Severity Daily

IT and AI security incidents, checked against the primary source

Tag: Boston Scientific

  • In six of today’s ten stories, the authoritative record has nothing to say at all

    In six of today’s ten stories, the authoritative record has nothing to say at all

    The most consequential item on the site today is cPanel’s parked-domain flaw. The vendor’s own advisory says an authenticated account holder who can add a parked or addon domain “can create arbitrary files on the server,” and that “successful exploitation leads to code execution as the root user, giving an attacker full control of the server and every account, website, and database on it.” Fixed builds are named across five branches, so this is a task you can finish tonight. It outranks the bigger-sounding story — Boston Scientific told the SEC that a cybersecurity incident caused a global disruption to its operations, and the clinical detail is worse than the filing, but almost nobody reading this can act on it. What decides the ranking is the second half of the cPanel item: three days after the advisory, CVE-2026-65643 has no record at NVD or the CVE Program, so nothing in your scanner or your ticket queue will raise it on its own. Tonight’s one fixable catastrophic flaw is the one your tooling is guaranteed to miss.

    The day had a thread, and it is yesterday’s failure mode inverted. Yesterday the authoritative record said the wrong thing; today, in six of ten stories, it says nothing at all. cPanel’s CVE has no record. AjaxPro’s record, now on a federal clock, still says no fixed version exists, though the maintainer shipped deserialization controls in November 2021. Two CVE records describe unauthenticated root code execution on the Unitree G1 EDU humanoid, one of them from Bluetooth range with no pairing, and neither the records, the CNA, nor Unitree names a firmware version that fixes it. The argocd-mcp flaw scored 10.0 on Saturday had a public GitHub advisory, and a fix, eighteen days before any CVE was attached to it. libuser’s only modern score says the bug cannot touch confidentiality or integrity, and NVD has published no primary v3 score of its own to arbitrate. And Anthropic’s warning to Claude users exists only as an email, with nothing on the newsroom or the status page.

    Order of business after cPanel. WPMU DEV Dashboard’s second unauthenticated admin bypass this month, CVSS 9.8, fixed in version 5.0.2 on August 24 and hitting exactly the Hub-connected sites the first one missed. Then MCP servers: VulnCheck published thirteen CVEs against thirteen separate projects inside a thirteen-second window on August 27, and the recurring defect — bind to every interface, accept sessions without credentials — is the one that earned argocd-mcp its 10.0. Then the two KEV additions that share a September 9, 2026 federal deadline, libuser and AjaxPro; ten days out rather than this week, and in both cases what an agency has to work around is the record, not the code. Unitree G1 operators have no patch to apply and should treat network and radio range as the only control they have.

    Four items moved without handing anyone a task, though one is worth an hour on your endpoints. Anthropic says commodity infostealers — Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, Atomic Stealer on macOS — are lifting Claude sessions off users’ machines, which makes it a workstation problem rather than a vendor one. An extortion group calling itself FulcrumSec put 86 GB, a sample, and a claimed access path behind the Manchester Airports breach. Socket found nineteen wallet-draining Chrome and Edge extensions, five of them bought from the developers who built them. And at Boston Scientific, every patient implanted since August 25 is storing data instead of sending it.

    Still open. CVE-2026-65643 still has no record, and nobody has said which CNA holds it. MAG’s statement, dated August 27 and not updated since, lists four field types; FulcrumSec’s sample shows itineraries and payment amounts, which are not among them. Anthropic has neither confirmed nor disputed the email, and nobody outside the company knows how many accounts received it. No one has named fixed firmware for the Unitree G1. Boston Scientific says the timeline for a full restoration is not yet known. And the September 9 deadline falls a week from Wednesday.

  • Boston Scientific says implanted cardiac devices still work, but patients implanted since August 25 are not transmitting

    Boston Scientific says implanted cardiac devices still work, but patients implanted since August 25 are not transmitting

    The company’s own updates say implanted devices still function and existing remote monitoring still works — but new communicators cannot be activated and new insertable cardiac monitors cannot pair, so every patient implanted since the incident began is storing data instead of sending it.

    What happened

    Boston Scientific identified a cybersecurity incident on Tuesday, August 25, 2026. It filed a Form 8-K with the Securities and Exchange Commission on August 26 and has posted four dated updates to its newsroom since, the most recent on Saturday, August 29, 2026 at 4:55 p.m. ET. Everything below comes from that filing and those updates.

    The 8-K, accession number 0000885725-26-000056, is filed under Item 8.01, Other Events. Its language is worth reading exactly as written: “On August 25, 2026, Boston Scientific Corporation (the ‘Company’) identified a cybersecurity incident affecting certain of its information technology systems that has resulted in a global disruption to the Company’s operations.” The filing continues that the incident “has caused, and is expected to continue to cause, disruptions and limitations of access to certain of the Company’s information systems and business applications that support aspects of the Company’s operations, including the ability to process and ship customer orders,” and that “the timeline for a full restoration is not yet known.” On materiality the company says plainly that it “has not yet determined whether the incident is reasonably likely to have a material impact on the Company.” Item 1.05, the SEC’s dedicated cybersecurity item, does not appear anywhere in the document.

    The clinically significant detail is not in the filing. It is in the August 28 newsroom update, which breaks the impact down by product line. On cardiac rhythm management devices the company states there are “No known impacts to implantable device function or the ability for remote patient monitoring.” Then the exception: “New remote monitoring communicators cannot be activated, thus available device data will NOT be transmitted.” For insertable cardiac monitors the same shape appears: “New ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data will NOT be transmitted.” The capitalization of “NOT” is the company’s own.

