Weekend Update

Weekend Update

Simplicity is a virtue.

Happy Summer Solstice.

From Washington, DC,

  • The Coalition against Surprise Medical Billing opines,
    • “When the Congressional Budget Office (CBO) puts out a public call for new research on the cost impacts of the No Surprises Act, it’s the latest signal that the law’s arbitration process, also known as Independent Dispute Resolution (IDR), has veered far off course.
    • ‘In a new blog post, CBO asks for the latest data on inflationary awards and the excessive flood of disputes that have now become standard with IDR. The agency’s takeaway is clear: the data now point to arbitration as a growing threat to the cost savings the law was meant to deliver.
    • “CBO does not mince words about the impact:
    • “Although evidence suggests that prices for services affected by the No Surprises Act may have initially decreased, arbitration outcomes could lead to higher prices over time. If providers can systematically secure large payments through the IDR process, they have an incentive to remain out of network or demand higher in-network rates.”
    • “This is one of the many unintended consequences from IDR abuse and misuse. A handful of private equity-backed providers and IDR middlemen have turned IDR into a profit engine: from 2022 through 2025, 4.8 million disputes were filed — against the roughly 17,000 disputes a year that were originally projected. Providers prevail in roughly 88 percent of cases, and awards routinely run 3-9 times in-network rates, with some specialties receiving upwards of 17 times in-network payments.
    • “And here is the part that has raised alarms for employers and consumers footing the bill. CBO cautions that IDR’s spillover effect has broad cost implications:
    • “Although surveys of insurers suggest that less than 0.05 percent of all claims go to arbitration, those claims could have an outsized effect on bargaining and, over time, cause negotiated prices to increase. An increase in prices would increase premiums for commercial health insurance and, in turn, lead to larger federal deficits.”

From the public health and medical / Rx research front

  • The New York Times reports,
    • “Buildings May Soon Have ‘Immune Systems’ That Fight Airborne Disease.”
      • “Following the pandemic, the federal government is spending $150 million on new technology to ensure clean indoor air. Here’s what scientists are pursuing.”
  • The Wall Street Journal adds,
    • “I Don’t Expect My Grandchildren to Experience Dementia
      • “An Alzheimer’s specialist says science will continue to make great leaps in diagnosing and treating Alzheimer’s. But that’s only part of the battle.” * * *
      • “If I could boil my formula for the future of dementia care into two words, it would be this: Hope heals. Alzheimer’s disease and other forms of dementia are so frightening because they threaten to rob us of the very essence of our history and being. This fear can tilt aging into a dark space, devoid of any good future.
      • “Fortunately, we have entered a new era of disease management in which we know more and can do more, enabling us to implement brain-healthy strategies before symptoms begin and mitigating them after they start. This proactive approach will broaden and improve the span of normal and meaningful living. 
      • “At the same time, we must acknowledge that caring for someone with dementia is extremely challenging and might seem impossible to do it right. The solutions have already been discovered; now they need wider implementation. We have both the opportunity and the responsibility to do better by actively engaging with affected individuals and families in comprehensive ways that will, I am certain, not only improve care but also the very course of this disease. In doing so, we send a powerful message to ourselves and our society about every person’s inherent value. The central goal in this brave new world is to help affected individuals not just survive, but to thrive.”
  • Medscape tells us,
    • “Protein supplements = convenience foods; help meet 1.2-1.6 g/kg/d targets.
    • “Creatine monohydrate: best-studied; 3-5 g/d effective for most adults.
    • “Kidney safety concerns in healthy adults are repeatedly debunked for protein + creatine.
    • “GLP-1 users may need lower protein intake; resistance training remains primary for muscle preservation.
    • “Whey isolate or plant-based leucine-augmented blends can support muscle protein synthesis.”
  • and
    • “According to findings from a phase 2 trial published in Nature Medicine, a monoclonal antibody targeting myostatin reduced lean body mass loss by more than half during treatment with the GLP-1 or glucose-dependent insulinotropic polypeptide receptor agonist tirzepatide, while the overall weight loss remained unchanged.
    • “These findings address a growing concern surrounding obesity pharmacotherapy. Weight loss typically involves a reduction in both fat mass and lean body mass, which includes muscle, bone, connective tissue, and body water. Loss of muscle mass is considered particularly important because of its potential effects on strength, physical performance, and metabolic health.”
  • MedPage Today informs us,
    • “An increasing number of Americans are getting — and surviving — cancer. There were more than 18 million cancer survivors in the U.S. in 2025, and the National Cancer Institute estimates that number will grow to 22 million by 2035. But long after completing treatment, many survivors face lingering mental health challenges that go unaddressed.” * * *
    • Studiesopens in a new tab or window show cancer survivors experience anxiety and depression that can last years after they finish treatment.
    • The advocacy group Cancer Nation surveyed patients nationwide last year. It found that about a third of those who had finished treatment reported anxiety about their cancer potentially coming back, as well as problems with not feeling like their “old self.” Only 1 in 5 of the surveyed survivors reported seeing a mental health professional.

From the U.S. healthcare business and artificial intelligence front,

  • Modern Healthcare reports,
    • “More procedures are shifting from hospitals to ambulatory surgery centers, and the lower-reimbursement settings are driving demand for surgical robots that are more affordable and more agile. 
    • “Intuitive Surgical remains the dominant player in hospital-based, soft-tissue robotic surgery and is trying to gain a foothold in ambulatory surgery centers. Distalmotion, which announced the first U.S. sale of its Dexter Robotic Surgery System in March 2025, designed the robot with the outpatient setting in mind.” * * *
    • “In an interview, Distalmotion CEO Greg Roche said all the robots it’s sold this year in the U.S. went to ambulatory surgery centers. Dexter’s compact footprint and mobility make it well suited for this environment, he said.”
  • MedTech Dive adds,
    • “‘Putting the body back together’ with MMI’s microsurgery robot
      • “MMI built a robot to help surgeons perform microsurgical procedures with more control than is possible with the human hand alone.”
  • The Health Care Cost Institute relates,
    • “Use of medications for opioid use disorder (MOUD) grew from 2018 to 2022, but fewer than half of people with opioid use disorder and employer-sponsored insurance received MOUD.
    • “Primary care providers prescribed more than 70% of MOUD among people with employer-sponsored insurance.
    • “Fewer than half of patients with employer-sponsored insurance filled enough prescriptions to regularly take MOUD for one year.” * * *
    • “Clinical guidelines say that patients should be on MOUD for at least six months, but experts believe that a year or more of treatment is needed to achieve sustainable recovery from OUD.” * * *
    • “MOUD treatment rates and adherence may be low because of stigma associated with the disease and treatment. Public health campaigns targeted at employed adults may also increase demand for MOUD.”
  • Beckers Payer Issues tells us,
    • ‘Pharmacy benefit managers Abarca Health and LucyRx are merging, the companies said in a June 17 news release.
    • “Together, the organizations will reach 9 million members. The companies will operate as subsidiaries under Healthcare Revolution Partners. The news release said clients and members will not experience disruptions due to the merger.
    • “The transaction is expected to close in the third quarter of 2026.'”
  • Modern Healthcare informs us,
    • “At UnitedHealth Group Inc., artificial intelligence reads aloud summaries of medical charts as nurses drive to patients’ homes. It listens to millions of customer calls to find the causes of complaints. One trial even has AI agents calling doctors’ offices to schedule appointments for patients.
    • “The largest U.S. health insurer plans to invest $3 billion in AI over 2026 and 2027. UnitedHealth executives say they’re seeing a 2-to-1 return, as AI automates cumbersome manual processes and makes workers more efficient. Executives say the technology can reduce friction for patients while lowering costs.
    • “There’s a lot riding on them being right. UnitedHealth put AI at the heart of its turnaround strategy since profits collapsed last year, to drive efficiency and to address customers’ frustrations such as by speeding up care approvals. Wall Street expects it to boost earnings by cutting expenses. Insurers and medical providers together spend $80 billion a year on administrative transactions, Morgan Stanley analysts led by Erin Wright said in a June research note.”
    • “The cost savings potential is clear, particularly for manual, data-intensive processes such as prior authorization,” they said, adding that UnitedHealth will also profit from selling AI products and services to other healthcare companies.
    • “Many healthcare transactions that have long been digitized in other industries still involve phone calls, faxes and paper. An early example UnitedHealth points to is a system called Optum Real that allows medical providers to check in real time whether a service is covered. The system has processed about a billion transactions since it started last year.”

Cybersecurity Saturday

From the Project Glasswing front,

  • Politico reports on June 18,
    • “The White House and Anthropic are working on a framework that would assess the severity of security flaws in new AI models and guide potential government intervention, according to a senior White House official and an administration official familiar with the matter granted anonymity to discuss it.
    • “The effort comes after the White House imposed export controls on Anthropic, which forced the company to suspend access for all users to Fable 5 and Mythos 5, its latest powerful AI models over a perceived security flaw, known in the industry as a jailbreak.
    • Administration officials and Anthropic CEO Dario Amodei disagreed over the severity of the jailbreak, POLITICO previously reported, but the technology has outpaced the government infrastructure to define and assess such disputes.
    • “The attempt to create a standardized method to evaluate this and future such incidents underscores how the administration is racing to establish guardrails for new and powerful models that some fear can, if left unchecked, threaten economic and national security.
    • “The negotiations between Anthropic and the administration also reflect an understanding that no AI model can be completely immune to hacking — part of Anthropic’s initial defense of its model — and that government should lay out the rules for companies to measure security risks by, a sentiment relayed by other leading AI companies and country leaders at G7 meetings earlier this week in France.”
  • Bloomberg adds also on June 18,
    • “Some firms have preserved their access to a preview version of the Mythos AI model through Project Glasswing, despite a US government order.
    • “Businesses including banks and technology firms are accessing Mythos Preview to hunt for cyber vulnerabilities, with companies like Dragos Inc. and Cisco Systems Inc. confirming they have access.
    • “The US government order led to the shutdown of other versions of the Mythos AI model, but it didn’t explicitly address the Preview version, and Anthropic hasn’t directly addressed its availability.”
  • Cyberscoop points out,
    • “While Washington D.C. frets over the potential impact of Anthropic’s Claude Fable 5, security researchers continue to track how the integration of frontier AI tools are transforming the digital security landscape for malicious hackers and defenders alike.
    • “The breakneck speed of model releases may be creating short, silent security gaps for developers who must choose between performance and security, according to a new report.”
  • Cybersecurity Dive notes
    • “More than one-fifth of organizations running macOS networks have lost money or experienced a cyberattack because of their use of AI tools, according to a report that network management vendor Jamf released on Tuesday.
    • “Roughly six in 10 macOS-based organizations expect an AI-related incident in the near future, the survey found.
    • “The report, based on interviews with 687 IT and security leaders managing MacOS network environments, also describes system administrators’ AI implementation priorities, the largest areas of risk they face and Jamf’s recommendations for mitigating those risks.”

From the cybersecurity policy and law enforcement front,

  • Cybersecurity Dive reports,
    • “U.S. cybersecurity resilience in the face of sophisticated threats from China and other adversaries will increasingly depend on critical infrastructure’s ability to weather major disruptions, a top U.S. cyber official said Wednesday.
    • “Each and every one of us is operating right now on the front lines of a war that is never going to be cleared,” Nick Andersen, the acting director of the Cybersecurity and Infrastructure Security Agency (CISA), said at ICS Village and the Institute for Security and Technology’s Critical Effect conference.
    • “We are going to see an adversarial disruption of our critical infrastructure,” Andersen said. “It’s going to have significant not just technical impact, it’s going to have a significant psychological impact on the safety of the American people. … We need to start operating like that’s the reality of where we’re at — that we’re not going to be able to keep everything persistently online and available as much as we would like.”
    • “CISA’s emphasis on resilience marks a shift from earlier government cybersecurity doctrines that focused on preventing intrusions. In recent years, advanced nation-state hacking campaigns — especially Beijing’s Volt Typhoon espionage operation — have increasingly convinced government and industry strategists that their primary goal should be ensuring that infrastructure can continue operating during an attack.”
  • Federal News Network adds,
    • “A new White House memo aims to strengthen the cybersecurity of sensitive government systems by centralizing oversight of those systems, while also setting aggressive deadlines for updating incident response procedures and other policies.
    • “In a national security presidential memorandum signed out Friday, President Donald Trump re-establishes and updates the Committee on National Security Systems (CNSS), a decades-old interagency body that sets security policies for military and intelligence systems, as well as systems that process classified information. It charges the committee with leading a policy aimed at fostering “a proactive, adaptive, and resilient cybersecurity ecosystem for all NSS to better safeguard the nation against persistent cyber threats from sophisticated adversaries.”
    • “The memo gives the committee the power to establish “baseline cybersecurity requirements” for all national security systems. It formalizes the director of the National Security Agency’s role as the “national manager” for national security systems. That role involves identifying emerging threats and providing minimum security protections, including through emergency directives.
    • “The memo includes the federal chief information officer on the reconstituted CNSS body, along with the deputy national manager at the NSA and the CIOs at the Defense Department and the intelligence community, respectively.
    • “It also mandates that national security systems should meet or exceed the level of cybersecurity standards issued by the National Institute of Standards and Technology.”
  • Cyberscoop relates,
    • “Authorities on Thursday [June 18] disrupted a botnet, a malware framework and seized infrastructure that Evil Corp and other cybercrime groups used to steal data and break into various networks.
    • “The globally coordinated effort targeted SocGholish, multi-stage malware that has compromised websites, redirected users to traffic distribution systems (TDS) and slipped malware into their networks since 2017.
    • “The malware establishes an initial foothold into victim computers, collectively known as a botnet, and is then used by threat actors for further targeting with ransomware campaigns and espionage,” the FBI’s cyber division said in a statement. 
    • “Cybersecurity firms, researchers and officials from the United States, Canada, Germany, the Netherlands and Europol took down 106 servers and remediated nearly 15,000 sites that were infected with the malware. Officials also disabled the botnet and notified victims.
    • “Sites infected with SocGholish, which are primarily hosted on WordPress, were widespread and provided everyday services including restaurants and auto repair shops, according to the Dutch National Police
    • “The botnet, also known as “FakeUpdates,” is linked to the Russian cybercrime group Evil Corp. It also provided initial access to other ransomware variants, including DoppelPaymer, WastedLoocker, Hades Ransomware, LockBit, RansomHub and others, according to Infoblox, which participated in the takedown.” 
  • Per an HHS news release,
    • “The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) today announced a settlement with Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans (the Plan), the employer-sponsored group health plan of Spencer Gifts LLC, a national retail company, over potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules.” * * *
    • “The settlement resolves an investigation that OCR initiated after the Plan filed a breach report on January 24, 2022. The Plan had received employee complaints that employees were unable to connect to the virtual private network. The Plan discovered that in November 2021, an unauthorized actor accessed the company’s network and deployed ransomware, encrypting data on the company’s systems, including servers storing the Plan’s PHI, and demanding a ransom. The PHI of 10,023 individuals was potentially affected by the breach, including health plan members’ names, addresses, zip codes, phone numbers, email addresses, and Social Security numbers.” * * *
    • “The resolution agreement and corrective action plan can be found at: https://www.hhs.gov/sites/default/files/ocr-ra-cap-spencer.pdf [PDF, 654 KB].”
  • Security Week tells us,
    • “A Ukrainian national pleaded guilty in a US court to his role in the notorious Conti ransomware group, the Department of Justice announced.
    • “The man, Oleksii Oleksiyovych Lytvynenko, 44, of Cork, Ireland, was arrested in Ireland in 2023 and was extradited to the US in October 2025 to face Conti-related charges.
    • “Lytvynenko admitted in court to joining the Conti operation in September 2021 and working on the development of a malware loader for the group. He also admitted to possessing data from 12 victims, including eight in the US.
    • “Authorities in the US believe that the Ukrainian national continued to engage in cybercriminal activities after the Conti operation shut down.
    • “Lytvynenko pleaded guilty to wire fraud conspiracy and faces up to 20 years in prison. He is scheduled for sentencing on September 10, 2026.
    • “One of the most prolific ransomware groups half a decade ago, Conti was used in attacks against over 1,000 organizations in the US and abroad between 2020 and 2022.”

From the cybersecurity breaches and vulnerabilities front,

  • Tech Target identifies the largest healthcare data breaches so far reported to HHS OCR this year.
  • Dark Reading reports,
    • “A recent — and likely massive — breach at Novo Nordisk, where attackers reportedly gained an initial foothold using a single GitHub access token, underscores how code repositories and developer environments have become ground zero for attackers seeking intellectual property, credentials, and software supply chain assets.
    • “Novo Nordisk, the Danish pharmaceutical giant behind blockbuster drugs Ozempic and Wegovy, disclosed the breach June 11 after detecting unauthorized access to what it claimed were a “limited number of its internal IT systems.” 
  • Bleeping Computer relates on June 19,
    • “The Texas Parks and Wildlife Department (TPWD) disclosed a data breach at its license system vendor that exposed personal information for more than three million individuals.
    • “The Texas Cyber Command discovered the intrusion and launched an investigation to determine the extent and impact of the unauthorized access. The state authority found that Social Security Numbers (SSNs), dates of birth, or any financial information, such as credit cards, have not been impacted.
    • “However, the threat actor may have obtained personally identifiable information that includes the data types [identified in the article] associated with 3,087,721 Texas hunting and fishing license customers,
  • and
    • “The U.S. Cybersecurity and Infrastructure Security Agency (CISA) urged Fortinet customers to secure their devices after nearly 74,000 firewall and VPN credentials were exposed in a data leak dubbed “FortiBleed.”
    • “This warning comes after threat actors used compromised credentials to target internet-accessible Fortinet devices across government and private-sector organizations worldwide.
    • “CISA is aware of global reports that malicious cyber actors have targeted internet-accessible Fortinet devices across government and private sector organizations using compromised credentials,” it said.
    • “This activity, referred to as FortiBleed, involves the exposure of leaked credentials associated with approximately 74,000 Fortinet devices, including firewalls and virtual private network (VPN) gateways.”
    • ‘The agency called on affected FortiGate appliance owners to terminate all SSL VPN and administrative sessions, reset all VPN and administrative passwords, enable phishing-resistant multifactor authentication, and review logs for signs of unauthorized access or lateral movement.
    • “CISA also advised Fortinet customers to store admin credentials using the modern Password-Based Key Derivation Function 2 (PBKDF2) hashing algorithm, and to restrict firewall management interfaces from public internet access and remove any unauthorized accounts to reduce the attack surface as much as possible.”
  • CISA added four known exploited vulnerabilities to its catalog this week.
    • June 15, 2026
      • CVE-2026-20262 Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability
      • CVE-2026-54420 LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
        • Security Affairs discusses these KVE here.
    • June 16, 2026
      • CVE-2026-48907 Widget Factory Joomla Content Editor Improper Access Control Vulnerability
        • Bleeping Computer discusses this “patch by Sunday June 21” KVE here.
    • June 18, 2026
      • CVE-2026-20253 Splunk Enterprise Missing Authentication for Critical Function Vulnerability
        • Bleeping Computer discusses this “patch by Sunday June 21” KVE here.
  • Security Week informs us,
    • Microsoft on Wednesday published an advisory acknowledging the public disclosure of a vulnerability in Defender that could lead to privilege escalation.
    • The security defect, now tracked as CVE-2026-50656 (CVSS score of 7.8), was dropped last week by security researcher Nightmare Eclipse (also known as Chaotic Eclipse).
    • “Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as ‘RoguePlanet’,” the tech giant’s advisory reads.
    • “We are working to provide a high-quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available,” Microsoft adds.
    • RoguePlanet, Nightmare Eclipse explained last week, targets a race condition in Microsoft Defender and allows attackers to gain System privileges.
    • The researcher released a proof-of-concept (PoC) exploit that demonstrates local privilege escalation (LPE) on Windows 11 and Windows 10 systems with the June 2026 patches installed.
  • and
    • “Cybersecurity firms Huntress and Recorded Future have disclosed the impact of a supply chain attack that hit market intelligence platform Klue.
    • “The attack started on June 11 and affected systems associated with software platform integrations. The hackers connected to Klue’s backend servers and executed unauthorized commands, pushing a code update to harvest OAuth tokens for customers’ Klue integrations.
    • “Klue notified customers of the incident on June 12, warning that it had deactivated OAuth tokens for all customers and disabled integrations with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack.
    • According to ReliaQuest, the hackers abused the Salesforce REST API to exfiltrate large volumes of customer relationship management (CRM) data over a 24-hour window, “including a concentrated burst of nearly a thousand queries in 15 minutes and sustained extraction windows lasting over 6 hours”. * * *
    • “On Thursday [June 18], both Huntress and Recorded Future confirmed that they were among the companies affected by the supply chain attack.”
  • The Wall Street Journal reports,
    • “Millions of digital home devices in the U.S. have pre-installed backdoor software, creating residential proxy networks used by nation-state hackers to mask cyberattacks.
    • “Government agencies from nine countries warned that Chinese state-sponsored hackers use these networks to conduct operations, making attribution challenging.
    • “Midnight Blizzard, a Russian hacking group that broke into Microsoft, used residential proxy networks to steal Microsoft 365 credentials by logging in from U.S. home networks.” * * *
    • “This is a bigger problem because of the sheer numbers,” said Noopur Davis, Comcast’s head of information security. It is one of the most worrying problems the telecommunications company has seen, she said.
    • “[This story explains how to protect yourself from a sneaky back door that can let hackers into your home.]”

