Hims Breach Exposes the Most Sensitive Kinds of PHI
2026-04-13T14:51:49Z•2b4cf2a71123681394d77a9486c347c2166854bc3895a6d8608176d70a0681f9
AI-assisted-attacksAPT28BlueHammerCVE-2026-35616FortiClientGitHubMedusaOT-ICSPHIPLC-compromiseReact2ShellSOHO-router-DNS-tamperingStorm-1175Windows-zero-daycredential-harvestingdata-breachexploit-writing-AIhealthcareincident-responseransomwaresupply-chain-attackvulnerability-managementzero-day
What happened
This DarkReading roundup highlights multiple high-risk incidents and trends: a Hims telehealth breach exposing sensitive PHI; active exploitation of a FortiClient authentication bypass (CVE-2026-35616) with an emergency patch; a Windows local-privilege zero-day PoC release (BlueHammer); Storm-1175’s fast Medusa ransomware campaigns leveraging n-day and zero-day flaws; automated credential-harvesting attacks against exposed Next.js apps (React2Shell exploitation); AI-assisted supply-chain and exploit development activity targeting GitHub and open-source maintainers; and nation-state/APT attacks
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 2b4cf2a71123681394d77a9486c347c2166854bc3895a6d8608176d70a0681f9
- Enrichment time
- 2026-04-13T14:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.