Výsledky hledání

sektor: zdravotnictví× v celém archivu zrušit filtry

56 karet z 56 položek CZ · EN/orig

1

1

The story behind the intelligence

Welcome to this week’s edition of the Threat Source newsletter. Our goal is to get accurate threat intelligence to our audience as quickly as possible, with all the context you need to ask the right questions of your own environment: How at risk are we from this threat? Are we prepared for it? And what can we do about it? What you don’t often see is all the... well, frankly, “mess” involved in producing it. All the dead ends we followed until we could confirm those ends were as dead as a…

Cisco McKesson PaperCut Anthropic zdravotnictví US

tg: rozbor tg: návod tg: názor tp: malware tp: únik dat tp: AI tp: identita

Cisco Talos ·

2

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

In this article Attack chain overviewCampaign scope and targetingMitigation and protection guidanceReferencesLearn more Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers. The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of…

Microsoft Razer Kaspersky zdravotnictví výroba a průmysl veřejná správa školství US

tg: varování tg: rozbor tp: malware

Microsoft Security Blog ·

4

Rockwell Automation Historian ME

View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution. The following versions of Rockwell Automation Historian ME are affected: Series B 5.202 (CVE-2025-12768, CVE-2026-12661) Series C 7.101 (CVE-2025-12768, CVE-2026-12661) CVSS Vendor Equipment Vulnerabilities v3 8 Rockwell Automation Rockwell Automation Historian ME Out-of-bounds Write, Stack-based Buffer Overflow Background…

CVSS 8.0 CVE-2025-12768 CVE-2026-12661 Rockwell Automation výroba a průmysl energetika vodárenství zdravotnictví US

tg: zranitelnost tp: průmyslové systémy

CISA Advisories ·

3

McKesson confirms cyber incident after ShinyHunters claims patient-data theft

Healthcare and pharmaceutical-distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and the theft of data. McKesson Corporation is an American healthcare company that distributes pharmaceuticals and provides medical supplies, health information technology, and care management tools. McKesson says it discovered the cybersecurity incident on August 25, 2026, and that its investigation is still in early stages. “Based on our…

McKesson Okta Salesforce Snowflake zdravotnictví US

tg: incident tg: zneužíváno tp: phishing tp: únik dat tp: identita

Malwarebytes Labs ·

31th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and East Midlands airports, has disclosed a cyberattack that exposed data belonging to about 8.7 million customers. The compromised information includes contact details, vehicle registration numbers, and information collected through car park, lounge, fast-track, and Wi-Fi…

KEV ✓ CVSS 10.0 CVE-2026-18885 CVE-2026-18886 CVE-2026-74820 CVE-2026-75604 CVE-2026-81578 CVE-2026-82078 Check Point PaperCut Ubiquiti Vercel veřejná správa zdravotnictví doprava IL

tg: incident tg: zneužíváno tg: zranitelnost tg: přehled tp: malware tp: phishing tp: ransomware tp: únik dat tp: AI tp: špionáž tp: průmyslové systémy

Check Point Research ·

1

2

New Instagram and Facebook rules set a default two-hour limit for teens

Meta decided that discretion was the better part of valor on Wednesday, agreeing to settle a landmark child safety case for up to $17 billion. The agreement would introduce a default two-hour daily limit for teens on Instagram and Facebook, overnight restrictions, and a range of other protections. It also brings the trial to an early end before Mark Zuckerberg, who was listed as a witness, could testify. The company reached the settlement with a bipartisan coalition of 51 state attorneys…

Meta zdravotnictví US

Malwarebytes Labs ·

2

2

1

24th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 24th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Latvia’s Road Traffic Safety Directorate (CSDD) has confirmed a breach affecting payment records of more than 1.2 million people – roughly two-thirds of the country’s population – as well as 200,000 organizations. The stolen data included identification numbers, license plates, payment amounts, dates and addresses. Attackers reportedly exploited a…

KEV ✓ EPSS 0.41 CVSS 10.0 CVE-2026-12569 CVE-2026-19478 CVE-2026-19489 CVE-2026-19490 Snowflake Siemens GitLab Cisco zdravotnictví výroba a průmysl energetika vodárenství IL

Check Point Research ·

4

Medical records, SSNs, and bank details exposed in CareCloud data breach

Healthcare technology giant CareCloud has confirmed that a data breach earlier this year impacted more than 3.75 million people, making it one of the largest healthcare data incidents disclosed this year. The New Jersey-based company, which provides electronic health record (EHR) and practice management services, first flagged the intrusion in an SEC filing back in March, but the true scope only became clear this month when the Department of Health and Human Services (HHS) breach tracker…