From the ransomware front,

  • Industrial Cyber reports,
    • “CYFIRMA reported that healthcare organizations are facing an increasingly hostile cyber threat environment, with ransomware emerging as the sector’s most significant risk. Over the past 90 days, healthcare accounted for 216 verified ransomware victims, representing 9.05% of ransomware victims globally and ranking the sector third among 14 industries. The report found that ransomware attacks against healthcare increased 8.5% quarter over quarter, with April alone recording 90 victims, well above the sector’s previous six-month average. 
    • “In a new report, CYFIRMA identified healthcare victims in 42 countries, up from 33 in the prior period, while 50 of 81 active ransomware gangs targeted healthcare organizations, highlighting broad criminal interest in hospitals, pharmaceutical firms, and specialized medicine providers. The report also warned that nation-state activity and supply chain risks are compounding the threat landscape. Healthcare organizations appeared in 10 of 33 observed advanced persistent threat (APT) campaigns, up from three of 19 campaigns in the previous reporting period. North Korea-linked Lazarus Group led observed activity, while Russia-, China-, and Iran-linked actors also targeted the sector. 
    • “The researchers further noted that web applications, operating systems, web portals, and access management platforms remain key targets as attackers pursue credential theft and patient data. The company further identified supply chain concentration as a defining structural risk, warning that breaches involving specialized healthcare IT providers can cascade across multiple hospitals and healthcare networks simultaneously, amplifying operational disruption and cyber exposure.” 
  • Security Week relates,
    • “Commercial printing and imaging technologies company Kodak has confirmed suffering a data breach after the ShinyHunters cybercrime group claimed to have stolen information from its systems. 
    • “Kodak was named on the ShinyHunters website on June 15, with the hackers claiming to have obtained more than 2.2 million records of customer personal information and other corporate data. 
    • “The hackers threatened to leak the stolen data on June 18 unless the company pays a ransom.
    • Contacted by SecurityWeek, Kodak said it’s conducting an investigation with the aid of external cybersecurity experts and promised to share additional information “as appropriate”.
    • “Kodak recently discovered that an unauthorized third party illegally gained access to a limited amount of company data,” said a spokesperson for Kodak.
    • “Although our investigation is ongoing, we are confident the incident was limited in scope and has been contained and that there is no threat to our systems or operations as a result of the incident,” the spokesperson added. “We have also notified law enforcement and are continuing to support their investigation.”
  • Dark Reading tells us,
    • “INC is a ransomware group that has excelled in the ransomware-as-a-service (RaaS) space through doing the basics effectively — alongside a bit of good timing.
    • “Researchers with security vendor Acronis today published a blog post covering RaaS gang INC, a group that emerged in 2023 and has claimed more than 800 victims to date. INC is a ransomware actor that greatly benefited from the shutdown of ALPHV/BlackCat and the disruption of LockBit; this is an attribute shared with other ascendant gangs, such as The Gentlemen.”
    • “And according to the Acronis Threat Research Unit (TRU), the group is one of the most active of its kind right now. On the surface, INC doesn’t stand out so much. It’s a double extortion ransomware actor (meaning it uses encryptionand data leaking to get victims to pay up), drawing victims from manufacturing, legal services, healthcare, technology, construction, and educational sectors, among others. The group appears to have a certain preference for organizations with especially sensitive data to add extra extortion pressure.” 
       
  • Bleeping Computer adds,
    • “The Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks.
    • “The gang employs a collection of EDR-killing tools, most notably a utility that researchers dubbed GentleKiller. The tool has at least eight variants and impersonates various legitimate security products, including Kaspersky, Valorant, Javelin, and WatchDog.
    • “The gang is using a suite of EDR killers, the most frequently used being a custom tool that researchers named GentleKiller, which has at least eight variants impersonating various legitimate products.
    • The Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks.
    • “An EDR killer is typically used to disable defenses in the early phases of an attack, and in ransomware incidents, they ensure that data theft or encryption processes run unencumbered.
    • “These tools work by leveraging the ‘bring your own vulnerable driver’ (BYOVD) technique to elevate privileges and disable security engines.”
  • and
    • “DragonForce ransomware used a custom malware named ‘Backdoor.Turn’ to hide command-and-control traffic inside Microsoft Teams relay infrastructure.
    • “The backdoor abuses the Traversal Using Relays around NAT (TURN) protocol used by Microsoft Teams to distribute messages when a direct connection to the client is unavailable (e.g., clients on a private network).
    • “DragonForce is a ransomware operation active since at least 2023, that adopted a cartel-style organizational structure and has been linked to the infamous Scattered Spider threat group.

From the cybersecurity business and defenses front,

  • Cyberscoop reports,
    • “Accenture announced Thursday it would acquire a majority stake in industrial cybersecurity firm Dragos for $3.25 billion and purchase two smaller security companies outright, essentially making a $4.18 billion bet that defending the IT networks of power grids, pipelines, factories and critical infrastructure sectors will become one of the defining challenges of the AI era.
    • “The deals — which also include two Austin, Texas-based companies, runZero and NetRise —  represent a significant strategic pivot for Accenture toward operational technology (OT) security,  a segment of the cybersecurity market that has long been underfunded relative to traditional IT defenses. The announcement comes as the consulting giant faces pressure on its core business from the same AI tools reshaping the threat environment it is now moving to address.”
  • HIPAA Journal adds,
    • “Compliancy Group has acquired Healthicity in a deal that combines two healthcare compliance software companies and expands Compliancy Group’s platform to include healthcare compliance, workforce compliance, risk assessment, third-party risk management, incident management, provider auditing, coding auditing, and documentation auditing.
    • “The acquisition was announced on June 17, 2026. Financial terms of the transaction were not disclosed. Compliancy Group said the combined organization will serve more than 3,000 healthcare organizations across the United States and selected global markets.”
  • Dark Reading advises,
    • “Get Out of Security Debt by Tackling the Exposure Problem.
      • “Teams digging out of security debt need to answer only two simple questions: Which vulnerabilities in our systems are exposed, and how long should they stay that way?”
  • Tech Target adds,
    • “It’s time to update incident response for the AI era”
    • “Your latest cybersecurity incident might not be a threat actor, but an internal AI agent doing what it’s authorized to do. Incident response must evolve to accommodate AI.”
  • ZDNet offers
    • “10 signs that someone is monitoring or accessing your accounts – how to stop them
      • “Learn how to spot the signs of account monitoring and compromise – and take back control.”
  • and
    • “5 steps to ensure HIPAA compliance on mobile devices
      • “HIPAA compliance on mobile devices depends on governing access to PHI across both managed and personal endpoints. Here are five steps to achieving compliance in clinical settings.”
  • Security Week lets us know about
    • “AI and Cybersecurity – Everything You Wanted to Know, But Were Afraid to Ask
      • “From defending networks to enabling attacks, artificial intelligence is changing every aspect of cybersecurity. Here’s what dozens of experts say security leaders need to understand now.”
  • Here’s a link to Dark Readings’s CISO Corner.

Thursday report

Simplicity is a virtue.

In recognition of Juneteenth, a Friday report will not be posted tomorrow. The FEHBlog will return on Saturday with the latest Cybersecurity Saturday post.

From Washington, DC.

  • Healthcare Dive reports,
    • The CMS is recalculating 2026 Medicare Advantage stars for insurers after the agency lost a court case over its methodology.
    • Only plans that see their stars increase will have their ratings updated and be able to resubmit bids for next year, regulators said in a memo to plans Wednesday. It could be a major boon for insurers, given the stars are linked to lucrative bonuses and competitive advantages in the privatized Medicare program.
    • Still, the recalculation basically results in no change in average star ratings for other insurers besides Clover Health, which brought the lawsuit against the CMS, according to TD Cowen analysts. Some insurers may choose to sue over the approach.
  • STAT News relates,
    • “Making good on its threat, Eli Lilly has begun eliminating mandated price breaks to a few dozen hospitals that participate in a federal drug discount program after failing to receive comprehensive claims data.
    • “The move comes after the company warned earlier this month it would take such a step as part of a policy announced in January in order to reduce what it calls duplicate discounts paid to the hospitals. Trade groups representing hospitals, however, argue the move is unlawful and want Congress to intervene.
    • “At the time, Lilly maintained that more than 2,300 hospitals had complied with its demand, but some larger hospitals systems around the U.S. refused to do so, despite recent follow-up letters regarding the policy, which went into effect Feb. 1. Up to 1,000 had so far not complied, and Lilly indicated it was pressing about 50 larger hospitals to provide data.
    • “A Lilly spokesperson declined to say how many hospitals are now being denied the mandated discounts but sent us a statement saying, “Lilly is collecting claims data to stop the rampant fraud, waste, and abuse in the 340B program that is harming employers, state and federal governments, and patients.”
  • The American Hospital Association News tells us,
    • “The Health Resources and Services Administration Maternal and Child Health Bureau has announced grant opportunities available supporting maternal and child health initiatives. The Maternal Produce Prescription Program, or MP3, will provide grants for the development and implementation of community-based produce prescription programs and related nutrition education for maternal populations at risk of poor health outcomes due to nutrition insecurity and other health-related factors. Grants are also available for the Regional Pediatric Prevention Network, which will provide funding to hospitals working on advancing pediatric emergency and disaster preparedness locally, regionally and nationally, including for children with special healthcare needs and behavioral health concerns, children living in poverty, and children in rural, remote and tribal areas. The network will include at least 10 children’s hospitals, or their university pediatric partners, as well as community partners. The application deadline is July 17 for the MP3 and RPPN programs. 
    • “Funding is also available for the Maternal Health Emergency Management Training program, which seeks to increase capacity and improve the quality of care provided by clinicians and first responders who encounter pregnant and postpartum women in nondelivery and/or low-resource clinical settings. The deadline to apply for the MHEMT program is July 20.” 
  • Federal News Network inteviews Tammy Flanagan about the Federal Employees Group Life Insurance Program.
  • JAMA discusses original research concerning the Inflation Reduction Act.
    • Question  How did prescription drug use change after the Inflation Reduction Act implemented annual out-of-pocket spending caps in Medicare starting in 2024?
    • Findings  In this cohort study using a difference-in-differences framework of 3053 medications covering 92.9% of gross Medicare Part D spending in 2023, prescriptions for medications paid by Medicare increased after the out-of-pocket cap was implemented in 2024 compared with those paid by commercial insurance; this change was most pronounced among the highest-cost medications, with a 22.7% increase in 2024-2025.
    • Meaning  Results of this study suggest that implementing annual out-of-pocket caps in Medicare was associated with higher use of medications and that the policy improved Medicare-insured patients’ access to costly medications.”
  • Fierce Pharma notes,
    • “Before Indian drugmaker Aurobindo can complete its acquisition of Pennsylvania generics specialist Lannet, it will have to divest four drugs from the proposed $250 million buyout to resolve anticompetitive concerns, the Federal Trade Commission said.
    • “Aurobindo’s acquisition of Lannett would combine two of a limited number of competitors in the markets for four different generic pharmaceutical products that provide critical relief for patients,” the FTC wrote of its proposed consent order (PDF).
    • “The U.S. regulator has specified that Aurobindo must sell the products to New Jersey generics maker Quagen Pharmaceuticals.”

From the Food and Drug Administration front,

  • The Wall Street Journal reports,
    • “A Food and Drug Administration advisory committee voted that the benefits of a seasonal flu vaccine from Moderna MRNA outweigh its risks, part of the agency’s review of a potential new treatment.
    • “Moderna said Thursday the FDA’s Vaccines and Related Biological Products Advisory Committee voted unanimously that the benefits of the vaccine, mRNA-1010, exceed the risks for the prevention of flu in adults 50 through 64 years old, and in adults 65 years of age and older.
    • “The FDA plans to consider the committee’s recommendations as part of its ongoing review of Moderna’s biologics license application for mRNA-1010, the company said. Advisory committee recommendations are nonbinding, and the FDA is responsible for making final approval.”
  • Fierce Pharma relates,
    • “With FDA acceptance of its application, Roche has moved a step closer to gaining a thumbs up for its potential combination treatment of Polivy and subcutaneous Lunsumiofor adults with relapsed or refractory large B-cell lymphoma (LBCL), including diffuse large B-cell lymphoma (DLBCL), after at least one prior line of systemic therapy.
    • “The U.S. regulator says it’s aiming to decide whether to approve the application by Feb. 9, 2027.
    • “The application is backed by results from a phase 3 study, which showed that after a median follow-up of 23 months, the Lunsumio and Polivy combination demonstrated a 59% reduction in risk of disease progression or death compared to Rituxan plus the chemotherapies gemcitabine and oxaliplatin.”
  • Per an HHS news release,
    • “The U.S. Department of Health and Human Services, through the U.S. Food and Drug Administration (FDA), announced today that it is requesting updates to the prescribing information for testosterone replacement therapy products following a comprehensive review of new clinical data and existing scientific evidence.
    • “The proposed changes would:
      • “Remove the limitation of use stating that the safety and effectiveness of testosterone replacement therapy in men with age-related hypogonadism have not been established.
      • “Update information related to prostate cancer risk.
      • “Revise warnings regarding benign prostatic hyperplasia, also known as enlarged prostate.
    • “During Men’s Health Month, we are putting science back at the center of men’s healthcare,” said HHS Secretary Robert F. Kennedy, Jr. “By updating testosterone therapy labels to reflect current evidence, we are giving patients and physicians clearer information, supporting informed medical decisions, and improving care for millions of American men.”
  • Cardiovascular Business informs us,
    • “More than 11,000 bottles of a popular blood pressure medication have been recalled due to a failed test. The voluntary recall was initiated on June 5, according to key details provided by the U.S. Food and Drug Administration (FDA).
    • “This recall includes 11,460 bottles of Chlorthalidone Tablets manufactured by India-based Inventia Healthcare Limitedand distributed by New Jersey-based Rising Pharma Holdings. Chlorthalidone is a diuretic or “water pill” used to treat hypertension and reduce excess fluid caused by heart, kidney or liver disease. 
    • “These drugs have been recalled due to “failed dissolution specifications.” This means tablets tested by a regulatory body did not break down correctly, creating a risk of the drug being less effective than intended.
    • “The recalled bottles include either 100 or 1,000 of these tablets. They all have an expiration date of April 2027.
    • “Click here for additional details about this recall from the FDA. The incident has not yet been classified as a Class I or II recall.”

From the judicial front,

  • Healthcare Dive reports,
    • “Pharmacy benefit managers want to make sure that an Illinois law creating drug pricing transparency and reforming health benefits administration doesn’t apply to them.
    • “On Tuesday, powerful PBM lobby the Pharmaceutical Care Management Association filed a complaint in federal court against the Illinois Department of Insurance, arguing that the Prescription Drug Affordability Act signed into law last summer clashes with federal oversight of employee benefit plans and that PBMs should be carved out from its provisions.”
  • Beckers Hospital Review relates,
    • “A federal judge has denied The Leapfrog Group’s attempt to reverse a ruling that found its hospital safety grades violated Florida consumer protection law, and separately put a $10.5 million fee dispute on hold, pending appeal.
    • “On June 17, U.S. District Judge Donald Middlebrooks rejected Leapfrog’s motion to reconsider his March 6 ruling, which found the organization violated Florida’s Deceptive and Unfair Trade Practices Act by penalizing hospitals that declined to participate in its voluntary survey with artificially low safety grades.”
  • The Wall Street Journal informs us,
    • “Luigi Mangione’s defense team said Thursday they no longer intended to present a psychiatric defense at his coming New York state-court murder trial, abruptly reversing course after a judge made public the unusual strategy a day earlier.
    • ‘In a single-sentence letter to the presiding judge, the lawyers wrote that, at this time, they were withdrawing a defense in which Mangione would have argued he killed UnitedHealthcare Chief Executive Brian Thompson due to an emotional disturbance.
    • “Mangione’s defense team and a spokesman for the Manhattan district attorney’s office declined to comment.”

From the public health and medical / Rx research front,

  • STAT News reports,
    • “While infant formula in the U.S. has a good overall safety record, the stakes are incredibly high if something goes wrong. Food safety experts who spoke with STAT say they want regulators and the industry to take even stronger measures to prevent disease outbreaks that put babies’ lives at risk. And they want consumers to be wary of marketing from newer, high-end formula companies like ByHeart and Nara that position their products as safer than other options.
    • “I think a lot of parents can be confused and think that if they spend more money on a formula, it’s safer,” said Steven Abrams, a professor of pediatrics at Dell Medical School at the University of Texas at Austin. In fact, formulas are remarkably similar to one another because they’re required to use a blend of 30 ingredients necessary to give babies the nutrition they need. All formulas are also subject to annual FDA inspections and requirements to test for the pathogens salmonella and Cronobacter.
    • “Of designations like organic, GMO-free, or added probiotics and prebiotics, Abrams said, there’s no evidence that such features “have the slightest health effect on babies.”
    • “Nara and ByHeart were both manufacturers “claiming to produce a healthier type of infant formula because they were using whole milk,” said Frank Yiannas, a former deputy commissioner for food policy and response at the FDA. The fact that both brands have been linked with infant botulism, he said, suggests that “reformulating powdered infant formula should be done with extreme due diligence and caution.”
  • and
    • “If you’re an older adult, getting vaccinated against shingles could lower your risk of developing dementia.
    • “A new study found that elderly nursing home residents who received at least one dose of the shingles vaccine known as Shingrix, the only shot of its kind available in the United States, were 24 percent less likely to develop dementia over a four-year period compared to those who were not vaccinated, according to results published this week in the peer-reviewed journal Annals of Internal Medicine.
    • The research adds to the growing body of evidence showing a connection between the viral infection and cognitive decline.
    • “The fact that this is a super high-risk population for dementia and we’re still seeing a potential benefit is really remarkable and important evidence for this population,” said Kaleen Hayes, the study’s lead author and an assistant professor at Brown University who studies the use of medications for chronic conditions in older adults.”
  • and
    • “Fentanyl is by far the biggest opioid killer in the U.S. With more than a quarter of a million deaths since 2021 and about 200 fatalities a day, fentanyl is one of the country’s most urgent public health crises. But drug experts warn that nitazenes can be even more potent and are being mixed with fentanyl and other substances, creating increasingly lethal combinations.
    • “We’re always concerned about fentanyl being mixed in with other drugs — cocaine, meth, heroin,” said Frank Tarentino, associate chief of operations for the DEA’s northeast region. “You add nitazenes to that and it makes it exponentially more dangerous and frightening for drug law enforcement, parents, caregivers, educators, and the young.”
    • “Data obtained from the DEA’s National Forensic Laboratory Information System (NFLIS) show reports of confirmed seizures from nitazenes rising sharply — from 43 positive tests in 2019 to almost 2,000 in 2024 (the most recent year for which data are available). By March this year, more than 8,000 nitazene reports had been recorded since 2019. But experts said that not all laboratories can test for nitazenes — which come in many forms including powders, pills, and sprays — and many don’t feed into the NFLIS system, meaning these numbers are almost certainly an underestimate.” * * *
    • “Nitazenes are predominantly sold online, both on the clear web and dark web, and are often laced into other substances to increase their potency. Experts say this puts unsuspecting users seeking more common drugs, such as oxycodone, fentanyl, or stimulants like cocaine, at risk of fatal overdoses.”
  • The Washington Post tells us “7 unexpected takeaways from the newest research on cannabis and brain effects.”
    • “Whether it’s used in adolescence, midlife or older age may make a big difference.”
  • The American Medical Association lets us know “What doctors want patients to know about summer skin safety.”
    • “Too much sun exposure can have damaging effects on skin, but following proper precautions can help. Follow these summer sun safety tips.”
  • Health Day points out,
    • “Pregnant women are exposed to dozens of common chemicals linked to early delivery and low birth weight, according to a new study.
    • “Researchers tested urine samples from more than 5,000 women who gave birth between 2000 and 2021, and compared the findings with pregnancy outcomes.
    • “They screened for 113 chemicals commonly found in food, water, air pollution, personal care products, fragrances and other household items.
    • “On average, the tests detected 45 chemicals in each sample, with as many as 64 found in some participants.
    • “Among them were phthalates used to make plastics more flexible, as well as some newer plasticizers.
    • “Some of these compounds were consistently associated with earlier delivery and lower birth weight, according to the results.” * * *
    • “The researchers are calling on governments and companies to do more to reduce harmful chemicals in everyday products and ensure new ones are safe.”
  • MedPage Today informs us,
    • “In a cohort study, U.S. women logging at least 2 hours a week of resistance training had a 20% lower risk of incident major cardiovascular disease (CVD) over nearly 15 years.
    • “The benefit of resistance training persisted even if women also engaged in aerobic activity and limited sedentary time.
    • “A lower risk of major CVD could also be observed in those who reached ≥1 hour of weekly resistance training and were consistent about it over the years.”

