惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
B
Blog
V
V2EX
T
Tailwind CSS Blog
Hugging Face - Blog
Hugging Face - Blog
博客园 - 【当耐特】
博客园 - 聂微东
博客园 - 叶小钗
博客园 - 三生石上(FineUI控件)
The Cloudflare Blog
J
Java Code Geeks
H
Help Net Security
雷峰网
雷峰网
Apple Machine Learning Research
Apple Machine Learning Research
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Engineering at Meta
Engineering at Meta
F
Fortinet All Blogs
Martin Fowler
Martin Fowler
D
Docker
L
LangChain Blog
人人都是产品经理
人人都是产品经理
爱范儿
爱范儿
WordPress大学
WordPress大学
V
Visual Studio Blog

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
A Quarter of Healthcare Organizations Report Medical Devi...
Phil Muncaster · 2026-04-29 · via www.infosecurity-magazine.com

One-in-four (24%) healthcare organizations (HCOs) experienced cyber-attacks impacting medical devices over the past year, causing potentially significant disruption to patient care, according to RunSafe Security.

The security vendor polled 551 healthcare professionals across the US, UK and Germany to produce its 2026 Medical Device Cybersecurity Index.

It revealed that, in 80% of cases, attacks affecting devices had a “moderate” or “significant” impact on patients.

This could range from delayed imaging and postponed procedures to interruptions to critical care delivery, RunSafe claimed.

Read more on medical devices: Nine in Ten Healthcare Organizations Use the Most Vulnerable IoT Devices

Cybersecurity is increasingly being integrated into procurement and operations. Some 82% of respondents said they have deployed or are actively piloting runtime exploit protection, 84% said they include cyber in vendor RFPs, and 76% that they would pay extra for advanced protection.

However, legacy equipment continues to expose many HCOs.

Over two-fifths (44%) of responding organizations said they use devices with known, unpatched vulnerabilities, and 28% admit operating devices past end-of-support.

Medical Device Manufacturers Hit by Major Cyber-Attacks

The findings come as device manufacturers themselves come under attack.

This week, US giant Medtronic admitted suffering a data security incident after notorious extortion group ShinyHunters listed the firm on its leak site in mid-April.

The threat actors claimed to have exfiltrated more than nine million records containing personal information, alongside large volumes of internal corporate data.

Separately, Fortune 500 medical technology vendor Stryker was impacted in March when the Iranian-sponsored Handala group wiped tens of thousands of corporate devices after accessing an Intune admin account.

“The findings land against a backdrop of large-scale healthcare cyber incidents that have disrupted care delivery and revenue flows, underscoring how quickly attacks on device-adjacent systems can translate into patient harm,” said Joseph Saunders, CEO of RunSafe Security.

“Medical device cybersecurity is increasing in importance to healthcare buyers as they see it as a patient safety and regulatory imperative.”

The tension between security and productivity in HCOs is likely to continue into the AI age.

Over half (57%) of organizations polled by RunSafe said they have adopted AI-enabled or AI-assisted medical systems. Yet 80% reported moderate to high concern about the cybersecurity risks associated with these technologies.

More positively, 56% of respondents said they rejected devices at a procurement stage due to cybersecurity concerns, up from 46% last year.