Consumer Advisory: Fake Windows Updates, Qilin in Healthcare, and patches you shouldn't skip

A stealer campaign with 0 detections is hiding inside fake Windows 11 upgrade ads. Qilin ransomware hit a Florida dermatology practice. And CISA added more bugs to the mandatory patch list.

Read More

The Billion-Dollar Bill: Why the Cost of a Breach Never Ends

A major breach cycle only lasts a week in the news but can last five years on the balance sheet. UnitedHealth spent $3.1 billion before the SEC fine even landed.

Read More

When the Breach Isn't at Your Bank: Third-Party Risk Hits Healthcare and Finance in the Same Week

A hospital email account, a fintech ransomware attack still sending notifications eight months later, and a Lapsus$ claim against a financial vendor. Third-party concentration risk landed in two sectors at once this week.

Read More

The Breach Happened in February 2025. Patients Are Just Hearing About It Now.

DermCare Management, which handles billing and records for dozens of dermatology practices, suffered a breach in February 2025. They confirmed it in March 2026. Patients are getting notified now. The exposed data includes Social Security numbers, financial account info, and medical records.

Read More

The Healthcare Multiplier: One Ransomware Attack, Dozens of Hospitals

Ransomware hit ChipSoft, the EHR vendor behind HiX. One intrusion took down clinical systems across hospitals in the Netherlands and Belgium at the same time. That's the geometry attackers are after.

Read More

$20.88 Billion Gone: What the FBI's New Cybercrime Report Actually Says

The FBI's IC3 report crossed $20 billion for the first time. Crypto fraud, AI-enabled scams, and elder exploitation tell a story the headline number doesn't capture.

Read More

A Massachusetts Hospital Is Diverting Ambulances and Cancelling Chemo. The Attacks You Haven't Heard About Are Worse.

Brockton Hospital is running on paper after a cyberattack forced ambulance diversions and chemo cancellations. Health ISAC says multiple undisclosed incidents are hitting healthcare right now.

Read More

ShinyHunters Popped a Telehealth Giant Through Its Help Desk

Two employees tricked out of their Okta creds. Millions of telehealth support tickets stolen. And Hims says no medical records were exposed. Sure.

Read More

Stryker Recovered from an Iranian Wiper Attack. It Took Three Weeks and 80,000 Devices.

Iran's Handala group wiped 80,000 devices across Stryker's global network. Maryland EMS lost digital ECG transmission. The DOJ confirmed Iran's government runs Handala.

Read More

The Week Toolchain Trust Collapsed, Again

TeamPCP kept hitting developer tooling. AI attack surfaces went from theoretical to exploited. Attackers logged in instead of breaking in. And Iran went after the FBI director's personal inbox.

Read More

Healthcare Had a Bad Week. A Really, Really Bad Week.

Three healthcare breaches in one week, all tracing back to the same problem: third-party vendors with access to patient data and not enough security around it.

Read More

Stryker Finds a Malicious File in Its Systems. Production Is Coming Back Online.

Stryker's forensic investigation with Palo Alto Networks Unit 42 found a malicious file used to run commands and conceal activity, a separate finding from the initial Handala attack. Production recovery is underway.

Read More

The Healthcare Benefits Breach You Haven't Heard About (or the One After It, or the One After That)

Three healthcare and benefits data breaches disclosed in the same week -- TriZetto (3.4M), Navia (2.7M), and Marquis (672K) -- follow the same disturbing pattern: your most sensitive data lives with vendors you've never heard of, and you find out months later.

Read More

Iran Didn't Need Malware to Cripple Stryker. They Just Used Microsoft Intune.

The Handala group wiped tens of thousands of Stryker devices using the company's own MDM platform. No malware. No exploit. Just admin access and the willingness to press the button.

Read More

Hackers Used Stryker's Own IT Tool to Nuke Its Entire Device Fleet

An Iranian-linked group called Handala reportedly hijacked Microsoft Intune and wiped Stryker's devices at scale. The tool designed to secure their fleet became the weapon that destroyed it.

Read More

Your Vendors Got Hacked: Supply Chain Breaches Keep Piling Up

ShinyHunters hit 400 companies through Salesforce misconfigs. Cognizant lost 3.4 million patient records. Ericsson got popped via a vendor. The supply chain is the perimeter now, and it's breaking.

Read More