CISA Advisories

3.7 Million Medical Records Exposed 🏥 and a Bug Hackers Are Using Right Now 🚨

Two stories from today's security news deserve your attention: one of the largest healthcare breaches of the year just got ten times bigger, and attackers are actively exploiting a flaw in a tool sitting inside thousands of company AI systems. Here's what happened and why it matters to you.

The Healthcare Breach That Quietly Grew 10x

Back in March, medical software company CareCloud noticed something wrong with its electronic health record system. It turned out that intruders had been inside its cloud environment for roughly a week, and they walked away with a lot. Originally, the company reported about 350,000 people affected. The official count now stands at 3,756,469 — more than ten times the original estimate.

What was taken isn't trivial: names and identity details, insurance information, medical records, and payment card data for some individuals. Medical records are especially valuable to criminals because, unlike a credit card, you can't cancel your medical history. If you've received care from a provider that uses CareCloud, watch your insurance statements for services you never received, and consider freezing your credit.

The bigger lesson for businesses: breach numbers almost always grow. If a vendor tells you "a small number of records" were affected in week one, plan for that figure to climb.

Read more →

Hackers Are Stealing Cloud Keys Through a Popular AI Tool

MLflow is a widely used open-source tool that helps companies build and manage machine learning projects. Researchers found a serious flaw in it (tracked as CVE-2026-64849), and attackers are already exploiting it in the wild — this isn't a theoretical risk.

The attack lets someone who isn't logged in at all trick the server into handing over the company's cloud credentials. Those keys are essentially the master keys to a company's cloud account: the databases, the file storage, the backups. Once an attacker has them, the AI project is the least of your worries.

If your engineering or data science team runs MLflow, the fix is simple and urgent: upgrade to version 3.15.0 or later today. It's also a reminder that the AI tools being rushed into production across every industry are software like any other — and they need patching, access controls, and monitoring just like your email server does.

Read more →

Stay ahead of threats with GOCO Security at gocosecurity.com.

Comments

Popular Posts