Author: Osiris

  • Cyberattack Disrupts Boston Scientific’s Global Order Processing and Shipping

    Cyberattack Disrupts Boston Scientific’s Global Order Processing and Shipping

    Boston Scientific, the Massachusetts-based medical device manufacturer, disclosed on August 26, 2026 that a cyberattack identified the previous day had disrupted its global operations, including its ability to process and ship customer orders. According to a filing with the U.S. Securities and Exchange Commission reported by Cybersecurity Dive, the company said the incident affected its IT network and “certain operating systems and business applications” beginning August 25.

    In a statement posted to its newsroom, Boston Scientific said it activated its incident response plan upon detection and is working with third-party cybersecurity experts to investigate, contain and remediate the threat. The company said it could not immediately estimate how long full restoration of affected systems would take, according to reporting from SecurityWeek and pharmaphorum.

    The disruption has drawn attention because of Boston Scientific’s role as a major supplier of cardiovascular, endoscopy and neuromodulation devices to hospitals and clinics worldwide. Dray Agha, senior manager of security operations at the security platform Huntress, told pharmaphorum that “the attack on Boston Scientific demonstrates that cyber incidents in the MedTech sector extend far beyond IT and actively threaten the global healthcare supply chain,” warning that an inability to process or ship medical orders “creates immediate ripple effects that can ultimately delay critical treatments and impact patient care down the line.”

    Boston Scientific has not publicly attributed the attack to a specific threat actor or confirmed whether patient or customer data was exposed. Medical Device Network, citing the company’s own account, reported that the incident has continued to affect access to operating systems and business applications supporting order processing days after it was first detected.

    The incident adds to what industry outlets describe as a continuing pattern of cybersecurity incidents affecting medical technology manufacturers in 2026, underscoring the exposure that device makers face when enterprise IT outages ripple into physical supply chains for hospitals and clinicians who depend on timely equipment and consumable shipments.

  • CISA Red-Team Assessments Show Why One SOC Detected an Intrusion and Another Did Not

    CISA Red-Team Assessments Show Why One SOC Detected an Intrusion and Another Did Not

    The US Cybersecurity and Infrastructure Security Agency published A Tale of Two SOCs: Insights From Two Red Team Assessments on August 25, 2026. The advisory compares assessments conducted at two critical-infrastructure organizations and shows how similar adversary techniques produced very different defensive outcomes.

    Two assessments, two outcomes

    At the first organization, CISA’s red team gained access to multiple workstations, elevated privileges across the domain and moved laterally without being detected by the security operations center. The assessment identified gaps in monitoring, cloud visibility, identity protection and communication between separate security teams.

    At the second organization, the SOC detected and quarantined the red team’s initial access. That response forced the assessors to move to an assumed-breach scenario. Defenders also detected and contained portions of the follow-on activity, limiting the red team’s freedom of movement.

    What made the difference

    CISA’s comparison emphasizes operational fundamentals rather than a single security product. Tuned alerts, established network and identity baselines, documented escalation procedures, communication between SOC teams and system owners, and visibility across IT, cloud and operational-technology environments all affected the result.

    The advisory also highlights the risk created by fragmented tooling. Multiple SOCs or endpoint-detection platforms do not automatically improve security when teams cannot see one another’s alerts or coordinate investigations. Cloud identity and application controls require the same operational ownership as traditional endpoint and network monitoring.

    Why it matters for critical infrastructure

    Critical-infrastructure operators increasingly manage connected IT, cloud and OT environments. An attacker who begins on a workstation may use identity systems, remote administration paths or cloud services to move toward operationally important resources. Detection quality therefore depends on whether defenders can correlate events across those boundaries before activity becomes a domain-wide compromise.

    Red-team assessments do not predict every real intrusion, but they provide controlled evidence of how existing people, procedures and technology perform against realistic adversary behavior. CISA’s findings support a practical priority: organizations should test whether their SOC can detect and coordinate a response across the complete environment, rather than assuming that deployed tools are functioning as an integrated defense.