From the U.S. healthcare business and artificial intelligence report,

  • The American Hospital Association News reports,
    • “Hospital and health system leaders gathered June 17 and 18 in Washington, D.C., for U.S. News & World Report’s Healthcare of Tomorrow Conference, focusing on the future of healthcare delivery. AHA Chair-elect Bill Gassen, president and CEO of Sanford Health in Sioux Falls, S.D., participated in a panel titled “Reimagining Healthcare: The Hospital and Health System of Tomorrow.” The session included discussion on challenges and opportunities shaping the future of hospitals and health systems, and involved topics such as artificial intelligence and digital transformation, care delivery models, community partnerships and sustainable financial performance.  
    • “When I think about the future of health care, I believe success will be defined by how well organizations can connect care across settings, specialties and communities to better serve patients,” said Gassen. “The organizations that will be best positioned for the future are those that can combine deep local relationships and community trust with the capabilities needed to deliver increasingly complex care, invest in innovation, develop the workforce and keep care accessible and affordable over the long term.” Former AHA Board Member Warner Thomas, president and CEO of Sutter Health, and Redonda Miller, M.D., president and CEO of The Johns Hopkins Hospital, also participated on the panel.” 
  • Kaufmann Hall relates,
    • The latest issue [April 2026] of the National Hospital Flash Report covers these and other key performance metrics.
    • Key Takeaways:
      • Hospital performance remains under pressure in 2026. Mixed performance on key volume indicators, staffing challenges, and expense growth continue to pressure hospital operations, reinforcing the need for focused prioritization and strategic planning.
      • Expense growth continues to outpace inflation. Drug and labor expense remains a key contributor to expense growth, driven by both cost and utilization as the population ages, underscoring the importance of strategic spend management across the board.
      • Payer mix continues to erode. Year-over-year climbs in bad debt and charity care reflect broader shifts in payer mix, shifts in coverage, and growth in uninsured populations, requiring hospitals to proactively adapt and manage long-term revenue risks.
    • To view more insights on trends affecting hospitals and steps you can consider taking to address them, download the latest issue of the National Hospital Flash Report.
  • Beckers Hospital Review ranks 81 health systems by annual revenue and identifies four hospital closures that have happened in 2026.
  • Bloomberg tells us,
    • Johnson & Johnson has no plans to enter the booming obesity market, opting instead to focus on diseases such as cancer, Chief Executive Officer Joaquin Duato said in an interview for an upcoming episode of The David Rubenstein Show: Peer to Peer Conversations.
    • “The comments set J&J apart from many of its rivals trying to develop or acquire obesity medicines following blockbuster weight-loss drugs from Eli Lilly & Co. and Novo Nordisk A/S.
  • Fierce Pharma informs us,
    • “What’s been Novo Nordisk’s secret weapon to turn the tables on Eli Lilly and win the current market battle over their oral GLP-1 obesity drugs? Name recognition.
    • “That’s according to Jim Hickey, an analyst with Spherix Global Insights, who has studied the competition by surveying 50 primary care physicians (PCPs) and 50 endocrinologists in the United States, as well as writing monthly reports on the uptake of the drugs, both of which debuted on the market earlier this year. 
    • “It’s interesting to see how strongly Novo Nordisk has come out of the gate,” Hickey said in an interview with Fierce. “It’s a very strong launch from what we can see. That lines up with the data Novo Nordisk has shared. I think a big difference between the two really comes down to familiarity. We see the familiarity ratings for the Wegovy pill as being much stronger than what we can see for Foundayo.”
  • Fierce Healthcare points out,
    • “Lantern and Marathon Health are joining forces to launch an integrated model that brings together primary and specialty care, a key concern for employers as costs rise.
    • “The partnership combines Marathon’s advanced primary care model with Lantern’s specialty care platform, simplifying the patient care journey, better managing costs and reducing unnecessary procedures. Marathon clients that do not currently work with Lantern can purchase its services through Marathon, making the process easier for employers, too.
    • “The two initially collaborated on a pilot program with early adopters, focused on orthopedic care, and found between a 37% and 100% increase in referrals to Lantern. Referrals from Marathon led to a 47% increase in either completed or averted surgical procedures, the companies said.”
  • Per BioPharma Dive,
    • “Biogen plans to buy startup RayThera to gain access to a portfolio of immunology drug candidates, including one slated to enter the clinic in the third quarter. 
    • “Founded in 2023, RayThera says its mission is to develop safer, more effective therapies for immunological diseases. But the company has said little publicly about what it’s doing. RayThera’s website doesn’t detail what it’s been working on, instead touting the company’s “nimble and adaptable approach” and containing a pipeline page with three prospects listed only as “anti-inflammatory.”
    • “The deal with Biogen is also rather opaque, per a statement released Wednesday. RayThera investors will get an undisclosed upfront payment and could reap as much as $1 billion if unspecified clinical and regulatory goals are met.”
  • and
    • “An emerging area of drug development got more crowded Wednesday, with the debut of a biotechnology startup trying to create new migraine prevention therapies.
    • “Vedana Therapeutics formed in response to an earlier class of migraine-thwarting medicines that first hit the market toward the end of the last decade. These medicines inhibit specific proteins, “CGRPs,” that play a key role in migraines by transmitting pain signals, widening blood vessels and triggering inflammation in the tissues around the brain. While effective for many, a large portion of patients — more than halfby some estimates — don’t respond to, or stop taking, CGRP-blocking therapies.”
  • McKinsey & Co. discusses “The health system CEO imperative: Turning AI’s promise into performance.”
  • The Wall Street Journal reports,
    • “The clash over AI doctors has begun, and its front line is in Utah.
    • “It started with technology from the startup Doctronic. The state launched a project in January that will allow the service to renew prescriptions for patients. The hope is it will improve medication access.
    • “Any Utah adult can log in to get a refill on cholesterol medications or antidepressants, among other prescriptions. When fully implemented, the project will break new ground by letting an artificial-intelligence product, acting on its own, perform this job typically done by physicians.
    • “Doctors aren’t happy about it.
    • “People can have life and death reactions to medications,” said Dr. Alan Smith, a family physician who chairs the Utah medical board but said he wasn’t speaking for the group. “And then I worry about liability. Who is actually liable for problems that may occur because of a refill of a medication?”
    • “Most of the state’s medical licensing board, including Smith, signed a letter calling for the project to be suspended on safety grounds. They said Doctronic’s tool hasn’t been vetted enough, and prescribing can create risks because drugs cause side effects or might not be appropriate to continue. The Utah Medical Association said it agreed with the letter.
    • “State officials overseeing the pilot program said that the medical board has no authority over the project but that they will consult with it.
    • “The debate over AI doctors extends far beyond Utah’s borders.” 

Cybersecurity Saturday

From the Project Glasswing front,

  • Tech Crunch reports,
    • “The U.S. government on Friday ordered Anthropic to immediately shut off access to two of its most powerful AI models — Claude Fable 5 and Claude Mythos 5 — citing national security concerns. Anthropic announced on X that it has complied, but it made clear it thinks the government got this one wrong.
    • “The directive, which Anthropic said it received on Friday [June 12] at 5:21 pm ET, forces the company to disable both models for all users worldwide — not just the foreign nationals the government’s export control order was nominally aimed at. Access to Anthropic’s other models isn’t affected.” * * *
    • “Fable 5, released just three days ago, was Anthropic’s answer to the obvious commercial pressure: a version of Mythos fitted with guardrails that block responses in high-risk areas like cybersecurity and biology, making it safe enough for general release, the company argued. It was immediately the most capable AI model available to the public, according to benchmark tests from Vals AI, a company that tracks AI tech performance.” * * *
    • “Anthropic is widely expected to pursue an IPO this year and has staked much of its public identity on being the safety-conscious alternative to its rivals. The irony isn’t lost on observers that the very caution Anthropic displayed in restricting Mythos — which it promoted as a model so dangerous it couldn’t be released publicly — has now apparently attracted exactly the kind of government scrutiny that could disrupt its business most.”

From the cybersecurity policy and law enforcement front,

  • Federal News Network reminds us,
    • “The Cybersecurity and Infrastructure Security Agency is restarting public engagements on delayed cyber incident reporting rules that will likely cover tens of thousands of critical infrastructure organizations.
    • “The meetings come as CISA faces pressure to issue the final regulations quickly, while some lawmakers and industry groups also want the agency to amend the draft rules to be less broad and burdensome.
    • “Starting Monday, CISA will host a series of virtual town halls to get feedback on the draft regulations to implement the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). The meetings will run through Wednesday.”
  • Cyberscoop reports,
    • “The Cybersecurity and Infrastructure Security Agency on Wednesday [June 10] ordered federal agencies to prioritize vulnerabilities based on four criteria, as part of push to “patch smarter, not harder.”
    • “Federal agencies should emphasize patches for vulnerabilities that affect a publicly exposed asset, allow an attacker to fully automate exploitation, give attackers the ability to take over control of a system or relate to evidence of active, real-world exploitation, CISA declared.
    • “CISA acting director Nick Andersen previewed the binding operational directive (BOD) Tuesday [June 9], framing it as a rethinking of vulnerability management more broadly.” * * *
    • BOD 26-04 sets forth timelines for how quickly agencies must fix a vulnerability based on how many of the four criteria it meets. If it meets all four, for example, agencies need to fix it within three days and carry out a “forensic triage” to assess whether their systems were compromised. 
    • “More generally, agencies must immediately update their vulnerability management policies, including establishing a process for ongoing remediation of known, exploited vulnerabilities (KEVs) on CISA’s “must-patch” list. Within 60 days, agencies need to update their processes for remediating common vulnerabilities, and within 180 days, agencies must meet the order’s remediation timelines.
    • “The directive is motivated in part by how artificial intelligence is shifting the window from vulnerability discovery to weaponization, and CISA said it reflects priorities in an executive order on AI that President Donald Trump signed last week.”
  • and
    • “The FBI, along with Google and Lumen Technologies, took down a major cybercrime network based in China that was responsible for an estimated $1.9 billion in losses, officials said Friday. 
    • “Outsider, which provided phishing kits and hosted infrastructure for cybercriminals since July 2023, facilitated a wave of phishing attacks against people and businesses in 55 countries, including the United States, the FBI said in a LinkedIn post.
    • “The jointly coordinated effort dubbed “Operation Ghost Hook” netted the seizure of several domains of the group’s core admin servers, a Shopify storefront, roughly $100,000 from Outsider payment wallets and thousands of domains registered through U.S.-based providers, officials said.
    • “The FBI said it also used an Outsider Telegram bot to access information on the cybercrime network’s customers.”
  • and
    • “A longtime former member of Conti, a ransomware group that attacked more than 1,000 organizations globally before it disbanded in 2022, pleaded guilty to participating in some of those attacks in federal court Wednesday [June 10], the Justice Department said.
    • “Oleksii Oleksiyovych Lytvynenko, also known as Alexsey Alexseevich Litvinenko, admitted he joined the prolific cybercrime group in September 2021 and held data on 12 victims, including eight based in the United States. The 44-year-old told the court he developed malware that Conti used in some of its attacks, according to officials.” 
  • Bleeping Computer adds,
    • “Law enforcement has dismantled the “AudiA6” cryptocurrency service allegedly used by ransomware actors and other cybercriminals to launder more than $380 million.
    • “Europol says that the service has been linked to more than 15 distinct international investigations of ransomware attacks.
    • “It is believed that the platform acted as a central money laundering hub between 2022 and 2025.”

From the cybersecurity breaches and vulnerabilities front,

  • Bleeping Computer reports,
    • “Danish pharmaceutical giant Novo Nordisk, the world’s largest producer of insulin, disclosed a data breach affecting patient information from some clinical trials.
    • “Founded in 1923, Novo Nordisk now employs around 67,900 people across 80 offices worldwide and is the maker of viral GLP-1 receptor agonist drugs Wegovy and Ozempic.
    • “The company revealed on Thursday [June 11] that attackers gained access to its internal IT systems and data related to patients participating in some clinical trials, including their patient IDs (random alphanumeric strings) and information on trial participation, sex, year of birth, biomarkers, health/immunogenicity data, and lifestyle factors (e.g., smoking, alcohol use, BMI).
    • “However, Novo Nordisk said that this data was pseudonymized and that the attackers can’t use it to identify any affected patients by name.
    • “While our investigation and response are ongoing, we have discovered that certain non-public data, including personal data, was copied externally without authorisation. We are informing the impacted parties as appropriate,” the company said.”
  • HIPAA Journal tells us,
    • “Episource, a provider of medical coding, risk adjustment services, and software solutions, experienced a cyberattack in early 2025, in which files containing patient data were exfiltrated from its network. In June 2025, the forensic investigation had progressed, and it was confirmed that 5.4 million individuals had been affected.
    • “The investigation has since revealed the data breach was more extensive, involving unauthorized access to the electronic protected health information of 6,725,572 individuals, according to updated figures provided to the HHS’ Office for Civil Rights. With more than 6.7 million affected individuals, the data breach currently ranks as the third-largest healthcare data breach of 2025, behind the 13.9 million-record data breach at Aflac and the 62.2 million-record data breach at Conduent Business Services, and ranks as the 16th-largest healthcare data breach of all time. The threat group behind the incident remains unknown.”
  • Industrial Cyber relates,
    • “Global cyberattack activity eased in May 2026 following April’s sharp rebound, but the broader threat landscape remained volatile, according to research from Check Point Research. Organizations experienced an average of 2,055 weekly cyberattacks during the month, representing a 2% increase year-over-year despite a 7% decline from April. Education remained the most targeted sector, averaging 4,641 weekly attacks per organization, while government and telecommunications also continued to face elevated attack volumes. 
    • “The report noted notable year-over-year increases in attacks targeting agriculture, hospitality, travel, recreation, and construction sectors as digitalization expands across these industries. The most significant trend was a sharp rise in ransomware activity. Check Point recorded 698 ransomware attacks globally in May, a 48% increase compared to the same month last year and the highest year-over-year growth rate recorded in 2026. Business services accounted for 35% of all ransomware victims, while consumer goods and industrial manufacturing also experienced substantial increases. 
    • “The report found that ransomware activity has become increasingly fragmented, with 61 active groups operating during the month. Qilin emerged as the most active ransomware group, responsible for 14% of published attacks, followed by The Gentlemen and DragonForce.”
  • Dark Reading adds,
    • “Phishing attacks are down across most industries, yet researchers argue the phishing threat is higher today than ever, as the fewer attacks that are perpetrated are becoming more dangerous.
    • “In its 2026 annual phishing report, Zscaler researchers framed the trend not as a drop but as a “rebalancing” — threat actors moving from wide spray-and-pray campaigns to more focused attacks with higher conversion rates.”
  • CISA added seven known exploited vulnerabilities to its catalog this week.
    • June 8, 2026
      • CVE-2026-42271 BerriAI LiteLLM Command Injection Vulnerability
      • CVE-2026-50751 Check Point Security Gateway Improper Authentication Vulnerability
        • Infosec discusses the BerriAI KVE here.
        • Cybersecurity Dive discusses the Check Point KVE here.
    • June 9, 2026
      • CVE-2026-7473 Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
      • CVE-2026-11645 Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
      • CVE-2026-20245 Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
        • Scorifya discusses the Arista KVE here.
        • Cybersecurity News discusses the Google KVE here.
        • Cybersecurity Dive discusses the Cisco KVE here.
    • June 11, 2026
      • CVE-2026-10520. Ivanti Sentry OS Command Injection Vulnerability
        • Dark Reading discusses this KVE here.
    • June 12, 2026
      • CVE-2026-35273 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
        • Cybersscoop discusses this KVE here.
  • Info Security Magazine informs us,
    • “Cybersecurity software regularly fails to detect and prevent the cyber-attacks they are designed to protect organizations from, especially within the bowser layer, research by Menlo Security has warned.
    • “Published on June 9, Menlo Security’s 2026 Browser Threat Report found that one in five phishing attacks which target the enterprise browser users go completely undetected by the tools which are supposed to protect the network and its users from attacks.
    • “Based on platform telemetry across millions of active browser sessions in enterprise customer environments between January 1 and March 31 2026, the research warned that threat actors are gaining entry to enterprise environments through the browser session layer.
    • “The problem, the paper said, is that attacks via the browser target areas which many traditional enterprise cybersecurity products are not designed to identify or prevent suspicious activity in.
  • Cybersecurity Dive points out,
    • “Financial services organizations are widely using AI agents for common business operations, but many of them aren’t sure whether their AI tools have opened the door for hackers, according to a new report.
    • “Sixty-two percent of financial services firms have deployed AI agents, and 93% of those firms have given them some level of autonomy, the Cloud Security Alliance (CSA) said in its Tuesday report.
    • “The report’s authors said the main conclusion from their survey, which consisted of interviews with 340 global IT and security professionals between Jan. 15 and March 1, is that “financial institutions have deployed AI faster than they have secured it.”
  • Per Security Week,
    • Palo Alto Networks drew attention to a high-severity security flaw in the Cortex XSOAR and Cortex XSIAM platforms that could allow attackers to access and modify restricted resources.
    • “Tracked as CVE-2026-0274, the issue is described as the improper validation of credentials in the CommvaultSecurityIQ integration of the affected products and does not require a special configuration to be triggered.
    • “The company also rolled out patches for eight medium and low-severity security defects in PAN-OS, Prisma Access Agent, Cortex XSOAR, and GlobalProtect App.
    • “Palo Alto Networks says it is not aware of any of these vulnerabilities being exploited in the wild.
    • “On Wednesday [June 10], Splunk published a dozen advisories detailing security weaknesses in its products and third-party libraries they use.”

From the ransomware front,

  • Health Exec reports,
    • “A health system in Mississippi has revealed a December 2025 data breach of its network resulted in records on 53,888 patients being stolen by hackers. Meanwhile an infamous cybercrime cell has claimed credit for the attack, posting proof on the dark web.
    • “Last month Singing River Health System reported official numbers from the incident to the U.S. Department of Health and Human Services’ Office for Civil Rights, which operates a data breach tracker. This came after an investigation into what it called a “cybersecurity incident” that staff at Singing River discovered a few days after cybercriminals were already inside its network.
    • “According to the health system, which said it worked with a third-party cybersecurity firm on its investigation, its network was compromised from Dec. 19 to 21, 2025, before the unauthorized access was discovered and containment protocols were deployed.” * * *
    • “Researchers at Comparitech released a report last week showing that Anubis—a cybercrime syndicate known for its ransomware attacks against healthcare entities—had claimed credit for the data breach in a post on its own dark web leak site.
    • “The group claims to have 293 GB of data from Singing River, much of it containing sensitive patient information. It posted samples to prove it had the goods, including what Comparitech described as “intimate images of surgeries and injuries.”
  • The Hacker News relates,
    • “A new analysis of The Gentlemen operation has revealed that the financially motivated threat group initially operated as an affiliate responsible for conducting double extortion attacks, while leveraging resources from various ransomware-as-a-service (RaaS) schemes like LockBit (aka Tenacious Mantis), Qilin (aka Pestilent Mantis), and Medusa (aka Venomous Mantis).
    • “According to a detailed report published by PRODAFT, the group, which it tracks as Phantom Mantis, is led by a Russian-speaking cybercriminal it calls LARVA-368, who goes by the online aliases hastalamuerte, ArmCorp, zeta88, nobody0, and santamuerte. The Gentlemen is known to be active since March 2025, claiming a total of 478 victims to date, per data from Ransomware.Live.”
  • Cybersecurity Insiders tells us,
    • “In recent years, ransomware has evolved from simple file-encrypting malware into highly sophisticated cyber weapons capable of disrupting entire organizations. Among these emerging threats, Time Bomb Ransomware has gained significant attention due to its ability to remain dormant within systems before launching a coordinated attack. This delayed-execution strategy makes it particularly dangerous for backup engines, which serve as the last line of defense against data loss and cyber incidents.
    • “Time Bomb Ransomware operates by infiltrating an organization’s network and remaining undetected for an extended period. Instead of immediately encrypting files, the malware silently spreads across systems, identifies critical assets, and waits for a predetermined trigger date or condition. 
    • “During this dormant phase, it can infect data backup repositories, storage servers, and disaster recovery environments without raising suspicion. As a result, organizations may unknowingly back up infected data for weeks or even months- depending on the backup engine configuration that can range on weekly to monthly time intervals.
    • “The primary danger lies in the ransomware’s ability to compromise backup engines before activating its payload. Traditional backup solutions are designed to create multiple copies of data to ensure business continuity. However, when ransomware infiltrates these backup systems, it can encrypt, corrupt, or delete backup copies along with the primary data. Consequently, organizations lose their ability to recover information, forcing them to either pay the ransom or suffer significant operational disruptions.”

From the Cybersecurity defenses front,

  • The Wall Street Journal reports,
    • “Frontier artificial intelligence models, like Anthropic’s Mythos, are forcing organizations to rethink cybersecurity by rapidly identifying attack chains.
    • “Visa developed a “Mean Time to Adapt” metric and the VVAH framework to automate vulnerability fixing and testing.
    • “Mean Time to Adapt,” measures how quickly an organization identifies, triages and fixes vulnerabilities once discovered.
    • “The rapid AI-driven discovery of flaws creates pressure on organizations, especially smaller vendors and the public sector, to automate defenses.”
  • JP Morgan Chase suggests ten actions to take now for AI-ready cyber resilience.
    • Run the Latest Software Versions
    • Manage Assets and Software Components with Reference Data
    • Build and Operate a Robust Vulnerability Management Program
    • Stress Test Incident Response and Resiliency Plans
    • Know Your Major SaaS and Outsourced Dependencies
    • Optimize Change Management for Speed
    • Aggressively Filter Outbound Traffic from Production Systems
    • Remove Standing Privileges from Employee Entitlements
    • Manage Remote Access and Segment Where Possible
    • Embed Security into the AI Development and Deployment Lifecycle
  • Bleeping Computer adds,
    • “AI is transforming the speed and scale of cybercrime in ways traditional security operations were never designed to handle.
    • Gartner predicts AI agents will cut the time it takes to exploit account exposures by 50% by 2027. Phishing campaigns that once took days to craft can now be generated in minutes, free of the telltale errors that once gave them away, while vulnerabilities that once required manual reconnaissance can now be identified and exploited automatically.
    • “For MSPs, the stakes are clear. Those still relying on a fragmented security stack will not just be slower to respond but will also struggle to prove to clients that their environments are fully protected.
    • “Keeping pace with AI-driven threats requires a more unified, AI-powered approach that strengthens security, simplifies operations and delivers greater value without putting additional pressure on margins.’
  • CSO raises “15 tough cybersecurity questions every CISO must answer.”
  • Here is a link to Dark Reading’s CISO Corner.

