Hims Breach Exposes the Most Sensitive Kinds of PHI

2026-04-10T20:51:44Zf3a410c73d82a643cfcb24009e603232cf4fd72324c5acdf11a9ca28265f0f79
AI-securityAPTAPT28BlueHammerCVE-2026-35616FancyBearFortiClientGitHubGrafana-patchMedusaOT-ICSPHIPLCsReact2ShellSOHO-routerscredential-harvestingcybersecurity-newsdata-breachexploit-writing-AIhealthcareransomwaresupply-chain-attackthreat-actor-activitywindows-zero-dayzero-day

What happened

A DarkReading news roundup highlighting multiple active threats and high-impact security events: a telehealth breach at Hims exposing sensitive PHI; an emergency FortiClient authentication-bypass zero-day (CVE-2026-35616) being patched and reported exploited in the wild; a released PoC for a local Windows takeover (BlueHammer/Chaotic Eclipse); AI-related risks including an exploit-writing Mythos model and AI-assisted supply-chain/GitHub targeting (PRT-scan); rapid ransomware campaigns (Storm-1175/Medusa) leveraging n-day and zero-day flaws; Iranian actors and other groups targeting Internet-ex

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
f3a410c73d82a643cfcb24009e603232cf4fd72324c5acdf11a9ca28265f0f79
Enrichment time
2026-04-10T20:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Hims Breach Exposes the Most Sensitive Kinds of PHI · Baitaphish