Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records

2026-04-28T02:51:48Zd48827ba9deab98e91665ef6d88980b5e824c1f5b067edf51b6a9a0a52988b9d
APTCVE-2026-40050CVE-2026-6770China-linkedbrowser-vulnerabilitydata-breachespionagefingerprintingincident-responsemalwaremedical-sectorpath-traversalphishingutilities

What happened

A set of high-impact security stories: Medtronic confirmed a corporate IT breach after ShinyHunters claimed theft of over 9 million records; U.S. utility vendor Itron disclosed unauthorized access to internal systems; and CrowdStrike fixed a critical LogScale self‑hosted vulnerability (CVE-2026-40050) — an unauthenticated path‑traversal allowing arbitrary file reads. Browser/privacy issues include a Firefox/Tor Browser fingerprinting vulnerability (CVE-2026-6770) that worked even in Private/Tor New Identity, and an investigation ("BrowserGate") alleging LinkedIn fingerprinting via extensions.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
d48827ba9deab98e91665ef6d88980b5e824c1f5b067edf51b6a9a0a52988b9d
Enrichment time
2026-04-28T02:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.