Monday report

Simplicity is a virtue.

From Washington, DC

  • Roll Call takes a look at what’s ahead of Congress this week,
  • and also lets us know,
    • “President Donald Trump on Monday sent to the Senate the nomination of acting Attorney General Todd Blanche to fill the role permanently, teeing up what could be a bruising confirmation process for a Trump ally who has drawn bipartisan criticism for recent Justice Department moves.”
  • Per a HHS news release,
    • “The U.S. Department of Health and Human Services (HHS) and the U.S. Department of Education today hosted eight of the nation’s leading accreditors, assessors, and medical organizations to announce a historic development to increase nutrition requirements at every level of U.S. medical education, competency-evaluation, training, and residency. Additionally, 19 medical schools across the country have signed the Trump administration’s Nutrition Education Pledge, vowing to incorporate 40 hours of nutritional education or its competency equivalent into graduation requirements starting this fall.
    • “Poor diets are the primary driver of America’s chronic disease epidemic, and today’s announcement reflects the shifting landscape toward placing nutrition and prevention at the core of patient health,” said Secretary Robert F. Kennedy, Jr. “Still, more work remains, and I look forward to seeing nutrition play an increased role as the latest science, data, and best practices develop.”
    • “Last August, HHS and the Department of Education sent a letter to medical organizations encouraging them to improve their standards and place nutrition at the core of their programs.”
  • Beckers Hospital Review informs us,
    • “TrumpRx.gov is adding 160 prescription drugs to the platform, bringing its total to more than 800  according to a June 5 Truth Social post from President Donald Trump.
    • “The president said the expansion would allow TrumpRx.gov to offer discounted pricing for medications that account for roughly four out of every five prescriptions filled in the U.S. The administration also claims the platform has saved American patients more than $400 million since its February launch.”
  • Per an OPM news release,
    • “The US Office of Personnel Management (OPM) today announced additional leading technology companies have committed to partnering with the US Tech Force (Tech Force), the government-wide initiative to recruit top technologists to modernize the federal government and strengthen America’s technical workforce.
    • “The new industry partners include Arista Networks, Armada, Cisco, Cognition AI, Cognizant, Payward, Moveworks from ServiceNow, Scale AI, and Wiz.
    • “These companies will contribute to Tech Force by providing technical training resources, executive engagement and programming, nominating employees for temporary government service, and helping create paths for Tech Force alumni into the private sector.” * * *
    • “More information about Tech Force is available here.”
  • The American Hospital Association News reports,
    • “The Drug Enforcement Administration today released a final rule implementing provisions from the Restoring Hope for Mental Health and Well-Being Act of 2022, which passed as part of the Consolidated Appropriations Act of 2023, eliminating the need for a separate waiver for qualified practitioners to dispense certain types of controlled substances for medications for opioid use disorder treatment, or MOUD. While the original requirements were amended by the SUPPORT Act of 2018 and changes were implemented in an interim final rule in 2020, the 2022 legislation struck the amended section from regulation, thus requiring DEA to respond to public comments on the interim final rule and update regulatory language accordingly.”

From the Food and Drug Administration front,

  • Fierce Pharma informs us
    • “The FDA has expanded the label for Pfizer’s subcutaneous hemophilia drug Hympavzi, now including patients age 6 and older who have hemophilia A or B.
    • “The anti-tissue factor pathway inhibitor was initially approved in October of 2024 for those age 12 and older with hemophilia A or B who have not developed the antibodies—also known as inhibitors—produced by the immune system that block or destroy infused clotting factor medications.
    • “The new expansion covers all patients 6 and older, regardless of their inhibitor status. The new nod also opens up the treatment to those 12 and older who have developed the inhibitors.”
  • CBS News reports,
    • “Retatrutide isn’t supposed to be everywhere.
    • “Touted as the next generation in the GLP-1 craze, it’s an experimental weight-loss drug that is not authorized outside of clinical trials. The Food and Drug Administration hasn’t reviewed whether it is safe and effective, which is the legal path for prescription drugs to come to market. And yet retatrutide is for sale all over the internet, a phenomenon with no modern precedent.
    • “It isn’t just shadowy online vendors offering what they claim to be research-grade retatrutide.
    • “A CBS News investigation found dozens of clinics across the country, staffed by licensed physicians and nurse practitioners, openly advertising retatrutide. That practice defies a longstanding norm in medicine – to wait for the FDA to approve a drug before prescribing it – and is contributing to a booming commercial marketplace for a drug that is barred from sale by federal law.” * * *
    • “It’s on the states to really police this kind of conduct,” said Nathan Cortez, a professor at SMU Dedman School of Law, adding that they often lack enforcement resources. “At some point it becomes so blatant and widespread that, you’re wondering, ‘What are we doing here? Are we going to enforce the law or not?'”
  • The Wall Street Journal adds,
    • Eli Lilly LLY shares rose in early European trade after a late-stage trial showed its drug was effective in weight loss and in alleviating obesity-linked conditions.
    • “Shares jumped 4.4% premarket to $1,181, extending a record high hit at Friday’s market close. The stock is up over 30% since the Indiana-based company reported first-quarter earnings on April 30.
    • “Participants in a Phase 3 trial of retatrutide—an experimental drug targeting obesity-related hormones—showed substantial weight loss, with those taking 12 mg doses losing an average of around 70 pounds over an 80-week period, the company said.
    • ‘One-third of participants on 12 mg doses saw their weight fall into a healthy weight range, while two-thirds fell below the threshold for obesity, Eli Lilly said.”

From the judicial front,

  • The American Hospital Association News reports,
    • “The U.S. District Court for the District of Massachusetts June 8 vacated the $100,000 fee for new H-1B visas established by a proclamation in September 2025. Judge Leo T. Sorkin declared the fees unlawful and said in his decision that it “exceeds the fee-setting authority delegated by Congress.” The AHA last year asked the administration to make healthcare personnel exempt from the fees. The federal government is likely to appeal the June 8 decision.”

Reports from the American Diabetes Association’s annual meeting,

  • Fierce Pharma adds,
    • “With an obesity green light already in hand, Eli Lilly is pushing for its newly launched Foundayo (orforglipron) to break into Type 2 diabetes, in turn rounding out its oral offering in line with Novo Nordisk’s duo of GLP-1 pills in both indications. 
    • “Now, in results from a trio of pivotal phase 3 studies presented Monday at the American Diabetes Association 2026 Scientific Sessions, Lilly is aiming its diabetes data squarely at two of the oral GLP-1’s biggest potential rivals.
    • “Sure to grab the most attention at the conference are results from Achieve-3, a head-to-head trial in which Foundayo topped Novo’s oral semaglutide on metrics of blood sugar reduction and weight loss in T2D patients.” 
  • STAT News notes,
    • “AstraZeneca’s investigational GLP-1 pill showed promise in mid-stage obesity and diabetes studies, but it may still be too early to determine how it stacks up against oral treatments already on the market.
    • “In one Phase 2 trial of people with obesity, called VISTA, those on the highest dose of the drug, called elecoglipron, lost 11.2% of their weight after 36 weeks, when looking at all patients regardless of discontinuations, according to data presented Monday at the annual meeting of the American Diabetes Association and published in the Lancet. (Eli Lilly’s pill Foundayo led to the same rate of weight loss in a Phase 3 study that lasted twice as long, but it’s hard to compare across trials in different phases.)”
    • “In a separate Phase 2 trial in people with diabetes, called SOLSTICE, patients on the highest dose saw up to a 1.74 percentage-point decrease in a measure of blood sugar called A1C after 26 weeks. The study, also published in the Lancet, enrolled people taking oral Ozempic open-label as a comparator group, and they experienced a smaller A1C decrease of 1.32 percentage points.”
  • The American Journal of Managed Care relates,
    • “A trio of studies presented at the American Diabetes Association 2026 Scientific Sessions has reframed the conversation of diet during pregnancy, pointing to diet quality, not just quantity, as a meaningful lever for managing gestational glycemia and postpartum metabolic risk. This is a conversation that has long been viewed through the narrow lens of weight gain and fetal growth.
    • “Across hundreds of pregnancies, researchers of 3 oral presentations found that higher intake of fiber, nonstarchy vegetables, and plant protein were independently associated with lower continuous glucose monitor (CGM) readings,1 while lower-carbohydrate diets in women with gestational diabetes improved glycemic control but raised micronutrient concerns.2 Perhaps most strikingly, women randomly assigned to a higher-complex carbohydrate diet during pregnancy still showed measurably lower postpartum glucose responses 2 months after delivery, suggesting that what a pregnant woman eats may matter long after the birth.3
    • “Together, these findings challenge prevailing assumptions about optimal gestational nutrition and open new questions about how prenatal dietary interventions might be designed to protect both mother and child over the long term.”

From the public health and medical / Rx research front,

  • BioPharma Dive reports,
    • “Tango Therapeutics said Monday its experimental drug vopimetostat showed promise in a small trial in pancreatic cancer, with nearly all of the enrollees followed so far responding to a regimen that combined its medicine with Revolution Medicines’ closely watched treatment daraxonrasib.
    • “The data suggest vopimetostat outperformed daraxonrasib alone in a similar population of people whose disease had progressed after at least one treatment line and exceeded Wall Street expectations. The company plans to initiate a Phase 3 trial later this year testing the combination.” 
  • The American Medical Association lets us know what doctors wish their patient knew about diverticulitis.
    • “Diverticulitis can turn silent colon pouches into painful inflammation. But plenty of interventions are available, depending on severity of diverticulitis.”
  • Per a National Institutes of Health news release,
    • “By inducing specific patterns of activity in small portions of the brain in awake mice, researchers supported by the National Institutes of Health (NIH) have triggered a recalibration of neural connections that normally only occurs during sleep. This new approach offset the effects of sleep deprivation in memory tasks and revealed features of sleep that are key to its restorative effect.
    • “What we’re essentially doing is forcing sleep in a local region of the brain. While that part is solidifying memories and restoring learning capacity, other parts stay aware/vigilant and connected to environment,” said corresponding author Chiara Cirelli, M.D., Ph.D., a professor of psychiatry at the University of Wisconsin-Madison. “Dolphins do something similar, sleeping with only one brain hemisphere at a time.”
    • “Non-rapid eye movement (NREM) sleep, which makes up about 80% of sleep for adults, is when the junctions between neurons that make memories are evaluated. During this phase, the brain protects important connections for long-term storage, prunes those that are less necessary, and makes space for new ones.”
  • Genetic Engineering and Biotechnology News relates,
    • “A study tracking thousands of B cells across more than 100 germinal centers (GCs) in mice has revealed how the system consistently produces highly effective antibodies. The findings overturn longstanding ideas about how germinal centers function, revealing that they are far more selective than once thought, and challenge the idea that antibody improvement is driven mainly by rare growth “bursts” among the most successful B cells. The discovery could have implications for immune cell evolution, and ultimately guide the design of vaccines against rapidly mutating pathogens like influenza. It could also lead to new ways of studying evolution itself.
    • “The traditional, mechanistic view of germinal centers is to think of them as selection machines sorting out the best antibodies,” said research lead Gabriel D. Victora, PhD, head of the Laboratory of Lymphocyte Dynamics at The Rockefeller University. “But when you look very, very closely, you see a process that’s almost essentially random—a little bit better than a coin toss—which repeats many times until the immune system arrives at the right answer consistently. That’s much more akin to how evolution operates than the way a machine does.”
    • “Victora and colleagues reported on their findings in Cell, in a paper titled “Replaying germinal center evolution on a quantified affinity landscape.”
  • Medscape points out,
    • “Metabolic-bariatric surgery (MBS) in patients aged 65 years or older resulted in long-term meaningful weight loss and remission of obesity-related conditions, although complication rates of about 8% were noted.”
  • The Cancer Therapy Advisor notes,
    • “Hyperthyroidism may be associated with an increased risk of breast cancer, particularly premenopausal breast cancer, according to research published in Cancer Epidemiology, Biomarkers & Prevention.
    • “Findings from in vitro studies have indicated that thyroid hormones can have estrogen-like effects. That suggests that thyroid hormones may affect cellular proliferation of breast tissue and subsequently increase breast cancer risk in people with hyperthyroidism, researchers explained. In this study, the researchers assessed the effects of hyperthyroidism and hypothyroidism on incident breast cancer in women from the Sister Study.
    • “Women diagnosed with hyperthyroidism or receiving related treatment may have elevated BC [breast cancer] risk, particularly premenopausal BC,” the researchers concluded. “Although more research is needed, premenopausal women treated for hyperthyroidism may benefit from enhanced breast cancer screening.”

From the U.S. healthcare business and artificial intelligence front,

  • Fierce Healthcare reports,
    • “Medicare Advantage insurer Essence Healthcare is continuing to build out its partnership with Oura and has unveiled a new clinical program that aims to identify potential sleep apnea risk.
    • “Essence is rolling out a new clinical workflow that will arm physicians with insights into patients’ nighttime breathing habits to identify those who may be at risk for obstructive sleep apnea. The insurer offers the ring as a covered benefit through some of its plans and has been working with Oura’s team to identify more clinical applications for its data.
    • “News of the partnership expansion was shared first with Fierce Healthcare.
    • “Through the program, insights into members’ sleep, as identified by the Oura Ring, will be shared with Essence with the patients’ consent. The insurer then uses Lumeris’ Tom platform to reach out to at-risk individuals and guide them through STOP-BANG, a common evidence-based screening for sleep apnea.”
  • and
    • “Artificial intelligence is here to stay in healthcare, and the industry’s largest players, like CVS Health, are making huge commitments to the tech.
    • “But embracing AI requires a workforce that’s ready for the revolution. With that backdrop, CVS has rolled out its internal AI Learning Academy, which aims to educate its workforce on practical applications for the technology and how it can impact and improve their workflows.
    • “The program was built in collaboration between human resources and tech leaders at the company. Greg Karanastasis, senior vice president for talent and development at CVS, told Fierce Healthcare that the aim was to build something bigger than just a training program.”
  • Per an Institute for Clinical and Economic Research (ICER) news release,
  • MedCity News tells us about “The 3 Biggest Roadblocks to Egg Freezing — and How Providers Are Working to Remove Them.”
    • “Egg freezing has gained popularity as a fertility preservation tool, but experts say high costs, uncertain outcomes and timing challenges continue to deter many women from pursuing it.”
  • MedTech Dive informs us,
    • “Boston Scientific is investing approximately $138 million to build a 500,000-square-foot distribution facility in Plainfield, Indiana.
    • “Indiana Gov. Mike Braun, who announced the project last week, said Boston Scientific will break ground on the facility this year and ultimately create up to 300 jobs. 
    • “Boston Scientific is building the facility to complement its existing distribution network, which includes sites in Georgia, Massachusetts and Minnesota.”
  • BioPharma Dive notes,
    • “Incyte, a drugmaker with a heavy focus on blood diseases and cancers, plans to take control of an experimental medicine that could help control bleeding in a variety of disorders.
    • “Vega Therapeutics, a subsidiary of the “hub-and-spoke” biotech Star Therapeutics, has been developing this “VGA039” medicine primarily as a treatment for von Willebrand disease — the most common inherited bleeding disorder. Now, Incyte has agreed to buy Vega for $1.25 billion up front. Star would be eligible to receive as much as $750 million more if certain sales goals are eventually met.
    • “Patients with von Willebrand disease lack an important clotting protein, meaning that, when they suffer any kind of injury, the bleeding usually takes longer to stop. In severe cases, this bleeding can cause joint or organ damage and be life-threatening. Current preventative treatments include so-called factor replacement therapies given as intravenous infusions two to three times a week. VGA039, meanwhile, comes as a once-monthly, under-the-skin injection that patients can do themselves.”
  • The Wall Street Journal relates,
    • “Roche Holding struck a deal with Nurix Therapeutics NRIX to license an experimental blood-cancer drug for up to $2.3 billion, expanding its pipeline in oncology and potentially other therapeutic areas.
    • The Swiss drugmaker on Monday said it would make an upfront cash payment to Nurix of $700 million, with additional payments subject to the drug, bexobrutideg, reaching development, regulatory and sales targets.
    • Bexobrutideg is due to enter late-stage studies for the treatment of chronic lymphocytic leukemia this summer, Roche said.
    • “The main opportunity for us is in B-cell malignancies. There are many B-cell malignancies and the most dominant of interest for us is chronic lymphocytic leukemia,” Roche’s deputy chief medical officer, Stefan Frings, said in an interview.
    • “The company said the medicine has potential to offer higher efficacy and more favorable tolerability than established therapies for leukemia. The drug is a so-called BTK degrader designed to remove the BTK enzyme from cells, rather than blocking its effects, and overcome resistance.”
  • and
    • “Johnson & Johnson JNJ  has agreed to buy biotechnology company Firefly Bio for $1 billion in cash in a deal that bolsters the drugmaker’s oncology pipeline.
    • “J&J on Monday said Firefly is developing its proprietary Firelink degrader antibody conjugate platform, for KRAS-driven cancers, which have limited treatment options with survival measured in months.
    • “Mutations of the KRAS gene have long been considered undruggable because the gene’s structure lacks the deep binding pockets most drugs need.
    • ‘J&J said the Firelink platform is a novel approach to overcome limitations of existing treatments by delivering a highly selective protein degrader to tumor cells, while avoiding healthy cells.”
  • and
    • Novo Nordisk NOVO.B said prescriptions for its Wegovy weight-loss pill have surpassed three million since launching in early January.
    • “The Danish drugmaker said late Sunday that the pill hit one million prescriptions 12 weeks after reaching U.S. pharmacies and online providers, with a further two million prescriptions achieved in the following 10 weeks.
    • “More than 80% of new prescriptions filled for the Wegovy pill are for patients new to the GLP-1 class of drugs, which the company says indicates that the new oral formulation is expanding the obesity treatment market, rather than replacing existing injectable therapies.”
  • Fierce Pharma adds,
    • “On a weekly basis, total GLP-1 prescriptions were trending downward over the week of June 1, falling 5.7% week-over-week, Citi analysts noted. Other than the continued rollout of Lilly and Novo’s respective weight loss pills, the analysts cited the effect of the Trump administration’s “most favored nation” pricing policies as a key future event that they think could impact total prescriptions.” 

Noteworthy Death

  • AP reports
    • “Harvard University professor Robert Coles, the psychiatrist and Pulitzer Prize-winning author who championed the cause of children grappling with poverty and segregation, has died at 97, his son said Sunday.
    • “The son, also named Robert Coles, told The Associated Press that his father died Thursday at a hospice center in Lincoln, Massachusetts.
    • “The elder Coles was famed for documenting the needs of children, particularly those caught in the crucible of social upheaval. The second and third parts of his five-volume “Children of Crisis” won him a Pulitzer Prize in 1973 for general nonfiction.
    • “In a 1965 Washington Post essay, he wrote that, expecting to find many psychiatric problems among the children of poverty, that instead “I was constantly surprised at the endurance shown by children we would all call poor or, in the current fashion, ‘culturally disadvantaged.’”
  • RIP

Cybersecurity Saturday

From the War with Iran front,

  • Cybersecurity Dive reports,
    • “The Cybersecurity and Infrastructure Security Agency, FBI and other federal authorities warned Tuesday [June 2] that hackers have targeted automatic tank gauge systems in threat activity across multiple industry sectors.
    • “Tank gauge, or ATG, systems are used to measure temperature, check fuel or other liquid levels and detect leaks, according to guidance released by the agencies. Hackers have targeted internet-exposed devices and used command execution to disable alerts or otherwise obscure the monitoring of these devices.” * * *
    • “Federal authorities have not attributed the attacks to any specific group, but CNN previously reported an investigation into the hack of ATG systems that serve gas stations in multiple U.S. states. The threat activity is suspected to be connected to Iran-linked hackers, but federal officials are not publicly making that link. 
    • “OT security experts cautioned there are limits to how a hacker might manipulate these devices. 
    • “A malicious actor could take control of an ATG and disrupt its functions, including leak detection, but they cannot cause a leak with an ATG,” said Markus Mueller, field CISO at Nozomi Networks. “Similarly, a malicious actor could disrupt the ability to fill or use a tank to fill a vehicle.” 

From the Project Glasswing front,

  • Cybersecurity Dive reports,
    • “Anthropic is significantly expanding the number of organizations that have access to its powerful Claude Mythos Preview AI model, a move that reflects growing interest in Mythos’s vulnerability-hunting capabilities within government agencies and critical infrastructure sectors.
    • “Following several weeks of close collaboration with our Project Glasswing partners, the security industry, open-source software maintainers, and the U.S. government, we’re extending the partnership to approximately 150 new organizations,” Anthropic said in a statement on Tuesday [June 2].
    • “The new organizations, which are based in more than 15 countries, include infrastructure operators in sectors that weren’t represented in Project Glasswing’s membership, such as power, water, healthcare and telecommunications. Other new members include hardware vendors and critical software maintainers, including nonprofit groups.”
  • Beckers Hospital Review adds,
    • “Health system leaders told Becker’s they’re encouraged by AI developer Anthropic opening up its Project Glasswing cybersecurity initiative to healthcare.”
  • Cybersecurity Dive notes,
    • One of the most important jobs for CISOs in the AI era is to stay calm and carefully assess their organizations’ risk exposure, experts said this week at the annual Gartner Security & Risk Management Summit here.
    • “Don’t panic,” Katell Thielemann, a VP analyst at Gartner, said during a talk on Tuesday about AI’s impact on the security of cyber-physical systems such as industrial control equipment.
    • “Yes, things are changing fast,” Thielemann said, “but there are some low-hanging fruit” that CISOs can tackle, such as disconnecting critical devices from the internet and monitoring remote access to the remaining infrastructure.

