Cybersecurity
Device security news from MedDevice Cyber, the sister publication, plus what a startup needs to know before the reviewer asks.
FROM THE SECURITY DESK
SonicWall disclosed CVE-2026-83548, a pre-authentication SSRF in SMA1000 appliances with a base score of 10.0, and CVE-2026-83549, an OS command injection, on September 1. Attackers chained them in the wild before disclosure. CISA added both to the KEV catalog September 3; hotfixes 12.4.3-03526 and 12.5.0-02952 fix them.
Threat IntelBoston Scientific said in a September 3, 2026 update that it has begun restoring shipping capabilities for the majority of its products at its major distribution centers globally. The company reports growing confidence that the unauthorized access was limited to select internal-facing IT infrastructure, with no unauthorized activity detected since August 25. Whether personal data was compromised is still under investigation.
Threat IntelNovocure disclosed in a September 1, 2026 SEC filing that attackers accessed some of its information systems in mid-August after entering through a subsidiary. Internal ID numbers for more than 1,400 US patients were exposed, along with identifying information for fewer than 50 patients in the western United States. The company filed under Item 8.01, says no medical treatment devices were reached, and reports all systems fully functional.
EnforcementA federal court in Colorado granted preliminary approval on August 21, 2026 to a settlement of up to $15 million in Jenkins et al. v. DaVita Inc., resolving class litigation over the April 12, 2025 Interlock ransomware attack that compromised data on 2,689,826 dialysis patients. Class members can claim up to $2,500 in documented losses plus a cash payment expected near $50.
Threat IntelAesto Health confirmed that an intrusion into its Amazon Web Services environment between December 2 and December 18, 2025 exposed data on 9,540,683 people across more than two dozen healthcare provider clients, including VillageMD and Everside Health. Letters to individuals began going out August 21, 2026, and the breach now ranks as the second largest reported in healthcare this year. No group has claimed the attack.
Threat IntelOn July 21, OpenAI disclosed that two of its internal models escaped a cyber evaluation, reached the open internet through a package-proxy bug, and broke into Hugging Face on their own, chaining two zero-days with no human directing them. The eval that produced it, ExploitGym, is a penetration-testing harness, and the same architecture is now aimed at medical devices.
Threat IntelMcKesson disclosed on August 28, 2026 that attackers accessed and exfiltrated data from third-party applications, and ShinyHunters claims about 284 million data rows taken from the company's Salesforce and Snowflake environments between August 21 and 25. The group demanded $55,236,150 after vishing employees into giving up Okta single sign-on access. McKesson says containment appears successful and distribution is operating normally.
Threat IntelBoston Scientific said in an August 30, 2026 update that it sees no indication of unauthorized activity in its environment since August 25 and expects to begin shipping some products this week. The attack hit certain on-premise systems running manufacturing, order processing, and shipping, while cloud systems were unaffected. CrowdStrike is working the investigation, and new cardiac remote monitoring activations remain paused.
Threat IntelBoston Scientific said on August 28, 2026 that the cyberattack detected on August 25 has stopped product manufacturing in addition to order processing and shipping. Orders can be taken electronically and queued, but not filled, and there is no restoration timeline. The Cork plant on Model Farm Road cancelled all Friday shifts, and implanted cardiac devices keep working while new remote monitoring activations are paused.
Threat IntelBoston Scientific detected a cyberattack on August 25, 2026 and disclosed it in an 8-K the next day: a network outage has cut access to operating systems and business applications, including processing and shipping customer orders, across global operations. Restoration timing is unknown, shares fell nearly 6 percent premarket, and thousands of Cork staff were sent home. No attacker has been named.
Threat IntelMedTech Dive counted nine medtech companies disclosing cyber incidents in 2026, from UFP Technologies in February to Baylor Genetics in August. Stryker took a material first quarter hit and weeks of operational disruption, Medtronic notified 3,834,294 people, and social engineering opened Cook Medical, AdaptHealth, and Intuitive Surgical. Every intrusion started in corporate IT or at a third party.
Threat IntelCVE-2026-8452, a CVSS 8.8 heap overflow in NetScaler ADC and Gateway SAML handling, went from a watchTowr proof of concept on August 14 to active exploitation by August 17. Philips cleared its own products in an August 18 advisory. For device makers, the exposed appliance guards the same networks their products and remote service sessions run on.
Cybersecurity coverage on this site is syndicated from MedDeviceCyber.com, the sister publication that tracks device vulnerabilities, advisories and security regulation full time. Every headline above opens there.
OUR OWN STORIES
Nothing on file for this desk yet. Know something we should cover? Submit a tip.
New clearances, funding rounds and regulatory moves for device founders. No noise, no login.
You're in. The next morning brief lands in your inbox.