Nirad Threat Research
Bharat-first threat intelligence for healthcare. Patch the edge appliances first, then verify that the laboratory record can be trusted.
July 2026 was the heaviest ransomware leak-site month of the year, with 811 organisations listed globally, and healthcare led every sector with 71 of them. India ranked sixth by country with 24 listed victims across all sectors. The concentration is not accidental: hospitals combine intolerance of downtime with regulated personal data, which gives extortion crews two levers at once. Set that against the scale of the Indian digital health estate, where ABDM crossed 100 crore ABHA-linked health records in May 2026 with more than 450 health-tech solutions integrated, and the defensive surface now runs from HIS, EMR and PACS through laboratory instruments to the edge appliances that publish all of it. Seqrite's India Cyber Threat Report 2026 placed education, healthcare and manufacturing together at close to 47 per cent of all detections in its Indian telemetry.
Healthcare topped the July 2026 ransomware leak-site table. Of 811 victims posted globally, 71 were healthcare organisations, the sector's highest count since February. The Gentlemen and Qilin tied for first place with 119 victims each, INC Ransom followed with 40 and DragonForce with 38. Leak-site counts measure claims rather than confirmed intrusions, and they omit victims who settle quietly, so treat the figure as a floor for sector pressure and not as a census. Source (with date): Breachsense July 2026 Ransomware Report (1 Aug 2026).
Ransomware is now measurable as patient harm, not only as downtime. A peer-reviewed study in the American Economic Journal: Economic Policy linked hospital ransomware incidents to Medicare claims data and found that in-hospital mortality among patients already admitted when an attack begins rises by 34 to 38 per cent, while hospital volume falls 17 to 24 per cent in the first week and recovers over roughly three weeks. Black Hat USA and HIMSS held their first joint healthcare summit on 4 August 2026 on the strength of this class of evidence. For an Indian hospital board, that converts continuity funding from an IT line item into a clinical governance obligation. Source (with date): American Economic Journal: Economic Policy, Neprash, McGlave and Nikpay (Feb 2026); TechTimes (1 Aug 2026).
Qilin, the most persistent operator against health providers, entered victims through a VPN authentication bypass. Check Point Research confirmed exploitation of CVE-2026-50751 (CVSS 9.3), a certificate-validation logic flaw in Remote Access VPN and Mobile Access deployments that still use the deprecated IKEv1 key exchange, allowing an attacker to establish a VPN session without a valid password. Activity began on 7 May 2026 and rose through early June, affecting a few dozen organisations worldwide, with post-compromise activity in at least one case attributed to a Qilin affiliate. A related flaw, CVE-2026-50752 (CVSS 7.4), affects site-to-site tunnels in the same code path. CISA added CVE-2026-50751 to its Known Exploited Vulnerabilities catalogue on 8 June 2026. Indian hospital groups that kept IKEv1 enabled for legacy branch or vendor tunnels are the exposed population; the vendor hotfix is available and IKEv1 can be disabled. Source (with date): Check Point Research advisory; Help Net Security; Rapid7 (8 Jun 2026).
Progress Kemp LoadMaster, CVE-2026-8037, added to CISA KEV. A command injection flaw in the appliance's escape_quotes() handling, reachable through several LoadMaster API endpoints, lets an unauthenticated attacker run operating-system commands on the load balancer; the vendor rates it 9.6. Progress shipped fixes in June 2026 in GA 7.2.63.2 and LTSF 7.2.54.18. Health-ISAC issued a TLP White bulletin to the health sector on 1 July 2026 after eSentire's Threat Response Unit observed in-the-wild exploitation attempts, and CISA added the flaw to KEV on 7 August 2026 with a 10 August federal remediation deadline. Public telemetry counted 792 exploitation attempts over 41 days from 65 addresses in 18 countries, assessed as largely unsuccessful. Hospitals commonly place LoadMaster in front of patient portals, HIS front ends and Citrix workloads, the position that makes a pre-authentication flaw urgent. Source (with date): Health-ISAC and American Hospital Association TLP White bulletin (1 Jul 2026); CISA KEV (7 Aug 2026); The Hacker News (8 Aug 2026).
Medixant RadiAnt DICOM viewer, CVE-2026-17264 — the attack arrives as a study, not as an email. A DICOM file carrying malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of-bounds write in RadiAnt 2025.2 and earlier, with remote code execution as the stated worst case. The scores are moderate, CVSS v4.0 5.3 and v3.1 4.3, and the vendor notes that Control Flow Guard, DEP and ASLR reduce practical exploitability. The delivery path is what matters for hospitals: radiology workstations open studies from patient-carried media, referral portals and imaging partners as routine work. Version 2026.1 carries the fix. Source (with date): CISA advisory ICSMA-26-218-01; HIPAA Journal (6 Aug 2026).