From the cybersecurity policy front,

  • Cyberscoop reports,
    • “The Trump administration issued a revised executive order Tuesday [June 2] focused on artificial intelligence, offering a significantly pared-back vision for the federal government’s role vetting AI systems compared with a draft version that was spiked weeks ago.
    • “The order keeps in place the administration’s largely voluntary framework for companies to engage with the federal government around testing new models before release, but appears to considerably weaken or loosen provisions that had been opposed by industry.
    • “Under the order, AI companies would voluntarily provide the federal government access to frontier models before release, but now it will be for “up to” 30 days instead of the 90-day timeline included in previous drafts.
    • “It also explicitly states that nothing in the program will be construed as mandatory or part of a federal licensing or permitting regime, and gives AI companies significant influence to help define what models would and would not be covered under for testing.
    • “It also states that all federal testing and access to the models would be subject to “confidentiality, cybersecurity, insider-risk, and intellectual-property protection, use, and nondisclosure requirements.”
  • Federal News Network relates,
    • During a House Homeland Security Committee hearing on Wednesday June 3, Homeland Security Secretary Markwayne Mullin “said the Cybersecurity and Infrastructure Security Agency needs to hire hundreds of additional staff. CISA’s staff has gone from roughly 3,400 people to 2,200 under the Trump administration, with many taking deferred resignations or early retirements.
    • “We probably need somewhere around [2,800] if we can actually have the partnerships we need with states and to be able to use the grants, the monies that stayed with CISA to be able to invest with local and state municipalities,” Mullin said. “We’re not going to fail on the mission that we have in front of us, and cyber attacks are only getting stronger, and they’re attacking our private partnership the most.”
    • “Mullin’s comments somewhat conflict with the Trump administration’s fiscal 2027 budget request for CISA, which would reduce the agency’s budget by $707 million compared to 2025 spending levels.” * * *
    • “Mullin also teased that Trump may be close to naming a new CISA director nominee. Former DHS official Sean Plankey’s nomination for CISA director was rescinded earlier this year after facing lengthy delays in the Senate.
    • “We’ve got a person soon to be nominated that will be running CISA that has the ability to recruit and focus on the authorities we have,” Mullin said. “We want CISA to be the leader in cybersecurity. They should be, and they will be.”
  • The American Hospital Association News tells us,
    • “The Health Sector Coordinating Council’s Cybersecurity Working Group has released a guide to help healthcare organizations establish cyber governance frameworks for secure artificial intelligence implementation. The guide addresses challenges in identifying and mitigating AI-specific cyber risks, including data poisoning, model drift and adversarial attacks, while ensuring compliance with current regulations. It also explores a spectrum of AI technologies used in healthcare, including traditional machine learning models, generative AI and agentic AI systems capable of autonomous action. 
    • “This comprehensive guide is a must-read for all healthcare organizations, vendors and suppliers as the development and implementation of various forms of AI into healthcare settings has become widespread at tremendous speed and scale,” said John Riggi, AHA national advisor for cybersecurity and risk. “The secure-by-design and implementation recommendations offered in this guide will help mitigate unintended cybersecurity risk and consequences of AI use in healthcare and help prevent adversarial exploitation of AI-related technical flaws. Mitigating AI cybersecurity risk is part of cyber safety, and cyber safety is patient safety.” 

From the cybersecurity vulnerabilities and breaches front,

  • Bleeping Computer reports,
    • “A data breach at the dental benefits administrator DentaQuest has reportedly exposed the sensitive data of 2.6 million accounts.
    • “The security incident came to light last month, when the infamous extortion group ShinyHunters listed the company on its data leak site and claimed to have stolen more than 234 GB of data.
    • “Following what the threat actor describes as a failure to reach an agreement with the company, the data was publicly leaked.” * * *
    • “On June 2, DentaQuest confirmed on its website that its networks had been breached and the incident caused “limited disruption” in customer service.
    • “DentaQuest is actively managing a cybersecurity incident involving unauthorized access to a limited portion of our network,” reads the statement.” * * *
    • “Yesterday, [June 3], data breach alerting service Have I Been Pwned (HIBP) analyzed the leaked information and found that it contained records for 2.6 million accounts.”
  • The HIPAA Journal has been keeping track of all healthcare data breaches since 2009.
    • “There was a sharp increase in data breaches between 2018 and 2021, with data breaches doubling in just three years as cybercriminals aggressively adopted ransomware and actively targeted the healthcare sector. The large annual increases in data breaches came to an end in 2021, increasing by around 4% between 2022 and 2023, and again by around 4% from 2024 to 2025, when a new annual record was set with 772 large data breaches reported.”
  • CISA added five known exploited vulnerabilities to its catalog this week.
  • Cybersecurity Dive adds,
    • “Cisco on Thursday [June 4] warned of a zero-day vulnerability in its Catalyst SD-WAN product that could allow an attacker to execute arbitrary commands as root. 
    • “The vulnerability, tracked as CVE-2026-20245, is the result of insufficient validation of user-supplied input. The flaw, which has a severity score of 7.8, could allow an attacker to conduct command-injection attacks and elevate privileges as the root user. 
    • “The company said it has confirmed a limited number of cases where the flaw was exploited, leading to a configuration change being pushed to edge devices.”
    • “Cisco has thus far not released any patches and has no current workarounds. 
    • “The vulnerability was disclosed by Mandiant.” 
  • and
    • “Researchers on Monday [June 1] warned that more than 30 Red Hat npm packages have been compromised in a supply-chain attack that used a credential-stealing worm. 
    • A total of 96 versions across 32 packages have been identified as compromised, according to researchers at Aikido Security. The accumulated downloads exceed 116,000, according to researchers. 
    • “The packages were published through the GitHub Actions OIDC, which indicates the compromise was linked to the continuous integration/continuous delivery pipeline, instead of a npm token, researchers noted.” 
  • The American Hospital Association News informs us,
    • “The FBI and international agencies have released an alert on Chinese military intelligence services using professional networking sites and online job platforms to target government, military and any other personnel with access to classified or privileged information. The agencies said intelligence officers or affiliates pose as employees of private consultancies, research institutions or human resources firms, and post job advertisements online for foreign policy and defense analysts. Successful candidates are then pressured to provide “non-public” information for unspecified clients associated with the Chinese government.
    • “This alert is important for healthcare since many individuals in the sector have current or former access to classified information,” said John Riggi, AHA national advisor for cybersecurity and risk. “Many healthcare organizations are also engaged in highly sensitive, taxpayer-funded medical research, innovation and clinical trials. For decades, the Chinese government has been engaged in an aggressive campaign to legitimately acquire, steal or hack the results of this research and innovation for their own strategic national security priorities, economic advantage or weaponization. Use of social media platforms to engage and compromise individuals with access to classified or unclassified, but sensitive information is one of their most effective tactics. As such, we should remain wary of connecting with unknown individuals on these platforms seeking to discuss research, or provide unusually lucrative offers for employment, speaking engagements, opinions or research — especially those which may involve foreign contacts or travel.”
  • Dark Reading identifies “4 Critical Threats Where Attackers Have the Advantage
    • “Gartner analysts issued a call to action to bolster defenses against several emerging critical threats, such as deepfakes and prompt injections.”

From the ransomware front,

  • Industrial Cyber reports,
    • “Microsoft Threat Intelligence detailed a growing RaaS (ransomware-as-a-service) operation known as The Gentlemen, tracked by Microsoft as Storm-2697, warning that the threat combines strong file encryption with aggressive self-propagation capabilities that can compromise entire enterprise networks. The analysis disclosed that the Go-based ransomware uses per-file ephemeral key encryption built on Curve25519 and XChaCha20, while simultaneously leveraging multiple lateral movement techniques to spread across connected systems, significantly increasing the speed and impact of attacks once initial access is obtained. 
    • “Researchers mentioned that The Gentlemen emerged in mid-2025 before evolving into a RaaS platform that recruits affiliates to conduct attacks at scale. The company noted that the malware’s self-propagation module enables broad network compromise, making it more dangerous than conventional ransomware focused solely on file encryption. The operation has been linked to widespread attacks across multiple sectors and regions, with threat actors using the ransomware alongside data theft and extortion tactics to maximize pressure on victims. 
    • “In addition to using per-file ephemeral Curve25519 keys with XChaCha20 stream cipher, The Gentlemen ransomware attempts to spread across an environment using a series of simultaneous, distinct lateral movement methods, increasing likelihood of widespread impact once initial access is achieved. Microsoft has observed The Gentlemen ransomware impacting organizations across education, transportation, healthcare, and financial industries in North America, South America, Europe, Africa, and Asia.”
  • Bleeping Computer relates,
    • “A threat actor is using an AI-built ransomware attack toolkit that automates Active Directory discovery and helps evade endpoint detection and response (EDR) solutions.
    • “Tool and payload development was assisted by Cursor and Claude Opus agents in various stages, including initial coding, analysis, and revisioning. Additionally, some agents were tasked with checking security research posts for various bypass techniques.
    • “Some of the malware created this way was tested in virtual environments against EDR tools from Sophos, CrowdStrike, and Microsoft.
    • “Despite the malware research and development orchestrated using AI technology, the researchers note that the workflow is entirely human-driven.”
  • Cybersecurity Insiders informs us,
    • “The traditional pattern of ransomware attacks appears to be changing, according to a recent analysis published by Ransomnews. For years, cybersecurity experts observed that many ransomware groups preferred launching attacks during weekends, particularly on Fridays and Sundays, when organizations often operated with reduced staffing levels.
    • “However, new data suggests that cybercriminals have shifted their tactics and are now focusing more heavily on weekdays, especially between Monday and Friday.
    • “The research indicates that ransomware incidents are increasingly occurring during standard European business hours rather than late at night or during weekends. This marks a significant departure from previous attack strategies, which were designed to exploit periods when IT teams and security personnel were less likely to be available to respond quickly.
    • “According to the findings, Sunday has become the least active day for ransomware-related activity. In contrast, October stands out as the busiest month of the year, recording the highest number of ransomware attacks. While the reasons behind the October surge are not entirely clear, experts believe that threat actors may take advantage of increased business activity during the final quarter of the year, when organizations are often focused on meeting annual targets and may have less time to dedicate to cybersecurity preparedness.”

From the cybersecurity business and defenses front,

  • Cybersecurity Dive reports,
    • “CrowdStrike reported better-than-expected earnings during the fiscal first quarter, as accelerating demand for AI is pushing more enterprises to focus on tighter cybersecurity controls. 
    • “CrowdStrike CEO George Kurtz said demand for AI and the introduction of Anthropic’s Mythos created an inflection point that demonstrated to the market that cybersecurity is an essential part of the AI ecosystem. 
    • “AI has now directly entered the world of cybersecurity across two dimensions,” Kurtz said during the company earnings call Wednesday. “First, you need cybersecurity to secure AI itself. Deploying AI across the enterprise is simply too risky without cybersecurity from the start.” * * *
    • The company said revenue increased 26%, to $1.39 billion, during the fiscal first quarter ended April 30, compared with year-ago revenue of $1.1 billion. * * *
    • “On Tuesday, CrowdStrike rival Palo Alto Networks reported a 31% increase in revenue, to $3 billion, during the company’s fiscal third quarter. 
    • “These results are materializing as AI fundamentally redefines the enterprise tech stack, elevating cybersecurity to a mission-critical priority for every organization,” Nikesh Arora, chairman and CEO of Palo Alto Networks, said during his company conference call on Tuesday.”
  • Dark Reading points out “Cyber Insurance Rates Are Dropping, but Exclusions Widen.”
    • “Cyber insurance coverage is slowly changing, and some policies may not provide coverage for social engineering attacks like ClickFix.”
  • Tech Target calls attention to “Lost in translation: Cybersecurity board reporting for CISOs.”
    • “Cybersecurity board reports don’t always land. At the Security and Risk Management Summit 2026, Gartner analysts suggested a novel way to communicate cyber-risk to corporate directors.”
  • A Cybersecurity Dive commentator delves into “Turning tension into collaboration: How CIOs and CISOs can lead together.”
    • If properly managed and channeled, age-old friction between IT and cybersecurity can create a more resilient organization.
  • Here is a link to Dark Reading’s CISO Corner.

Friday report

Simplicity is a virtue

From Washington, DC,

  • The American Hospital Association News reports,
    • “The House Appropriations Committee June 4 released the fiscal year 2027 appropriations bill for the Departments of Labor, Health and Human Services, Education, and related agencies. The bill provides a total discretionary allocation of $189.3 billion. HHS is provided with $110.8 billion, which is $4 billion, or 4%, below the FY 2026 enacted level. The bill provides support for rural health, primary care, workforce, behavioral health and other programs. The appropriations subcommittee approved the bill today on a party-line basis, and additional details are expected to be released before a full committee markup currently scheduled for June 9.” 
  • Beckers Payers Issues relates
    • “CMS has logged nearly 40,000 complaints alleging potential violations of federal health insurance law since the agency began tracking them in 2022, with the vast majority of closed complaints related to the No Surprises Act, according to an enforcement report covering data through December 2025.
    • “The report tracked complaints under Title XXVII of the Public Health Service Act, which includes the NSA, Mental Health Parity and Addiction Equity Act, and ACA compliance. 
    • “The agency closed 15,145 complaints in total, which were defined broadly to include stakeholder feedback, congressional and state referrals, No Surprises Help Desk submissions, and news articles. Of those, 2,086 were closed with a violation found and 7,838 with no violation found; the remainder were duplicates or withdrawals. Complaints referred to other agencies were not included in the data.”
  • FedSmith tells us,
    • “The average federal employee salary has reached a record high, exceeding $112,000 for the first time according to data from the Office of Personnel Management. For critics, that figure may confirm a long-held belief that government employees are overpaid. For supporters of federal employees, it reflects the reality of an aging, highly educated workforce that performs increasingly complex work.” * * *
    • “The average federal employee salary has reached a record high, exceeding $112,000 for the first time according to data from the Office of Personnel Management. For critics, that figure may confirm a long-held belief that government employees are overpaid. For supporters of federal employees, it reflects the reality of an aging, highly educated workforce that performs increasingly complex work.”
  • KFF informs us
    • Three new KFF analyses examine the latest data about Medicare Advantage, including trends in enrollment, premiums, out-of-pocket limits, supplemental benefits and prior authorization.
    • The first analysis, focusing on enrollment trends, finds that 55% of eligible Medicare beneficiaries are enrolled in Medicare Advantage in 2026, though the pace of enrollment growth continued to slow. Nearly one quarter (23%) of Medicare Advantage enrollees are in special needs plans (SNPs), which limit enrollment to beneficiaries with specialized health needs or who are eligible for both Medicare and Medicaid. Most (85%) of the net increase in Medicare Advantage enrollment between 2025 and 2026 across all plan types was among SNPs. Medicare Advantage enrollment remains highly concentrated, with UnitedHealth Group leading the market, and, together with Humana, accounting for nearly half (46%) of all Medicare Advantage enrollees nationwide, the same as last year.
    • companion analysis finds that three quarters (75%) of enrollees in individual Medicare Advantage plans with prescription drug coverage pay no premium other than the Medicare Part B premium, a selling point for enrollees. Nearly a third of enrollees (31%) are in plans that also reduce the Part B premium. Nearly all Medicare Advantage enrollees (99%) are in plans that require prior authorization for some services. Most Medicare Advantage enrollees are in plans that offer supplemental benefits not covered by traditional Medicare, such as vision, hearing and dental. Access to those three benefits remained stable, though there were decreases in the share of enrollees in plans providing other benefits, such as over-the-counter benefits, meals, and transportation.
    • Also recently available is a KFF analysis with a more detailed examination of out-of-pocket limits in Medicare Advantage plans in 2026, including variation by plan type, the distribution of enrollees facing different out-of-pocket limits, and trends over time.

From the Food and Drug Administration front,

  • The Wall Street Journal reports,
    • “The Food and Drug Administration launched a safety study of the abortion pill mifepristone, potentially leading to restrictions on its distribution.
    • “The FDA study, using existing drug-safety systems, is expected to take six months and aims to withstand legal criticism.
    • “Antiabortion advocates target mifepristone’s mail and telehealth distribution rules; 65% of U.S. abortions use the pill.”
  • Fierce Pharma relates,
    • “Three times as many deaths in the study arm versus the control arm in a trial of ADC Therapeutics’ Zynlonta have raised questions about the antibody-drug conjugate (ADC), which has been on the market since the FDA granted it accelerated approval in 2021.
    • “In the phase 3 LOTIS-5 trial, which included 440 patients with relapsed or refractory diffuse large B-cell lymphoma (DLBCL), there were 27 deaths (13.2%) in the study arm compared to nine (4.6%) in the control group. Zynlonta was paired with Roche’s monoclonal antibody Rituxan, while those in the control arm received Rituxan plus the chemotherapies gemcitabine and oxaliplatin.
    • “Most of the deaths in the treatment arm were among patients age 75 and older and were due to infections, ADC execs said on a conference call on Wednesday. The company added that the higher rate could also be chalked up to extended monitoring of patients in the treatment arm as opposed to those in the control arm.”
  • Healio tells us,
    • “The FDA has approved a label expansion for the interleukin-23 inhibitor guselkumab to include the inhibition of structural joint damage progression in adults with psoriatic arthritis.
    • “The label update follows data from the APEX trial, in which guselkumab (Tremfya, Janssen) yielded significantly lower rates of radiographic progression compared with placebo at 24 weeks. The analysis, which was published by Philip J. Mease, MD, of Swedish Medical Center and the University of Washington, and colleagues in the Annals of the Rheumatic Diseases in December, included more than 1,000 biologic-naïve adults with active PsA.”

From the judicial front,

  • Per a Justice Department news release,
    • “The Justice Department’s National Fraud Enforcement Division today [June 4] announced that its Health Care Fraud Unit, one of the most active white-collar litigating components across the Department, secured federal jury trial convictions in six trials in just under three weeks. The convictions in six trials between May 13 and June 1 spanned federal courtrooms across the United States, including in Fort Lauderdale, Los Angeles, Detroit, New York and Nashville.
    • “Six trial convictions in under three weeks ties the Health Care Fraud Unit record for number of trials to result in a conviction in a single month period. The cases behind these recent convictions, however, represent a greater level of sophistication and complexity: more than $1.1 billion in fraud losses across six distinct schemes, including a digital health platform that industrialized Medicare fraud at national scale, a proactive data-driven prosecution of a physician who out-billed every other Medicare provider in the country for Botox, and prosecutions requiring simultaneous command of health care data analytics, financial forensics, sophisticated digital evidence, and expert testimony. These results reflect not merely the volume of trials but the caliber of the Fraud Division’s trial practice that carried each one of them to conviction. The Health Care Fraud Unit has completed nine trials to date in 2026 (all of which have resulted in convictions) and 17 trials in 2025, maintaining an extraordinary pace of white-collar trial activity.”

