LIVE · cybersecurity feed
Live wire
CVE-2026-19478 · GitLab Critical GraphQL Flaw Actively ExploitedCVE-2026-73570 · Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite FlawCISA Urges Immediate Patching of Exploited TrueConf VulnerabilitiesCVE-2026-12569 · Cl0p Targets 40+ Organizations Through PTC Windchill FlawCVE-2026-69836 · Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code ExecutionManic: The Android Malware That Exfiltrates Data Even When the Phone Is OfflineHackers poison arrayref Rust crate to push infostealer malwareNSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCsSenators press TikTok over withholding of safety features for some usersAI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
breach

SickKids data breach exposes employee and job applicant info

Toronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not affected. (264) [...]

zeroday.news ·

The Hospital for Sick Children (SickKids) has disclosed a cybersecurity incident that exposed the personal information of some current and former employees, as well as job applicants. The Toronto-based pediatric hospital confirmed that the breach originated from a vulnerability in a third-party software application used by SickKids and other organizations.

According to SickKids, its clinical systems and patient records were not affected by the incident, and patient care continued without disruption. However, the hospital's public-facing Careers website was temporarily taken offline following the discovery of the breach. The Careers site has since been restored.

The incident resulted in unauthorized access to data belonging to current and former employees of SickKids, Boomerang (a SickKids-owned pediatric clinic), and the SickKids Foundation, in addition to SickKids job applicants. The hospital has not specified the exact categories of data exposed, the total number of individuals affected, or the date of the intrusion.

SickKids has initiated an investigation into the incident with the assistance of external cybersecurity experts. While the review of the impacted information is ongoing, the hospital is directly notifying individuals confirmed to be affected. Out of an abundance of caution, SickKids has also alerted all potentially impacted individuals and is offering 24 months of complimentary credit monitoring and identity protection services.

The hospital has not publicly identified the third-party vendor, the specific software application, or any associated CVE ID related to the vulnerability. The phrasing of the disclosure suggests a potential wider campaign targeting users of the same product.

This incident marks at least the third publicly known security event impacting SickKids in recent years. In December 2022, the hospital was hit by a ransomware attack attributed to the LockBit gang, which disrupted internal systems and caused delays in lab and imaging results. Although LockBit later issued an apology and provided a free decryptor, SickKids had already spent nearly two weeks restoring its systems independently.

In September 2023, SickKids was also among several Ontario healthcare providers affected by a data breach at a third-party organization that manages perinatal and child health data. That incident, which stemmed from the mass exploitation of the MOVEit Transfer zero-day vulnerability (CVE-2023-34362), exposed information on 3.4 million individuals, including names, home addresses, dates of birth, and health card numbers.

breachvulnerabilityhealthcare
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

vulnerability

Microsoft warns of max severity Entra ID flaw exploited in attacks

Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. [...]

malware

Hackers abuse FTP server banners to deliver new Windows malware

Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. [...]

CVE-2026-19478critical

GitLab Critical GraphQL Flaw Actively Exploited

GitLab has released an emergency patch for a critical vulnerability in its GraphQL API that allows unauthenticated attackers to modify or delete public projects and user data. Researchers from WatchTowr discovered the flaw, tracked as CVE-2026-19478, which has a CVSS score of 9.4 and is reportedly under active exploitation. The vulnerability affects self-managed installations, and users are urged to upgrade to specific patched versions, as older branches will not receive direct fixes.

ai

More Incidents of AIs Going Rogue in Cybersecurity Challenges

The AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “genie behavior—while being tested on their cybersecurity capabilities. The incident stemmed from a single evaluation where agents were given a task of solving a cyber security challenge. We ran this challenge 122 times across several models. Our investigation found that in 10 of t

security

Rust Supply Chain Attack Linked to North Korean Hackers

Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server. The post Rust Supply Chain Attack Linked to North Korean Hackers appeared first on SecurityWeek.