    Sources

    Follow additional developments on Technology News.

  • Third Drone and Suspected Explosives Found in Widening Leipzig Airport Sabotage Probe

    Third Drone and Suspected Explosives Found in Widening Leipzig Airport Sabotage Probe

    German investigators have found a third drone and a substance suspected to be military-grade explosive near Leipzig/Halle Airport, widening the investigation into an attempted attack earlier this month, German broadcasters NDR and WDR and the newspaper Sueddeutsche Zeitung reported on August 25, 2026.

    What was found

    According to the reports, the drone was recovered on August 14, ten days after the original incident, in an area west of the airport. Investigators also found roughly 50 grams (1.8 ounces) of a substance they suspect is hexogen, a military explosive, along with drone-control equipment reportedly taped to a tree in Kursdorf near the airport and a suspected blast site nearby.

    The original incident

    The case began on August 4, 2026, when an airport employee found a drone carrying an explosive device with a faulty detonator near a Ukrainian Antonov cargo aircraft in the airport’s secure cargo operations area. The discovery forced a temporary shutdown of the airport’s southern runway. German Interior Minister Alexander Dobrindt described the incident as representing a “new quality of danger” and a hybrid-style attack.

    Why it matters for aviation security

    Leipzig/Halle is a major European cargo hub used by Ukrainian Antonov aircraft, NATO and German military logistics, and DHL. The fact that an armed drone reached a secure airside cargo area — and that investigators are still recovering additional devices and evidence weeks later — underscores the difficulty of defending sensitive perimeter and airside zones against small, low-cost unmanned aircraft. Chancellor Friedrich Merz has said the government intends to formally attribute the attack; German security sources have pointed to possible Russian intelligence involvement, which Moscow denies.

    Sources

    More coverage like this is available on Technology News.

  • Johnson Controls Launches Next-Generation Fire and Life Safety Networking Platforms

    Johnson Controls Launches Next-Generation Fire and Life Safety Networking Platforms

    Johnson Controls announced on August 25, 2026, the next generation of its fire and life safety networking and workstation solutions, aimed at giving building operators broader visibility across fire alarm systems in large or mission-critical facilities.

    What was announced

    The company introduced two new fire safety workstations — Simplex Incident Manager and Autocall Fire Site Administrator — built to centralize monitoring and control across large device counts. According to Johnson Controls, the new offerings can monitor and control up to 250,000 devices and connect up to 687 fire alarm control units from multiple manufacturers, which the company says is more than other alternatives currently on the market.

    Target environments

    Johnson Controls positions the new platforms for data centers, campuses, hospitals, sports arenas and other high-traffic, high-density venues where fire and life safety systems must integrate data from many separate control units and support faster emergency decision-making.

    Why it matters

    As data centers, campuses and other mission-critical facilities scale up, fire detection and notification infrastructure has to scale with them — a single facility can now involve hundreds of interconnected fire alarm control panels rather than a handful of standalone systems. Centralized workstations that can aggregate multi-vendor fire alarm data are a response to that growth, and reflect a broader trend across the fire and life safety sector toward networked, software-driven incident management rather than panel-by-panel monitoring.

    Sources

    More coverage like this is available on Technology News.

  • SoftBank Plans $6.3 Billion Retail Bond Sale to Fund OpenAI Investment Commitments

    SoftBank Plans $6.3 Billion Retail Bond Sale to Fund OpenAI Investment Commitments

    SoftBank is planning a $6.3 billion retail bond sale, described by Bloomberg Technology as a record issuance, to help raise funds for its investment commitments to OpenAI, according to reporting published August 24, 2026.