From the public health and medical / Rx research front,

  • The Centers for Disease Control and Prevention announced,
    • “As of June 5, 2026, the amount of acute respiratory illness causing people to seek health care is very low.
    • “RSV activity is low in most areas of the country. Emergency department visits and hospitalizations for RSV are highest among infants and children younger than 4 years old.
    • “COVID-19 activity is low in most areas of the country.
    • “Seasonal influenza activity is low.” * * *
    • “Parainfluenza virus (PIV) is elevated nationally. Human metapneumovirus (HMPV) and Rhinovirus/enterovirus (RV/EV) activities are elevated nationally but are beginning to decrease. CDC data show these trends are expected for this time of year. HMPVPIV, and RV/EV are like other viruses that cause respiratory infections, including cough, fever, nasal congestion, and shortness of breath. Severe infection due to HMPV, PIV or RV/EV may progress to bronchitis or pneumonia. There are no vaccines available for these illnesses. Prevention measures include hand washing, cleaning surfaces, and staying home when sick.”
  • The Hill reports,
    • “The number of U.S. measles cases in 2026 has now exceeded 2,000, quickly approaching the full annual total of last year.
    • “As of June 4, the Centers for Disease Control and Prevention (CDC) has confirmed 2,030 cases so far this year, with 93 percent — or 1,890 cases — associated with outbreaks. Throughout all of 2025, the CDC confirmed 2,288 measles cases. Thirty new measles outbreaks have been confirmed this year.”
  • STAT News relates,
    • “Americans who have high-risk exposures to Ebola in the current outbreak in Central Africa will have access to an antibody treatment that has shown great promise in animal testing but hasn’t yet undergone a clinical trial to show whether it is efficacious in people, the Department of Health and Human Services confirmed Thursday.
    • “The antibody treatment, known as MBP-134, is made by San Diego-based Mapp Biopharmaceuticals, with funding from the Biomedical Advanced Research and Development Authority, an agency within HHS that helps develop medical countermeasures for rare and emerging diseases, and biological threats.
    • “It is not clear how many doses of MBP-134 exist at present. STAT asked the company and was told Mapp Bio could not reveal the number because BARDA owned the doses.
    • “An American doctor who contracted Ebola in the outbreak zone was flown last month to Germany for care; his wife, also a doctor, and their four children were also taken to Germany for quarantine. The ill physician, Peter Stafford, remains in care but is reportedly recovering. Another doctor from the same Christian missionary group who had what was considered a high-risk exposure is in quarantine in the Czech Republic; he remains healthy. There are currently no other known exposures among Americans.
    • “An expert panel advising the World Health Organization on possible therapeutics that could be tested or used in this outbreak — occurring in the northeastern part of the Democratic Republic of the Congo and neighboring Uganda — deemed MBP-134 one of the products to be prioritized for testing.”
  • Health Day tells us,
    • “The age-adjusted Parkinson disease death rate among adults aged 65 years and older declined from 2021 to 2024, according to a June 4 data brief published by the National Center for Health Statistics.
    • “Ellen A. Kramarow, Ph.D., from the National Center for Health Statistics in Hyattsville, Maryland, and colleagues used data from the National Vital Statistics System to examine trends in Parkinson disease mortality among adults aged 65 years and older in the United States.
    • “The researchers found that for adults aged 65 years and older, the age-adjusted Parkinson disease death rate was 72.0 deaths per 100,000 standard population in 2024. From 2014 through 2021, there was an increase in Parkinson disease death rates, from 57.2 to 76.3, followed by a decline, with the rate lower in 2024 than in 2021. Higher Parkinson disease death rates were seen for men than women in each age group (65 to 74, 75 to 84, and 85 years and older) in 2024. Compared with other race and Hispanic origin groups, White non-Hispanic adults had the highest death rates from Parkinson disease. There was variation seen in Parkinson disease death rates by state of residence, ranging from 47.7 to 102.1 in New York and Utah, respectively.”
  • and
    • “Rurality is associated with worse epilepsy outcomes, although the associations are attenuated among privately insured patients, according to a study published online June 3 in Neurology.
    • “Edward R. Bader, M.B., Ch.B., from the Albert Einstein College of Medicine in Bronx, New York, and colleagues conducted a retrospective cohort study using the National Inpatient Sample for 2016 to 2021 to examine the association between rurality and epilepsy outcomes.” * * *
    • “The reduction in disparities among people with private insurance suggests that there may be other factors, not just where someone lives, that could be contributing to these differences,” Bader said in a statement. “Our study highlights the need for additional research and public health efforts aimed at improving access to epilepsy care for people living in rural areas, which might include the expansion of telehealth services.”
  • MedPage Today informs us,
    • “A study of women undergoing breast imaging showed a significantly lower incidence of breast cancer in those who had a history of treatment with GLP-1 agonists.
    • “Involving more than 30,000 women, the study showed an overall breast cancer rate of 1.97%, including 1.62% in patients who received GLP-1 agonists for overweight or obesity and 2.31% in those who did not. The difference represented a 30% lower risk of breast cancer in the GLP-1 group.
    • “The findings, combined with multiple other studies, have provided impetus for a prospective clinical trial of GLP-1 drugs to prevent breast cancer, reported Elizabeth S. McDonald, MD, PhD, of Penn Medicine and Abramson Cancer Center in Philadelphia, at the American Society of Clinical Oncology (ASCO) meeting.
    • “Observational data cannot establish a causal relationship,” said McDonald. “We are seeing signals at this meeting in multiple cancers — colon, lung, liver, leukemia, endometrial, multiple myeloma — for decreased progression to metastatic disease, decreased recurrence, decreased incidence, and increased survival. The time is now to invest in a clinical trial to see if these drugs are causal for cancer prevention.”
  • Medscape points out,
    • “Patients discontinuing GLP-1 treatments often regain weight rapidly, but emerging strategies like endoscopic procedures and new oral medications show promise in maintaining weight loss. These alternatives may offer cost-effective, long-term solutions.”
  • Genetic Engineering and Biotechnology News lets us know,
    • “The injectable form of the polio vaccine has proven effective at preventing illness but it does not block the transmission of the virus as well as the oral version of the vaccine. That is because the virus is usually transmitted through contaminated food or water and is first exposed to the GI tract, where the oral vaccine induces a mucosal immune response. To date, several countries no longer use the oral vaccine because there is a small risk of infection. It is also possible for people who receive the injected polio vaccine to spread the virus even though they are asymptomatic. 
    • “Now according to data from an Massachusetts Institute of Technology-led study, it may be possible to modify the injectable vaccine so that it can also promote a mucosal immune response. This way, the vaccine could support polio eradication efforts without the risks of the oral polio vaccine. Details are published in a new Science Advances paper titled “Am80-Lipid nanoparticles serve as an enteric mucosal adjuvant 3 following parenteral immunization with inactivated polio vaccine.”
  • Cardiovascular Business notes,
    • “Engineers with the Massachusetts Institute of Technology (MIT) have developed a noninvasive pacemaker that uses ultrasound to stimulate the heart. The group shared its early experience with the device in Nature Biomedical Engineering, highlighting its compact, wearable design.
    • “Pacemakers are one of the most important and widely used human implants, and they have saved millions of lives,” Gengxi Lu, the study’s co-corresponding author, said in a statement. “But they are invasive, and they make direct contact with the beating heart. The dream for many years has been noninvasive heart stimulation with ultrasound.”
    • “The team’s device is a small sticker worn on the chest. Tiny transducers on the sticker use ultrasound pulses to stimulate the heart in a way that opens certain ion channels in cardiac cells. Lab experiments have been a success, with the device maintaining healthy contractions in human cardiac cells.
    • “For an ultrasound pacemaker to become a reality, researchers believe they would likely begin the process by giving patient’s a one-time injection that boosts the sensitivity of cardiac cells. Once this injection was done, the patient could then theoretically attach the stamp-sized sticker and start experiencing the benefits of the small device right away.
    • “While it’s still early, the group at MIT is optimistic about this new-look pacemaker’s potential. In fact, they hope to combine this latest approach with previous research into sticker-based medical imaging to deliver a single ultrasound sticker that can simultaneously monitor and regulate a patient’s heart.”
  • Per BioPharma Dive,
    • “A clinical trial testing a migraine prevention therapy from Denmark-based Lundbeck has produced data that some on Wall Street see as mixed but still good enough to forge ahead with further development.
    • “The therapy, called bocunebart, is designed to inhibit a nervous system protein known as PACAP. This protein regulates stress and, when triggered, causes pain-sensing nerves to fire and blood vessels in the head to drastically widen. Lundbeck’s study has been evaluating bocunebart — as a direct infusion to the veins or as an under-the-skin shot — in hundreds of patients who continued experiencing migraines even after trying up to four other treatments.”

From the U.S. healthcare business front,

  • Beckers Hospital Review reports,
    • “Hospitals and health systems are losing money on virtual care across every major payer category even as adoption climbs, according Strata’s latest Performance Trends report.
    • “The national analysis found telehealth encounters rose 79% between January 2019 and January 2026, marking the shift from a pandemic stopgap to a permanent fixture of care delivery. Despite that growth, average total cost margins for telehealth stayed negative in 2025 across commercial, Medicare, Medicaid and self-pay patients. Remote patient monitoring has soared 4,000% over the same time period.
    • “Healthcare organizations are increasingly turning to technology and new care delivery models to address workforce shortages and improve patient access,” said Steve Wasson, Strata’s chief data and intelligence officer. “The challenge is that many of these investments, particularly in virtual care, are occurring at a time when margins remain extremely narrow.”
  • and
    • “Nashville, Tenn.-based HCA Healthcare has acquired 17 urgent care clinics from Urgent Care Group in North and South Carolina. 
    • “The clinics include locations in Charleston, Columbia, Myrtle Beach and Spartanburg in South Carolina, and Wilmington in North Carolina, according to a June 2 news release. 
    • “The South Carolina clinics are now operating under the first HCA CareNow brand name, becoming the first such clinics in the state, The North Carolina clinics are continuing to operate under the Medac name used by Urgent Care Group.” 
  • Kaufman Hall opines,
    • “Healthcare leaders must confront whether scorecards are improving patient safety or reshaping priorities in ways that may not benefit patients.”
    • Quick take
      • The debate is no longer about whether hospitals should be measured; it’s about whether the industry is measuring what truly matters.
      • Rankings shape reputation, revenue, and strategic priorities, not just public transparency.
      • Health systems are confronting a growing tension between improving patient care and improving publicly visible scores.
      • The number of public rankings is continuously growing.
      • Leaders are questioning whether current scorecards drive meaningful safety improvements or create administrative distraction.
      • The outcome of this debate could redefine how healthcare approaches transparency, accountability, and patient trust in the years ahead.
  • Health Exec relates,
    • “In a new state-by-state analysis of patient spending on healthcare, Utah, Virginia and California are at one end of the “spend the most” vs. “spend the least” rankings. Alaska, Oregon and Maine land at the other. Can you guess which trio’s residents spend the most and which the least?
    • “Time’s up. Alaska takes the undesirable No. 1 pole position: It’s the most expensive state for people who have to pay out of pocket. On average they shell out 10.1% of the median monthly household income to pay for essential medical services and prescriptions. 
    • “Spending the least are residents of Utah, where wallets only take a hit of 5.11%.
    • “The calculations are from WalletHub, which released a report on the topic May 28.” * * *
    • For WalletHub’s full report, click here.
  • Fierce Healthcare informs us,
    • “Community health system WellSpan Health inked a seven-year strategic alliance with Philips to drive advanced imaging technology across its network and co-develop new AI and tech tools.
    • “Philips’ technology will support WellSpan’s full network of 12 hospitals, diagnostic imaging centers and ambulatory surgery centers across Central Pennsylvania and Northern Maryland. A long-term commercial agreement establishes Philips as WellSpan’s preferred vendor across patient monitoring, enterprise informatics and all applicable imaging modalities, including CT, MR, digital X-ray, ultrasound and image-guided therapy.
    • “The commercial agreement includes a structured approach to technology lifecycle management: WellSpan and Philips will align equipment, services, training and upgrade planning under a single, coordinated framework, according to the organizations.
    • “The alliance marks Philips’s first research and innovation collaboration with a U.S. community health system. The health tech giant and WellSpan plan to co-develop net-new products and features that advance care delivery, drawing on Philips’ R&D pipeline, with WellSpan serving as both a proving ground and a co-creator.”
  • Per Fierce Pharma,
    • “With a new patent settlement, Axsome Therapeutics can lower its sword against prospective generics makers taking aim at its narcolepsy med Sunosi.
    • “The central nervous system-focused drugmaker closed the books on years of Sunosi intellectual property litigation by striking a settlement with “the only remaining first-to-file generic applicant with pending product litigation related to Axsome’s product Sunosi,” the drugmaker announced in a June 3 press release.
    • “Through the settlements, five companies will be cleared to market their generic versions of Sunosi starting on September 1, 2040, if Axsome nabs a pediatric exclusivity period for the drug. If not, the knockoffs can launch on March 1, 2040, the company explained. With that, “no other patent litigation relating to Sunosi remains pending.”

Thursday report

Simplicity is a virtue

From Washington, DC,

  • The Wall Street Journal reports,
    • “Republican senators stopped short of using their political leverage to kill President Trump’s $1.8 billion “anti-weaponization” fund, approving a critical immigration-enforcement bill without adding language reining in the controversial program.
    • “Passage of the $70 billion package funding Immigration and Customs Enforcement and Border Patrol through the end of Trump’s second term came after a more than 19-hour session of amendment votes and intraparty negotiations. The GOP-backed measure passed 52 to 47 shortly before 5 a.m., with Republican Sen. Lisa Murkowski of Alaska voting with Democrats against the bill.
    • “The session’s votes allowed GOP senators in competitive election fights this fall—including Susan Collins of Maine, Dan Sullivan of Alaska, Jon Husted of Ohio and Ashley Moody of Florida—to register their objections to the fund without derailing a bill that is a priority for Trump and the party.
    • “The House is expected to take up the immigration-enforcement measure next week.”
  • The No Surprises Act’s final independent dispute resolution (IDR) rule was published in the Federal Register today. Federal Hearings and Appeals Services, which a certified IDR entity, offers its summary of the rule with helpful charts!
  • Federal News Network reports
    • The Postal Service, on the verge of running out of cash early next year, is pricing out a wide range of possible reforms that, if passed by Congress, could address the agency’s long-term financial problems.
    • Postmaster General David Steiner told House lawmakers in March that USPS is set to run out of cash in early 2027 and that lawmakers need to act soon to keep the agency running.
    • The agency’s wish-list of possible legislative reforms, outlined in a document titled “Accelerating Progress: Elements of Postal Reform,” includes several longstanding proposals supported by postal watchdogs and unions. The document also considers more controversial options, such as closing post offices and reducing delivery days to save USPS billions of dollars each year.
  • Per a House of Representatives Oversight and Government Reform news release,
    • “Subcommittee on Government Operations Chairman Pete Sessions (R-Texas) delivered his opening statement at today’s hearing with the Commissioners of the Postal Regulatory Commission. In his opening remarks, Subcommittee Chairman Sessions highlighted the financial crisis the U.S. Postal Service (USPS) is facing and how actions to reform the agency have fallen short of expectations. He also emphasized that Congress and the American people have to decide what they want out of USPS to help resolve procedural and financial issues in the agency.” 
  • The OPM Director Scott Kupor added to his Secrets of OPM blog (available on LinkedIn and Substack) concerning a Presidential Memorandum approving the use of critical position pay to support investment programs related to national security.
  • Tammy Flangan, writing in Govexec, discusses whether a record number of new retirees this year will slow your retirement claim.
    • “New OPM data offers clues about processing times, potential delays and why retiring employees may need a larger financial cushion than expected.” 
  • Per a National Institutes of Health news release,
    • “National Institutes of Health Director Jay Bhattacharya, M.D., today announced the selection of Steven Schiff, M.D., Ph.D., as the next director of the Fogarty International Center (FIC) and NIH associate director for international research. Schiff began his role on June 4, 2026. 
    • “A pediatric neurosurgeon and global health researcher, Schiff currently serves as the Harvey and Kate Cushing Professor of Neurosurgery, vice chair for global health in the Department of Neurosurgery, and professor of epidemiology and of electrical and computer engineering at Yale University in New Haven, Connecticut.” * * *
    • “As director of FIC, Schiff will lead NIH’s global health research efforts by supporting collaborations between U.S. and international investigators, strengthening partnerships among research institutions worldwide, and training future global health scientists. He will oversee the center’s approximately $95 million annual budget, most of which supports research grants and training programs.” 
  • Beckers Health IT lets us know,
    • “The White House is backing a push for AI to take over more of the duties of physicians, The Washington Post reported.
    • “The Trump administration supports an experiment in Utah where AI is writing prescriptions, plans to offer over $50 million in research awards to developers of conversational AI for cardiovascular care, has created an expedited approval process for digital health products like AI chatbots, and is working on a regulatory pathway for independent AI physicians, according to the June 4 story.
    • “People are seeing the difference the AI is bringing,” Amy Gleason, the administrator of the Department of Government Efficiency who is now a healthcare AI advisor at HHS, told the news outlet. “And it’s like the genie is out of the bottle.”
  • and
    • “HHS, under Secretary Robert F. Kennedy Jr., has sought access to detailed patient records held by state health information exchange systems as part of an effort to research a potential link between vaccines and autism, KFF Health News reported June 4.
    • “Federal officials met with leaders of state-run health information exchanges several times over the past year, asking how the medical records they maintain from hospitals and health systems could be used for vaccine research, according to seven people familiar with the meetings.”

From the Food and Drug Administration front,

  • STAT News reports,
    • “Leaders at the Food and Drug Administration on Thursday listened to criticisms and recommendations for how to move forward with a speedy drug review program put in place by former FDA commissioner Marty Makary. 
    • “The listening session, held on the FDA’s White Oak Campus, featured 17 speakers representing patient groups, drug companies, and academic organizations. Some had positive feedback, particularly those whose drugs have already been approved through the program. But most asked the agency to pause the program, and then bring it back through normal regulatory procedures that require public feedback.” 
  • Per a corporate news release,
    • “Global pharmaceutical leader Lupin Limited (Lupin) (BSE: 500257) (NSE: LUPIN) (REUTERS: LUPIN.BO) (BLOOMBERG: LPCIN) today announced that the United States Food and Drug Administration (U.S. FDA) has approved its ranibizumab, Ranluspec™ (ranibizumab-hkdz), as an interchangeable biosimilar referencing to Lucentis® (Genentech).”
  • Reuters relates,
    • “The U.S. FDA’s Center for Drug Evaluation and Research said on Wednesday it has accepted a letter of intent for ​an artificial intelligence-based drug development tool designed to ‌help predict drug-induced liver injury.
    • ‘Drug-induced liver damage is a major cause of trial failures, and current methods do not reliably ​predict human risk. The U.S. Food and Drug Administration said ​the tool could potentially help improve early safety assessments, reduce reliance ⁠on animal testing and support more informed decisions before human trials ​begin.’

From the judicial front,

  • Bloomberg Law reports,
    • “The US Supreme Court raised the bar for branded pharmaceutical companies seeking to sue over a competitor’s generic versions of their drugs that are marketed using what’s called a skinny label.
    • “The justices unanimously concluded that a district court judge was right to dismiss Amarin Pharma Inc.’s infringement suit over claims that Hikma Pharmaceuticals USA Inc. was encouraging doctors to prescribe its generic version of Amarin’s Vascepa heart health drug for a still-patented treatment method.
    • “Drugmakers frequently obtain patents not just on chemical compounds they discover for novel drugs, but separately for methods of using such drugs to treat various medical conditions. When some uses are covered by active patents while others aren’t, generics can get government approval of a “skinny label” that carves out the patented uses.
    • “Thursday’s ruling ramps up the evidence that branded drugmakers need in order to sue when they think the generic label in combination with a generic company’s marketing statements or other communications cross a line into actively inducing patent infringement.”

From the public health and medical / Rx research front,

  • The New York Times reports,
    • “Scientists have made a discovery that may help prevent some people from developing lung cancer, which kills more people worldwide than any other cancer. 
    • “A team of more than 80 researchers working across four continents have identified a set of proteins in the blood that accurately predict lung cancers more than five years before diagnosis. The scientists also found early evidence that an existing anti-inflammatory drug could significantly reduce lung cancer risk in people with elevated concentrations of these proteins, which they linked to inflammation.
    • “More research is needed before a test based on these proteins could be ready for use in patients. And scientists would still need to run a randomized trial to determine whether the drug prevents lung cancers. Still, outside experts said the findings, which were published on Thursday in the journal Cell, offer a promising starting point toward a long-held public health goal.”
  • The Washington Post adds,
    • “The story of GLP-1 drugs keeps getting bigger.
    • “First they transformed the treatment of diabetes. Then they upended the science — and culture — of weight loss. Now a growing body of research is raising another possibility: that these drugs may help protect against cancer.
    • “At this year’s American Society of Clinical Oncology (ASCO) meeting in Chicago, more than 40 studies, abstracts, oral presentations and poster presentations examined the relationship between GLP-1-based drugs and cancer. The results were strikingly consistent. Taken together, they suggest that people taking medications such as Ozempic, Wegovy and Mounjaro may develop certain cancers at lower rates than comparable patients who are not taking the drugs — and that those already diagnosed may experience a slower decline and better outcomes.
    • “For oncologists, the accumulation of evidence is hard to dismiss. The findings are “super promising,” said Mark Orland, a cancer researcher at the Cleveland Clinic. “We’re really excited to be on the forefront of looking at the effects of these drugs.”
  • Health Day relates,
    • “A simple urine test might help identify children who are likely to have autism earlier than the best assessment tools now available, a new study says.
    • “Autistic children appear to have specific gut microbe profiles that can be used to distinguish them from neurotypical (or typically developing) children, researchers reported May 26 in the journal Molecular Psychiatry.
    • “A urine test based on these profiles correctly identified 90% of autistic children and did not misidentify any children without autism, researchers found.
    • “What’s really striking about the bacteria is that they make metabolites that are basically altered versions of serotonin and dopamine,” said researcher James Adams, a professor of engineering at the Biodesign Center for Health Through Microbiomes at Arizona State University (ASU) in Tempe.”
  • and
    • “Mailed fecal immunochemical tests (FITs) can significantly increase colorectal cancer (CRC) screening across racial and ethnic groups, according to a study published in the May/June issue of the Annals of Family Medicine.
    • “Anisha P. Ganguly, M.D., from the University of North Carolina at Chapel Hill, and colleagues compared the effects of a CRC intervention (mailed FIT for screening-eligible patients plus patient navigation for positive results) across race/ethnicity. The analysis included 3,734 patients at federally qualified health centers.” * * *
    • “This analysis showed that mailed colorectal cancer screening tests have the power to improve screening rates for diverse populations,” Ganguly said in a statement. “This is really important, because we want these innovations in screening to improve outcomes among the hardest to reach populations and move the needle on colorectal cancer disparities.”
  • The American Journal of Managed Care tells us,
    • “Sudden death has long been considered an abrupt and unpredictable event in patients with heart failure
       (HF). But a new post hoc analysis of the FINEARTS-HF randomized clinical trial challenges that assumption, finding that most sudden deaths in patients with HF with mildly reduced ejection fraction (HFmrEF) or preserved ejection fraction (HFpEF) are preceded by measurable clinical deterioration in the months before death.”
  • According to Infectious Diseases Advisor,
    • “Maternal SARS-CoV-2 mRNA vaccination during the third trimester reduces risk for infection and related hospitalization in infants through 6 months of age, highlighting the importance of maternal vaccine timing.”
  • STAT News informs us,
    • “Otsuka’s Voyxact slowed the loss of kidney function after one year in patients with a chronic autoimmune kidney disease, but the benefit was less than expected and left room for competing treatments to perform better. 
    • “In a Phase 3 study, patients with IgA nephropathy, or IgAN, who received injections of Voyxact saw their kidneys lose function at an annualized rate of 3 points over one year compared to an annualized function loss of 7.6 points over one year for patients receiving a placebo, the Japanese drugmaker reported Thursday.” * * *
    • “While the relative improvement in kidney function was positive, the result was also less robust than what was seen in an earlier Otsuka study. The data left open the possibility that competing drugs from Vera Therapeutics and Vertex Pharmaceuticals may be able to show a larger effect on kidney function when their respective studies read out results.” 

