scope, rather than a network-wide intrusion, continues 2026&#x27;s structural theme: the weakest point in large enterprises&#x27; security posture is increasingly a specific third-party access path, not the core network. Veradigm&#x27;s containment (no clinical data, no server/network compromise) is what a mature incident-response posture looks like when the blast radius is architecturally limited — worth noting precisely because so many of this year&#x27;s headline breaches (McKesson, Trezor/ShipMonk) show the opposite pattern. Segmenting vendor and partner API access remains the highest-leverage healthcare-sector control available today. BleepingComputer [🌍 GEOPOLITICS]</description></item><item><title>McKesson/ShinyHunters</title><link>/briefings/2026/09/09/2026-09-09/</link><guid isPermaLink="false">2026-09-09-McKesson/ShinyHunters</guid><pubDate>Wed, 09 Sep 2026 06:00:00 +0000</pubDate><description>McKesson/ShinyHunters — Sep 9 data-publication deadline is today; no public resolution confirmed as of this writing. The Sep 1 contact deadline passed without engagement, and ShinyHunters&#x27; operative threat is to publish the claimed haul today. 🟥 The 284M-record figure remains the attacker&#x27;s own characterization of raw Salesforce/Snowflake rows, not a unique-patient count; McKesson has not disclosed a number. A publication today would be the largest US healthcare breach-notification event of 2026. SecurityWeek · CyberScoop [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>ShinyHunters runs the same playbook twice in one week against very different targets</title><link>/briefings/2026/09/09/2026-09-09/</link><guid isPermaLink="false">2026-09-09-ShinyHunters runs the same playbook twice in one week agains</guid><pubDate>Wed, 09 Sep 2026 06:00:00 +0000</pubDate><description>ShinyHunters runs the same playbook twice in one week against very different targets — a Fortune 10 healthcare distributor and a state DMV — underscoring that its methodology (social-engineer or password-reset your way to a data store, then extort) doesn&#x27;t require a specific tech stack. McKesson via voice-phished Okta SSO into Salesforce/Snowflake; Florida DAVID via a password-reset flaw. See Intelligence Agency Alerts above for the group&#x27;s other current AI-related news cycle context. BleepingComputer [🌐 THREAT ACTOR &amp; CAMPAIGN ACTIVITY]</description></item><item><title>McKesson&#x27;s Sep 9 deadline is the second major US healthcare extortion clock to run out this quarter, and healthcare&#x27;s specific vulnerability</title><link>/briefings/2026/09/09/2026-09-09/</link><guid isPermaLink="false">2026-09-09-McKesson&#x27;s Sep 9 deadline is the second major US healthcare </guid><pubDate>Wed, 09 Sep 2026 06:00:00 +0000</pubDate><description>McKesson&#x27;s Sep 9 deadline is the second major US healthcare extortion clock to run out this quarter, and healthcare&#x27;s specific vulnerability is structural, not incidental: third-party SaaS sprawl (Salesforce, Snowflake) now sits between the industry&#x27;s HIPAA obligations and its actual attack surface. Voice-phishing a help desk into resetting SSO credentials bypasses most of the technical controls healthcare compliance programs are built around, because the weak point is a human process, not a system. Expect this incident, if data publishes today, to accelerate the same vendor-risk-audit conversation already underway after Trezor/ShipMonk — but for identity providers and CRM/data-warehouse vendors specifically rather than fulfillment partners. SecurityWeek [🌍 GEOPOLITICS]</description></item><item><title>McKesson / ShinyHunters</title><link>/briefings/2026/09/08/2026-09-08/</link><guid isPermaLink="false">2026-09-08-McKesson / ShinyHunters</guid><pubDate>Tue, 08 Sep 2026 06:00:00 +0000</pubDate><description>McKesson / ShinyHunters — Sep 9 publication deadline one day out; no public resolution signal — As of Sep 8, McKesson has made no statement on payment or negotiation status. The Sep 1 contact deadline passed without public engagement; Sep 9 is the operative data-publication threshold ShinyHunters has set. 