Skip to content

Sam's News — security — 2026-08-16

Security

8 Poland's MyDr Health Platform Suffers Major Data Breach Affecting 18 Million Citizens

Hackers claim to have breached MyDr, Poland's medical platform, exposing health data of 18 million citizens including government officials.

  • 18–19 million patient records compromised
  • MyDr healthcare platform targeted
  • Sensitive medical information across multiple terabytes exposed
  • High-profile individuals' records included

Sources: Cybernews Web Search Update to: Poland's MyDr Platform Breached: 18 Million Citizens' Health Data Exposed in Historic Leak

8 Clop Ransomware Exploits PTC Windchill Zero-Day to Breach 43 Organizations

Clop ransomware exploited a PTC Windchill zero-day vulnerability to breach 43 multinational organizations including Shell, GE, and Philips.

Sources: Tech Times Web Search, Computing UK Web Search Update to: Clop ransomware exploits PTC Windchill zero-day to breach 43 organizations including Shell, GE, Philips

TP-Link disclosed multiple high-severity vulnerabilities in Omada Gateway and Archer router devices enabling authentication bypass, arbitrary command execution, and privilege escalation. CVE-2025-6541 allows attackers to inject malicious payloads through unsafe web interface parameter handling, potentially leading to full device compromise and lateral movement within enterprise networks.

  • CVE-2025-6541: critical Remote Command Injection in Omada Gateway devices
  • Related vulnerabilities including CVE-2025-6542 enable remote control without authentication
  • Archer series routers affected by four additional high-severity vulnerabilities
  • Exploitation risks include credential theft, lateral movement, and privilege escalation in enterprise networks

Sources: CYFIRMA AI Web Searched, CyberSecurityNews Web Search

7 Hospital Software Vendor Breached in Healthcare Supply-Chain Attack

Hackers stole customer data from a major hospital software vendor, highlighting vulnerabilities in healthcare supply chains.

Sources: Cybersecurity Dive Web Search Update to: Hospital Software Vendor Suffers Data Breach Exposing Supply Chain Vulnerability

7 Hugging Face Confirms Internal Data and Credential Breach

Hugging Face disclosed a breach affecting internal datasets and stored credentials, urging users to rotate access tokens.

Sources: TechCrunch Web Search Update to: Hugging Face Confirms Breach of Internal Datasets and Credentials; Users Urged to Rotate Tokens

6.5 Verizon 2026 Data Breach Report: Vulnerability Exploitation Surpasses Credential Theft

Verizon's 2026 breach report shows that vulnerability exploitation has become the leading attack vector, surpassing credential theft.

Sources: JD Supra Web Search Update to: 2026 Verizon Data Breach Investigations Report: Vulnerability Exploitation Overtakes Credential Theft

6.5 Nissan Suffers Data Breach in Oracle PeopleSoft Zero-Day Attack

Nissan suffered a data breach between May 27 and June 9 through an Oracle PeopleSoft attack, raising cybersecurity lessons for enterprise systems.

Sources: IT Brew Web Search, IT Brew Web Search

6.5 AmnesiaStealer macOS malware hijacks browser sessions via remote control

A new macOS malware called AmnesiaStealer uses ClickFix attacks to steal browser sessions and allow attacker-controlled browsing.

  • Distributed through counterfeit GitHub pages installed via pasted Terminal commands
  • Targets six Chromium-based browsers including Chrome, Brave, Arc, and Edge
  • Overwrites per-browser Safe Storage key to render saved passwords and cookies unrecoverable
  • Includes TCC framework bypasses for Safari cookies; installs LaunchDaemon for persistence
  • Remote_stream command enables attacker control of cloned browser profile

Sources: BleepingComputer RSS Update to: AmnesiaStealer macOS Malware Steals Data and Controls Browser Sessions

6.5 Multiple DDoS attacks disrupt Threema secure messaging service

Threema secure messaging service experienced severe disruptions from coordinated distributed denial-of-service attacks earlier this week.

Sources: BleepingComputer RSS

6 Safepal security breach exposes 39,798 customer records

A security vulnerability in Safepal exposed personal order information for approximately 40,000 customers, though private keys and seed phrases remained protected.

Sources: CoinDesk RSS