From the U.S. healthcare business and artificial intelligence front,

  • Beckers Payers Issues reports,
    • “UnitedHealth Group and CVS Health, Aetna’s parent company, are among the top 10 companies on the Fortune 500 this year.
    • Fortune‘s June 3 list ranks the top 500 U.S. companies by revenue. Nine health payers [which are listed in the article] made the cut, with 2025 revenues ranging from $11.7 billion to $447.6 billion.
    • “UnitedHealth Group held its third-place standing from 2025. Amazon topped the list, ending Walmart’s 13-year tenure in the top spot.”
  • Beckers Hospital Review relates,
    • “Brentwood, Tenn.-based Lifepoint Health has completed its acquisition of eight community hospitals from Louisville, Ky.-based ScionHealth.
    • “The hospitals are spread across six states, according to a June 2 news release. Lifepoint acquired:
      • “Bolivar Medical Center in Cleveland, Miss.
      • “Ennis (Texas) Regional Medical Center
      • “Livingston (Tenn.) Regional Hospital
      • “Logan (W.Va.) Regional Medical Center
      • “Palestine (Texas) Regional Medical Center
      • “Parkview Regional Hospital in Mexia, Texas
      • “St. Joseph Regional Medical Center in Lewiston, Idaho
      • “Watertown (Wis.) Regional Medical Center
    • “Lifepoint originally signed an agreement to acquire the hospitals in March.
    • “ScionHealth said the eight hospitals will keep their current employees, providers and services. The company described the divestiture as part of a broader effort to strengthen its capital structure and focus on core operations.”
  • Healthcare Dive adds,
    • “West Virginia University Health System has solidified the next phase in its plan to acquire Greensburg, Pennsylvania-based nonprofit Independence Health System, announcing this week the two parties had signed a definitive agreement to combine.
    • “As part of the deal, which was announced last year, WVU Health System will invest $800 million into Independence’s five hospitals in order to install a new electronic health record and upgrade the facilities.
    • “The health systems now expect the acquisition will close in September or October, pending regulatory approval.”
  • Fierce Healthcare tells us,
    • “Due to advances in cancer treatment and early detection, the population of cancer survivors continues to grow, reaching more than 18 million individuals in the U.S. By 2035, that number is projected to exceed 22 million.
    • “But many cancer survivors have ongoing medical and mental health needs after cancer treatment ends. Faced with long-term side effects, behavioral health challenges and hormone therapies, many survivors are left to manage these healthcare challenges on their own.
    • “Value-based cancer care navigation company Thyme Care has expanded its cancer survivorship program, called Next Chapter Care, to provide a personalized, longitudinal approach to survivorship support. That program provides coordinated oncology support beyond active treatment for the more than 15,000 Thyme Care members who have completed cancer treatment.
    • “Rather than treating survivorship as a disconnected phase of care, the program extends the existing relationship Thyme Care already has with members across diagnosis, treatment and recovery, according to the company.”
  • and
    • “Artificial intelligence-powered payer intelligence startup Anomaly Insights launched a new tool aimed at providing managed care executives with evidence to bring to payer negotiations. 
    • “Anomaly Insights seeks to take on what Anomaly CEO Mike Desjadon told Fierce Healthcare is an “adversarial payment system” in the U.S. healthcare industry. He added there is also a “fundamental asymmetry” in data between insurance companies and health systems. 
    • “It’s that asymmetry that allows an insurance company to basically make the health care system chase its tail with denials and all the things that they do with data,” Desjadon said. 
    • “Artificial intelligence-powered payer intelligence startup Anomaly Insights launched a new tool aimed at providing managed care executives with evidence to bring to payer negotiations. 
    • “Anomaly Insights seeks to take on what Anomaly CEO Mike Desjadon told Fierce Healthcare is an “adversarial payment system” in the U.S. healthcare industry. He added there is also a “fundamental asymmetry” in data between insurance companies and health systems. 
    • “It’s that asymmetry that allows an insurance company to basically make the health care system chase its tail with denials and all the things that they do with data,” Desjadon said. “
  • Beckers Hospital Review points out,
    • “Active drug shortages in the U.S. rose for the second consecutive quarter in 2026, reaching 223 in the first quarter, according to the American Society of Health-System Pharmacists — and the FDA’s database continues to reflect new discontinuations weekly. The database is updated daily to reflect manufacturing recoveries, regulatory actions and how shortages are classified — not solely day-to-day availability at the hospital level.”
    • The article also lists eight recent additions to the shortage list.

Midweek Update

Simplicity is a virtue.

Simplicity is not about doing less; it’s about focusing on what matters most. The future of performance management is about creating value with clarity & ease.”

From Washington, DC,

  • BioPharma Dive reports,
    • “A bipartisan House bill proposed Tuesday would require government screening of U.S. investments in Chinese biotechnology in the wake of two pharmaceutical deals potentially worth more than $10 billion each.
    • “Reps. John Moolenaar, R-Mich., chairman of the Select Committee on China, and Debbie Dingell, D-Mich., are sponsoring the bill, dubbed the Biotech Investment National Security Act. It would amend the COINS legislation passed last year to restrict investment in certain sensitive technologies, adding biotechnology to the list.
    • “Under the new bill, licensing deals, joint ventures and equity investments in China could be subject to both Treasury and Defense Department reviews. Moolenaar and Dingell focused on licensing deals involving technology and intellectual property and excluded agricultural biotechnology, industrial fermentation and basic academic research.”
  • Federal News Network relates
    • “Close to 8,000 career federal employees will be moved into a new employment category with limited job protections, after the Trump administration took the final step to make Schedule Policy/Career a reality.
    • ‘An executive order President Donald Trump signed Wednesday afternoon formalizes the long-expected federal employment classification and eliminates civil service protections for thousands of senior-level positions across government. The move is meant to boost workforce accountability, but has also drawn sharp criticism from federal unions, employee organizations and other stakeholders.
    • “Trump administration officials said the creation of Schedule Policy/Career aims to improve employee accountability and ensure the federal workforce is carrying out the president’s policy agenda. Officials also said it’s currently too difficult to remove federal employees for poor performance.
    • “It’s also about a restoration, in our mind, of the democratic process,” Office of Personnel Management Director Scott Kupor told reporters during a press call Wednesday. “What Schedule Policy/Career does is really nothing new. This is exactly the way the system worked for a very long time … In order to affect the policy priorities of the administration, we need to have people willing to and capable of carrying out those directives.” * * *
    • “The targeted 8,000 career federal positions for the new classification is far lower than OPM’s initial estimate that Schedule Policy/Career would cover about 50,000 positions. Some earlier estimates had also suggested as many as 200,000 positions could be converted.”
  • Govexec tells us,
    • “With one protest withdrawn and a second one denied, the Office of Personnel Management is now free to move forward with its plan to award a 10-year contract to modernize the government’s human resource systems.
    • “OPM released the final solicitation in October for the Federal HR 2.0 contract to modernize systems that cover 2 million employees across the government. The agency wants a single integrated platform that will be the infrastructure for a more data-driven federal HR ecosystem, according to solicitation documents.
    • “Bidders had to submit proposals by Oct. 31 and OPM followed a two-step process for evaluation. After step one, IBM Corp. and then Economic Systems Inc. filed their protests.
    • “IBM filed its protest on Feb. 25 but withdrew without explanation on April 3. Meanwhile, Economic Systems filed a protest on March 2. On Monday, the Government Accountability Office posted on its public docket that it had denied Economic Systems protest.
    • “OPM could not make an award while the protests were active, but it could continue to evaluate proposals. Now it can pick a winner with the protests out of the way.
    • ‘While no dollar value has been disclosed, the undertaking is massive.”
  • Kevin Moss, writing in Federal News Network, encourages federal employees to take a look at joining FEHB and PSHB high deductible plans that allow them to contribute to triple tax deductible health savings accounts.

From the Food and Drug Administration front,

  • U.S. News and World Report reports,
    • “Acting U.S. FDA Commissioner Kyle Diamantas met ⁠with ⁠rare disease groups on Wednesday, according to groups ⁠attending and a government official, as the new chief seeks to repair relations with a sector disappointed ​by his predecessor.
    • “Representatives for rare disease organizations including Friends of Cancer Research and the Foundation for Angelman Syndrome Therapeutics are pushing Diamantas for greater certainty and support ‌for treatments for small patient populations, the ‌groups said.
    • “The acting chief is seeking to steady operations and mend fences following Commissioner Marty Makary’s resignation last month. Makary had clashed with the White ⁠House over issues including ⁠vaping products.
    • “Jeff Allen, CEO of Friends of Cancer Research, in a phone interview with Reuters ​following the meeting, described it as a “breath of fresh air.”
  • MedTech Dive relates,
    • “Edwards Lifesciences said it has secured FDA approval for the first surgical valve replacement designed for patients with tricuspid valve disease.
    • “The approval introduces a surgical option for a long-underserved area of structural heart care, extending Edwards’ Resilia tissue technology to the tricuspid position, a spokesperson told MedTech Dive in an email. 
    • “Called Triformis Resilia, the valve has a flattened sewing ring shape that mirrors the native tricuspid valve’s annulus anatomy.”

From the judicial front,

  • STAT News reports,
    • ‘A fourth major health insurer is suing HaloMD over its use of the No Surprises Act’s arbitration process, arguing that the middleman deceived arbitrators by sending them a “sham letter” and misleading price data. 
    • “Highmark Health, a Pennsylvania-based Blue Cross Blue Shield licensee with over 7 million members, claims in a complaint filed June 1 in U.S. District Court in Western Pennsylvania that HaloMD and one of its clients, a neuromonitoring provider called Bromedicon, submitted more than 450 ineligible disputes with the company and won more than $3.9 million. Like the three Blue Cross plans before it, Highmark wants those awards tossed and its money returned.” * * *
    • “Other insurers have so far gotten chilly receptions to their suits. Judges in California and Texas have dismissed similar lawsuits against HaloMD and its provider clients, finding their allegations — that the company deliberately submitted ineligible disputes and won huge payouts anyway — didn’t warrant the court’s review. The rulings don’t bode well for Highmark or outstanding cases in Georgia and Ohio.”

From the public health and medical / Rx research front,

  • The Wall Street Journal reports,
    • “Eating a diet high in ultraprocessed foods is associated with an increased risk of dementia, according to new research, adding to the growing list of health problems linked to foods such as packaged cookies, hot dogs and chips.
    • “In a study published Wednesday in the American Journal of Public Health, the group of people who reported eating the highest amount of ultraprocessed foods had a 58% higher risk of later developing dementia and a 46% increased risk of developing cognitive impairment than those who said they ate the least.” * * *
    • “Nutrition researchers generally define ultraprocessed foods as items containing ingredients that wouldn’t generally be found in a home kitchen, such as emulsifiers—used to improve the texture of food—and high-fructose corn syrup. 
    • “The new study found that diets high in minimally processed foods, such as fresh fruits, vegetables, whole grains, fish and unprocessed meats, were linked to a decreased risk of dementia and cognitive impairment. People who ate the most minimally processed foods had a 41% lower risk of dementia compared with those who ate the least.”
  • and
    • “New research suggests anesthesia may be closer to being in a coma than previously thought, not just a deep sleep.
    • “Researchers compared brain-wave data from anesthetized patients with those awake, asleep or in a coma.
    • “Understanding these brain patterns could help redesign anesthesia to resemble natural sleep, reducing postoperative issues, experts say.”
  • MedPage Today relates,
    • “Deaths of despair — fatalities from drugs, alcohol, and suicide — declined by 16% in 2024, according to a report from Trust for America’s Health.
  • and
    • “Weight loss is known to reduce the need for joint replacement surgery in overweight or obese people with knee osteoarthritis (OA), and glucagon-like peptide-1 (GLP-1) receptor agonists are an established way to lose weight.
    • “This study of health records demonstrated that use of GLP-1 drugs was associated with reduced arthroplasty rates, with longer exposure leading to correspondingly lower rates.
    • “Reasons for initiating GLP-1 drug therapy were not known, however, and weight loss was not tracked over time, so the mechanisms underlying the observed associations remain unknown.”
  • Gastroenterology Advisor tells us,
    • “A baseline colonoscopy among individuals aged 40 to 49 years is associated with a significantly reduced risk for colorectal cancer (CRC), especially for men aged 45 to 49 years, according to study results published in the American Journal of Gastroenterology.” * * *
    • “These findings provide large-scale observational evidence that the risk-reducing association of an early baseline evaluation becomes increasingly apparent over several years of follow-up,” the study authors stated.”
  • Health Day notes,
    • “Scientists may be one step closer to staging Alzheimer’s disease with a simple blood test.
    • “The test could offer a cheaper, less invasive alternative to brain scans and spinal taps now used to diagnose and determine the extent of disease.
    • “Researchers developed a model that uses just two forms of tau protein in the blood to track Alzheimer’s progression. They tried it on more than 1,000 patients, including people who were cognitively unimpaired, patients with mild cognitive impairment, patients with Alzheimer’s dementia and people with other neurodegenerative diseases.
    • “The result: Staging from the blood model closely matched the accuracy of PET brain scans.”
  • and
    • “Population-based screening for early-stage type 1 diabetes identifies most children who progress to clinical type 1 diabetes, with additional cases detected with repeat screening, according to a study published online May 21 in the Journal of the American Medical Association.”

From the U.S. healthcare business and artificial intelligence front,

  • Beckers Payer Issues reports,
    • “Cigna will stop covering GLP-1s for weight loss through its own employee health plan July 1, the company confirmed to Becker’s.
    • “We regularly review our health benefits to ensure they remain sustainable, accessible and aligned with the unique needs of our workforce. As availability has increased and new options have emerged, we’ve made the decision to end our plan’s coverage for GLP-1s for weight loss,” a company spokesperson said. “We remain committed to supporting our employees’ health through a range of weight-management programs and resources.”
    • “The change will not apply to those using GLP-1s for diabetes, the spokesperson said. It also will not apply to Cigna plans beyond its own, a spokesperson confirmed to Reuters, which first reported the development June 2. GLP-1 users for weight loss have until June 30 to obtain refills. 
    • ‘An internal document reviewed by Reuters said employees can pay for these drugs with cash directly through manufacturer websites or TrumpRx. However, that spending would not count toward deductibles. Cigna will continue to cover generic weight-loss drugs that predate GLP-1s, such as phentermine, diethylpropion, benzphetamine and phendimetrazine, according to Reuters.
    • “Cigna joins a wave of healthcare employers cutting back GLP-1 access for their workers as cost pressures mount.”
  • The Wall Street Journal provides “Five Takeaways From the WSJ’s Autism Billing-Abuse Investigation — Insurers’ fraud warnings, a nearly $1 million surprise therapy bill and the back story of a visit to the Brooklyn-based provider the Perfect Child.”
  • MedTech Dive relates,
    • “Medtronic ended its fiscal year on a high note, growing revenue by nearly double digits in its fiscal fourth quarter.
    • “The medtech company brought in $9.8 billion of revenue in the quarter, representing year-over-year growth of nearly 10%. The performance was better than expected, J.P. Morgan analyst Robbie Marcus said in a note to investors.
    • CEO Geoff Martha said Medtronic delivered its strongest annual top-line growth in 10 years.
    • “Through a dynamic macro environment, we have executed, and we’ve executed with discipline to deliver an excellent fiscal ’26 that will continue into fiscal ’27,” Martha told investors Wednesday morning.
    • “The performance was driven by solid sales for its cardiovascular unit and strong growth for businesses within the segment.”
  • The Wall Street Journal inform us,
    • Eli Lilly LLY signed a collaboration and licensing agreement worth up to $1.9 billion with Ascidian Therapeutics to research and develop kidney-disease treatments.
    • “Ascidian, a Boston-based biotechnology company, said Wednesday it granted Eli Lilly exclusive, target-specific rights to its RNA-exon-editing technology for undisclosed kidney-disease targets.
    • “The RNA-exon editors are capable of altering parts of genetic code to repair genetic instructions that cause disease.
    • “Ascidian said it will lead discovery and certain preclinical activities, while Eli Lilly will be responsible for other preclinical work, clinical development, manufacturing and commercialization.
    • “Ascidian is eligible to receive up to $1.9 billion, including an upfront payment, development and commercial milestone payments, and tiered royalties on commercial sales worldwide, it said.”
  • Fierce Healthcare tells us,
    • “Mayo Clinic plans to develop and deploy a frontier AI model specifically designed for healthcare in collaboration with Microsoft. 
    • “The strategic collaboration combines Mayo Clinic’s global healthcare expertise, de-identified clinical health data and longitudinal insights with Microsoft’s advanced AI, cloud engineering and tech capabilities, the companies announced Tuesday.
    • “The two organizations say they are developing a frontier AI model “capable of supporting the broadest scope of clinical reasoning and healthcare use cases,” according to a press release.
    • “The frontier AI model is designed to synthesize diverse clinical data to support earlier diagnoses, more personalized treatment decisions and better patient outcomes. The AI collaboration will make Mayo Clinic’s medical expertise and integrated model of care available to more people when and where they need it, the two organizations said.”
  • Beckers Hospital Review adds,
    • “Washington, D.C.-based Children’s National Hospital has introduced a pediatric AI innovation hub to translate the technology from concept to bedside use.
    • “The partnership with Blacksburg-based Virginia Tech will bring together pediatric clinicians, biomedical researchers and AI specialists to create advancements for what has been an underserved community thus far in the technology’s evolution.
    • “Children have historically been underrepresented in AI research despite having fundamentally different physiology, disease patterns and developmental needs,” said Marius George Linguraru, director of AI research at Children’s National, in a June 2 news release. “We have an opportunity to build pediatric AI the right way from the beginning by developing and validating these technologies specifically for children and within pediatric clinical settings.”
  • Fierce Pharma points out,
    • “Pharma solutions firm Cencora and Gilead Sciences have expanded their longstanding partnership, cutting a deal in which the distribution giant will support access to Gilead’s CAR-T cancer therapies Yescarta and Tecartus.
    • “The collaboration is designed to facilitate more efficient access to the blood cancer therapies, which were developed by Gilead’s CAR-T subsidiary Kite Pharma. 
    • “Under the agreement, Cencora will leverage its substantial distribution infrastructure to bolster cell therapy availability at an “increasing number” of authorized U.S. treatment centers, including health systems and community oncology practices, according to a June 2 release.” 
  • HR Dive lets us know,
    • “Workers over age 55 make up almost a quarter of the workforce (23.2%), according to a report from MyPerfectResume. Moreover, according to researchers, the growth of the older workforce outpaces the general workforce. Likewise, the share of workers over age 65 increased by more than 40%, according to the report.”

Cybersecurity Saturday

From the War with Iran front

  • SC Media reports,
    • The Iran state-sponsored threat group Nimbus Manticore conducted attacks during the U.S.-Israel military campaign Operation Epic Fury targeting the U.S. aviation industry and others for deployment of a new AI-assisted backdoor called “MiniFast,” Check Point Research reported Friday [May 22].
    • The attacks, seen throughout the 2026 Iran war in March, followed previous campaigns throughout February using an older backdoor called MiniJunk. Both waves of attacks utilized career-themed phishing lures for initial access and AppDomain hijacking techniques to execute malicious payloads. * * *
    • Check Point said Nimbus Manticore has shifted tactics in its most recent attacks, seen after the Iran war ceasefire in April, using search engine optimization (SEO) poisoning to impersonate the software Oracle SQL Developer and spread MiniFast.
    • “MiniFast, the successor of MiniJunk, enables extensive control of the victim’s machine through API-based communications with the attacker’s command-and-control (C2) server. As in previous attacks, Nimbus Manticore used career-themed phishing lures to spread MiniFast during Operation Epic Fury, specifically impersonating a U.S. domestic airline.”
  • Cybersecurity Dive adds,
    • “Iranian government-linked hackers sabotaged the computer infrastructure of Los Angeles’s transit system by using access to a virtual machine to delete critical operating-system data, the Israeli cybersecurity firm Gambit Security said in a report published on Tuesday.
    • “The same threat actor also conducted data-wiping attacks on the South Florida Regional Transportation Authority, the connected-vehicle technology firm Agnik and a Saudi Arabian construction company that handles critical infrastructure projects, according to the report.
    • “Gambit dismissed the hackers’ claims of being a new pro-Iranian hacktivist gang, instead attributing their operations to Black Shadow, a group that the Israeli government and private security firms have linked to Iran’s Ministry of Intelligence and Security.”

