Cybersecurity Saturday

Cybersecurity Saturday

From the Iranian war front,

  • Cybersecurity Dive reports,
    • “A threat group linked to Iranian intelligence has been running a months-long false-flag operation to hack organizations in the U.S. and other countries under the guise of a criminal ransomware group, according to a report released Wednesday [May 6] by researchers at Rapid7. 
    • “The state-sponsored threat group, tracked as MuddyWater, operated a social engineering campaign beginning in early 2026 that abused Microsoft Teams to harvest credentials and bypass multifactor authentication. 
    • “The attacks were made to look as if they were the work of Chaos, a ransomware-as-a-service group that has been active since 2025. Researchers said the false flag creates ambiguity that could affect how security teams investigate an intrusion. 
    • “If an operation looks like ransomware, defenders may initially treat it as financially motivated cybercrime rather than a state-linked operation,” Christiaan Beek, vice president of cyber intelligence at Rapid7, told Cybersecurity Dive. “That can slow attribution, complicate response, and give the actor plausible deniability.”

From the cybersecurity policy and law enforcement front,

  • Dark Reading reports,
    • “It’s been a brutal 16 months since the Cybersecurity and Infrastructure Security Agency (CISA) has had a Senate-confirmed director. Now, a new name has bubbled up as a possible pick to take over the beleaguered agency: Tom Parker, a low-key, British-born cybersecurity expert known for business savvy, technical expertise, and decades of focus on the delicate economics of cybercrime and cyber defense. 
    • “Reports say that although he has not yet been officially nominated, Parker is a contender to get the nod from new Department of Homeland Security Secretary, Markwayne Mullin. A request for comment from Dark Reading to DHS was referred to the White House, which has not yet responded. 
    • “Parker however tells Dark Reading that despite recent reporting, he has not had any “direct engagement” with the administration on taking on the role, but would welcome the conversation.” 
  • Federal News Network adds,
    • “The Office of Management and Budget (OMB) picked a long-time federal technology manager to take over as the deputy federal CIO. Thomas Flagg is set to assume that role. Federal News Network has learned that Federal CIO Greg Barbaccia made the announcement to agency CIOs yesterday. Flagg, who is the Education Department CIO, will replace Drew Mykelgard, who left in September to join the private sector after three-plus years in the role. Barbaccia wrote in his email that Flagg stood out among a large number of candidates because of the depth and seriousness of his experience across multiple technology leadership roles. Flagg also worked at the Labor Department for 11 years before moving to Education in 2025. 
  • Cybersecurity Dive reports,
    • “The Cybersecurity and Infrastructure Security Agency (CISA) wants to help critical infrastructure operators keep their systems running during a major cyberattack or other serious incident.
    • “CISA on Tuesday [May 5, 2026,] released guidance as part of an international “CI Fortify” initiative focused on activities that infrastructure operators can take to isolate the effects of a cyber intrusion and recover from them.
    • “In a geopolitical crisis, the critical infrastructure organizations Americans rely on must be able to continue delivering—at a minimum—crucial services,” acting CISA Director Nick Andersen said in a statement. “They must be able to isolate vital systems from harm, continue operating in that isolated state, and quickly recover any systems that an adversary may successfully compromise.
    • “The new guidance, modeled on advice that the Australian government published in 2025, comes as intelligence agencies warn that China might sabotage Western critical infrastructure to keep the U.S. and its allies from interfering with Beijing’s long-rumored invasion of Taiwan. China’s Volt Typhoon hacking campaign indicated that Beijing had already begun laying the groundwork for such disruption, prompting U.S. officials to step up warnings about the dangers of interdependencies in operational technology.”
  • and
    • “The U.S. government’s AI security center will evaluate frontier models from Google, Microsoft and xAI before their release to determine whether the models’ advanced capabilities pose cybersecurity risks.
    • The newly announced plan for the National Institute of Standards and Technology’s (NIST) Center for AI Standards and Innovation (CAISI) to conduct “pre-deployment evaluations” represents the U.S. government’s most significant attempt yet to get ahead of security threats from powerful AI systems.
    • “Independent, rigorous measurement science is essential to understanding frontier AI and its national security implications,” CAISI Director Chris Fall said in a statement. “These expanded industry collaborations help us scale our work in the public interest at a critical moment.”
  • The Wall Street Journal adds,
    • “The White House is weighing a new government-review process for artificial-intelligence tools that the government deems to pose cybersecurity risks, a move that could further expand its oversight of AI in response to Anthropic’s powerful Mythos model.
    • “The White House is considering a cybersecurity-focused executive order that could include formalizing a government oversight group to create standards for the most powerful AI models, such as Mythos, people familiar with the discussions said. The goal is to protect consumers and businesses from cyberattacks and other disruptions caused by the premature release of such models, and a range of ideas are being considered, the people said. 
    • ‘The internal conversations show how Mythos has forced the Trump administration to recalibrate aspects of its laissez-faire approach to AI oversight. The administration has unwound Biden administration efforts to implement safety standards and attacked states trying to impose regulations, hoping to ease constraints tech companies face in rolling out new models.” 
  • Cyberscoop notes,
    • “The Cybersecurity and Infrastructure Security Agency has gotten “by far” the biggest gains from artificial intelligence automation in its security operations unit to help analysts sift through threats, but it’s also proven valuable elsewhere within the agency, CISA officials said Tuesday.
    • “It’s “really allowing those analysts to do triage very fast, so they focus on what matters versus the noise,” Tammy Barbour, acting chief of application management at CISA, said. “They’re able to do a lot of real-time, quick looks before events happen in most places.”
    • “Barbour, speaking at the UiPath FUSION Public Sector event hosted by Scoop News Group, said automation has also been a boon to CISA’s Technology Operations Center.
    • “The top analysts are able to quickly respond to customers who are reaching out to talk and asking questions, and be able to get real-time efficiencies with that,” she said.”
  • Security Week tells us,
    • “A Latvian member of the Karakurt ransomware gang was sentenced to 8.5 years in prison in the US for his involvement in extorting victims.
    • “The individual, Deniss Zolotarjovs, 35, of Latvia, was arrested in Georgia in December 2023 and extradited to the US in August 2024. He pleaded guilty in July 2025.
    • “Associated with the infamous Conti group and also known as TommyLeaks, Schoolboys Ransomware Gang, and Blockbit, Karakurt was one of the most notorious ransomware groups half a decade ago.”
  • Cyberscoop informs us,
    • “Two U.S. nationals were sentenced to 18 months in prison for running laptop farms that facilitated North Korea’s expansive remote IT workers scheme, the Justice Department said Wednesday.
    • “Matthew Issac Knoot and Erick Ntekereze Prince both received and hosted laptops at their residences to dupe U.S. companies into thinking remote IT workers they hired were located in the country. The pair’s separate schemes impacted almost 70 U.S. companies and generated a combined $1.2 million in revenue for the North Korean regime.”
  • Bleeping Computer adds,
    • “A 34-year-old Virginia man was found guilty of conspiring to destroy dozens of government databases after getting fired from his job as a federal contractor.
    • “In 2016, Sohaib Akhter and his twin brother and co-defendant Muneeb Akhter were also sentenced to several years in prison after pleading guilty to accessing U.S. State Department systems without authorization and stealing the personal information of dozens of co-workers and a federal law enforcement agent who was investigating their crimes.
    • After serving their sentences, the two brothers were rehired as government contractors by a company that worked with more than 45 federal agencies and hosted government data on servers in Ashburn.
    • “When the company discovered Sohaib Akhter’s felony conviction, it terminated both brothers’ employment during an online remote meeting on Feb. 18, 2025,” the Justice Department said. “Immediately after being fired during this meeting, the brothers sought to harm their employer and its U.S. government customers by accessing computers without authorization, write-protecting databases, deleting databases, and destroying evidence of their unlawful activities.”

