The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Medical Equipment
Breach intelligence, attack campaigns, and threat reports targeting the Medical Equipment sector.
Explore Other Sectors
Medical Equipment Threat Reports
Critical Orthanc DICOM Server Vulnerability Threatens Healthcare Imaging Systems
A critical vulnerability (CVE-2026-87020) has been discovered in Orthanc DICOM Server versions prior to 1.13.0, affecting healthcare systems worldwide. The vulnerability stems from an integer overflow in pitch and buffer-size computation that leads to a heap out-of-bounds write when the server processes maliciously crafted PNG or JPEG images. Authenticated remote attackers can exploit this flaw to crash the Orthanc process, causing denial-of-service conditions that disrupt medical imaging operations. The vulnerability has been assigned a CVSS score of 8.1 (High), indicating significant risk to healthcare infrastructure. With medical imaging systems being critical components of healthcare delivery, this vulnerability poses substantial operational risks including disrupted patient care, delayed diagnoses, and potential compliance violations under HIPAA and other healthcare regulations. This vulnerability highlights the growing threat landscape targeting healthcare infrastructure, particularly as medical devices become increasingly connected and digitized. The timing coincides with heightened scrutiny of healthcare cybersecurity following recent high-profile attacks on medical facilities and increased regulatory focus on protecting patient data and ensuring continuity of care.
2 weeks ago
Kill Chain
AdaptHealth Breach Exposes 4.1M Patients in ShinyHunters Attack
In July 2026, healthcare provider AdaptHealth disclosed a major data breach affecting 4.1 million patients after the ShinyHunters ransomware group successfully executed a social engineering attack against a third-party contractor. The attack, which occurred on June 5, 2026, compromised privileged credentials and enabled access to cloud-based patient management systems, document storage platforms, and electronic health records. The breach exposed full names, contact information, demographic data, health insurance details, and protected health information across AdaptHealth's network of 680 locations serving all 50 U.S. states. This incident exemplifies the escalating threat landscape targeting healthcare organizations through sophisticated social engineering tactics and third-party supply chain vulnerabilities. The breach highlights the increasing trend of ransomware groups specifically targeting healthcare data for maximum impact and regulatory pressure, making it a critical reference point for current cybersecurity strategies in the healthcare sector.
2 weeks ago
Kill Chain
Boston Scientific Cyberattack Disrupts Global Medical Device Operations
On August 25, 2026, Boston Scientific, a major medical device manufacturer with $20 billion in annual revenue, suffered a cyberattack that disrupted IT systems and caused global operational outages. The incident impacted critical business applications and halted the company's ability to process and ship customer orders across its 127-country presence. While the attack vector and threat actor remain undisclosed, the company activated incident response procedures and engaged external cybersecurity experts for containment and investigation efforts. The attack highlights the increasing threat to critical healthcare infrastructure and medical device supply chains. Healthcare organizations face heightened risks as ransomware groups target high-value entities with essential services, potentially affecting patient care and medical device availability worldwide.
4 weeks ago
Kill Chain
Critical Security Flaw in Flow Neuroscience FL-100: CVE-2026-18164
In August 2026, a critical vulnerability (CVE-2026-18164) was identified in Flow Neuroscience's FL-100 device, a transcranial direct current stimulation headset used for treating major depressive disorder. The flaw involved hard-coded credentials that allowed attackers within Bluetooth range to bypass authentication and manipulate brain stimulation parameters, potentially overriding safety limits. This vulnerability affected all FL-100 devices manufactured before July 2026. Flow Neuroscience promptly released firmware updates to address the issue, urging users to update their devices via the Flow app. This incident underscores the persistent risks associated with hard-coded credentials in medical devices, a known issue in industrial control systems. The exploitation of such vulnerabilities can lead to unauthorized control over critical device functions, posing significant safety hazards. The healthcare sector must prioritize robust security measures to prevent similar threats, especially as medical devices increasingly incorporate wireless technologies.
1 month ago
Kill Chain
Critical Vulnerability in Pulsetto Vagus Nerve Stimulator: CVE-2026-18844
In August 2026, a critical vulnerability (CVE-2026-18844) was identified in the Pulsetto Vagus Nerve Stimulator, a device widely used for non-invasive wellness applications. The flaw allows unauthenticated commands to be sent over its Bluetooth Low Energy (BLE) interface, enabling attackers to disable safety mechanisms or alter stimulation settings. Pulsetto has not responded to mitigation requests, leaving users exposed to potential exploitation. This incident underscores the growing security risks associated with IoT medical devices, emphasizing the need for robust security measures and prompt vendor responses to vulnerabilities to protect patient safety and device integrity.
1 month ago
Kill Chain
Critical Vulnerability in Medixant RadiAnt DICOM Viewer: CVE-2025-1001
In February 2025, a vulnerability (CVE-2025-1001) was identified in Medixant's RadiAnt DICOM Viewer, a widely used medical imaging application. The flaw stemmed from improper certificate validation in the software's update mechanism, allowing attackers to perform machine-in-the-middle (MITM) attacks. By intercepting and modifying network traffic, malicious actors could deliver harmful updates to users, potentially compromising medical imaging systems. Medixant promptly addressed the issue by releasing version 2025.1, which rectified the vulnerability. Users were advised to update to this version or later to mitigate the risk. ([cisa.gov](https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-051-01?utm_source=openai)) This incident underscores the critical importance of robust certificate validation in software update mechanisms, especially within the healthcare sector. As cyber threats targeting medical infrastructure continue to evolve, ensuring the integrity and security of software updates remains paramount to protect sensitive patient data and maintain operational continuity.
