Hims Breach Exposes the Most Sensitive Kinds of PHI

2026-04-13T14:51:49Z2b4cf2a71123681394d77a9486c347c2166854bc3895a6d8608176d70a0681f9
AI-assisted-attacksAPT28BlueHammerCVE-2026-35616FortiClientGitHubMedusaOT-ICSPHIPLC-compromiseReact2ShellSOHO-router-DNS-tamperingStorm-1175Windows-zero-daycredential-harvestingdata-breachexploit-writing-AIhealthcareincident-responseransomwaresupply-chain-attackvulnerability-managementzero-day

What happened

This DarkReading roundup highlights multiple high-risk incidents and trends: a Hims telehealth breach exposing sensitive PHI; active exploitation of a FortiClient authentication bypass (CVE-2026-35616) with an emergency patch; a Windows local-privilege zero-day PoC release (BlueHammer); Storm-1175’s fast Medusa ransomware campaigns leveraging n-day and zero-day flaws; automated credential-harvesting attacks against exposed Next.js apps (React2Shell exploitation); AI-assisted supply-chain and exploit development activity targeting GitHub and open-source maintainers; and nation-state/APT attacks

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
2b4cf2a71123681394d77a9486c347c2166854bc3895a6d8608176d70a0681f9
Enrichment time
2026-04-13T14:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Hims Breach Exposes the Most Sensitive Kinds of PHI · Baitaphish