Výsledky hledání

sektor: zdravotnictví× v celém archivu zrušit filtry

63 karet z 63 položek · strana 1 z 2 CZ · EN/orig

1

Digital Watchdog VMAX DVR and NVR Product Lineups

View CSAF Summary Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a network pivot point. The following versions of Digital Watchdog VMAX DVR and NVR Product Lineups are affected: VMAX A1 G4 DVRs vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VMAX IP G4 NVRs vers:all/* …

EPSS 0.00 CVSS 9.6 CVE-2026-66372 CVE-2026-66887 CVE-2026-66890 CVE-2026-68070 CVE-2026-68950 CVE-2026-68953 Digital Watchdog veřejná správa zdravotnictví doprava US

tg: zranitelnost tp: identita

· CISA Advisories · Digital Watchdog VMAX DVR and NVR Product Lineups

3

NextGen Healthcare Mirth Connect

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition. The following versions of NextGen Healthcare Mirth Connect are affected: Mirth Connect <=v4.7.1 (CVE-2026-82583, CVE-2026-78224, CVE-2026-82578) CVSS Vendor Equipment Vulnerabilities v3 8.3 NextGen Healthcare NextGen Healthcare Mirth Connect Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), Improper Restriction…

EPSS 0.00 CVSS 8.3 CVE-2026-78224 CVE-2026-82578 CVE-2026-82583 NextGen Healthcare zdravotnictví US

tg: zranitelnost

· CISA Advisories · NextGen Healthcare Mirth Connect

Orthanc DICOM Server

View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition. The following versions of Orthanc DICOM Server are affected: Orthanc DICOM Server <1.13.0. (CVE-2026-87020) CVSS Vendor Equipment Vulnerabilities v3 8.1 Orthanc Orthanc DICOM Server Integer Overflow or…

EPSS 0.01 CVSS 8.1 CVE-2026-87020 Orthanc zdravotnictví US

tg: zranitelnost

· CISA Advisories · Orthanc DICOM Server

3

1

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan,…

PyPI npm Docker GitHub zdravotnictví veřejná správa média US

tg: varování tg: rozbor tp: malware tp: dodavatelský řetězec tp: AI tp: identita

· Mandiant / Google TI · GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

1

2

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

In this article Attack chain overviewCampaign scope and targetingMitigation and protection guidanceReferencesLearn more Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers. The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of…

zdravotnictví výroba a průmysl veřejná správa školství US

tg: varování tg: rozbor tp: malware

· Microsoft Security Blog · Counterfeit installers to system compromise: Tracking a deceptive software download campaign

5

Rockwell Automation Historian ME

View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution. The following versions of Rockwell Automation Historian ME are affected: Series B 5.202 (CVE-2025-12768, CVE-2026-12661) Series C 7.101 (CVE-2025-12768, CVE-2026-12661) CVSS Vendor Equipment Vulnerabilities v3 8 Rockwell Automation Rockwell Automation Historian ME Out-of-bounds Write, Stack-based Buffer Overflow Background…

EPSS 0.00 CVSS 8.0 CVE-2025-12768 CVE-2026-12661 Rockwell Automation výroba a průmysl zdravotnictví vodárenství US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation Historian ME

2

McKesson confirms cyber incident after ShinyHunters claims patient-data theft

Healthcare and pharmaceutical-distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and the theft of data. McKesson Corporation is an American healthcare company that distributes pharmaceuticals and provides medical supplies, health information technology, and care management tools. McKesson says it discovered the cybersecurity incident on August 25, 2026, and that its investigation is still in early stages. “Based on our…

McKesson zdravotnictví US

tg: incident tg: návod tp: phishing tp: únik dat tp: identita

· Malwarebytes Labs · McKesson confirms cyber incident after ShinyHunters claims patient-data theft

1

2

New Instagram and Facebook rules set a default two-hour limit for teens

Meta decided that discretion was the better part of valor on Wednesday, agreeing to settle a landmark child safety case for up to $17 billion. The agreement would introduce a default two-hour daily limit for teens on Instagram and Facebook, overnight restrictions, and a range of other protections. It also brings the trial to an early end before Mark Zuckerberg, who was listed as a witness, could testify. The company reached the settlement with a bipartisan coalition of 51 state attorneys…

