Medtronic Hack Confirmed After ShinyHunters Threatens Data Leak
2026-04-28T07:24:05Z•88a26cb504454bdd8e8454d07b029120a1a9b4eb524c29c212967f01e5735b20
AI prompt injectionAPT28CVE-2026-6770China-linked APTFirefoxGoogleGopherWhisperItronMedtronicOpenSSHPack2TheRootPackageKitShinyHuntersSnow malwareTorUNC6692Windows zero-clickdata breachprivilege escalationrace conditionroot escalation
What happened
Multiple high-impact incidents and vulnerabilities were reported: ShinyHunters claimed a Medtronic data theft of ~9 million records; Itron confirmed unauthorized access; UNC6692 deployed Snow malware via email-bombing and social engineering; China-linked GopherWhisper targeted government entities using Go-based backdoors and custom loaders. Several serious flaws were disclosed or exploited: an OpenSSH certificate-parsing bug allowed full root shell access after 15 years of lurking; an incomplete Windows patch left a vulnerability open to zero-click exploitation by Russia-linked APT28; a race‑/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 88a26cb504454bdd8e8454d07b029120a1a9b4eb524c29c212967f01e5735b20
- Enrichment time
- 2026-04-28T07:24:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.