ZeroHour
Victim

Boston Scientific

1 mentions in 7 days · 7 in 30 days · 7 total · first seen · last

Timeline

ShinyHunters expose 6.4M in attack on medical supplier McKesson

ShinyHunters leaked stolen McKesson data exposing roughly 6.4 million individuals after the medical supplier reportedly declined a $55.2 million extortion demand.

Have I Been Pwned added records leaked by ShinyHunters from medical and pharmaceutical supply company McKesson, confirming the August 2026 attack affected about 6.4 million people. Exposed data includes names, email and physical addresses, dates of birth, phone numbers, employer details, and sensitive health information; ShinyHunters claimed SSNs and 284 million documents were taken, though HIBP found no SSNs. The group issued a $55.2 million extortion demand that was apparently unpaid before publication. The article also notes Boston Scientific expects to miss Q3 guidance after its own attack, and that Veradigm disclosed attackers used third-party vendor credentials to access an API and steal roughly 3.5 million patient records claimed by ransomware group The Gentlemen.

The Register · Securityupdated · 5d agofirst · 5d agoData breach 5 sources

Boston Scientific left nursing its bottom line after cyberattack

Boston Scientific says its August 25 network intrusion will materially hit third-quarter and full-year sales and earnings, likely missing guidance.

Boston Scientific detected unauthorized activity on its network on August 25 and took systems offline, disrupting order processing and shipping operations worldwide. In an SEC filing, the medical device maker warned of a material impact on Q3 and full-year results, making it unlikely to meet the net sales growth and adjusted EPS guidance issued in July. Its distribution network has been substantially restored, sterilization facilities are operational, manufacturing resumed at most sites, and an interruption affecting cardiac device remote-monitoring activations was resolved. The company has not revealed the attack vector, whether ransomware was involved, or whether data was stolen; no ransomware group has claimed responsibility and the investigation continues.

The Register · Security · 7d agoData breach

Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited

Help Net Security's weekly digest highlights 274 compromised Zimbra servers, Gitea and Citrix NetScaler KEV additions, a PaperCut zero-day, and a suspected Iran-linked power plant attack.

The roundup reports at least 274 internet-facing Zimbra instances compromised via CVE-2026-73570, critical Gitea CVE-2026-60004 added to CISA's KEV catalog after exploitation began, and previously patched Citrix NetScaler flaw CVE-2026-8452 exploited in the wild. It also covers PaperCut NG/MF zero-day attacks, a suspected Iran-linked shutdown of a UK power plant, an FBI seizure of domains tied to a China-linked group that hit NASA, DOJ and the Senate, a cyberattack disrupting Boston Scientific, and the Manchester Airports Group breach. Additional items include Chameleon SEO poisoning phishing, Android car head unit proxy botnet malware, ReliaQuest social engineering by ShinyHunters, fake OpenAI Codex macOS malware, and AI-related workforce and supply chain interviews.

Boston Scientific Reveals Global Disruption After Cyber Incident

MedTech giant Boston Scientific disclosed a cyber incident causing IT outages and disruption across its global operations.

Boston Scientific revealed that a cyber incident triggered IT outages disrupting its worldwide operations. The medical device manufacturer has not yet confirmed whether data was accessed or whether ransomware is involved. Details on scope and impact remain limited as the investigation continues.

Infosecurity Magazine · 19d agoData breach

Cyberattack causes network outage at Boston Scientific, disrupts global operations

Boston Scientific disclosed a cyberattack that caused a network outage, disrupting global operations including order processing and shipping.

The medical device maker detected the incident on August 25, activated incident response protocols with third-party cybersecurity experts, and told the SEC that access to systems supporting operations, including order processing and shipping, was disrupted. Boston Scientific employs about 59,000 people across 127 countries and posted more than $20 billion in net sales in 2025; it has not determined whether the incident is material and no group has claimed responsibility. The company joins a recent run of medtech attacks including Stryker, iRhythm, Novo Nordisk and Xsolis.

Help Net Security · 20d agoData breach

Medical device firm Boston Scientific says cyberattack has disrupted shipment processes

Boston Scientific says a cyberattack disrupted shipment and operating systems, forcing engagement of an incident response firm with no restoration timeline.