CareCloud zdravotnictví US

Malwarebytes Labs ·

Uso de credenciales embebidas en Virtuagym

Embedded credentials in Virtuagym Fri, 08/21/2026 - 11:51 Aviso Affected Resources Virtuagym / Resamania Backend API & Mobile Apps. All versions are affected at the time of reporting. Description INCIBE has coordinated the disclosure of a high-severity vulnerability affecting the backend API and mobile app of Virtuagym, a comprehensive technology platform and mobile app specialising in the fitness and health sector. The vulnerability was discovered by Pau Hinojosa.This vulnerability has been…

EPSS 0.00 CVSS 8.6 CVE-2026-12587 Virtuagym zdravotnictví obchod ES

INCIBE-CERT ·

3

2

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive…

CVSS 7.0 Rapid7 Microsoft veřejná správa zdravotnictví finance výroba a průmysl US

Rapid7 ·

Siemens Simcenter Nastran

View CSAF Summary Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions. The…

EPSS 0.00 CVSS 7.8 CVE-2026-59086 Siemens výroba a průmysl obrana energetika zdravotnictví US

CISA Advisories ·

2

17th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experienced a ransomware attack that affected part of its technology infrastructure and disrupted public services related to illicit-drug monitoring and legal processes. Officials confirmed that some files were encrypted but stated that no data theft was detected during the incident. MyDr, Poland’s primary…

KEV ✓ EPSS 0.25 CVSS 9.8 CVE-2026-53413 CVE-2026-65400 CVE-2026-68820 CVE-2026-71362 Microsoft Apple Adobe Zoom veřejná správa zdravotnictví obrana energetika IL

Check Point Research ·

2

Flow Neuroscience FL-100

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to manipulate brain stimulation parameters and override safety limits. The following versions of Flow Neuroscience FL-100 are affected: Flow Neuroscience FL-100 Halo Neuroscience FL-100 CVSS Vendor Equipment Vulnerabilities v3 8.1 Flow Neuroscience Flow Neuroscience FL-100 Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Healthcare and Public Health Countries…

EPSS 0.00 CVSS 8.1 CVE-2026-18164 Flow Neuroscience zdravotnictví US

CISA Advisories ·

Siemens Desigo DXR and PXC Controllers

View CSAF Summary A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Desigo DXR and PXC Controllers are affected: Desigo DXR2 vers:intdot/<01.21.233.16-7862 …

EPSS 0.00 CVSS 4.3 CVE-2026-59693 Siemens energetika zdravotnictví výroba a průmysl doprava US

CISA Advisories ·

2

Pulsetto Vagus Nerve Stimulator

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to use hidden commands to disable electrical safety mechanisms or modify other stimulation output settings. The following versions of Pulsetto Vagus Nerve Stimulator are affected: Pulsetto Vagus Nerve Stimulator vers:all/* (CVE-2026-18844) CVSS Vendor Equipment Vulnerabilities v3 8.1 Pulsetto Pulsetto Vagus Nerve Stimulator Hidden Functionality Background Critical Infrastructure Sectors: Healthcare and…

EPSS 0.00 CVSS 8.1 CVE-2026-18844 Pulsetto zdravotnictví US

CISA Advisories ·

Mira Hormone Monitor, Mira Android App

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token information, and obtain control of user accounts. The following versions of Mira Hormone Monitor, Mira Android App are affected: Mira Monitor Firmware 1.7.1.47 (CVE-2026-66875, CVE-2026-66098, CVE-2026-67558, CVE-2026-67568, CVE-2026-68067, CVE-2026-66340, CVE…

EPSS 0.00 CVSS 9.8 CVE-2026-64934 CVE-2026-66098 CVE-2026-66340 CVE-2026-66832 CVE-2026-66875 CVE-2026-67558 CVE-2026-67568 CVE-2026-68067 Quanovate Tech Inc. zdravotnictví US

CISA Advisories ·

1

#StopRansomware: Gunra Ransomware

Advisory at a Glance Title #StopRansomware: Gunra Ransomware Original Publication August 10, 2026 Executive Summary Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom…

KEV ✓ EPSS 0.98 CVE-2024-55591 CVE-2025-24472 veřejná správa zdravotnictví finance energetika US

CISA Advisories ·

2

Medixant RadiAnt DICOM

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause the application to crash if a maliciously crafted DICOM file is opened. The following versions of Medixant RadiAnt DICOM are affected: RadiAnt DICOM <=2025.2 CVSS Vendor Equipment Vulnerabilities v3 4.3 Medixant Medixant RadiAnt DICOM Out-of-bounds Write Background Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwide Company Headquarters Location: Poland…

EPSS 0.00 CVSS 4.3 CVE-2026-17264 Medixant zdravotnictví US

CISA Advisories ·

ABB Ability Zenon

View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data. The following versions of ABB Ability Zenon are affected: IIoT services with MongoDB (4.2) installed on ABB Ability Zenon vers:all/* CVSS Vendor Equipment Vulnerabilities v3 7.8 ABB ABB Ability Zenon Improper Handling of Length Parameter Inconsistency, Improper Neutralization of Null Byte or NUL Character, Collapse of Data…