Meta zdravotnictví US

· Malwarebytes Labs · New Instagram and Facebook rules set a default two-hour limit for teens

2

2

1

24th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 24th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Latvia’s Road Traffic Safety Directorate (CSDD) has confirmed a breach affecting payment records of more than 1.2 million people – roughly two-thirds of the country’s population – as well as 200,000 organizations. The stolen data included identification numbers, license plates, payment amounts, dates and addresses. Attackers reportedly exploited a…

KEV ✓ · ransomware EPSS 0.41 CVSS 10.0 CVE-2026-12569 CVE-2026-19478 CVE-2026-19489 CVE-2026-19490 Snowflake Siemens GitLab Cisco zdravotnictví výroba a průmysl energetika vodárenství IL

· Check Point Research · 24th August – Threat Intelligence Report

4

Medical records, SSNs, and bank details exposed in CareCloud data breach

Healthcare technology giant CareCloud has confirmed that a data breach earlier this year impacted more than 3.75 million people, making it one of the largest healthcare data incidents disclosed this year. The New Jersey-based company, which provides electronic health record (EHR) and practice management services, first flagged the intrusion in an SEC filing back in March, but the true scope only became clear this month when the Department of Health and Human Services (HHS) breach tracker…

CareCloud zdravotnictví US

· Malwarebytes Labs · Medical records, SSNs, and bank details exposed in CareCloud data breach

SickKids data breach exposes employee and job applicant info

Toronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not affected. (264) [...]

KEV ✓ · ransomware EPSS 1.00 CVE-2023-34362 SickKids zdravotnictví US

· BleepingComputer · SickKids data breach exposes employee and job applicant info

Uso de credenciales embebidas en Virtuagym

Embedded credentials in Virtuagym Fri, 08/21/2026 - 11:51 Aviso Affected Resources Virtuagym / Resamania Backend API & Mobile Apps. All versions are affected at the time of reporting. Description INCIBE has coordinated the disclosure of a high-severity vulnerability affecting the backend API and mobile app of Virtuagym, a comprehensive technology platform and mobile app specialising in the fitness and health sector. The vulnerability was discovered by Pau Hinojosa.This vulnerability has been…

EPSS 0.00 CVSS 8.6 CVE-2026-12587 Virtuagym zdravotnictví obchod ES

· INCIBE-CERT · Uso de credenciales embebidas en Virtuagym

3

2

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive…

CVSS 7.0 Microsoft veřejná správa finance zdravotnictví výroba a průmysl US

tg: rozbor tp: ransomware tp: AI tp: špionáž tp: průmyslové systémy

· Rapid7 · New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

Siemens Simcenter Nastran

View CSAF Summary Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions. The…

EPSS 0.00 CVSS 7.8 CVE-2026-59086 Siemens výroba a průmysl obrana energetika zdravotnictví US

· CISA Advisories · Siemens Simcenter Nastran

2

17th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experienced a ransomware attack that affected part of its technology infrastructure and disrupted public services related to illicit-drug monitoring and legal processes. Officials confirmed that some files were encrypted but stated that no data theft was detected during the incident. MyDr, Poland’s primary…

KEV ✓ EPSS 0.25 CVSS 9.8 CVE-2026-53413 CVE-2026-65400 CVE-2026-68820 CVE-2026-71362 Microsoft Apple Adobe Zoom veřejná správa zdravotnictví obrana energetika IL

· Check Point Research · 17th August – Threat Intelligence Report

2

Flow Neuroscience FL-100

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to manipulate brain stimulation parameters and override safety limits. The following versions of Flow Neuroscience FL-100 are affected: Flow Neuroscience FL-100 Halo Neuroscience FL-100 CVSS Vendor Equipment Vulnerabilities v3 8.1 Flow Neuroscience Flow Neuroscience FL-100 Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Healthcare and Public Health Countries…

EPSS 0.00 CVSS 8.1 CVE-2026-18164 Flow Neuroscience zdravotnictví US

· CISA Advisories · Flow Neuroscience FL-100

Siemens Desigo DXR and PXC Controllers

View CSAF Summary A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Desigo DXR and PXC Controllers are affected: Desigo DXR2 vers:intdot/<01.21.233.16-7862 …

