Skip to main content
Security

Veradigm reports vendor credential breach exposed patient data

Veradigm reports vendor credential breach exposed patient data Image: Primary
Veradigm disclosed in a September 8 SEC filing that an unauthorized party used credentials obtained from a third-party vendor to access a vendor-facing API and download patient personal data. The company said some exposed records included Social Security numbers, while clinical and medical information was not compromised. Veradigm said its wider network, servers and databases were not accessed, services were not disrupted, and it is notifying affected customers and individuals.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from cybersecuritynews.com and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security
Security

CISA adds exploited Chromium V8 flaw to KEV catalog

CISA has added CVE-2026-85046, a Chromium V8 type-confusion vulnerability, to its Known Exploited Vulnerabilities catalog, saying it is actively exploited. The flaw can be triggered when a target loads a specially crafted HTML pag...

Security
Security

Microsoft fixes 974 flaws, including two exploited Windows zero-days

Microsoft released patches for 974 CVEs across its products, including two Windows zero-days reported as exploited in the wild. One is an ALPC heap-buffer-overflow flaw that can let a local attacker escape a low-privilege AppCont...

Security
Security

N-able issues hotfix for N-central zero-day

N-able released an urgent hotfix for CVE-2026-86218, a critical unauthenticated remote-code-execution vulnerability in its N-central endpoint-management platform. The company said the flaw had been exploited as a zero-day and that...

Security
Security

Chrome 153 fixes actively exploited V8 flaw

Google released Chrome 153 to the stable channel with fixes for 230 vulnerabilities, including CVE-2026-87491, an out-of-bounds write flaw in the V8 JavaScript and WebAssembly engine. Google says an exploit for the medium-severity...