🟥 The 284M-record figure remains ShinyHunters&#x27; own characterization; unique-individual count unverified. A publication would be the largest US healthcare breach-notification event of 2026. SecurityWeek · CyberScoop [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>Boston Scientific</title><link>/briefings/2026/09/08/2026-09-08/</link><guid isPermaLink="false">2026-09-08-Boston Scientific</guid><pubDate>Tue, 08 Sep 2026 06:00:00 +0000</pubDate><description>Boston Scientific — no material change since Sep 7; shipping restoration continuing toward Piper Sandler&#x27;s mid-September estimate. Major distribution centers have resumed shipping for most products; Cork remains at reduced capacity. No new intrusion activity reported since Aug 25. MedTech Dive [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>McKesson / ShinyHunters</title><link>/briefings/2026/09/07/2026-09-07/</link><guid isPermaLink="false">2026-09-07-McKesson / ShinyHunters</guid><pubDate>Mon, 07 Sep 2026 06:00:00 +0000</pubDate><description>McKesson / ShinyHunters — Sep 9 publication deadline 2 days out; no resolution signal; 284M-record publication would be the largest US healthcare breach notification event of 2026 — As of Sep 7, McKesson has made no public statement on payment or resolution. ShinyHunters&#x27; Sep 9 data-publication deadline is the operative threshold. The Sep 1 contact deadline passed without McKesson public engagement. 🟥 The 284M-record count is ShinyHunters&#x27; own characterisation; unique-individual figure unverified. A publication triggers OCR breach investigation, state AG enforcement, class actions across multiple jurisdictions, and Senate Commerce Committee scrutiny. SecurityWeek · CyberScoop [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>Boston Scientific</title><link>/briefings/2026/09/07/2026-09-07/</link><guid isPermaLink="false">2026-09-07-Boston Scientific</guid><pubDate>Mon, 07 Sep 2026 06:00:00 +0000</pubDate><description>Boston Scientific — Day 13 of recovery; no new adverse network activity; Cork manufacturing remains at reduced capacity — No material change since Sep 6. Distribution shipping restored at major global centres; Cork site partially restored. CrowdStrike and third-party experts leading investigation confirm no new intrusion activity since Aug 25. Piper Sandler mid-September full-restoration estimate unchanged. 🟥 Threat actor and attack vector not publicly disclosed. Boston Scientific · SecurityWeek [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>McKesson / ShinyHunters</title><link>/briefings/2026/09/06/2026-09-06/</link><guid isPermaLink="false">2026-09-06-McKesson / ShinyHunters</guid><pubDate>Sun, 06 Sep 2026 06:00:00 +0000</pubDate><description>McKesson / ShinyHunters — Sep 9 data-publication deadline 3 days out; $55M demand unanswered; no public settlement signal — As of Sep 6, McKesson has not confirmed payment or resolution. ShinyHunters has not published the claimed 284M-record Snowflake exfiltration (attack window Aug 21–25, vishing → Okta SSO → multi-SaaS pivot). The initial Sep 1 negotiation deadline passed without public McKesson engagement; the Sep 9 publication deadline is the operative threshold. 🟥 The 284M-record count is ShinyHunters&#x27; own characterisation; unique-individual figure TBD. SecurityWeek · Malwarebytes [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>Boston Scientific</title><link>/briefings/2026/09/06/2026-09-06/</link><guid isPermaLink="false">2026-09-06-Boston Scientific</guid><pubDate>Sun, 06 Sep 2026 06:00:00 +0000</pubDate><description>Boston Scientific — Day 13 recovery; no new adverse network activity since Aug 25; mid-September full-restoration estimate unchanged — No material change from Sep 5. Shipping capabilities restored for the majority of product lines at major distribution centres globally; Cork manufacturing remains at reduced capacity. The Piper Sandler mid-September restoration estimate stands. 