EPSS 0.00 CVSS 4.3 CVE-2026-59693 Siemens energetika zdravotnictví výroba a průmysl doprava US

· CISA Advisories · Siemens Desigo DXR and PXC Controllers

2

Pulsetto Vagus Nerve Stimulator

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to use hidden commands to disable electrical safety mechanisms or modify other stimulation output settings. The following versions of Pulsetto Vagus Nerve Stimulator are affected: Pulsetto Vagus Nerve Stimulator vers:all/* (CVE-2026-18844) CVSS Vendor Equipment Vulnerabilities v3 8.1 Pulsetto Pulsetto Vagus Nerve Stimulator Hidden Functionality Background Critical Infrastructure Sectors: Healthcare and…

EPSS 0.00 CVSS 8.1 CVE-2026-18844 Pulsetto zdravotnictví US

· CISA Advisories · Pulsetto Vagus Nerve Stimulator

Mira Hormone Monitor, Mira Android App

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token information, and obtain control of user accounts. The following versions of Mira Hormone Monitor, Mira Android App are affected: Mira Monitor Firmware 1.7.1.47 (CVE-2026-66875, CVE-2026-66098, CVE-2026-67558, CVE-2026-67568, CVE-2026-68067, CVE-2026-66340, CVE…

EPSS 0.00 CVSS 9.8 CVE-2026-64934 CVE-2026-66098 CVE-2026-66340 CVE-2026-66832 CVE-2026-66875 CVE-2026-67558 CVE-2026-67568 CVE-2026-68067 Quanovate Tech Inc. zdravotnictví US

· CISA Advisories · Mira Hormone Monitor, Mira Android App

1

#StopRansomware: Gunra Ransomware

Advisory at a Glance Title #StopRansomware: Gunra Ransomware Original Publication August 10, 2026 Executive Summary Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom…

KEV ✓ · ransomware EPSS 0.98 CVE-2024-55591 CVE-2025-24472 veřejná správa zdravotnictví finance energetika US

· CISA Advisories · #StopRansomware: Gunra Ransomware

2

Medixant RadiAnt DICOM

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause the application to crash if a maliciously crafted DICOM file is opened. The following versions of Medixant RadiAnt DICOM are affected: RadiAnt DICOM <=2025.2 CVSS Vendor Equipment Vulnerabilities v3 4.3 Medixant Medixant RadiAnt DICOM Out-of-bounds Write Background Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwide Company Headquarters Location: Poland…

EPSS 0.00 CVSS 4.3 CVE-2026-17264 Medixant zdravotnictví US

· CISA Advisories · Medixant RadiAnt DICOM

ABB Ability Zenon

View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data. The following versions of ABB Ability Zenon are affected: IIoT services with MongoDB (4.2) installed on ABB Ability Zenon vers:all/* CVSS Vendor Equipment Vulnerabilities v3 7.8 ABB ABB Ability Zenon Improper Handling of Length Parameter Inconsistency, Improper Neutralization of Null Byte or NUL Character, Collapse of Data…

KEV ✓ EPSS 0.83 CVSS 7.8 CVE-2020-7921 CVE-2020-7928 CVE-2025-14847 ABB energetika zdravotnictví vodárenství výroba a průmysl US

· CISA Advisories · ABB Ability Zenon

1

Thermo Fisher Applied Biosystems Genetic Analyzers

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to modify .fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results. The following versions of Thermo Fisher Applied Biosystems Genetic Analyzers are affected: Applied Biosystems 3500/3500xL Series Data Collection Software <=4.0.2 Applied Biosystems 3730/3730xL Series Data Collection Software <=5.0.2 Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software <=1.2.5…

EPSS 0.00 CVSS 8.4 CVE-2026-17583 Thermo Fisher zdravotnictví US

· CISA Advisories · Thermo Fisher Applied Biosystems Genetic Analyzers

1

3rd August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported that drinking water safety was not affected. While the attack was not officially attributed, federal…

KEV ✓ · ransomware EPSS 0.87 CVSS 9.8 CVE-2026-20316 CVE-2026-42897 CVE-2026-59309 CVE-2026-59310 CVE-2026-59726 CVE-2026-63077 CVE-2026-66066 Cisco Broadcom JetBrains Microsoft vodárenství finance zdravotnictví telekomunikace IL

tg: incident tg: zranitelnost tg: přehled tp: phishing tp: únik dat tp: AI tp: průmyslové systémy

