Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records

2026-09-01T20:51:37Zedbc35a21e30eeaa6a4c688ffd8482be20d0b5160d26e0c128360f8c4af36ed2
CVE-2026-81578AWSAvast AntivirusCISA KEVChina-linked espionageCisco routersDLL sideloadingFire AntGiveWPKaspersky Endpoint SecurityPHIPHP object injectionPIIPaperCutSilver FoxValleyRATWordPresscredential theftdata breachhealthcarelog tamperingולinfostealer?malwareprivilege escalationpublic exploitremote code executionzero-day

What happened

Security news covering a major healthcare data breach affecting 9.5 million people, public proof-of-concept zero-day privilege-escalation exploits in Avast and Kaspersky products, actively exploited PaperCut vulnerabilities added to CISA KEV, malware delivery and espionage campaigns, infostealer theft of Claude sessions, and a critical unauthenticated GiveWP WordPress command-execution flaw. The highest-priority items are the KEV-listed PaperCut issues, publicly available endpoint-security exploits, and the GiveWP remote command-execution vulnerability.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
edbc35a21e30eeaa6a4c688ffd8482be20d0b5160d26e0c128360f8c4af36ed2
Enrichment time
2026-09-01T20:51:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records · Baitaphish