1 month ago
Kill Chain
Health-ISAC Alerts Healthcare Sector to Rising ShinyHunters Data Theft Attacks
In July 2026, Health-ISAC issued a warning about a surge in data theft attacks targeting healthcare organizations by the cyber extortion group ShinyHunters. The group employs sophisticated social engineering techniques, including voice phishing (vishing), to compromise single sign-on (SSO) accounts. Once access is gained, they exploit these credentials to infiltrate various cloud-based services such as Salesforce, Microsoft 365, and SharePoint, leading to significant data exfiltration and potential extortion. This escalation underscores the critical need for healthcare entities to bolster their cybersecurity defenses, particularly in securing SSO systems and training staff to recognize and resist social engineering attacks. The healthcare sector's increasing reliance on cloud services makes it a prime target for such sophisticated cyber threats.
1 month ago
Kill Chain
Abbott Laboratories Faces Cyber Attacks: ShinyHunters' Vishing Tactics in 2026
In July 2026, Abbott Laboratories disclosed two separate cybersecurity incidents. The first involved unauthorized access to internal systems within its Cancer Diagnostics business, attributed to the ShinyHunters extortion group. The attackers reportedly used a vishing attack in mid-June to compromise a Microsoft Entra single sign-on account, leading to data exfiltration. The second incident pertained to a potential breach of Abbott's LabCentral portal, with claims of stolen company data. Abbott stated that these incidents did not impact business operations, product availability, or patient services, and that the affected systems were separate from its core infrastructure. These incidents underscore the escalating threat posed by sophisticated social engineering attacks targeting healthcare organizations. The ShinyHunters group has been increasingly active, employing tactics like vishing to exploit single sign-on vulnerabilities, highlighting the need for enhanced security measures and employee awareness training to mitigate such risks.
2 months ago
Kill Chain
Medtronic Data Breach: ShinyHunters Claims 9 Million Records Stolen
In April 2026, Medtronic, a leading global medical device manufacturer, detected unauthorized access to its corporate IT systems. The cybercriminal group ShinyHunters claimed responsibility, alleging the theft of over 9 million records containing personally identifiable information (PII) and internal corporate data. Medtronic confirmed the breach but has not verified the exact number of records compromised. The company assured that the incident did not impact product security, patient safety, or operational systems. Investigations are ongoing to determine the full scope of the data accessed. This incident underscores the persistent threat posed by cyber extortion groups targeting critical infrastructure sectors. The healthcare industry, in particular, remains a prime target due to the sensitive nature of the data it handles. Organizations must continually enhance their cybersecurity measures to protect against such sophisticated attacks.
2 months ago
Kill Chain
Critical Vulnerabilities Discovered in OFFIS DCMTK Toolkit Used in Medical Imaging
In June 2026, multiple critical vulnerabilities were identified in the OFFIS DCMTK Toolkit, a widely used DICOM toolkit in medical imaging software. These vulnerabilities, including CVE-2026-50003, CVE-2026-50254, CVE-2026-35505, CVE-2026-52868, and CVE-2026-44628, could allow attackers to write files outside intended directories, access unauthorized information, exhaust memory, or crash affected DCMTK client or server processes. The vulnerabilities affect DCMTK versions up to 3.7.0. ([hipaajournal.com](https://www.hipaajournal.com/offis-dcmtk-vulnerabilities-june-2026/?utm_source=openai)) The healthcare sector's reliance on DICOM standards for medical imaging makes these vulnerabilities particularly concerning. Exploitation could lead to unauthorized access to sensitive patient data and disruption of critical medical services. Organizations using affected versions are urged to apply the provided patches promptly to mitigate potential risks.
2 months ago
Kill Chain
Critical Vulnerability in pydicom's pynetdicom Library Exposes Healthcare Systems
In June 2026, a critical vulnerability (CVE-2026-56445) was identified in the pydicom pynetdicom library, specifically affecting versions from 1.0.0 up to and including 3.0.4. This flaw resides in the qrscp application's C-STORE handler, which improperly handles attacker-supplied DICOM datasets, allowing unauthenticated attackers to write files to arbitrary paths on the server. The vulnerability poses significant risks, particularly to the healthcare sector, as it could lead to unauthorized data manipulation or system compromise. The maintainers of pynetdicom have not yet released a fix for this vulnerability. Organizations utilizing affected versions are advised to restrict network exposure of the qrscp DICOM port (default 11112) to trusted peers, implement firewall protections, and monitor for updates from the project's repository. This incident underscores the importance of securing medical imaging software against potential cyber threats.
2 months ago
Kill Chain
Critical SSRF Vulnerability in OHIF DICOM Web Viewer Framework (CVE-2026-12473)
In June 2026, a critical vulnerability (CVE-2026-12473) was identified in the OHIF DICOM Web Viewer Framework versions up to 3.12.0. This Server-Side Request Forgery (SSRF) flaw allowed attackers to steal authenticated clinicians' OIDC Bearer tokens via crafted links, potentially granting unauthorized access to sensitive patient data. The issue stemmed from two data sources—DICOMWebProxy and DICOMJSON—fetching arbitrary URL parameters without validation, leading to token exposure when requests were sent to attacker-controlled servers. ([hipaajournal.com](https://www.hipaajournal.com/high-severity-vulnerability-identified-in-ohif-viewers-dicom/?utm_source=openai)) The vulnerability was addressed with the release of version 3.12.2 on May 18, 2026. Users are strongly advised to upgrade to this version or later to mitigate the risk. This incident underscores the critical importance of validating external inputs and implementing robust security measures in healthcare applications to protect sensitive information. ([machinespirits.com](https://www.machinespirits.com/advisory/0a7f3c/?utm_source=openai))
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports