27 July 2026
ShinyHunters uses healthcare help desks to break into cloud accounts
The group is using phone calls to persuade help desks to reset multifactor authentication, then taking over cloud accounts and stealing data from connected services—often without deploying traditional ransomware.
CISO Quick Read
- 01
Craneware contains an intrusion while assessing stolen data
Craneware disclosed unauthorized access and data exfiltration but reported no disruption to customer services or company operations.
The unresolved scope includes some employee data and a subset of customer and partner records tied to a healthcare financial-technology supplier.
Open the supporting recordCraneware still has to determine the precise scope of the exfiltrated customer, partner and employee data and identify the affected parties.
Timing20 July 2026
- 02
Oracle WebCenter Content flaw allows unauthenticated takeover
An unauthenticated attacker with HTTP network access can exploit affected WebCenter Content versions to take over the platform and potentially affect connected products.
Where WebCenter Content or a dependent service is deployed, a takeover could expose or alter content and disrupt access to the platform.
Open the supporting recordApplicable deployments are self-managed Oracle WebCenter Content releases 12.2.1.4.0 and 14.1.2.0.0 that untrusted parties can reach over HTTP.
TimingOracle disclosed the vulnerability on 21 July 2026, in its July Critical Patch Update.
- 03
Oracle PeopleSoft flaw exposes critical application data
An unauthenticated attacker with HTTP network access can exploit PeopleSoft Enterprise CC Common Application Objects 9.2 to read, create, delete or modify critical application data.
Where the affected PeopleSoft component is deployed, unauthorized data access and modification could undermine records and the business processes that depend on them.
Open the supporting recordThis applies to Oracle PeopleSoft Enterprise CC Common Application Objects release 9.2 when untrusted parties can reach it over HTTP.
TimingOracle disclosed the vulnerability on 21 July 2026, in its July Critical Patch Update.
- 04
FDA says affected ENROUTE catheters should not be used
FDA issued a potentially high-risk Early Alert for Boston Scientific ENROUTE NPS and NPS Plus products and directed affected product to be removed from use and distribution.
The instruction immediately removes affected transcarotid neuroprotection catheters from procedural inventory.
Open the supporting recordAffected ENROUTE inventory should remain segregated and out of use while FDA reviews the potentially high-risk issue and determines its recall classification.
Timing21 July 2026
- 05
OpenAI reports an incident in a Hugging Face evaluation dependency
OpenAI disclosed a security incident involving model-evaluation work conducted through Hugging Face infrastructure.
Healthcare AI programs using comparable external evaluation platforms inherit a dependency path involving credentials, model access and third-party infrastructure.
Open the supporting recordExternal evaluation platforms extend an AI program’s trust boundary to the credentials and model access they handle.
Timing21 July 2026
Healthcare Incident Watch
Healthcare Incident Watch
Craneware reports data theft but no service disruption
Craneware disclosed unauthorized access to a subset of its data environment and said the incident had been contained. The company reported no disruption to customer services or its operations.
A significant volume of file names was viewed and exfiltrated, together with some employee data and a subset of customer and partner records. The investigation has not resolved the precise nature or scope, including the final population affected; the disclosure neither identifies an attacker nor links the incident to patient harm.
Read Craneware’s incident noticeHealthcare Incident Watch
ShinyHunters uses identity resets to reach health-sector SaaS
Health-ISAC flagged an increase in successful ShinyHunters attacks affecting the health sector and documented the attack pattern: phone-based social engineering persuades help desks to reset multifactor authentication or re-enroll a device, enabling takeover of Microsoft Entra, Okta or Google SSO accounts and access to connected SaaS platforms for data theft and extortion.
The warning is sector-level rather than a comprehensive victim inventory. Its defensive focus is the identity control plane: stronger identity proofing, phishing-resistant MFA, tighter SaaS logging and containment playbooks prepared for rapid account takeover.
Read the Health-ISAC advisoryHealthcare Incident Watch
Malware disruption closes AnMed offices and imaging
AnMed said malware was impacting its network, creating a cybersecurity disruption whose scope beyond the immediate service plan was still developing. The notice did not attribute an attacker or establish ransomware or data exposure.
Medical Group offices and Imaging Services were scheduled to close Monday, July 27, while Urgent Care, Kids Care, Integrated Therapy and Laboratory Services were scheduled to open. Procedure, transfer, diversion and operational decisions were being guided by patient safety, with AnMed coordinating care access with EMS and regional hospitals.
Read AnMed’s systems disruption noticeRegulatory & Privacy
Regulatory & Privacy
Operation Vital Signs tests response across critical health functions
HSCC’s Operation Vital Signs invited all regulated entities to a national virtual exercise on July 21–22 testing enterprise and cross-sector response and recovery, including effects on critical functions and patient safety.
Pairing recovery mechanics with patient safety makes the exercise a test of sector coordination around care-critical functions. After-action results remain the next milestone.
View Operation Vital Signs informationRegulatory & Privacy
Health-ISAC’s first CISO benchmark spans five industry segments
Health-ISAC released its first CISO benchmarking report, drawing on survey input from 76 security leaders across providers, payers, pharmaceutical companies, medical-device organizations and global operations.
The report covers health-sector risks, emerging threats, governance, staffing, budgets, technology investment and CISO priorities for the next 12 to 24 months. Its 76-participant sample offers a peer benchmark across several industry segments, with broader interpretation dependent on the report’s methodology.
Read the CISO Benchmarking ReportRegulatory & Privacy
Health-ISAC puts AI exposure, medical IoT and policy on one agenda
Health-ISAC’s July 22 Quarterly Threat Insights briefing placed AI-server and MCP exposure, patient safety, legacy medical IoT and U.S. critical-infrastructure policy on one health-sector readiness agenda.
The grouping connects emerging AI dependencies, aging connected devices and policy developments within clinical technology planning. The page sets a readiness agenda and creates no new legal duty.
Watch Quarterly Threat InsightsRegulatory & Privacy
FDA and CMS test a real-world evidence route for digital health
Selecting the first TEMPO participant starts practical testing of FDA’s pilot regulatory approach; product approval and real-world outcome evidence remain later milestones.
Read the FDA TEMPO announcementAI & Clinical Automation Watch
AI & Clinical Automation
OpenAI incident exposes a third-party model-evaluation dependency
OpenAI disclosed a security incident in model-evaluation work using Hugging Face infrastructure. The compromise exposed a third-party dependency path spanning external evaluation platforms, credentials and model access.
Evaluation infrastructure therefore belongs inside the AI trust boundary, with credentials and model access as the principal control points. OpenAI reported no healthcare involvement.
Read OpenAI’s disclosureAI & Clinical Automation Watch
Health-ISAC puts AI-server and MCP exposure on the health-sector agenda
AI-server and MCP exposure belongs in clinical technology risk planning because the same readiness agenda connects it to patient safety and legacy medical IoT.
Watch Quarterly Threat InsightsAI & Clinical Automation
FDA selects Dexcom as the first TEMPO pilot participant
FDA selected Dexcom as the first participant in the TEMPO digital-health devices pilot on July 22, activating the pilot’s first manufacturer participation and FDA’s continuing evaluation of the Dexcom Glucose Health Program.
The selection moves TEMPO into a live test of how digital-health devices can generate real-world evidence for chronic-disease care. Product approval and outcome evidence remain later milestones.
Read the FDA TEMPO announcementPriority CVEs
An unauthenticated attacker can take over an affected Oracle WebCenter Content server with an HTTP request, potentially affecting connected products as well.
A hospital using WebCenter Content for policy, intranet or administrative documents could have those documents exposed, altered or made unavailable if the server is taken over.
Identify self-managed WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 instances reachable over HTTP from untrusted networks, then remove that reachability with network controls.
12.2.1.4.0 and 14.1.2.0.0
21 July 2026
27 July 2026
24 August 2026
CVE-2026-60606Oracle PeopleSoft Enterprise CC Common Application ObjectsNewCritical · CVSS 3.1 9.1 (Oracle/CNA)
An unauthenticated attacker can use HTTP requests to read, create, alter or delete data available through PeopleSoft Common Application Objects 9.2.
A hospital using PeopleSoft 9.2 for HR, payroll, finance or supply-chain administration could have records and transactions disclosed or changed through the affected component.
Identify PeopleSoft Enterprise CC Common Application Objects 9.2 endpoints reachable over HTTP from untrusted networks, then restrict access to trusted networks until the release-specific PUM/PRP custom change package is deployed.
9.2
21 July 2026
27 July 2026
24 August 2026
A crafted PNG or APNG eXIf chunk can make FFmpeg write past a heap buffer, crashing the process or potentially running attacker-controlled code.
Healthcare web, imaging-export or communications systems that encode untrusted PNG or APNG files with FFmpeg could suffer a media-processing outage or code execution under the service account.
Disable or isolate FFmpeg PNG/APNG encoding for untrusted input carrying eXIf metadata until a supported fixed release or backport is available.
FFmpeg 8.1.2 and earlier
21 July 2026
27 July 2026
24 August 2026
High · CVSS 3.1 8.8 (NVD)
An authorized attacker could exploit server-side request forgery in Azure AI Search to cross a service boundary and gain additional privileges.
If Azure AI Search indexes clinical, research or administrative content, an authorized account could reach resources outside its intended search-service boundary.
No customer action is required; Microsoft reports Azure AI Search is fully mitigated as a hosted service.
Authoritative record does not specify
23 July 2026
27 July 2026
24 August 2026
WPForms Pro writes uploaded chunks before checking their file type, allowing an unauthenticated attacker to place a potentially executable file on the WordPress host.
A healthcare website using WPForms Pro for public appointment, referral or contact forms could have its WordPress host compromised through the upload flaw, disrupting the site or exposing data available to that host.
Upgrade WPForms Pro to version 1.10.2 or later.
WPForms Pro 1.10.1.1 and earlier
25 July 2026
27 July 2026
24 August 2026
Clinical Engineering & Medical Device Watch
Clinical Engineering
FDA directs removal of affected ENROUTE neuroprotection catheters
The ENROUTE Transcarotid Neuroprotection System and ENROUTE Transcarotid Neuroprotection System Plus reverse blood flow to carry emboli away from carotid circulation before lesion crossing and during lesion manipulation. Specific lots can experience arterial sheath-tip separation or partial separation during use. A retained tip may require endovascular or surgical retrieval and can lead to embolism, stroke, transient ischemic attack, restenosis or thrombosis. Boston Scientific reported one serious injury and no deaths as of July 9.
FDA identifies this as a potentially high-risk Early Alert, with recall classification pending. Facilities should stop using and segregate affected product, return it and trace units distributed to downstream facilities. This is a clinical-engineering and inventory-control issue, not a cybersecurity incident.
Read the FDA ENROUTE Early AlertClinical Engineering
FDA flags three lots of Baxter Duo-Vent administration sets
Baxter Duo-Vent solution sets deliver fluid into the vascular system. Affected lots can develop air bubbles in the drip chamber and tubing when a pressure cuff is used or the tubing is flushed in the fully open position. Without an air-in-line detector, air can reach the patient; patients with a patent foramen ovale or another right-to-left shunt face the risk of stroke, myocardial ischemia or death. Baxter reported no serious injuries or deaths as of July 15.
FDA identifies this as a potentially high-risk Early Alert, with recall classification pending. Facilities should quarantine and stop using affected lots, return them and obtain replacements. This is a clinical-engineering and inventory-control issue, not a cybersecurity incident.
Read the FDA Baxter Early AlertCCD CVE Tracker
New, updated and continuing vulnerabilities under active CCD watch.
New this week0 additional new CVEs — 5 shown in Priority CVEs
Updated this week0 updated CVEs
Continuing watch12 continuing CVEs
Memory-overflow flaws can deny service when NetScaler ADC operates as an Oracle load balancer, DNS proxy or recursive resolver.
A hospital using an affected NetScaler ADC for Oracle load balancing or DNS could lose application routing or name resolution.
Install NetScaler 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS or 13.1-37.272 FIPS/NDcPP or later on affected Oracle load-balancer or DNS appliances, checking the configuration strings listed in CTX696604 to identify applicable systems.