🟥 Threat actor and attack method not disclosed; no confirmed data exfiltration. Hospital procurement planners for elective cardiac procedures should continue contingency sourcing. Boston Scientific · SecurityWeek [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>McKesson&#x27;s Sep 9 silence is itself an intelligence signal: either a private resolution is in progress at or above $55M, or a healthcare-data</title><link>/briefings/2026/09/06/2026-09-06/</link><guid isPermaLink="false">2026-09-06-McKesson&#x27;s Sep 9 silence is itself an intelligence signal: e</guid><pubDate>Sun, 06 Sep 2026 06:00:00 +0000</pubDate><description>McKesson&#x27;s Sep 9 silence is itself an intelligence signal: either a private resolution is in progress at or above $55M, or a healthcare-data publication of 284M records in the next 72 hours will trigger the largest US healthcare breach notification event of 2026. Either outcome reshapes the structural economics of US healthcare extortion. A disclosed payment sets a $55M price floor for the next attacker targeting a major US healthcare distributor — and every distributor knows who the other McKesson-scale players are. A publication triggers state AG enforcement actions, class actions in multiple jurisdictions, OCR breach investigation, and Senate Commerce Committee scrutiny. The vishing+Okta+Snowflake attack chain is now documented and repeatable; ShinyHunters demonstrated it at scale in 2024 against Snowflake customers, and the McKesson operation shows the methodology survives platform security improvements. SecurityWeek · ExZec Cyber [🌍 GEOPOLITICS]</description></item><item><title>McKesson / ShinyHunters</title><link>/briefings/2026/09/05/2026-09-05/</link><guid isPermaLink="false">2026-09-05-McKesson / ShinyHunters</guid><pubDate>Sat, 05 Sep 2026 06:00:00 +0000</pubDate><description>McKesson / ShinyHunters — Sep 9 data-publication deadline 4 days out; $55M demand unanswered; no public payment or settlement signal — As of Sep 5, ShinyHunters has not published data and McKesson has not confirmed payment or resolution. The Sep 9 deadline was the group&#x27;s second stated threshold (the initial September 1 negotiation window passed without McKesson engaging publicly). The 284M-record Snowflake exfiltration (attack window Aug 21–25) involved vishing → Okta SSO credential theft → multi-SaaS pivot, a methodology structurally identical to the Scattered Spider/UNC3944 playbook. One credible source reports the initial deadline already passed and ShinyHunters has not yet published — consistent with a private negotiation or deliberate delay for leverage. 🟥 The 284M-record count is ShinyHunters&#x27; own Snowflake row-count characterisation; unique-individual figure TBD. SecurityWeek · ExZec Cyber · Malwarebytes [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>Boston Scientific</title><link>/briefings/2026/09/05/2026-09-05/</link><guid isPermaLink="false">2026-09-05-Boston Scientific</guid><pubDate>Sat, 05 Sep 2026 06:00:00 +0000</pubDate><description>Boston Scientific — day 12 recovery; Piper Sandler mid-September restoration estimate; no new network activity since Aug 25 — No change in status since Sep 4. Cork manufacturing remains at reduced capacity; partial order processing resumed for select product lines. Mid-September is the Piper Sandler restoration estimate. Hospital procurement planners for elective cardiac procedures should continue contingency sourcing. 🟥 Server Killers attribution remains an unconfirmed hacktivist claim; no data-exfiltration scope disclosed. Boston Scientific [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>The McKesson Sep 9 deadline</title><link>/briefings/2026/09/05/2026-09-05/</link><guid isPermaLink="false">2026-09-05-The McKesson Sep 9 deadline</guid><pubDate>Sat, 05 Sep 2026 06:00:00 +0000</pubDate><description>The McKesson Sep 9 deadline — still 4 days out and unanswered publicly — is the clearest live test of whether US healthcare extortion has reached a scale where the payment calculus inverts: $55M may be less than the regulatory, litigation, and remediation cost of a 284M-record publication. The vishing+Okta+Snowflake attack chain is now documented for McKesson. If data publishes on September 9 (or shortly after, given the initial deadline already passed), the breach notification volume, state AG actions, and civil litigation that