KEV ✓ EPSS 0.83 CVSS 7.8 CVE-2020-7921 CVE-2020-7928 CVE-2025-14847 ABB energetika zdravotnictví vodárenství výroba a průmysl US

CISA Advisories ·

1

Thermo Fisher Applied Biosystems Genetic Analyzers

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to modify .fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results. The following versions of Thermo Fisher Applied Biosystems Genetic Analyzers are affected: Applied Biosystems 3500/3500xL Series Data Collection Software <=4.0.2 Applied Biosystems 3730/3730xL Series Data Collection Software <=5.0.2 Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software <=1.2.5…

EPSS 0.00 CVSS 8.4 CVE-2026-17583 Thermo Fisher zdravotnictví US

CISA Advisories ·

1

3rd August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported that drinking water safety was not affected. While the attack was not officially attributed, federal…

KEV ✓ EPSS 0.88 CVSS 9.8 CVE-2026-20316 CVE-2026-42897 CVE-2026-59309 CVE-2026-59310 CVE-2026-59726 CVE-2026-63077 CVE-2026-66066 Check Point Cisco Broadcom Microsoft vodárenství finance zdravotnictví telekomunikace IL

Check Point Research ·

2

You were onto something with “It’s the Climb,” Miley

Welcome to this week’s edition of the Threat Source newsletter. For my fianceé’s 30th birthday, I took her on a weekend trip to Shenandoah National Park – a favorite of ours since we went to a wedding there several years back. We’ve done several incredible hikes over the years, but one in particular had always loomed over my head: Old Rag, a 9.3 mile circuit hike that’s largely considered the most difficult in Virginia. I've always been warned that at the beginning and end, you hate Old Rag.…

Cisco Microsoft Check Point Zoho zdravotnictví veřejná správa vodárenství US

Cisco Talos ·

OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

Introduction We have been tracking two new backdoors, OctLurk and SilkLurk, observed in attacks against government organizations primarily in Central Asia since January 2025. Identified victims are located in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic. These organizations operate across several sectors, including healthcare, research, government offices, ministries of foreign affairs, logistics, law‑enforcement agencies, urban planning and…

veřejná správa zdravotnictví školství RU

Securelist (Kaspersky) ·

1

Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the…

KEV ✓ EPSS 0.92 CVE-2026-20127 CVE-2026-20182 CVE-2026-20245 Cisco telekomunikace energetika doprava finance obchod zdravotnictví US 2 zdrojů

Cisco PSIRT · Mandiant / Google TI

1

1

1

22nd June – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 22nd June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Texas Parks and Wildlife Department has been affected by a third-party data breach involving its license system vendor. The incident exposed driver’s license information, passport numbers, emails, phone numbers, and residential addresses for 3,087,721 hunting and fishing license customers. Social Security numbers and payment data were not affected.…

KEV ✓ EPSS 0.96 CVE-2026-20245 CVE-2026-33017 CVE-2026-34908 CVE-2026-34909 CVE-2026-34910 CVE-2026-41947 CVE-2026-41948 CVE-2026-55255 Cisco Ubiquiti Dify Langflow veřejná správa zdravotnictví finance IL

Check Point Research ·

1

Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

Written by: Patrick Whitsell, John McGuiness, Muhammad Umair Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. While remaining undetected for over a year, the threat actor compromised externally facing web applications, deployed bespoke malware, pivoted to sensitive internal systems, and…

Google zdravotnictví obrana školství US

Mandiant / Google TI ·

2

1

1

1

Лікарні, органи місцевого самоврядування та оператори FPV - у фокусі кластера кіберзагроз UAC-0247 (UAC-0244)

CERT-UA протягом березня-квітня 2026 року зафіксовано інтенсифікацію кібератак у відношенні органів місцевого самоврядування та, насамперед, комунальних закладів охорони здоров'я, зокрема клінічних лікарень та лікарень екстреної (швидкої) медичної допомоги.

zdravotnictví veřejná správa UA

CERT-UA ·

1

1

Кібератака UAC-0255 під виглядом сповіщення від CERT-UA із застосуванням програмного засобу AGEWHEEZE (CERT-UA#21075)

Національною командою реагування на кіберінциденти, кібератаки, кіберзагрози CERT-UA 26-27 березня 2026 року зафіксовано випадки розповсюдження електронних листів нібито від імені CERT-UA із закликом завантажити з сервісу Files.fm захищений паролем архів ("CERT_UA_protection_tool.zip", "protection_tool.zip") та встановити "спеціалізоване програмне забезпечення". Серед отримувачів листів: державні організації, медичні центри, охоронні фірми, навчальні заклади, фінансові установи, компанії…

veřejná správa zdravotnictví finance školství UA

CERT-UA ·

2

1