NetScaler 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 14.1 FIPS before 14.1-72.61; 13.1 FIPS/NDcPP before 13.1-37.272
2 July 2026
2 July 2026
30 July 2026
A memory-overflow flaw can make an affected NetScaler Gateway or AAA virtual server behave unpredictably or stop serving traffic.
A hospital using NetScaler for SSL VPN, ICA Proxy, CVPN, RDP Proxy or AAA access could lose remote-access or authentication availability during an attack.
Upgrade affected Gateway or AAA appliances to NetScaler 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS or 13.1-37.272 FIPS/NDcPP or later, using add authentication vserver and add vpn vserver entries to identify applicable configurations.
NetScaler 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 14.1 FIPS before 14.1-72.61; 13.1 FIPS/NDcPP before 13.1-37.272
2 July 2026
2 July 2026
30 July 2026
Insufficient input validation can make a NetScaler appliance configured as a SAML identity provider read past a memory boundary.
A hospital using a customer-managed NetScaler appliance as its SAML identity provider could have appliance memory exposed or sign-on service interrupted.
Upgrade affected NetScaler appliances to 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS or 13.1-37.272 FIPS/NDcPP or later, and identify SAML IdP configurations by checking for add authentication samlIdPProfile entries.
NetScaler 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 14.1 FIPS before 14.1-72.61; 13.1 FIPS/NDcPP before 13.1-37.272
2 July 2026
2 July 2026
30 July 2026
An empty value in an untrusted .desktop or .ini key file can trigger a one-byte out-of-bounds access in GLib and, in some cases, cause a denial of service.
General enterprise exposure—not a healthcare-specific finding—this CVE is retained only for organizations whose application inventory contains the affected GLib parser and a path for untrusted .desktop or .ini key files to reach it.
Upgrade upstream GLib to 2.88.1 or later; for affected Red Hat packages without an erratum, allow applications to load only trusted key files or reject empty values before calling g_key_file_get_locale_string_list.
Upstream GLib before 2.88.1; vendor-listed RHEL glib2 packages without an available erratum
2 July 2026
2 July 2026
30 July 2026
A SimpleHelp server can accept an unsigned OIDC identity token and grant an unauthenticated attacker a technician session, potentially bypassing multifactor authentication.
A hospital using OIDC for SimpleHelp technician login could give an attacker a trusted remote-support session with access to managed endpoints.
Upgrade SimpleHelp 5.5 deployments to 5.5.16 or later and 6.0 prereleases to 6.0 RC2 or later; if the update cannot be completed immediately, disconnect or stop the server until the exposure is resolved.
SimpleHelp 5.5.15 and earlier; SimpleHelp 6.0 prereleases before RC2
2 July 2026
29 June 2026
2 July 2026
30 July 2026
Critical · CVSS 4.0 9.5 (VulnCheck/CNA)
An authenticated SharePoint site member can send untrusted serialized data to an on-premises server and execute code remotely.
A hospital running on-premises SharePoint for internal documents or collaboration could have the server taken over and its content exposed or altered by an authenticated site member.
Install KB5002868 on SharePoint 2016, KB5002870 on SharePoint 2019 or KB5002863 on SharePoint Subscription Edition, reaching builds 16.0.5552.1002, 16.0.10417.20128 or 16.0.19725.20280 respectively.
SharePoint Server 2016 before build 16.0.5552.1002; SharePoint Server 2019 before 16.0.10417.20128; SharePoint Subscription Edition before 16.0.19725.20280
4 July 2026
1 July 2026
2 July 2026
30 July 2026
A second use-after-free in Chrome Views can corrupt heap memory when a user performs specific gestures on a crafted HTML page.
A healthcare endpoint running an older Chrome build could lose browser integrity or availability when its user interacts with a malicious page.
Install Chrome 150.0.7871.47 or later on Windows and macOS or 150.0.7871.46 or later on Linux.
Chrome before 150.0.7871.47 on Windows/macOS or before 150.0.7871.46 on Linux
2 July 2026
2 July 2026
30 July 2026
A crafted web page and specific user-interface gestures can trigger a use-after-free in Chrome Views and corrupt heap memory.
A hospital user browsing external content with an outdated Chrome build could have the browser compromised or crashed after interacting with a crafted page.
Update Windows and macOS endpoints to Chrome 150.0.7871.47 or later and Linux endpoints to 150.0.7871.46 or later.