    The company also states what happens afterward: “Once systems are restored and pairing with home monitoring equipment occurs, the device will transmit recorded data.” On ordering, customers can submit “orders through the Global Health Exchange (GHX) which will be held until we are back online,” and the August 29 update adds that Boston Scientific is “able to intake orders electronically (through EDI) and place them in a queue for future fulfillment.” That same update reports that “our investigation indicates there is no impact to our cloud-based systems and applications,” locating the damage on premises.

    CrowdStrike and other third-party experts are engaged. No threat actor has claimed the incident on any leak site we could find. Across four updates and one filing, the company has made no statement about whether data was accessed, copied, or removed. That is neither a denial nor a confirmation; it is an absence, and worth naming as one.

    Why it matters

    Start with the asymmetry in the device impact, because it is the part most likely to be misread. An implanted cardiac device is not a server that pages someone when it goes offline. It records, it stores, and it hands data off to a communicator at the patient’s bedside or to a phone app. When that handoff works, the device is a monitored asset. When the handoff was never established in the first place, the device is a functioning implant that no one is watching, and nothing in the monitoring system says so.

    That distinction matters operationally. A clinic’s remote monitoring dashboard shows enrolled patients. A patient implanted on August 27 whose communicator could not be activated was never enrolled, so they do not appear on the dashboard as a gap, an alert, or a missed transmission. They simply are not there. The failure mode is silence in a system whose entire purpose is to break silence, and it is invisible from inside the tool a clinic would normally use to find it. Finding these patients means going to the implant log, not the monitoring console — a manual step no workflow currently prompts.

    The company’s recovery language is genuinely reassuring on one axis and should not be over-read on the other. “The device will transmit recorded data” means the episodes are retained on the device and will arrive once pairing happens. This is a transmission outage, not a data loss event, and that is an important difference. But retained is not reviewed. An arrhythmia recorded on August 27 is read whenever the backlog clears, and the clinical value of remote monitoring is substantially about timeliness. Deferred review is better than lost data and worse than monitoring.

    On the SEC filing, this publication has twice recently reported companies routing cybersecurity disclosures away from Item 1.05 — McKesson under Item 7.01 and Hasbro under Item 8.01. Consistency requires saying that this one looks different. Item 1.05 is triggered by a determination that an incident is material. Boston Scientific states in the filing itself that it has not made that determination, and SEC staff guidance has been explicit that Item 8.01 is the appropriate home for an incident whose materiality is still undetermined. Filing under 8.01 while saying so in terms is the rule working as designed rather than around it. The thing to watch is what follows: if the determination changes, an amended filing under Item 1.05 is what the rule expects, and the absence of one after a global operational disruption of unknown duration would become the story.

    The supply-chain shape deserves attention beyond this company. Order intake still works; fulfillment does not. Orders placed through EDI and GHX enter a queue rather than bouncing. From a hospital materials-management view, that is a system behaving normally right up until the delivery does not arrive, and queued orders do not generate the exception reports that rejected orders do. A manufacturer outage becomes a hospital inventory problem on a delay, and the delay is exactly the period during which the problem looks smaller than it is. Cardiac devices are not commodity supplies with interchangeable vendors; substitution involves physician preference, sizing, and lead selection.

    Finally, note where the damage landed. The company reports no impact to cloud-based systems and applications, with the disruption confined to on-premise systems. For organizations that have spent years being told the cloud is the risk surface, an incident that stops manufacturing and shipping while leaving cloud applications untouched is a useful corrective. It does not make on-premise infrastructure worse than cloud infrastructure. It does mean the systems that move physical goods are often the older, more tightly coupled ones, and that resilience planning aimed at the customer-facing tier does not automatically protect the tier that puts a device on a truck.

    What to do

    If you run a cardiology or electrophysiology program, pull the implant log rather than the monitoring dashboard, and identify every patient who received a Boston Scientific cardiac rhythm management device or insertable cardiac monitor on or after August 25, 2026. Those are the patients whose remote monitoring was never activated. Track them on a manual list until pairing is confirmed, and for any patient in that window with a clinical reason not to wait, schedule an in-office interrogation rather than waiting on restoration with no published timeline.

    Do not tell patients in that group that their data is lost. Per the company, the device retains recorded data and transmits it once pairing occurs. The accurate message is that transmission is delayed, not that recording stopped.

    For materials management, confirm the status of every order submitted through EDI or GHX since August 25, treat all of them as queued rather than in process, and check consignment stock against scheduled cases for the next several weeks. The restoration timeline is stated as unknown, so plan against duration rather than a date.

    For risk and legal teams, the current filing is Item 8.01 with materiality expressly undetermined. Monitor for an amended or subsequent 8-K. If your organization is a customer, the absence of any statement about data access is the open question to put in writing to your account team now, rather than after a notification arrives.

    Sourcing note

    Checked: Boston Scientific’s Form 8-K, accession number 0000885725-26-000056, filed August 26, 2026, read directly from SEC EDGAR — the item designation and all quoted filing language come from that document, and the Item 8.01 designation was independently confirmed through SEC full-text search. Also checked: the company’s newsroom page “Update on recent cybersecurity incident,” which carries dated updates on August 26, 27, 28, and 29, 2026; all device, ordering, and cloud statements quoted above are from that page in the company’s own words.

    Could not reach: cisa.gov returns HTTP 403 to automated fetching, so we could not check for a CISA or sector-specific advisory; none was found through search. We found no FDA safety communication on this incident and no statement from any device-safety regulator. We found no attacker claim on any leak site.

    Unresolved: whether any data was accessed or removed — the company has said nothing on this point across four updates and one filing. Also unresolved: the number of patients implanted during the affected window, which the company has not disclosed and which is not derivable from public information; the initial access vector; and the restoration timeline, which the company states is not yet known. No exploited vulnerability has been named by the company or by any agency, so this page names none.