Oncology Institute Discloses Data Breach
2026-05-25T13:24:08Z•be1cd7ae7cf233d8e19aaf8f6c8e2abaf80b7056ec3361343903e3b4a4b90fde
CISACVE-2026-9082PHIbackdoorbotnetci-secrets-exfiltrationdata-breachdns-bypassdrupalgithub-actionshealthcareindustrial-exploitationkimwolflaravel-langmalwaremegalodonmythososs-vulnerabilitiessoftware-supply-chainsupply-chain-attacktelecom-outagethird-party-vendorunderminrvulnerability-scanning
What happened
Multiple high-impact security incidents and vulnerability reports were disclosed: several healthcare-related third‑party breaches (Oncology Institute — vendor possibly TriZetto; Radiology Associates of Richmond — ~266,000 impacted; DocketWise — ~143,000 impacted with SSNs, PHI) exposing names, PHI and financial data; large-scale supply‑chain attacks and repository compromises (5,500+ GitHub repos in the ‘Megalodon’ campaign; Laravel‑Lang packages poisoned to introduce backdoors and exfiltrate CI secrets); Anthropic’s Mythos tooling flagged ~23,000 potential vulnerabilities across ~1,000 OSS‑up
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- be1cd7ae7cf233d8e19aaf8f6c8e2abaf80b7056ec3361343903e3b4a4b90fde
- Enrichment time
- 2026-05-25T13:24:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.