    What was reported

    The bond sale would be aimed at Japanese retail investors and is intended to support SoftBank’s continued financial commitments as part of its investment relationship with OpenAI. The report was one of several pieces of AI-financing news that broke over the same weekend, alongside Alibaba’s Hong Kong share placement and continued reporting on rising AI server costs.

    Why it matters

    SoftBank has positioned itself as one of the largest financial backers of OpenAI’s infrastructure ambitions, and a bond sale of this size aimed at retail investors — rather than solely institutional capital — reflects how large a role AI-related financing has come to play in SoftBank’s overall capital strategy. Taken together with Alibaba’s share placement and reports of rising AI hardware costs the same week, it underscores how much new capital the current AI buildout requires across debt, equity and retail bond markets simultaneously.

    Sources

    More coverage like this is available on Technology News.

  • Alibaba Raises $10.2 Billion in Hong Kong Share Placement to Fund AI Push, Shares Fall 10%

    Alibaba Raises $10.2 Billion in Hong Kong Share Placement to Fund AI Push, Shares Fall 10%

    Alibaba raised $10.2 billion through a Hong Kong share placement to help fund its artificial intelligence buildout, in what CNBC and Bloomberg Television described as the largest follow-on stock offering in Hong Kong’s history, with the news breaking August 24, 2026, and Alibaba’s shares falling roughly 10% in response.

    What was announced

    The capital raise is aimed at supporting Alibaba’s continued investment in AI infrastructure as the company competes with global cloud and AI providers for compute capacity. Coverage described the share placement as taking the lead in what Bloomberg characterized as a broader race among Asian technology companies to fund AI expansion through public markets.

    Why it matters

    The scale of the offering, and the market’s roughly 10% negative reaction, illustrates the tension investors are currently pricing into large AI infrastructure bets: heavy capital spending is seen as necessary to remain competitive in AI and cloud services, but it also raises near-term dilution and return-on-investment questions for shareholders. Alibaba’s move follows a broader pattern this year of major technology companies — including US hyperscalers — turning to debt and equity markets to fund AI data center and chip commitments.

    Sources

    More coverage like this is available on Technology News.

  • Nvidia Customers Reportedly Warned of AI Server Price Hikes as Groq Deal Moves Forward

    Nvidia Customers Reportedly Warned of AI Server Price Hikes as Groq Deal Moves Forward

    Nvidia’s largest server customers have been told to expect price increases of more than 15% in many cases for AI servers, driven by rising memory chip costs, Bloomberg reported over the weekend of August 22–23, 2026, with the story continuing to be discussed heavily in tech and financial media on August 24. Separately, CNBC reported that Nvidia said racks built with hardware from Groq — in which Nvidia recently made a roughly $20 billion related investment — will come online later this year.

    What is driving the increases

    According to Bloomberg’s reporting, the price increases are being driven primarily by soaring memory chip costs rather than by Nvidia’s own component pricing, as server makers pass through higher costs for the memory needed to build AI-optimized systems. The report landed the week Nvidia is scheduled to report quarterly earnings, adding to investor focus on demand signals for the company’s AI hardware.

    Why it matters

    Rising AI server costs affect every organization planning large-scale data center buildouts, including security, video analytics and AI-driven monitoring platforms that increasingly depend on GPU-accelerated infrastructure. Higher per-server costs can slow the pace at which cloud providers and enterprises expand AI compute capacity, even as demand signals — including Nvidia’s push to bring Groq-linked infrastructure online this year — suggest that AI infrastructure investment is continuing at a rapid pace despite the added cost pressure.

    Sources

    More coverage like this is available on Technology News.

  • CISA Deadline Passes for Federal Agencies to Patch Actively Exploited Zimbra Flaw

    CISA Deadline Passes for Federal Agencies to Patch Actively Exploited Zimbra Flaw

    August 24, 2026, was the deadline for US federal civilian executive branch agencies to mitigate or discontinue use of Zimbra Collaboration Suite (ZCS) systems affected by CVE-2026-73570, a critical, actively exploited remote-code-execution flaw, after the US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalog on August 21, according to reporting from Dark Reading and The Hacker News.

