iRhythm discloses data breach, says hackers stole patient info
2026-06-16T07:23:35Z•05123e57264b80b6ac3e0c139e1f473ff240ef2cf9151fd0bbcdeb536e94e03b
cdn-compromisechina-linkedcve-2026-20262data-breachdeepfakeespionageinfinitecampusinfiniteredlaw-enforcementmicrosoft-365-copilotoidcoutider-enterprisephishing-as-a-serviceprivilege-escalationredcapremote-supportsearchleakshinyhunterssupply-chainvulnerabilitywordpress-pluginzero-day
What happened
Feed of security news (Jun 13–16, 2026) covering multiple breaches, supply‑chain compromises, exploited zero‑days, and law‑enforcement actions. Highlights: iRhythm disclosed a breach where patient personal and health data were stolen from third‑party hosted business apps; WordPress plugins (OptinMonster, TrustPulse, PushEngage) were compromised via an Awesome Motive CDN supply‑chain attack; a SimpleHelp vulnerability lets unauthenticated actors create privileged technician accounts via OIDC; Cisco patched CVE-2026-20262 in Catalyst SD‑WAN vManage after zero‑day exploitation for root escalation
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 05123e57264b80b6ac3e0c139e1f473ff240ef2cf9151fd0bbcdeb536e94e03b
- Enrichment time
- 2026-06-16T07:23:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.