Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records

2026-04-27T20:51:48Z05a8f1ae9da40fee851d6e490d03fac02a6ff69514b5ab25bc7cd591522f2d3b
CVE-2026-40050CVE-2026-6770Itronaptbrowser-fingerprintingchinacrowdstrikedata-breachespionagefast16firefoxgopherwhisperiTroonincident-responselinkedinlogscalemalwaremedtronicnasapath-traversalphishingprivacyshinyhunterstorvulnerability

What happened

A Security Affairs roundup covering multiple incidents: Medtronic confirmed a corporate IT breach after ShinyHunters claimed theft of 9M+ records; U.S. utility vendor Itron disclosed unauthorized access to parts of its IT environment; and BrowserGate allegations claim LinkedIn is fingerprinting users via extensions/device data. Two disclosed vulnerabilities: CVE-2026-40050 (critical path-traversal in CrowdStrike LogScale self-hosted allowing unauthenticated file access) and CVE-2026-6770 (Firefox/Tor fingerprinting bug impacting privacy). Additional reporting covers a China-linked spear-phish/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
05a8f1ae9da40fee851d6e490d03fac02a6ff69514b5ab25bc7cd591522f2d3b
Enrichment time
2026-04-27T20:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records · Baitaphish