From the Project Glasswing front,

  • Bleeping Computer reports,
    • “Anthropic has confirmed that it plans to bring Mythos-class models to the general public after delaying the rollout due to security risks to public and private software.” * * *
    • In a blog post, Anthropic confirmed that it plans to release Mythos-class models to the public in the coming weeks, but it has not committed to a specific timeframe.
    • “We’re making swift progress on developing these safeguards and expect to be able to bring Mythos-class models to all our customers in the coming weeks,” Anthropic said in a blog post.
    • “Anthropic says it is already allowing a small number of organizations to use Claude Mythos preview for cybersecurity work, but it is unclear if the same model will be rolled out to the public.
    • “According to the company, the Mythos model shows major improvements in code reasoning and autonomy, far above Claude’s current flagship model, Opus 4.8.”

From the cybersecurity policy and law enforcement front,

  • Beckers Health IT reports,
    • “House Republican leaders are calling on FBI Director Kash Patel to act aggressively to stop cybercriminal groups targeting the healthcare industry.
    • “In a May 28 letter to Mr. Patel, the lawmakers pointed to the sharp increase in healthcare ransomware attacks and data breaches over the past several years that jeopardize patient safety and cost hospitals and health systems millions of dollars.
    • “We strongly encourage continued collaboration between the FBI and healthcare stakeholders, including through public-private partnerships, streamlined reporting mechanisms, and clear guidance that enables hospitals — large and small — to participate effectively in information-sharing initiatives without undue burden,” the legislators wrote.”
  • Cyberscoop relates,
    • “House subcommittee will hold an open hearing next week on how frontier artificial intelligence models are shaping the cybersecurity landscape, for good and for ill.
    • “The June 4 hearing will be the second the Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection has held that was focused at least in part on the subject, following a similar hearing held in December. But unlike at that joint subcommittee hearing, where members also examined other emerging technologies, AI takes center stage next week. * * *
    • “The witnesses will be Sandra Joyce, vice president of Google Threat Intelligence; Chris Meserole, executive director of the Frontier Model Forum; Jack Cable, a former top official at the Cybersecurity and Infrastructure Security Agency and now chief executive officer and co-founder of Corridor Security; and Matthew Guariglia, senior policy analyst at the Electronic Frontier Foundation.”
  • and
    • “The White House has updated rules for federal agencies to keep logs of significant cyber activities in their networks, touting it as a measure to cut back on red tape and focus on how cybersecurity risks have evolved.
    • “The Office of Management and Budget memorandum, released Friday, replaces a 2021 memo signed by then-President Joe Biden. It continues revisions that President Donald Trump has made to federal cybersecurity guidance under his predecessor.
    • “The new memo, M-26-14, nods at the intentions of the earlier memo, M-21-31, saying that “Implementation of that memorandum improved foundational capabilities across agencies” to establish standards for logging and improve agencies’ record-keeping for the purposes of detecting and responding to cyberattacks.” * * *
    • There have been calls for the idea of updating the 2021 memo, and one observer praised the new version to CyberScoop. Another analyst, however, questioned how much harm the Trump administration might do by rescinding the earlier memo before having all of the new memo’s directives in place.
    • “One directive is for the Cybersecurity and Infrastructure Security Agency to develop a “logging reference architecture” within 90 days that prioritizes the objectives of conducting continuous event monitoring and enabling investigations of forensic analysis after a known or suspected compromise.
    • “Agencies would have another 90 days to submit a logging plan that adheres to those principles. The memo also establishes a new model for measuring agency progress in implementation. Multiple government watchdogs have concluded that agencies weren’t meeting the prior memo’s benchmarks.”
  • Federal News Network adds,
    • “Acting Federal Chief Information Security Officer Mike Duffy wrote on LinkedIn that the new policy “focuses agencies on what matters most: continuous visibility, rapid detection, effective threat hunting and actionable response capabilities.”
    • “And given the recent discovery by Claude’s Mythos of thousands of zero day vulnerabilities in systems that were previously known or not addressed, agencies and industry are being forced to figure out how best to strengthen their partnership against these AI-fueled attacks.
    • “Nick Andersen, the acting director of the Cybersecurity and Infrastructure Security Agency, said he has deep concerns specifically about one type of technology when it comes to cybersecurity vulnerabilities.
    • “The open source community is one that I’m particularly worried about when we start to think about the rapid escalation of vulnerability discovery. But it is going to result in us having to make some really, really hard decisions on the level of investment that’s going to be required,” Andersen said on May 21 at the Cyber Innovation Summit sponsored by the National Security Institute at George Mason University’s Antonin Scalia Law School.”
  • Cyberscoop cautions,
    • “A Department of Commerce inspector general report released Thursday [May 28] found that the National Institute of Standards and Technology has mismanaged a critical cybersecurity vulnerability database through poor planning, inefficient operations, duplicate federal programs, and failure to communicate with users.
    • “The National Vulnerability Database, maintained by NIST since 2005, collects information about computer security flaws and adds details like severity ratings and affected products. This information helps cybersecurity professionals across government and the private sector decide which security problems to fix first. In February 2024, the database’s enrichment contract lapsed, creating a backlog of unprocessed security flaws that has only grown worse.
    • “The report identified the lack of strategic planning as a core problem. NIST leaders admitted they had no long-term plan for clearing the backlog, even as it grew from about 13,000 unprocessed security flaws in June 2024 to over 27,000 by the end of 2025.
  • The American Hospital Association lets us know,
    • “The Cybersecurity and Infrastructure Security Agency May 26 announced a revised schedule for its series of virtual town hall meetings for public input on proposed rulemaking for the Cyber Incident Reporting for Critical Infrastructure Act of 2022. The meetings will now begin June 15. They were originally scheduled for March and April but were not held due to the partial shutdown of the Department of Homeland Security. CISA seeks input to finalize a proposed rule originally issued in March 2024. The proposed rule would require critical infrastructure organizations, including hospitals and health systems, to report certain cyber incidents to CISA within 72 hours and ransom payments within 24 hours, among other mandates. The AHA commented on the rule, calling certain proposed requirements redundant to those from other federal agencies and saying that they may add unnecessary burden to hospitals working to ensure access to needed services during cybersecurity incident response.”
  • CISA notes,
    • “The revised [town hall meeting] schedule is available in the Federal Register. Interested stakeholders may register for the town hall meetings at www.cisa.gov/circia. Any changes or updates to the town halls will be available on www.cisa.gov/circia
  • Cybersecurity Dive tells us,
    • “The Cybersecurity and Infrastructure Security Agency on Thursday [May 28] warned that hackers targeted software development pipelines in recent weeks and urged security teams to check for potential compromise of their environments. 
    • “CISA referenced two recent campaigns, including the “Megalodon” supply chain attack and a GitHub compromise through a malicious Nx Console Visual Studio Code extension.” * * *
    • “CISA is urging security teams to monitor and conduct audits on their workflow files and activity from contributors. Attention should be paid to suspicious pull requests or direct commits, specifically any coming from an automated account. 
    • “Security teams should revert any unauthorized changes, CISA advised, and check for anything that came in after May 18. 
    • ‘If a compromise is found in connection with a previously compromised Nx Console or GitHub account, CISA suggests the following:
      • “Undertake a forensics review of continuous integration/continuous delivery logs, impacted developer machines and cloud audit trails. 
      • “Rotate or revoke secrets, including credentials, tokens and secrets related to CI/CD pipelines.”
  • The Wall Street Journal informs us,
    • “The FBI’s latest report on internet crime complaints shows cybercriminals are using AI, causing $893 million in losses.
    • “Cryptocurrency investment fraud was the largest source of financial losses, totaling $7.2 billion last year.
    • “Government-impersonation scams increased to over 32,000 complaints last year, aided by AI for sophistication.”
  • Bleeping Computer points out,
    • “A North Carolina man was sentenced to more than 10 years in prison for selling the personal information of over 7 million elderly Americans to Jamaican scammers.
    • “57-year-old Troy Murray (who used the Steve Dixon pseudonym) pleaded guilty in January 2026 to one count of conspiracy to commit wire fraud and was sentenced Thursday to 121 months in prison, three years of supervised release, and ordered to forfeit $5,2 million.
    • ‘Prosecutors said that Murray’s alias was so widely known among Jamaican scammers that it was referenced in a 2022 song lyric by a Jamaican musical artist.
  • and
    • A Romanian national was sentenced this week to 56 months in federal prison for breaking into an Oregon state government computer network and fr cyberattacks targeting dozens of other U.S. victims.
    • 46-year-old Catalin Dragomir (who used the online handle “inthematrixl”) of Constanta, Romania, pleaded guilty on February 19 to one count of aggravated identity theft and one count of obtaining information from a protected computer.
    • The charges carried a maximum of five years in prison for the computer intrusion count, followed by a mandatory consecutive two-year term for the identity theft count, a fine of $250,000, and three years’ supervised release. The court also ordered Dragomir to forfeit approximately 23 Monero (XMR), a cryptocurrency, valued at roughly $8,500.

From the cybersecurity breaches and vulnerabilities front,

  • Bleeping Computer reports,
    • “The ShinyHunters extortion gang stole personal information from 4.9 million accounts after hacking the U.S. telecom giant Charter Communications in early April, according to data breach notification service Have I Been Pwned.
      “Charter has over 92,000 employees and provides internet, mobile, video, and voice services to more than 32 million customers and over 57 million homes in 41 states across the U.S. through its Spectrum brand.
      “The company confirmed the breach earlier this week, saying that the attackers did not steal sensitive personal customer information and that it had alerted authorities about the incident.”
    • * * * “After the company refused to pay the ransom demanded by ShinyHunters to have the stolen data returned and destroyed, the cybercrime group leaked the documents stolen from Charter’s Salesforce instance on their dark web leak site.
    • “Have I Been Pwned analyzed the leaked data and confirmed that the incident affected 4.9 million accounts, whose names, email addresses, job titles, phone numbers, and physical addresses were stolen.
    • “The group later published the data, which exposed 4.9M unique email addresses along with names, phone numbers and physical addresses,” Have I Been Pwned said. “A subset of approximately 85k records originating from an internal employee directory also included job titles.”
    • “The FBI has recently advised ShinyHunters’ victims not to give in to the gang’s ransom demands, after previously warning that doing so cannot guarantee that threat actors won’t attempt to sell the stolen data to other cybercriminals or extort them again.
  • and
    • “Threat actors are abusing ChatGPT’s content-sharing feature to display fake OpenAI outage pages that direct users to download malware disguised as the ChatGPT desktop application.
    • “The “LLMShare” campaign, discovered by Push Security, uses Google ads to direct users searching for ChatGPT to a malicious shared ChatGPT page hosted on chatgpt.com, allowing the attack to be delivered through a legitimate OpenAI domain.
    • “Users who click the advertisement are taken to a legitimate ChatGPT shared page, but instead of seeing a chat conversation, they are presented with a rendered outage notice claiming the web version is unavailable and that they should download the desktop application instead.”
  • Security Week relates,
    • “The infamous extortion gang Silent Ransom Group (SRG) has been impersonating IT support in a fresh campaign targeting law firms, the FBI warns.
    • “Active since at least 2022, SRG has been targeting law firms in the US since at least 2023, mainly through callback phishing emails and social engineering calls, claiming to aid victims in canceling subscription fees.
    • In a May 2025 alert, the FBI warned of SRG’s phishing emails containing links to remote access software that allowed the attackers to quickly exfiltrate data from the victims’ systems.
    • “In attacks observed this year, the threat actor has updated its tactics, now posing as an employee from the victim’s IT department.” * * *
    • “To prevent SRG attacks, organizations are advised to verify the credentials of all individuals with access to company assets, limit access to sensitive data, train employees to identify phishing attempts, and establish clear policies for IT support communication and authentication.
    • “Backing up all company data, implementing phishing-resistant multi-factor authentication (MFA), blocking access to commonly exploited ports, and disabling remote access and permissions for external drive installation should also prevent intrusions and the loss of sensitive and confidential data.”
  • Cybersecurity Dive tells us,
    • “Nearly all executives are confident their employees are using AI responsibly, but shadow AI is creeping its way into organizations, an Okta survey released Wednesday found. More than half of employeesreported they’re using personal AI tools without approval, the security platform provider learned in surveying nearly 300 tech executives and 500 knowledge workers along with market research firm Apprize360.
    • “Workers reported using unapproved AI tools for productivity reasons, saying they allow the tools access to internal messages, HR-related information and confidential company documents. The practice is heightening security risks, as 58% of executives said their organization had an AI-related security incident or a close call last year, according to the report. 
    • “Lack of clarity in AI usage policies or banning personal AI tools can actually increase shadow AI use, said Harish Peri, Okta’s SVP and GM for AI security, in an email. “By taking a more collaborative approach with employees, leaders can offer sanctioned, enterprise-grade alternatives to the unapproved tools that teams are using.”

From the ransomware front,

  • Industrial Cyber reports,
    • “The Federal Bureau of Investigation (FBI) disclosed that about 25 ransomware groups used a criminal VPN service known as ‘First VPN Service’ to conduct network intrusions, scanning operations, botnets, denial-of-service attacks, and scams. The service has been active since around 2014 across 32 exit nodes in 27 countries. It affects organizations by enabling ransomware groups and other cybercriminal actors to conduct network intrusions, reconnaissance, credential abuse, denial-of-service attacks, and broader malicious operations.
    • “At least 25 ransomware groups, such as Avaddon Ransomware, have used First VPN Service infrastructure to perform network reconnaissance and intrusions,” the FBI wrotein a recent FLASH advisory. “First VPN Service IP addresses have been used for scanning activity, botnets, denial of service attacks, scams, and hacking. First VPN Service was almost exclusively advertised in known criminal dark web forums such as Exploit[.]in and XSS[.]is, two of the most prominent Russian-language online forums which provide marketplaces for cyber criminals to buy and sell unauthorized access to computer systems, stolen personal identifying information, hacking tools, and contraband. This reporting applies solely to the First VPN Service and does not extend to other VPN providers with similar naming.” 
    • “The revelation came alongside a coordinated international takedown of the service, led by French and Dutch cybercrime units with support from Ukraine, the U.K., Switzerland, and Luxembourg. It follows from the findings that the VPN was marketed almost exclusively on prominent Russian-language dark web forums used by cybercriminals to trade stolen data, hacking tools, and unauthorized access to systems.”
  • Morphisec tells us “How AI is Changing Ransomware — and Why It’s Faster, Smarter, and Harder to Detect.” 
    • “AI-driven ransomware is still in its early stages, but the direction is clear. Threats are becoming:   
      • “faster  
      • “more adaptive
      • “more autonomous  
      • “harder to observe  
      • “increasingly resistant to detection    
    • “Organizations that continue relying solely on reactive security models will face growing exposure as attack timelines shrink, and visibility gaps expand. The future of cybersecurity will not be defined by who can detect threats fastest. It will be defined by who can prevent them from executing at all.”   
  • Tech Radar adds,
    • “There is a glaring misconception at the heart of cybersecurity that cyber-attacks are targeted at specific organizations or sectors. But while certain sectors do receive more than their fair share of attacks, this isn’t due to deliberate targeting; like any business, it’s driven by money.
    • “Threat groups are largely driven by financial gain, with actors looking to get the most ‘bang for their buck’. Targeting vulnerabilities that don’t just give them access to one organization, but multiple, to grow their potential revenue opportunities.
    • “And at the moment, organizations are leaving far too many of these vulnerabilities open for exploitation.”

Cybersecurity business and defenses front,

  • Cybersecurity Dive reports,
    • “IBM will spend $5 billion to help find and fix vulnerabilities in open-source software packages used throughout the business world, the company announced on Thursday [May 28].
    • “Through Project Lightwell, IBM will create “a trusted enterprise clearinghouse combined with a global force of engineers to identify and fix vulnerabilities at scale,” using AI to validate and test the patches before deployment, the company said. Businesses will be able to subscribe to the patching program for automated deployment of fixes that integrates with their existing life cycle management processes.
    • “Open source is the backbone of today’s digital economy and the foundation of modern AI, and we are at an inflection point in how it is built, secured, and scaled,” IBM CEO Arvind Krishna said in a statement. “This is about strengthening trust in the systems that power business, government, and society.”
  • Security Week relates,
    • “Google Cloud this week announced an always-on autonomous platform designed to protect enterprises from the rising wave of AI-powered cyberattacks.
    • “The new Google AI Threat Defense cybersecurity solution leverages AI to identify machine-powered threats faster and stop them before they can do harm.
    • “According to Google, the platform continuously prioritizes critical real-world risks and can help organizations implement defenses that predict attack paths and proactively deploy remediation.
    • “Google AI Threat Defense combines Mandiant’s frontline and incident response experience with Wiz’s cloud security platform (recently acquired by Google) and Gemini’s reasoning and code remediation capabilities powered by Gemini and CodeMender.
    • “By connecting real-world exposure directly to autonomously creating and prioritizing patching, AI Threat Defense helps organizations actively predict attack paths, prioritize the most significant threats, and deploy verified fixes faster than adversaries can exploit them,” Google says.”
  • and
    • “Anthropic has announced two new security features for its Claude AI: a self-hosted sandbox and a new security guidance plugin.
    • “The sandbox, currently in public beta, was announced at Anthorpic’s Code w/ Claude event in London this week.
    • “According to the company, Claude Managed Agents can now operate in a user-controlled sandbox connected to the user’s private MPC servers. 
    • “Tool execution moves to an environment you configure—your own infrastructure or a managed provider like Cloudflare, Daytona, Modal, or Vercel—while the agent loop that handles orchestration, context management, and error recovery stays on Anthropic’s infrastructure,” Anthropic explained. 
    • “It added, “Your network policies, audit logging, and security tooling apply, files and repositories don’t leave your perimeter, and you control compute sizing and the runtime image for compute-heavy work.”
    • “Separately, the company unveiled a security guidance plugin for Claude Code, designed to help developers detect and fix vulnerabilities as they write code.”
  • Cyberscoop informs us,
    • “CrowdStrike has dismantled the Glassworm botnet in an operation aided by Google and Shadowserver, stripping the operators’ access to infrastructure that helped threat actors infect hundreds of pieces of open-source software with malware since early 2025, the company said Tuesday [May 26]. 
    • “The coordinated effort involved the simultaneous takedown of four attacker-controlled servers that were designed to obscure the botnet’s operations and remain resilient against disruptions.
    • “CrowdStrike and partners took down infrastructure, severed access to the botnet’s most critical services, impeded operation momentum and slowed the attackers’ ability to scale, Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told CyberScoop.”
  • and
    • “Security researchers chained together five separate weaknesses in the popular workflow automation service Zapier that, if first discovered by a malicious actor, could have granted access to millions of user accounts and the systems those accounts connect to.
    • :The flaws, disclosed by security firm Token Security, did not require malware or insider access. The only prerequisite, according to the company’s report, was a free Zapier account. From there, researchers chained together weaknesses that, if taken individually, would have looked routine, but together opened a path to one of the most widely used services of the modern internet.
    • “Zapier’s software can be configured to move data between email, customer-relationship tools, payment processors, calendars, code repositories and thousands of other applications. Zapier says it supports more than 8,000 third-party integrations and has millions of users, which means breaking into Zapier could escalate into a wide-ranging supply-chain attack.” * * *
    • “The episode lands at a moment when automation platforms and artificial-intelligence tools are increasingly being granted the standing authority to act on behalf of users across dozens of services at once. Token Security’s researchers argued that the weaknesses they found were not unique to Zapier. Each link in the chain, they said, was a well-documented kind of mistake. The vulnerability was the chain itself, and the same pattern, they warned, almost certainly exists at other companies that have not yet looked.
    • “Zapier says the issues have been fixed and no further action is required. But the researchers suggested organizations with heightened sensitivity review their automation logs for anything they did not create, and consider reauthorizing Zapier connections to particularly sensitive systems.
    • “You can read the full research report on Token Security’s website.” 
  • Tech Target points out
    • “The unified platform versus best-of-breed tools debate continues as security teams struggle with integration challenges, alert fatigue and limited resources. Does buying software from individual vendors still make sense, or does that approach only further complicate today’s distributed networks? The pressure is prompting a fresh look at unified security platforms as a way to reduce complexity and costs, improve visibility and regain control.”
  • An SC Media commentator identifies “seven identity security best practices for the Agentic AI era.”
    • “Execute regular identity security risk assessments: Leverage tools that can clearly show what AI agents operate in our environment, including those that are operating as shadow IT. This analysis should put risks in clear context, including agent security posture, and potential escalation paths.
    • Encrypt credentials: Put them in a secure vault, with automatic key rotation to make it harder to steal or reuse valid credentials.
    • Restrict remote access to systems: Use leverage tooling that can perform automated credential injection from the company’s vaults to prevent adversary-in-the-middle attacks.
    • Use workload identity to avoid long-lived tokens: Also use scoped permissions, whether OAuth-based or otherwise, to reduce the “blast radius” of stolen credentials.
    • Limit permissions on endpoints with endpoint privilege management tools: Default permissions to “standard user” and set up policies that limit what local agents can do on those systems. Remove standing policies and replace them with JIT or time-limited policies and permissions.
    • “Implement IP allowlisting: This will reject AI agent requests coming from non-authorized locations.
    • Log and audit all privileged behavior: Do this in all systems, whether that’s through tools such as session logs, shipping event logs to a SIEM, or using anomalous behavior analysis tools in the SOC.”
  • Here is a link to Dark Reading’s CISO Corner.