Medical device manufacturer Boston Scientific disclosed a cybersecurity incident discovered Tuesday that impacted access to operating systems and business applications, including processing and shipping customer orders. The company filed documents with the SEC, hired a cybersecurity firm, and told investors full restoration may take weeks. No group has claimed responsibility and it is unclear whether ransomware is involved. The company reported $5.4 billion in net sales in Q2 2026 and produces pacemakers and stents.

The Record · 20d agoData breach

Medical device maker Boston Scientific says a cyberattack is causing a ‘global disruption’ to its operations

Boston Scientific says a cyberattack has caused global disruption to its operations, with no confirmation yet on device impact or data exfiltration.

Boston Scientific, a major medical device manufacturer, disclosed that a cyberattack is causing global disruption to its operations. The company has not confirmed whether medical devices are affected or whether any customer data was exfiltrated. The investigation appears to be ongoing, and healthcare-sector exposure raises patient-safety and supply-chain concerns.

TechCrunch · Security · 20d agoData breach

Related CVEs

  • Unauthenticated RCE in Gitea via diffpatch API Git Hook Injection
    Gitea before 1.27.1 contains a critical code injection flaw (CWE-94) in the diffpatch API that allows remote code execution by causing the installation of a Git hook. An attacker can submit a crafted request through the diffpatch API to plant a Git hook, which then executes arbitrary shell commands on the server when Git operations run; the CVSS vector indicates the attack requires no authentication or user interaction, while public reporting describes attackers with repository write access planting hooks to run shell commands. Successful exploitation yields full server compromise (confidentiality, integrity, and availability all rated high), and observed attacks have reportedly dropped a cryptocurrency miner. All Gitea deployments running versions prior to 1.27.1 are affected, with internet-facing instances at greatest risk; public scans identified over 8,300 vulnerable Gitea servers. The flaw is actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-25, and EPSS estimates an 86.8% probability of exploitation within 30 days.
    · Gitea all versions before 1.27.1 KEV PoC ×4moderate
  • Unauthenticated OS Command Injection RCE in Synacor Zimbra Collaboration Suite
    CVE-2026-73570 is an OS command injection vulnerability (CWE-78) in Synacor Zimbra Collaboration Suite (ZCS) before 10.1.20, caused by improper sanitization of untrusted input during SNMP notification processing. It is triggered when the optional zimbra-snmp package is installed and SNMP notifications are enabled: an unauthenticated attacker sends specially crafted SMTP requests that the flawed notification path turns into execution of arbitrary operating system commands. Successful exploitation runs commands as the Zimbra user, giving attackers control of the mail server's service account with high confidentiality and integrity impact across the host. Only ZCS deployments running the optional SNMP component with notifications enabled are vulnerable; other Zimbra installs are not exposed to this specific flaw. The flaw is under active exploitation: CISA added it to the KEV catalog on 2026-08-21, Poland's CERT has warned of in-the-wild attacks, unpatched Zimbra servers are reported compromised, and two public proof-of-concept exploits exist.
    · Synacor Zimbra Collaboration Suite (ZCS) before 10.1.20 (when the optional zimbra-snmp package is installed and SNMP notifications are enabled) KEV PoC ×4large
  • Memory Buffer Overflow in Citrix NetScaler ADC/Gateway Exploited in the Wild
    CVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that applies when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server. The flaw is reachable over the network without authentication (CVSS 4.0: AV:N/PR:N), so an unauthenticated attacker can trigger it remotely. Successful exploitation causes unpredictable or erroneous appliance behavior and denial of service, and the high confidentiality score suggests possible disclosure of memory contents; some reporting suggests pre-authentication remote code execution may be possible, though the vendor description emphasizes DoS. Organizations running affected NetScaler appliances in a Gateway or AAA role — a very common configuration for remote access to Citrix virtual apps and desktops — are potentially exposed. The flaw was added to CISA's KEV catalog on 2026-08-26 and is reported as exploited in the wild, with headlines noting the flaw was already patched before exploitation was confirmed.
    · Citrix NetScaler ADC · Citrix NetScaler Gateway KEVlarge

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.