๐ฅ BREACHES & INCIDENTS
- CareCloud notifies 345,000+ after March breach exposed medical records
CareCloud suffered a data breach exposing medical records of over 345,000 people.
- Applies to CareCloud, a U.S. health tech company serving 45,000+ providers
- Hackers accessed one electronic health record data store hosted on AWS
- Breach lasted at least six days in March 2026, from March 10 to March 16
- Stolen data includes names, addresses, Social Security numbers, IDs, financial and medical info
- No ransomware group has claimed responsibility; breach disclosed to multiple state AGs ๐ Coverage: techcrunch.com ยท ๐ via @zackwhittaker@mastodon.social
๐ต๏ธ RESEARCH & DEEP DIVES
-
Critical Remote Code Execution Flaw Discovered in Azure Cosmos DB (CVE-2026-66803)
CVE-2026-66803Azure Cosmos DB has a critical remote code execution vulnerability due to improper access control.- Applies to Azure Cosmos DB cloud database service
- Vulnerability allows unauthorized remote code execution
- Exploited via network without requiring privileges or user interaction
- Severity rated critical with CVSS score 10.0
- Root cause is improper access control (CWE-284) ๐ Coverage: cve.threatint.com ยท ๐ Original: cve.threatint.com ยท ๐ via CVE ThreatInt
-
Coordinated Cyberattacks Disrupt 30+ Minnesota Water Utilities' PLCs Iran-linked hackers coordinated cyberattacks on over 30 Minnesota water utilities' PLCs.
- Targets: More than 30 Minnesota community water and wastewater utilities
- Vulnerabilities: Internet-exposed programmable logic controllers (PLCs), including Rockwell Automation MicroLogix 1400
- Attack method: Remote intrusions modifying PLC passwords, changing IP addresses, disrupting automated controls
- Impact: Temporary operational disruptions, manual operations, boil water notices avoided
- Attribution: Linked to Iranian-affiliated threat groups like CyberAv3ngers and Handala, per state fusion center report ๐ Coverage: securityweek.com ยท ๐ Original: csoonline.com ยท ๐ via SecurityWeek, Dark Reading (+2)
๐ ADVISORIES
- JetBrains warns of critical remote code execution flaw in TeamCity On-Premises
JetBrains disclosed a critical authentication bypass vulnerability in TeamCity On-Premises enabling remote code execution.
- Affects all versions of TeamCity On-Premises; TeamCity Cloud not impacted
- Vulnerability CVE-2026-63077 allows attackers with HTTPS access to bypass authentication
- Exploitation via agent polling protocol enables arbitrary OS command execution with server privileges
- Disclosed July 27, 2026; no evidence of active exploitation at disclosure
- Patch available in TeamCity 2025.11.7, 2026.1.3, and as a plugin for versions 2017.1+ ๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer
๐ CVEs & KEV
- Other: 19 CVEs (worst 8.8)