Find notable cyber news and cases, enriched with sources, timelines, and signals.

Medical-imaging company hit by data theft breach

Incident
First reported
Last updated
Happening score
H score 67
1 unique sources, 1 articles

Summary

Hide ▲

A medical-imaging company suffered a weeks-long intrusion after an attacker exploited an SSRF vulnerability in an unauthenticated AI medical-imaging API, resulting in 6TB of data being compromised. The intruder used the access to find internal services and hunt for credentials to internal data stores. The event reflects a sustained, multi-stage compromise rather than a brief probe, raising the risk of data theft and follow-on abuse.

Timeline

  1. 05.10.2026 03:00 2 articles · 1d ago

    Medical-imaging company hit by SSRF intrusion through an unauthenticated AI medical-imaging API

    Initial Disclosure

    CloudSEK says Azazel exploited a server-side request forgery (SSRF) vulnerability in an unauthenticated AI medical-imaging API at a medical-imaging company, discovered internal services, and then searched for credentials to internal data stores in a sustained multi-stage compromise that ran for weeks and led to 6TB of data being compromised. The same disclosure says Azazel also used an AI coding assistant to send commands to a compromised machine on the victim’s network.

    Show sources