Thermo Fisher Applied Biosystems, CVE-2026-17583 — an integrity flaw in DNA results. The .fsa and .hid files produced by these genetic analysers carried no integrity verification, so anyone with access to a laboratory server or workstation could alter results before the analysis software loaded them, leaving no signal to the analyst. CVSS v4.0 8.2; no exploitation has been reported and the flaw is not in KEV. Fixed builds are 3500/3500xL Data Collection 4.0.3, 3730/3730xL 5.0.3, SeqStudio 1.2.6, SeqStudio Flex 1.2.1 and GeneMapper ID-X 1.7.4, and they add digital signatures so a laboratory can confirm a file has not changed since it left the instrument. For Indian genomics, forensic and clinical diagnostics laboratories this is a reporting-accuracy risk rather than a disclosure risk, and it is not covered by controls built for data theft. Source (with date): CISA advisory ICSMA-26-216-01; The Hacker News (4 Aug 2026).
The edge layer that publishes clinical systems keeps failing the same way. Citrix NetScaler ADC and Gateway CVE-2026-8451 (CVSS 8.8), disclosed on 30 June 2026, is a pre-authentication out-of-bounds read in SAML identity-provider configurations that leaks fragments of appliance memory, in the same class as CitrixBleed; CrowdSec published detection on 1 July and recorded exploitation attempts from 2 July 2026. Separately, CISA added Fortinet FortiOS CVE-2025-68686 to KEV on 27 July 2026. That flaw lets an attacker who already holds filesystem-level access bypass the patch Fortinet built against symbolic-link persistence, so an appliance patched after an earlier compromise may still be carrying that persistence. Indian hospital groups front clinical VDI, HIS access and patient portals with both product families. This cycle's vendor sweep also covered Cisco, Palo Alto Networks, Juniper, SonicWall, Sophos, Barracuda, WatchGuard, Zscaler, Ivanti, F5, Versa, VeloCloud, Aruba EdgeConnect and Seqrite by name. Source (with date): CrowdSec vulnerability tracking (2 Jul 2026); CISA KEV and Fortinet PSIRT (27 Jul 2026).
The DPDP transition clock is now short enough for hospitals to plan against. MeitY notified the DPDP Rules on 13 November 2025. Consent-manager registration provisions take effect around 13 November 2026, one year on from notification, and substantive obligations, including security safeguards, breach notification and data-principal rights, become enforceable on 13 May 2027. Penalties reach ₹250 crore for failure to maintain reasonable security safeguards and ₹200 crore for failure to notify a breach. Whether large hospital groups will be designated Significant Data Fiduciaries remains open, since the designation criteria had not been notified as of mid-2026; groups running ABDM and ABHA-linked flows should plan on the assumption that they will be. Source (with date): MeitY and PIB, DPDP Rules 2025 notification (13 Nov 2025); India Briefing DPDP compliance timeline (11 May 2026).
CERT-In's containment expectation sits badly with clinical change control. CERT-In's CISG-2026-02 guidance recommends containment, patching or mitigation within about 12 hours, where feasible, for known-exploited flaws on internet-facing and crown-jewel systems, and the six-hour incident reporting obligation under the 2022 directions remains separately in force. The three-day federal deadline attached to the LoadMaster KEV entry and the same-week exploitation of NetScaler show the pace the attacker side is setting. A hospital that can only patch an internet-facing appliance inside a monthly change window will not meet either clock. Source (with date): CERT-In CISG-2026-02, reported by The Hacker News (26 May 2026).
Why the group matters to Indian healthcare. The Gentlemen is a ransomware-as-a-service operation that has scaled unusually fast: roughly 300 claimed victims by March 2026, 478 by 11 June, 580 across 77 countries by 7 July, and 119 in July alone, tied for the busiest group of the month. Only a small share of victims are United States based, and public reporting places Thailand, the United Kingdom, Brazil, Germany and India among the most affected countries, with healthcare among its target sectors alongside IT services, manufacturing and financial services. Initial access is overwhelmingly the edge: VPN appliances and firewalls, with documented use of Fortinet FortiOS and FortiProxy CVE-2024-55591 and a stock of pre-compromised FortiGate devices, alongside stolen credentials and initial access brokers. Reported post-access tooling includes a custom Go backdoor, the GentleKiller EDR-killer framework, SharpADWS for Active Directory enumeration, netsh packet capture, AnyDesk and PsExec, and SystemBC for command and control. Microsoft has noted that the encryptor's spread argument turns a single host compromise into self-propagation across reachable systems, and the ESXi-capable variants map onto hospital virtualisation clusters. Attribution confidence is moderate to high for the operation and lower for any individual affiliate's tradecraft, which is normal for this model. ATT&CK: T1190, T1133, T1078, T1486, T1490, T1567. Source (with date): Palo Alto Networks Unit 42 (10 Jul 2026); PRODAFT via The Hacker News (11 Jun 2026); Breachsense (1 Aug 2026).
Every indicator below is already public in the named source and is reproduced with attribution.