· Check Point Research · 3rd August – Threat Intelligence Report

2

You were onto something with “It’s the Climb,” Miley

Welcome to this week’s edition of the Threat Source newsletter. For my fianceé’s 30th birthday, I took her on a weekend trip to Shenandoah National Park – a favorite of ours since we went to a wedding there several years back. We’ve done several incredible hikes over the years, but one in particular had always loomed over my head: Old Rag, a 9.3 mile circuit hike that’s largely considered the most difficult in Virginia. I've always been warned that at the beginning and end, you hate Old Rag.…

zdravotnictví veřejná správa US

tg: rozbor tg: přehled tp: phishing tp: ransomware tp: identita

· Cisco Talos · You were onto something with “It’s the Climb,” Miley

OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

Introduction We have been tracking two new backdoors, OctLurk and SilkLurk, observed in attacks against government organizations primarily in Central Asia since January 2025. Identified victims are located in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic. These organizations operate across several sectors, including healthcare, research, government offices, ministries of foreign affairs, logistics, law‑enforcement agencies, urban planning and…

veřejná správa zdravotnictví školství RU

· Securelist (Kaspersky) · OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

1

SPOJENO PŘES CVE Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the…

KEV ✓ EPSS 0.92 CVE-2026-20127 CVE-2026-20182 CVE-2026-20245 Cisco telekomunikace energetika doprava finance obchod zdravotnictví US

· Cisco PSIRT · Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability · Mandiant / Google TI · Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

1

1

1

22nd June – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 22nd June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Texas Parks and Wildlife Department has been affected by a third-party data breach involving its license system vendor. The incident exposed driver’s license information, passport numbers, emails, phone numbers, and residential addresses for 3,087,721 hunting and fishing license customers. Social Security numbers and payment data were not affected.…

KEV ✓ EPSS 0.96 CVE-2026-20245 CVE-2026-33017 CVE-2026-34908 CVE-2026-34909 CVE-2026-34910 CVE-2026-41947 CVE-2026-41948 CVE-2026-55255 Cisco Ubiquiti Dify Langflow veřejná správa zdravotnictví finance IL

· Check Point Research · 22nd June – Threat Intelligence Report

1

Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

Written by: Patrick Whitsell, John McGuiness, Muhammad Umair Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. While remaining undetected for over a year, the threat actor compromised externally facing web applications, deployed bespoke malware, pivoted to sensitive internal systems, and…

Google zdravotnictví obrana školství US

· Mandiant / Google TI · Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

2

1

1

1

Лікарні, органи місцевого самоврядування та оператори FPV - у фокусі кластера кіберзагроз UAC-0247 (UAC-0244)

CERT-UA протягом березня-квітня 2026 року зафіксовано інтенсифікацію кібератак у відношенні органів місцевого самоврядування та, насамперед, комунальних закладів охорони здоров'я, зокрема клінічних лікарень та лікарень екстреної (швидкої) медичної допомоги.

zdravotnictví veřejná správa UA

· CERT-UA · Лікарні, органи місцевого самоврядування та оператори FPV - у фокусі кластера кіберзагроз UAC-0247 (UAC-0244)

1

1

Кібератака UAC-0255 під виглядом сповіщення від CERT-UA із застосуванням програмного засобу AGEWHEEZE (CERT-UA#21075)

Національною командою реагування на кіберінциденти, кібератаки, кіберзагрози CERT-UA 26-27 березня 2026 року зафіксовано випадки розповсюдження електронних листів нібито від імені CERT-UA із закликом завантажити з сервісу Files.fm захищений паролем архів ("CERT_UA_protection_tool.zip", "protection_tool.zip") та встановити "спеціалізоване програмне забезпечення". Серед отримувачів листів: державні організації, медичні центри, охоронні фірми, навчальні заклади, фінансові установи, компанії…

veřejná správa zdravotnictví finance školství UA

· CERT-UA · Кібератака UAC-0255 під виглядом сповіщення від CERT-UA із застосуванням програмного засобу AGEWHEEZE (CERT-UA#21075)