Weekly Threat Intelligence

The Healthcare Cyber Brief

Aug 18Aug 24 · Last 7 days · 6 days reporting

Peak Score

7.5

HIGH

Avg Score

5.2

6 days

Unique Threats

512

253 vulns

Ransomware

44

0 healthcare

Threat Level This Week

4.5
Aug 18
7.5
Aug 20
4.5
Aug 21
5
Aug 22
5
Aug 23
4.5
Aug 24

Top Threats This Week

[Ransomware] qilin: Spoonful of Comfort

CRITICAL

Ransomware group 'qilin' has posted a new victim named 'Spoonful of Comfort', which is a US-based healthcare organization. This indicates that qilin continues to target and compromise entities within the healthcare sector.

Microsoft Faces Fresh Nightmare Eclipse Zero-Day

CRITICAL

Security researchers have reproduced ShieldBreak, a claimed Windows Defender zero-day that manipulates cloud hydration and privileged processes to place attacker-controlled DLLs in System32 and elevate low-privileged users to SYSTEM. This attack leverages Microsoft's Defender Cloud Hydration feature, posing significant risks for organizations using Microsoft 365 and related services.

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

CRITICAL

A critical vulnerability (CVE-2026-58231) in SAP Commerce Cloud was exploited by attackers just three days after its disclosure, allowing for arbitrary code execution and internal component compromise.

CVE-2026-58231

Mustang Panda Upgrades CoolClient With a Kernel Rootkit

CRITICAL

Mustang Panda upgraded CoolClient malware to include a signed kernel driver that enhances its stealth capabilities by hiding processes, files, and network activity from inspection. The actor has been observed targeting entities in Pakistan, Mongolia, Myanmar, Russia, and government organizations.

[Ransomware] qilin: ASCII Group

CRITICAL

The ransomware group 'qilin' has added ASCII Group as a victim in Japan's healthcare sector, indicating a targeted attack on critical infrastructure that could disrupt patient care and operations.

Key Vulnerabilities

[CVE] CVE-2026-74790 (CRITICAL 9.1)

CRITICAL

CVE-2026-74790 is a critical vulnerability affecting Scriban before version 7.0.0, where attackers can access filtered properties and fields by reusing TemplateContext instances after tightening MemberFilter settings, bypassing sandbox policies across requests or tenants.

CVE-2026-74790Actively Exploited

[CVE] CVE-2026-74872 (CRITICAL 9.8)

CRITICAL

A critical vulnerability (CVE-2026-74872) in OpenSSL versions before 1.4.0 allows arbitrary code execution through a flaw in the Whirlpool hash implementation that loads .so modules without integrity verification, enabling attackers to place malicious .so files for native code execution.

CVE-2026-74872Actively Exploited

[CVE] CVE-2026-66792 (CRITICAL 9.9)

CRITICAL

A critical vulnerability (CVE-2026-66792) was identified in the multicloud-operators-subscription component, allowing users on managed clusters to escalate privileges by creating a Subscription with specific annotations. This could lead to unauthorized access and control over cluster resources.

CVE-2026-66792Actively Exploited

[CVE] CVE-2026-66795 (CRITICAL 9.1)

CRITICAL

A critical vulnerability (CVE-2026-66795) was identified in managedcluster-import-controller, affecting its CSR auto-approval logic by not properly validating incoming CSRs. This flaw allows a privileged service account on a spoke cluster to submit malicious CSRs and potentially escalate privileges to obtain administrative credentials on the hub cluster.

CVE-2026-66795Actively Exploited

[CVE] CVE-2026-75110 (CRITICAL 9.8)

CRITICAL

CVE-2026-75110 is a critical vulnerability in MemOS where an unauthenticated remote attacker can bypass authentication by exploiting the absence of the INTERNAL_SERVICE_SECRET environment variable, granting full access to admin API-key management and data endpoints. This could allow attackers to mint, enumerate, revoke keys, and generate master keys for persistent privileged access.

CVE-2026-75110Actively Exploited

Healthcare Ransomware Watch

6

Active Groups

44

Total Victims

0

Healthcare Confirmed

Groups observed: Cl0p, Helix, The Gentlemen, Unknown, dragonforce, krybit

Healthcare-Specific Intelligence

[Ransomware] qilin: Spoonful of Comfort

CRITICAL

Ransomware group 'qilin' has posted a new victim named 'Spoonful of Comfort', which is a US-based healthcare organization. This indicates that qilin continues to target and compromise entities within the healthcare sector.

Microsoft Faces Fresh Nightmare Eclipse Zero-Day

CRITICAL

Security researchers have reproduced ShieldBreak, a claimed Windows Defender zero-day that manipulates cloud hydration and privileged processes to place attacker-controlled DLLs in System32 and elevate low-privileged users to SYSTEM. This attack leverages Microsoft's Defender Cloud Hydration feature, posing significant risks for organizations using Microsoft 365 and related services.

[Ransomware] qilin: ASCII Group

CRITICAL

The ransomware group 'qilin' has added ASCII Group as a victim in Japan's healthcare sector, indicating a targeted attack on critical infrastructure that could disrupt patient care and operations.

Morning Headlines 8/17/26

CRITICAL

The FTC is investigating Epic Systems for potential violations related to health records handling. This probe highlights risks associated with data privacy and regulatory compliance in healthcare technology providers.

New AI Playbooks Will Target Healthcare Cyber Risk

CRITICAL

Dr. Brian Anderson of CHAI warns that Frontier AI models can rapidly identify and exploit network vulnerabilities in healthcare environments, compressing attack times from days or weeks to seconds. This poses a significant risk due to the speed and precision with which these attacks can be executed.

Want this delivered daily?

The full portal includes daily executive briefs, IOC tracking, historical analysis, and healthcare-specific intelligence from 50+ sources.

Join the Waitlist

This brief is generated from automated daily threat intelligence collection and analysis. 765 unique items analyzed across 6 reporting days.