Healthcare Cybersecurity News

IT New

Health hands enterprise computing to Leidos in $91m deal

Matched: health

New Zealand's Ministry of Health has signed a $91 million contract with Leidos to take over enterprise computing services, beginning the unwinding of a long-standing arrangement with Datacom. The deal shifts responsibility for the ministry's core IT infrastructure to the US-based technology and defence contractor.

Cybersecurity News

Cybercriminals Are Selling Corporate Executives’ Social Security Numbers for Just 25 Cents

Matched: health

Rapid7 has tracked 476 compromised SSN records tied to 395 corporate executives on dark web marketplaces since early 2026, with records selling for as little as 25 cents. C-suite executives account for 44.6% of affected profiles. Three platforms — Xilo, Bankomat, and PeopleFinder — represent 81.5% of leaks, sourcing data from large breaches, infostealers, and phishing. Unlike passwords or cards, SSNs cannot be changed, making them permanently exploitable for fraud and impersonation schemes.

TechRadar

Trump signs order banning some foreign equipment from US energy grid, including some software

Matched: health

Trump has reissued a 2020 executive order declaring a national emergency over foreign bulk-power systems in the US energy grid, banning their purchase, import, or installation if deemed a national security risk. The order, widely seen as targeting Chinese equipment, also requires a review of existing foreign-built hardware and software. The Energy Department has 120 days to develop enforcement rules.

TechRadar

Boston Scientific says cyberattack is causing a ‘global disruption’ to medical device operations

Matched: health, medical

Boston Scientific confirmed a cyberattack causing global disruptions to IT systems and operations, filing an 8-K with the SEC. The incident has impacted order processing and shipping, with third-party cybersecurity experts brought in to assist. The attack type was not disclosed, though the disruption pattern suggests ransomware. No group has claimed responsibility, and no stolen data has been reported. Full restoration timeline remains unknown.

Hacker News

Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools

Matched: health

A campaign targeting Cambodia is deploying Spark RAT, an open-source remote access trojan, using lure themes including government notices, public health materials, and real estate content. The attack abuses a vulnerable OPSWAT driver to disable security tools, broadening its potential victim pool across individuals and organizations in the region.

Cybersecurity News

AccuKnox Launches AgentZ to Help Enterprises Build, Run, and Govern AI Agents at Scale

Matched: health

AccuKnox has launched AgentZ, a platform for building, running, and governing AI agents across enterprise teams. It consolidates agents, execution environments, tools, workflows, permissions, and governance into one system. Key features include model-agnostic LLM support, sandboxed isolated execution, audit logs, multi-team access controls, and flexible SaaS, on-prem, or air-gapped deployment. A free hosted plan and open-source repository are available.

Cybersecurity News

Nutex Health Data Breach – Hackers Gained Access to Network and Exfiltrated Data

Matched: health, medical

Nutex Health has disclosed a data breach after an unknown third party accessed and exfiltrated data from its network. The Houston-based healthcare company filed an SEC Form 8-K on August 24, 2026, confirming the intrusion. The full scope remains unclear, but potentially affected data includes patient records, employee information, financial data, and intellectual property. No material operational impact has been identified so far, though the investigation is ongoing.

Cybersecurity News

FBI Shuts Down China-Linked Hacking Platforms Used to Target NASA and U.S. Networks

Matched: health

The DOJ and FBI seized domains tied to two China-linked hacking platforms, QScan and QTRouter, connected to PRC state-sponsored group QTFY, operating through Nanjing Xinjiuwei Network Technology. The platforms infected IoT devices and routed malicious traffic through proxy networks to conceal attack origins. Victims included NASA, the Federal Reserve, DOJ, and the U.S. Senate. Seized domains rendered both platforms inoperable.

TechRadar

Anthropic staff told to work from home due to risk of possible security strikes

Matched: health

Anthropic told San Francisco employees to work from home after reports that security guards employed by contractor Allied Universal might strike. The union representing the workers, SEIU, said no strike vote had been called and denied threatening action on those dates. An underlying labor dispute over wages and benefits is ongoing. Anthropic's precautionary response comes amid broader rises in AI security spending and as the company reportedly eyes a $2 trillion IPO valuation.

Cybersecurity News

Mirage2FA Phishing Kit Bypasses MFA to Hijack Microsoft 365 Sessions, Targeting 3,500+ Organizations

Matched: health

A phishing-as-a-service toolkit called Mirage2FA, linked to the group LinX Coders, has potentially compromised 4,532 Microsoft 365 accounts across 3,518 organizations in 94 countries, with 63.7% of victims in the US. The kit uses HTML, XHTML, and SVG attachments to deploy adversary-in-the-middle proxies that capture authenticated session cookies, bypassing MFA without dropping malware. Over half of 9,332 recorded compromise events involved cookie theft, making simple password resets insufficient for remediation.