- LoadMaster CVE-2026-8037 exploitation-attempt sources, reported by KEVIntel via The Hacker News (8 Aug 2026): 192.42.116.58, 192.42.116.105, 146.70.139.154. These are attempt sources and appear to be shared or anonymising infrastructure, so alert and investigate rather than block permanently. - Exposure review by CVE: CVE-2026-8037 (Progress Kemp LoadMaster), CVE-2026-8451 (Citrix NetScaler ADC and Gateway), CVE-2025-68686 (Fortinet FortiOS), CVE-2026-50751 and CVE-2026-50752 (Check Point Remote Access VPN and Mobile Access, IKEv1), CVE-2026-17264 (Medixant RadiAnt DICOM), CVE-2026-17583 (Thermo Fisher Applied Biosystems), CVE-2024-55591 (Fortinet FortiOS and FortiProxy, used by The Gentlemen). - Hunting leads, not indicators, drawn from public Unit 42 and PRODAFT reporting on The Gentlemen and applicable to comparable operators: vulnerable-driver loading and EDR-killer execution; SharpADWS-style Active Directory enumeration; Advanced IP Scanner or NetScan sweeps originating in clinical subnets; netsh packet capture on servers; AnyDesk or PsExec outside approved change windows; SystemBC beacons; ESXi management access outside maintenance windows; bulk reads from HIS, EMR, PACS or billing file stores; shadow copy deletion.
No named public source in this research window published an India-specific host indicator for any of these campaigns, so none is listed here.
Board: Fund clinical downtime capability as a patient-safety control rather than an IT contingency; the mortality evidence published this year is the benchmark a regulator or a court will reach for. Approve pre-authorised emergency patching for internet-facing appliances outside the monthly change window. Ask the executive for a dated position on DPDP readiness against the 13 November 2026 and 13 May 2027 milestones, including the group's working assumption on Significant Data Fiduciary designation.
CISO: Treat CVE-2026-8037 on LoadMaster and CVE-2026-8451 on NetScaler as immediate: patch, remove management interfaces from the internet, and rotate credentials and sessions that traversed either appliance. Confirm whether IKEv1 remains enabled anywhere on Check Point gateways and apply the hotfix. Audit the FortiGate estate for symbolic-link persistence rather than assuming a patch closed an older compromise. Inventory radiology viewers and laboratory data-collection software, move RadiAnt to 2026.1 and Applied Biosystems software to the fixed builds, and add file-integrity verification to laboratory reporting workflows.
SOC: Hunt the leads above with priority on ESXi hosts, PACS and laboratory servers. Review edge-appliance authentication logs from 30 June 2026 onward for NetScaler, from early May 2026 for Check Point remote access, and from the July KEV additions onward for FortiGate. Alert on the LoadMaster attempt-source addresses. Validate that immutable, tested backups cover HIS, EMR, PACS, laboratory information systems and billing, and rehearse the CERT-In six-hour reporting path against a clinical downtime scenario rather than a data-theft one.
1. Breachsense — July 2026 Ransomware Report, 1 August 2026. 2. American Economic Journal: Economic Policy — Neprash, McGlave and Nikpay, hospital ransomware and patient outcomes, February 2026. 3. TechTimes — Black Hat and HIMSS joint healthcare summit, 1 August 2026. 4. Check Point Research — CVE-2026-50751 and CVE-2026-50752 IKEv1 advisory and hotfix, June 2026; Help Net Security and Rapid7 — Qilin affiliate exploitation, 8 June 2026. 5. Health-ISAC and American Hospital Association — TLP White threat bulletin on Progress Kemp LoadMaster exploitation attempts, 1 July 2026. 6. CISA — Known Exploited Vulnerabilities catalogue additions, 8 June 2026, 27 July 2026 and 7 August 2026. 7. The Hacker News — Progress Kemp LoadMaster KEV addition and exploitation telemetry, 8 August 2026; Thermo Fisher DNA file tampering, August 2026; CERT-In CISG-2026-02 patching guidance, 26 May 2026. 8. CISA — ICS Medical Advisory ICSMA-26-216-01, 4 August 2026; ICSMA-26-218-01, 6 August 2026. 9. HIPAA Journal — Medixant RadiAnt DICOM viewer vulnerability, August 2026; Hackread — Thermo Fisher forensic DNA file tampering flaw, August 2026. 10. Citrix — NetScaler ADC and Gateway security advisory, 30 June 2026; CrowdSec — CVE-2026-8451 exploitation tracking, July 2026. 11. Palo Alto Networks Unit 42 — The Gentlemen ransomware, 10 July 2026. 12. PRODAFT via The Hacker News — The Gentlemen victim count and self-propagation capability, 11 June 2026. 13. MeitY and PIB — DPDP Rules 2025 notification, 13 November 2025; PIB and National Health Authority — ABDM crosses 100 crore ABHA-linked health records, May 2026. 14. India Briefing — DPDP compliance timeline, 11 May 2026. 15. Seqrite — India Cyber Threat Report 2026.
Compiled by the Nirad Threat Research team. Every item was verified against a named public source with a publication date before inclusion. No leaked or stolen data is reproduced, and indicators are taken only from public advisories.
Bharat-first threat intelligence for healthcare. Patch the edge appliances first, then verify that the laboratory record can be trusted.