CareCloud Breach Exposes Medical and Financial Data of 345,000

2026-08-02T20:51:35Zd67c9e4a58b3f68a5e0206cf61a1705ca3424a994df43a3cf4a82228d813ee15
CVE-2026-48449APT29AWSAdobe Campaign ClassicCozy BearDNS hijackingICSMicrosoft 365Midnight BlizzardOT securityRussian SVRSCADAStorm-2945critical infrastructuredata breachfinancial datahealthcarehotel Wi-Fiinternet-exposed PLCsmalwaremedical dataphishingremote code executiontoken theftwater utilitieswatering hole

What happened

Security Affairs RSS collection covering a CareCloud breach exposing medical and financial data of approximately 345,000 people; attacks on Minnesota water utilities involving internet-exposed PLCs; Russian SVR-linked activity stealing Microsoft 365 tokens through hijacked hotel Wi-Fi; South Korean watering-hole campaigns; and multiple vulnerability, malware, AI security, and security evaluation reports. The most severe item is Adobe Campaign Classic CVE-2026-48449, a CVSS 10.0 authorization flaw enabling unauthenticated remote code execution.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
d67c9e4a58b3f68a5e0206cf61a1705ca3424a994df43a3cf4a82228d813ee15
Enrichment time
2026-08-02T20:51:35Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CareCloud Breach Exposes Medical and Financial Data of 345,000 · Baitaphish