Chrome before 150.0.7871.47 on Windows/macOS or before 150.0.7871.46 on Linux
2 July 2026
2 July 2026
30 July 2026
A malicious Chrome extension can trigger a use-after-free in the Extensions component and execute attacker-controlled code.
On hospital workstations that permit extension installation, a user who installs a malicious Chrome extension could run attacker code in the browser context.
Update desktop Chrome to 150.0.7871.47 or later on Windows and macOS or 150.0.7871.46 or later on Linux, and enforce the managed-browser extension allowlist.
Chrome before 150.0.7871.47 on Windows/macOS or before 150.0.7871.46 on Linux
2 July 2026
2 July 2026
30 July 2026
Malformed HTTP/2 requests can exhaust resources on an affected NetScaler virtual server and stop it from serving traffic.
A hospital using an HTTP/2-enabled NetScaler virtual server for load balancing, content switching or VPN access could lose access to applications or remote connectivity during an attack.
Upgrade to NetScaler 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS or 13.1-37.272 FIPS/NDcPP or later and, on non-HTTP-Strict profiles, run set ns httpProfile <profile_name> -http2SmallWndTimeout 30.
NetScaler 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 14.1 FIPS before 14.1-72.61; 13.1 FIPS/NDcPP before 13.1-37.272
3 July 2026
3 July 2026
31 July 2026
Malformed traffic can make a NetScaler TCP profile read past its memory boundary when TCP timestamps are enabled, potentially disclosing appliance memory.
A hospital virtual server or service using a timestamp-enabled NetScaler TCP profile could expose appliance memory through malformed traffic.
Upgrade affected NetScaler services to 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS or 13.1-37.272 FIPS/NDcPP or later, then inventory profiles with TimeStamp ENABLED and map them to virtual servers and services.
NetScaler 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 14.1 FIPS before 14.1-72.61; 13.1 FIPS/NDcPP before 13.1-37.272
3 July 2026
3 July 2026
31 July 2026
An unauthenticated attacker on an adjacent network can read arbitrary appliance files when a NetScaler management address is reachable.
A hospital with a reachable NetScaler management address could have configuration or other appliance-accessible files disclosed without authentication.
Update management-reachable NetScaler appliances to 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS or 13.1-37.272 FIPS/NDcPP or later, and restrict access to NSIP, Cluster Management IP and management-enabled SNIP addresses.
NetScaler 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 14.1 FIPS before 14.1-72.61; 13.1 FIPS/NDcPP before 13.1-37.272
3 July 2026
3 July 2026
31 July 2026
Sources and Methodology
Evidence window: 20–26 July 2026; cutoff 27 July at 12:00 a.m. America/New_York.
Open Source Index
Issue-level sources 3
Healthcare Incident Watch 3
Regulatory & Privacy 4
AI & Clinical Automation Watch 3
Other supporting sources 2
CVE sources 35
- Oracle Cpu
- Cve Cve-2026-60644
- Oracle WebCenter Content 12c Marketplace 26.7.1
- Oracle WebCenter Content 14c Marketplace 26.7.1
- Cve Cve-2026-60606
- Oracle PeopleSoft security-fix process
- Ffmpeg Patch
- Cve Cve-2026-66040
- FFmpeg official releases
- FFmpeg security and backport status
- Wpforms Changelog
- Cve Cve-2026-10818
- Msrc Azure
- Msrc Azure Products
- Cve Cve-2026-56167
- Netscaler Bulletin
- Cve Cve-2026-10816
- Cve Cve-2026-10817
- Cve Cve-2026-13474
- Chrome Release
- Cve Cve-2026-13774
- Cve Cve-2026-13783
- Cve Cve-2026-13784
- Msrc Sharepoint
- Msrc Sharepoint Products
- Cve Cve-2026-45659
- Simplehelp Notice
- Simplehelp Release
- Cve Cve-2026-48558
- CISA Known Exploited Vulnerabilities catalog (linked in applicable CVE records)
- Redhat Cve
- Cve Cve-2026-58014
- Cve Cve-2026-8451
- Cve Cve-2026-8452
- Cve Cve-2026-8655