Dutch healthcare software vendor goes dark after ransomware attack
2026-04-08T19:24:00Z•45141711982f59087401913af9f0a6aee38523843f7cc7d4267b224c42adbd1e
AI-assisted attacksAxiosChipSoftCitrix NetScalerFancy Bear (APT)FortiClient EMSGhostSocksIran-linked actorsLiteLLMMicrosoft phishingNHS ScotlandPyPI compromiseTelnyxTrivyVidar stealercritical infrastructuredevice-code phishingdomain hijackinghealthcarenpm backdoorpassword sprayingransomwaresupply chaintrojanized downloadszero-day
What happened
A broad set of high-impact cybersecurity incidents and trends were reported: a ransomware attack knocked Dutch healthcare vendor ChipSoft offline; multiple Scottish NHS-related domains were hijacked and redirected to porn/illegal streams; a critical FortiClient EMS vulnerability has been exploited in the wild and added to KEV; Citrix NetScaler flaws are being actively attacked; and supply‑chain compromises continue (npm Axios backdoor, PyPI Telnyx packages tied to the Trivy/LiteLLM campaign). Other notable items include trojanized Claude Code leak downloads (Vidar/GhostSocks), AI-assisted zero
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 45141711982f59087401913af9f0a6aee38523843f7cc7d4267b224c42adbd1e
- Enrichment time
- 2026-04-08T19:24:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.