follow will dwarf the ransom demand. If a private resolution is in progress — consistent with the current silence — it sets a $55M price floor for the next attacker targeting a major US healthcare distributor. Either outcome raises the structural ransomware-risk pricing for the entire healthcare supply chain. SecurityWeek · ExZec Cyber [🌍 GEOPOLITICS]</description></item><item><title>McKesson / ShinyHunters</title><link>/briefings/2026/09/04/2026-09-04/</link><guid isPermaLink="false">2026-09-04-McKesson / ShinyHunters</guid><pubDate>Fri, 04 Sep 2026 06:00:00 +0000</pubDate><description>McKesson / ShinyHunters — Sep 9 data-publication deadline 5 days out; $55M ransom demand confirmed; vishing-plus-Snowflake attack vector now documented — Reporting confirms the $55M demand (the largest on record against a US healthcare company) and attack methodology: ShinyHunters used voice phishing (vishing) against multiple McKesson employees to compromise Okta SSO credentials, then accessed McKesson&#x27;s Salesforce and Snowflake environments, exfiltrating data between August 21–25. McKesson confirmed the breach in an SEC 8-K filing and is under active investigation. No public payment or negotiation disclosure. If data publishes September 9, the 284M-record exposure — covering SSNs, Medicaid IDs, diagnoses, prescriptions, and physician-practice records — would be the largest healthcare breach on record. 🟥 The 284M figure is ShinyHunters&#x27; own characterization of Snowflake row counts; unique-individual count TBD. SecurityWeek · Malwarebytes · Tech Insider [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>Boston Scientific</title><link>/briefings/2026/09/04/2026-09-04/</link><guid isPermaLink="false">2026-09-04-Boston Scientific</guid><pubDate>Fri, 04 Sep 2026 06:00:00 +0000</pubDate><description>Boston Scientific — day 11 recovery; Piper Sandler projects full shipping restoration mid-September; CrowdStrike found no new network intrusion activity since Aug 25 — As of Sep 3–4, Boston Scientific reports no new unauthorized activity since containment on August 25. Partial order processing has resumed for some product lines; Cork, Ireland manufacturing facility remains at reduced capacity. Piper Sandler&#x27;s three-week recovery estimate from August 25 places full restoration around September 15. The company has not attributed the attack or disclosed data exfiltration scope. Hospital procurement planners for elective cardiac procedures should continue contingency sourcing into next week. 🟥 Server Killers attribution remains an unconfirmed hacktivist claim. SecurityWeek · Boston Scientific [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>DiaSorin S.p.A. / Settra</title><link>/briefings/2026/09/04/2026-09-04/</link><guid isPermaLink="false">2026-09-04-DiaSorin S.p.A. / Settra</guid><pubDate>Fri, 04 Sep 2026 06:00:00 +0000</pubDate><description>DiaSorin S.p.A. / Settra — Italian diagnostics giant listed on DLS September 3; 🟥 unverified claim — Settra ransomware group (emerged June 2026, double-extortion model) posted DiaSorin S.p.A. — an Italian multinational in vitro diagnostics company (EURONEXT Milan: DIA, €1B+ revenue, 3,000+ employees, 60+ countries) — to its DLS on September 3. If confirmed, this would be one of the largest European diagnostics companies hit this year. Scope and data volume not disclosed. 🟥 DLS claim only; verify before treating as a breach. DeXpose · Malware News [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>MedEvolve / Settra</title><link>/briefings/2026/09/04/2026-09-04/</link><guid isPermaLink="false">2026-09-04-MedEvolve / Settra</guid><pubDate>Fri, 04 Sep 2026 06:00:00 +0000</pubDate><description>MedEvolve / Settra — US medical billing company DLS claim; ~820GB exfiltrated; attack date estimated August 11 — Settra posted MedEvolve (medevolve.com), a US medical billing and practice management software provider, to its DLS on September 3. Estimated data volume: ~820GB including PHI from billing records. Attack estimated August 11; publication notice September 3. MedEvolve has prior disclosure history (FTP server exposure, 2018). 