Sam's News — security — 2026-08-16¶
Security¶
8 Poland's MyDr Health Platform Suffers Major Data Breach Affecting 18 Million Citizens¶
Hackers claim to have breached MyDr, Poland's medical platform, exposing health data of 18 million citizens including government officials.
- 18–19 million patient records compromised
- MyDr healthcare platform targeted
- Sensitive medical information across multiple terabytes exposed
- High-profile individuals' records included
Sources: Cybernews Web Search Update to: Poland's MyDr Platform Breached: 18 Million Citizens' Health Data Exposed in Historic Leak
8 Clop Ransomware Exploits PTC Windchill Zero-Day to Breach 43 Organizations¶
Clop ransomware exploited a PTC Windchill zero-day vulnerability to breach 43 multinational organizations including Shell, GE, and Philips.
Sources: Tech Times Web Search, Computing UK Web Search Update to: Clop ransomware exploits PTC Windchill zero-day to breach 43 organizations including Shell, GE, Philips
7 Multiple high-severity TP-Link vulnerabilities enable authentication bypass and privilege escalation¶
TP-Link disclosed multiple high-severity vulnerabilities in Omada Gateway and Archer router devices enabling authentication bypass, arbitrary command execution, and privilege escalation. CVE-2025-6541 allows attackers to inject malicious payloads through unsafe web interface parameter handling, potentially leading to full device compromise and lateral movement within enterprise networks.
- CVE-2025-6541: critical Remote Command Injection in Omada Gateway devices
- Related vulnerabilities including CVE-2025-6542 enable remote control without authentication
- Archer series routers affected by four additional high-severity vulnerabilities
- Exploitation risks include credential theft, lateral movement, and privilege escalation in enterprise networks
Sources: CYFIRMA AI Web Searched, CyberSecurityNews Web Search
7 Hospital Software Vendor Breached in Healthcare Supply-Chain Attack¶
Hackers stole customer data from a major hospital software vendor, highlighting vulnerabilities in healthcare supply chains.
Sources: Cybersecurity Dive Web Search Update to: Hospital Software Vendor Suffers Data Breach Exposing Supply Chain Vulnerability
7 Hugging Face Confirms Internal Data and Credential Breach¶
Hugging Face disclosed a breach affecting internal datasets and stored credentials, urging users to rotate access tokens.
Sources: TechCrunch Web Search Update to: Hugging Face Confirms Breach of Internal Datasets and Credentials; Users Urged to Rotate Tokens
6.5 Verizon 2026 Data Breach Report: Vulnerability Exploitation Surpasses Credential Theft¶
Verizon's 2026 breach report shows that vulnerability exploitation has become the leading attack vector, surpassing credential theft.
Sources: JD Supra Web Search Update to: 2026 Verizon Data Breach Investigations Report: Vulnerability Exploitation Overtakes Credential Theft
6.5 Nissan Suffers Data Breach in Oracle PeopleSoft Zero-Day Attack¶
Nissan suffered a data breach between May 27 and June 9 through an Oracle PeopleSoft attack, raising cybersecurity lessons for enterprise systems.
Sources: IT Brew Web Search, IT Brew Web Search
6.5 AmnesiaStealer macOS malware hijacks browser sessions via remote control¶
A new macOS malware called AmnesiaStealer uses ClickFix attacks to steal browser sessions and allow attacker-controlled browsing.
- Distributed through counterfeit GitHub pages installed via pasted Terminal commands
- Targets six Chromium-based browsers including Chrome, Brave, Arc, and Edge
- Overwrites per-browser Safe Storage key to render saved passwords and cookies unrecoverable
- Includes TCC framework bypasses for Safari cookies; installs LaunchDaemon for persistence
- Remote_stream command enables attacker control of cloned browser profile
Sources: BleepingComputer RSS Update to: AmnesiaStealer macOS Malware Steals Data and Controls Browser Sessions
6.5 Multiple DDoS attacks disrupt Threema secure messaging service¶
Threema secure messaging service experienced severe disruptions from coordinated distributed denial-of-service attacks earlier this week.
Sources: BleepingComputer RSS
6 Safepal security breach exposes 39,798 customer records¶
A security vulnerability in Safepal exposed personal order information for approximately 40,000 customers, though private keys and seed phrases remained protected.
Sources: CoinDesk RSS