Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

16 / 16 results
Active filter:tag: #healthcare✕ clear
France fines hospital €500K for breach exposing 727,000 patient recordshighpublicGeopolitical
publicGeopolitical

France fines hospital €500K for breach exposing 727,000 patient records

The enforcement action by France's CNIL represents a continuation of robust data protection regulatory activity under the EU's General Data Protection Regulation (GDPR) framework.

Hôpital privé de la Loire3 Sep · 20:01 UTC
Novocure breach exposes 1,400+ U.S. cancer patient recordshighpublicGeopolitical
publicGeopolitical

Novocure breach exposes 1,400+ U.S. cancer patient records

The Novocure incident reflects the sustained targeting of healthcare infrastructure, particularly oncology and patient data repositories, which has intensified across North American providers since late 2025.

Novocure1 Sep · 12:28 UTC
North Korean IT Worker Scheme Expands Into Healthcare and Sales Roleshighperson_alertThreat Actor
person_alertThreat Actor

North Korean IT Worker Scheme Expands Into Healthcare and Sales Roles

North Korean state-sponsored threat actors, tracked as Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta (formerly TAG-121), UNC5267, and Wagemole, operate a sophisticated job fraud scheme to generate revenue for the DPRK's nuclear weapons…

The Hacker News31 Aug · 15:24 UTC
ShinyHunters Claims 284M Patient Records from McKesson Breachcriticalperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims 284M Patient Records from McKesson Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations targeting organizations with valuable databases.

McKesson28 Aug · 20:40 UTC
Boston Scientific cyberattack disrupts global medical device operationshighpublicGeopolitical
publicGeopolitical

Boston Scientific cyberattack disrupts global medical device operations

The cyberattack on Boston Scientific, one of the world's largest medical device manufacturers with operations in 127 countries and over $20 billion in annual revenue, underscores the persistent vulnerability of critical healthcare supply chains to cy…

Boston Scientific26 Aug · 13:19 UTC
CareCloud breach exposes 3.7M patient records in AWS environmenthighpublicGeopolitical
publicGeopolitical

CareCloud breach exposes 3.7M patient records in AWS environment

The CareCloud incident reflects the persistent vulnerability of U.S. healthcare infrastructure to cyber intrusions, particularly cloud-hosted environments containing sensitive medical data.

CareCloud19 Aug · 18:07 UTC
Thermo Fisher patches DNA analysis file tampering flaw in forensic softwarehighbug_reportVulnerability
bug_reportVulnerability

Thermo Fisher patches DNA analysis file tampering flaw in forensic software

Thermo Fisher Applied Biosystems human identification software: 3500/3500xL Series Data Collection ≤4.0.2, 3730/3730xL Series ≤5.0.2, SeqStudio Genetic Analyzer ≤1.2.5, SeqStudio Flex ≤1.2.0, GeneMapper ID-X ≤v1.7.3.

CVE-2026-175833 Aug · 06:05 UTC
Chinese-Speaking Actor Deploys OctLurk & SilkLurk in Central Asiahighperson_alertThreat Actor
person_alertThreat Actor

Chinese-Speaking Actor Deploys OctLurk & SilkLurk in Central Asia

A Chinese-speaking threat actor, not yet attributed to any known APT group, has been conducting targeted cyber espionage operations against government and strategic organizations in Central Asia and Syria since January 2025.

The Hacker News31 Jul · 16:52 UTC
ShinyHunters escalates vishing-driven data theft against healthcare sectorhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters escalates vishing-driven data theft against healthcare sector

ShinyHunters is a financially motivated extortion gang specializing in data theft attacks against cloud SaaS and storage platforms. The group has gained notoriety over the past two years for conducting supply chain attacks on third-party integration…

BleepingComputer29 Jul · 15:54 UTC
JadeProx Deploys TriBack Loader Against Asian, Latin American Targetshighperson_alertThreat Actor
person_alertThreat Actor

JadeProx Deploys TriBack Loader Against Asian, Latin American Targets

JadeProx is a China-nexus threat actor tracked by Group-IB, discovered through an exposed Alibaba Cloud server in Singapore in mid-April 2026. The actor targets government, healthcare, and education organizations across Asia and Latin America.

Alibaba Cloud23 Jul · 10:20 UTC
bandcampro leverages Google Gemini CLI to control dental clinic botnethighperson_alertThreat Actor
person_alertThreat Actor

bandcampro leverages Google Gemini CLI to control dental clinic botnet

bandcampro is a Russian-speaking threat actor that has demonstrated novel tradecraft by weaponizing Google's Gemini CLI tool to orchestrate botnet operations.

The Hacker News20 Jul · 07:07 UTC
ShinyHunters Breaches Medtronic Healthcare Device Manufacturerhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches Medtronic Healthcare Device Manufacturer

ShinyHunters is a financially-motivated cybercrime group known for large-scale data breaches and database exfiltration operations. The group has been active since at least 2020, targeting organizations across multiple sectors to steal sensitive data…

Medtronic2 Jul · 02:25 UTC
China-linked espionage group targets North American research networkscriticalperson_alertThreat Actor
person_alertThreat Actor

China-linked espionage group targets North American research networks

A China-linked espionage group conducted a sustained intrusion campaign lasting over one year against North American institutions. The actor's motivation appears to be intelligence collection focused on medical research, academic intellectual propert…

Google Workspace15 Jun · 17:44 UTC
China-Linked Espionage Group Deploys InfiniteRed via REDCap Servershighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Espionage Group Deploys InfiniteRed via REDCap Servers

This activity is attributed to a China-linked espionage group targeting healthcare and medical research sectors. The actor's motivation appears to be intelligence collection focused on sensitive medical research data, consistent with strategic intere…

REDCap15 Jun · 12:00 UTC
Novo Nordisk discloses clinical trial data breach in DenmarkhighpublicGeopolitical
publicGeopolitical

Novo Nordisk discloses clinical trial data breach in Denmark

The breach at Novo Nordisk, a Danish pharmaceutical giant controlling approximately 50% of the global insulin market, highlights the strategic vulnerability of critical healthcare infrastructure.

Novo Nordisk12 Jun · 08:13 UTC
California sues 23andMe over 2023 breach of genetic datahighpublicGeopolitical
publicGeopolitical

California sues 23andMe over 2023 breach of genetic data

The lawsuit against 23andMe highlights growing regulatory enforcement around biometric and genetic data protection in the United States, particularly within the healthcare and biotechnology sectors.

23andMe29 May · 16:08 UTC