🟥 DLS claim; verify before treating as a breach. DeXpose · ransomware.live [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>CISA/FBI/HHS updated Medusa ransomware advisory (Aug 18–19)</title><link>/briefings/2026/09/04/2026-09-04/</link><guid isPermaLink="false">2026-09-04-CISA/FBI/HHS updated Medusa ransomware advisory (Aug 18–19)</guid><pubDate>Fri, 04 Sep 2026 06:00:00 +0000</pubDate><description>CISA/FBI/HHS updated Medusa ransomware advisory (Aug 18–19) — 500+ critical infrastructure victims confirmed; new TTPs documented; healthcare/public health sector specifically highlighted — The joint agencies updated the #StopRansomware: Medusa advisory (originally AA25-071A, March 2025) on August 18–19, 2026, incorporating FBI threat intelligence through April 2026. Key updates: 500+ critical infrastructure victims confirmed (up from 300+ in the March 2025 advisory); Medusa affiliates (including nation-state-linked Storm-1175) now exploit zero-days within 24 hours of disclosure and sometimes days before public announcement; access brokers now compensated $100 to $1M depending on exclusivity. The updated advisory specifically calls out the Healthcare and Public Health sector as primary targeting focus. Despite the Medusa Blog DLS going dark in February 2026, the underlying infrastructure and affiliate network remain active. Healthcare organizations should consult the updated advisory for new IOCs and ATT&amp;CK technique mappings. CISA Updated Advisory · Help Net Security · The Record [🚨 INTELLIGENCE AGENCY ALERTS &amp; POLICY]</description></item><item><title>Settra (emerging)</title><link>/briefings/2026/09/04/2026-09-04/</link><guid isPermaLink="false">2026-09-04-Settra (emerging)</guid><pubDate>Fri, 04 Sep 2026 06:00:00 +0000</pubDate><description>Settra (emerging) — 4+ victims across healthcare, construction, telecom on Sep 3; now tracking as a distinct threat — Settra (emerged June 2026, double-extortion RaaS) posted at least four victims on September 3: DiaSorin S.p.A. (Italy, healthcare/biotech), MedEvolve (US, medical billing), Hansler Smith Limited (Canada, professional services), and Teletek Structures Inc. (Canada, telecom infrastructure). The Sep 3 wave marks Settra as a group warranting dedicated monitoring; its targeting of European healthcare and North American telecom/construction on a single day suggests a surge in operational tempo. No reliable victim count or operational timeline published yet. 🟥 All DLS claims; unverified. DeXpose · SOCRadar [🌐 THREAT ACTOR &amp; CAMPAIGN ACTIVITY]</description></item><item><title>The McKesson extortion arc</title><link>/briefings/2026/09/04/2026-09-04/</link><guid isPermaLink="false">2026-09-04-The McKesson extortion arc</guid><pubDate>Fri, 04 Sep 2026 06:00:00 +0000</pubDate><description>The McKesson extortion arc — vishing, Okta SSO, and Snowflake in the same chain — is a forensic map of how credential-based attacks are industrializing at the healthcare sector scale; the Sep 9 outcome will price the next wave. The attack methodology now documented for McKesson (vishing employees → Okta SSO credential theft → Snowflake cloud data exfiltration) is structurally identical to the Scattered Spider / UNC3944 playbook that hit MGM, Caesars, and dozens of financial firms in 2023–2024 — and ShinyHunters operated alongside that community. The difference is scale: healthcare data at 284M records is an order of magnitude larger than any prior ShinyHunters target, suggesting a deliberate targeting of sectors where HIPAA notification requirements and patient-safety optics systematically raise the payment incentive. If McKesson pays (or a private settlement occurs), every major US healthcare distributor, PBM, and hospital chain becomes the next addressable target. SecurityWeek · Malwarebytes [🌍 GEOPOLITICS]</description></item><item><title>McKesson / ShinyHunters</title><link>/briefings/2026/09/03/2026-09-03/</link><guid isPermaLink="false">2026-09-03-McKesson / ShinyHunters</guid><pubDate>Thu, 03 Sep 2026 06:00:00 +0000</pubDate><description>McKesson / ShinyHunters — Sep 9 data-publication deadline now the primary near-term risk; no ransom payment confirmed; 284M