
Medusa tops 500 victims in health sector
FBI, CISA and HHS updated their Medusa alert, saying the group has hit more than 500 victims and kept targeting US health care.
Aug 22, 2026 · 2 min
Up-to-date cyber intelligence coverage. Filter by category or browse the full archive.

FBI, CISA and HHS updated their Medusa alert, saying the group has hit more than 500 victims and kept targeting US health care.
Aug 22, 2026 · 2 min

The OCC proposed in August 2026 a new framework to loosen the disclosure of confidential supervisory information and align it with the FDIC.
Aug 22, 2026 · 2 min

INCIBE-CERT issued alerts on PLCnext, Red Hat Quay, and OpenShift components, including one critical flaw with no active exploitation seen.
Aug 20, 2026 · 2 min

Security Arsenal tracked new U.S. victims from DIREWOLF, COINBASECARTEL and XPL0ITRS across health, tech and professional services.
Aug 19, 2026 · 2 min

The bill remains in committee and has not reached the House floor. It could expand federal control over data
Aug 19, 2026 · 3 min

FinCEN ended domestic beneficial ownership reporting, stripping banks of a federal KYC reference and raising the bar for correspondent controls.
Aug 18, 2026 · 4 min

US agencies warned on Gunra, while Unlimited Technology Systems raised its breach tally to 3.8 million patients.
Aug 16, 2026 · 3 min

SEC cyber disclosure rules remain in force, while the OCC is intensifying third-party oversight. The reach extends to Argentina.
Aug 16, 2026 · 2 min

HIPRA moved out of Senate committee, while the GUARD Financial Data Act added new rules on minimization, opt-out, access
Aug 15, 2026 · 5 min

California’s Suisun City shut down its computer network after an attack disrupted 911 routing, police, fire and other services.
Aug 14, 2026 · 2 min

Change Healthcare, OSF Healthcare and Unlimited Technology Systems surfaced in recent ransomware and breach reports tied to U.S. health care.
Aug 13, 2026 · 2 min

Fraud complaints and related amounts rose in Argentina’s banking sector in H1 2026, according to the central bank.
Aug 11, 2026 · 2 min

CISA added CVE-2026-34486 to KEV after active Apache Tomcat exploitation and set an Aug. 7 remediation deadline for federal agencies.
Aug 10, 2026 · 2 min

Suisun City declared an emergency after a malware attack disrupted 911 and other essential services. The FBI and EPA also warned of water incidents.
Aug 10, 2026 · 2 min

OSF Healthcare settled with HHS OCR over a 2021 Nephilim-linked breach. A separate report names a possible INCRANSOM health victim.
Aug 7, 2026 · 2 min

Interlock added Gardiner Family Chiropractic to its victim list, alleging patient data and internal financial information were exfiltrated.
Aug 5, 2026 · 2 min

More than 30 Minnesota water systems and nine in Michigan were targeted, as the FBI and EPA warned of activity in at least seven states.
Aug 4, 2026 · 3 min

INCIBE-CERT issued an alert for five VMware vulnerabilities, including three critical flaws. One can bypass authentication in vCenter.
Aug 3, 2026 · 2 min

CISA and the FBI report a rise in OT attacks on water and wastewater systems, including lockouts and password changes in several states.
Aug 1, 2026 · 2 min

Shieldworkz, the IDB and Cryptonomist warn of growing pressure on OT/ICS in water, energy and manufacturing, with exposure in focus.
Aug 1, 2026 · 2 min

NYDFS keeps its cybersecurity resource center and 23 NYCRR Part 500 active, while guidance also tracks GLBA and PCI DSS changes.
Aug 1, 2026 · 3 min

ransomware.live lists several U.S. local governments as alleged victims, while Minnesota says a coordinated attack hit more than 30 water systems.
Jul 31, 2026 · 3 min

Attacks on key U.S. health players disrupted claims, prescriptions and services. Ahhh Care appears in a possible ransomware case.
Jul 30, 2026 · 2 min

Coca-Cola confirmed a Fairlife attack that suspended U.S. production and led to a data breach. Anubis claimed the intrusion.
Jul 29, 2026 · 3 min

The Change Healthcare attack exposed how U.S. healthcare depends on a single intermediary and added an estimated $2.87 billion in losses.
Jul 28, 2026 · 2 min

The DOJ expanded a case over bulletproof hosting tied to LockBit, Cl0p, BlackSuit, Play and other ransomware groups.
Jul 21, 2026 · 2 min

The House Science Committee advanced a federal AI security center as Gold Eagle already coordinates critical infrastructure vulnerabilities.
Jul 21, 2026 · 3 min

CISA says three SharePoint Server on-premises flaws are being actively exploited and urges patching plus tighter hardening.
Jul 19, 2026 · 3 min

FINRA urged financial firms to fold generative AI risks into cybersecurity and add governance, testing and monitoring controls.
Jul 19, 2026 · 2 min

US and allies warned of a Russia-attributed campaign exploiting routers with weak SNMP, default passwords and unpatched firmware.
Jul 19, 2026 · 2 min

Fairlife paused U.S. production after a ransomware attack. A later analysis linked the case to CitrixBleed 2.
Jul 19, 2026 · 2 min

The Treasury sanctioned First VPN Service and its administrator for facilitating ransomware operations, with hospitals among the cited targets.
Jul 18, 2026 · 2 min

A bipartisan bill would define transnational repression, add up to 10 years in prison, and expand DOJ and FBI oversight.
Jul 17, 2026 · 3 min

Paraguay and the United States found Flax Typhoon on Paraguayan state networks after a joint review. Deputies asked for reports.
Jul 15, 2026 · 3 min

Karen Vardanyan pleaded guilty in Ryuk attacks on U.S. hospitals, bringing renewed scrutiny to ransomware's impact on healthcare.
Jul 11, 2026 · 2 min

CISA added CVE-2026-45659, a Microsoft SharePoint flaw, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. Federal
Jul 6, 2026 · 2 min