    Background on the flaw

    Zimbra disclosed CVE-2026-73570, a command-injection vulnerability in the optional zimbra-snmp component that can allow unauthenticated remote code execution when SNMP notifications are enabled, and released a patched version, ZCS 10.1.20, on July 20, 2026. Poland’s CERT Polska warned on August 16–17 that the flaw was being actively exploited in the wild, and BleepingComputer reported on the active exploitation campaign on August 20. CISA added the vulnerability to its KEV catalog on August 21 and required federal civilian agencies to remediate by August 24.

    Why it matters

    Zimbra Collaboration Suite is widely used email and collaboration software across businesses and government agencies. An unauthenticated remote-code-execution flaw in internet-facing collaboration infrastructure, already confirmed as being actively exploited before a patch was applied everywhere, is exactly the scenario CISA’s KEV deadlines are designed to force organizations to act on quickly. Security teams running Zimbra Collaboration Suite that have not yet applied version 10.1.20 or later, or disabled the affected SNMP component, should treat this as an active, ongoing exploitation risk rather than a theoretical one.

    Sources

    More coverage like this is available on Technology News.

  • UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

    UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

    A cybercrime group tracked as UAT-10147 is using artificial intelligence tools to help scale attacks against internet-facing servers, and is deploying a malware toolset called SPECTRE that includes endpoint detection and response (EDR) evasion capabilities and a Linux rootkit component, according to a report published by The Hacker News on August 24, 2026.

    What the campaign involves

    Reporting describes UAT-10147 as using AI-assisted techniques to accelerate reconnaissance and exploitation against server infrastructure, rather than relying solely on manual attack chains. Once inside a target environment, the group is reported to deploy SPECTRE, which combines capabilities to bypass or blind EDR tooling with a Linux-focused rootkit intended to maintain stealthy, persistent access.

    Why it matters

    The use of AI-assisted tooling to scale attacks against server infrastructure reflects a trend that both offensive and defensive researchers have flagged repeatedly through 2026: attackers are using automation and AI assistance to compress the time between reconnaissance and exploitation, while defenders increasingly rely on AI-assisted detection to keep pace. A rootkit paired with EDR-bypass capability is also a reminder that Linux server estates — often assumed to be lower-risk than Windows endpoints — remain a high-value target, particularly where detection tooling coverage is weaker than on the desktop fleet.

    Sources

    More coverage like this is available on Technology News.

  • Operation QUICSILVER: New QUICAgent Backdoor Targets Myanmar Government and IT Networks

    Operation QUICSILVER: New QUICAgent Backdoor Targets Myanmar Government and IT Networks

    Security researchers have disclosed a cyber-espionage campaign, tracked as Operation QUICSILVER, that targets government agencies and IT organizations in Myanmar using a previously undocumented backdoor named QUICAgent, according to a report published by The Hacker News on August 24, 2026.

    What researchers found

    The campaign is described as an active cyber-espionage operation focused on Myanmar government and information-technology sector networks. Reporting characterizes it as consistent with state-linked cyber-espionage tradecraft, deploying the QUICAgent backdoor to establish persistent access inside targeted networks. As is typical for early-stage espionage-malware disclosures, full attribution and complete technical indicators were still being documented publicly at the time of the report.

    Why it matters

    Espionage-focused backdoors like QUICAgent are built to stay hidden inside government and infrastructure-adjacent networks for extended periods rather than cause immediate disruption, which makes early public disclosure by researchers an important part of defenders’ ability to detect them. Campaigns targeting Southeast Asian government and IT-sector networks are also a reminder that nation-state espionage activity extends well beyond the small number of countries that dominate headlines, and that regional government and critical-infrastructure-adjacent IT operators remain a persistent target set.

    Sources

    More coverage like this is available on Technology News.