healthcare records at stake — ShinyHunters&#x27; Sep 1 contact deadline has lapsed without a confirmed McKesson response; the group&#x27;s separate data-publication deadline is September 9. Per reporting from multiple outlets, McKesson has not publicly confirmed payment or active negotiations. ShinyHunters has consistently followed through on publication threats when deadlines pass and no private deal is reached. The claimed dataset (284M records including SSNs, Medicaid IDs, diagnoses, and appointment data drawn from McKesson&#x27;s Salesforce and Snowflake environments) remains unconfirmed in scope but would constitute one of the largest healthcare data exposures on record. 🟥 The 284M figure is ShinyHunters&#x27; own characterization of Snowflake row counts — confirmed patient scope remains under investigation. SecurityWeek · BleepingComputer · HIPAA Journal [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>Boston Scientific</title><link>/briefings/2026/09/03/2026-09-03/</link><guid isPermaLink="false">2026-09-03-Boston Scientific</guid><pubDate>Thu, 03 Sep 2026 06:00:00 +0000</pubDate><description>Boston Scientific — partial order processing confirmed restored for select product lines (day 10); full recovery timeline still undisclosed — Boston Scientific confirmed on Sep 2 that partial order processing and shipping has resumed for some product lines following the Aug 25 cyberattack; the Cork, Ireland cardiovascular manufacturing facility remains in reduced-capacity mode. CrowdStrike confirmed no new malicious network activity since containment; forensics focus is now on scoping data access. Hospital procurement planners for elective cardiac procedures (stents, defibrillators, EP catheters) should continue contingency sourcing planning. 🟥 Server Killers attribution remains an unconfirmed hacktivist claim. SecurityWeek [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>McKesson&#x27;s Sep 9 data-publication deadline is a live test of the US healthcare sector&#x27;s ransom-payment posture; the outcome will calibrate S</title><link>/briefings/2026/09/03/2026-09-03/</link><guid isPermaLink="false">2026-09-03-McKesson&#x27;s Sep 9 data-publication deadline is a live test of</guid><pubDate>Thu, 03 Sep 2026 06:00:00 +0000</pubDate><description>McKesson&#x27;s Sep 9 data-publication deadline is a live test of the US healthcare sector&#x27;s ransom-payment posture; the outcome will calibrate ShinyHunters&#x27; next targeting cycle. Healthcare is structurally the most extortion-susceptible US sector — HIPAA breach-notification obligations, patient-safety optics, and supply-chain dependencies create overlapping pressure for private settlement. If McKesson pays or negotiates silently and no data appears, the incident disappears from the public record but validates the return on investment for the attack TTPs (vishing + Okta SSO + Snowflake exfiltration). If data is published Sep 9, the 284M-record exposure (one-third of US prescription-medicine supply chain&#x27;s patient data) creates regulatory, litigation, and market pressure that will restructure how major pharma distributors manage third-party data environments. Both outcomes reshape the sector&#x27;s threat calculus. SecurityWeek · HIPAA Journal [🌍 GEOPOLITICS]</description></item><item><title>NovoCure (SEC filing confirmed)</title><link>/briefings/2026/09/02/2026-09-02/</link><guid isPermaLink="false">2026-09-02-NovoCure (SEC filing confirmed)</guid><pubDate>Wed, 02 Sep 2026 06:00:00 +0000</pubDate><description>NovoCure (SEC filing confirmed) — company confirms mid-August unauthorized access; 1,400+ US cancer patients&#x27; records accessed; treatment devices not affected — NovoCure (NYSE: NVCR), which makes Tumor Treating Fields (TTFields) electromagnetic therapy devices for brain and lung cancer, filed a breach disclosure confirming unauthorized access to its information systems in mid-August. The investigation found attackers accessed over 1,400 US patient records containing patient ID numbers (but not names or other identifying data for most); fewer than 50 western US patients had fuller identifying and provider contact information exposed. Employee contact details (job titles, phone numbers) were also accessed. NovoCure states medical treatment devices were not accessed and systems remain functional. The company is assessing HIPAA notification obligations. This upgrades the previously 🟥 ShinyHunters DLS claim (Aug 22) to a company-confirmed breach; NovoCure&#x27;s disclosure does not name an attacker. BleepingComputer · The Register [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>McKesson</title><link>/briefings/2026/09/02/2026-09-02/</link><guid isPermaLink="false">2026-09-02-McKesson</guid><pubDate>Wed, 02 Sep 2026 06:00:00 +0000</pubDate><description>McKesson — ShinyHunters&#x27; Sep 1 ransom deadline has passed with no confirmed payment; data release risk now elevated — ShinyHunters&#x27; 72-hour deadline for McKesson to contact them for the $55,236,150 ransom expired on September 1. As of this briefing, McKesson has made no public statement confirming or denying payment, and the 284M-record dataset has not been confirmed released. ShinyHunters has historically followed through on data-dump threats when deadlines lapse; the absence of a confirmed payment or active negotiation means data release is the elevated near-term risk. 🟥 The 284M records figure remains ShinyHunters&#x27; own characterization of Snowflake row counts — confirmed patient scope is still under investigation. SecurityWeek · BleepingComputer [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>Boston Scientific</title><link>/briefings/2026/09/02/2026-09-02/</link><guid isPermaLink="false">2026-09-02-Boston Scientific</guid><pubDate>Wed, 02 Sep 2026 06:00:00 +0000</pubDate><description>Boston Scientific — partial order processing expected to resume &quot;this week&quot; (day 9); CrowdStrike investigating; Server Killers attribution remains unconfirmed — Boston Scientific&#x27;s incident response team (CrowdStrike) reports no signs of malicious network activity since August 25, and the breach appears contained to some on-premises systems. The company expects to resume partial order processing and shipping for some product lines this week, but a full restoration timeline has not been given. The Cork, Ireland cardiovascular manufacturing facility (stents, defibrillators, electrophysiology catheters) remains in reduced-capacity mode. Hospital procurement planners for elective cardiac procedures should continue contingency sourcing. 🟥 Server Killers attribution remains an unconfirmed claim by the hacktivist group; Boston Scientific has not confirmed any attacker identity. SecurityWeek · Supply Chain Dive [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>PaperCut NG/MF (CVE-2026-81578 + CVE-2026-82078)</title><link>/briefings/2026/09/02/2026-09-02/</link><guid isPermaLink="false">2026-09-02-PaperCut NG/MF (CVE-2026-81578 + CVE-2026-82078)</guid><pubDate>Wed, 02 Sep 2026 06:00:00 +0000</pubDate><description>PaperCut NG/MF (CVE-2026-81578 + CVE-2026-82078) — Metasploit module published Sep 1; attacks escalated to hands-on-keyboard; CISA KEV Aug 31; federal deadline Sep 14; 1,000+ internet-exposed instances — The PaperCut zero-day exploit chain (CVE-2026-81578 improper access control CVSS 8.8 + CVE-2026-82078 unsafe Java class-loading CVSS 9.4) has moved from active zero-day to Metasploit-module-available in six days. Rapid7 published module `multi/http/papercut_ng_external_user_lookup_rce` (PR #21842, 845 lines) supporting unauthenticated RCE on PaperCut MF/NG versions 24.x, 25.x, 26.x. The module bypasses PaperCut&#x27;s first emergency patch (v1 bypassed within 48h; v2 is the current remediation). CISA added both CVEs to KEV on August 31; federal agency deadline is September 14. ShadowServer counts 1,000+ internet-exposed PaperCut instances. Attacks have progressed from scanning to hands-on-keyboard intrusion activity, per SecurityWeek. Any organization running PaperCut in higher education, healthcare, or government — the primary deployment verticals — must treat this as critical and patch to v2 immediately. SecurityWeek · Rapid7 · BleepingComputer · The Hacker News [🔓 CRITICAL VULNERABILITIES]</description></item></channel></rss>