From the cybersecurity breaches and vulnerabilities front,

  • Cyberscoop reports,
    • “A defense technology company with Department of Defense contracts exposed user records and military training materials through API endpoints that lacked meaningful authorization checks, according to an account published by Strix, an open-source autonomous security testing project.
    • “The issue affected Schemata, an AI-powered virtual training platform used in military and defense settings. According to Strix, an ordinary low-privilege account was able to access data across multiple tenants, including user listings, organization records, course information, training metadata and direct links to documents hosted on the Schemata’s Amazon Web Services instances.”
  • CISA added three known exploited vulnerabilities (KVES) to its catalog this week.
  • SC Media points out,
    • “The Cybersecurity and Infrastructure Security Agency (CISA) is reportedly considering shortening remediation deadlines for vulnerabilities added to the Known Exploited Vulnerabilities catalog, according to Reuters.
    • “Citing two sources familiar with the matter, Reuters reported Friday [May 1, 2026] that CISA Acting Director Nick Anderson and U.S. National Cyber Director Sean Cairncross were discussing proposals to cut KEV deadlines for federal civilian executive branch agencies from an average of two to three weeks to just three days.
    • The discussion was reportedly spurred by the emergence of advanced AI tools such as Anthropic’s Claude Mythos and OpenAI’s GPT-5.4-Cyber that have the potential to identify and exploit flaws at unprecedented speed.
    • A CISA spokesperson declined to comment on whether such discussions were taking place or whether a decision had been made.
  • Security Week lets us know,
    • “Microsoft has warned organizations in the United States about a sophisticated phishing campaign that uses a “code of conduct review” theme to lure victims to a malicious website.
    • “The tech giant observed more than 35,000 attempts between April 14 and 16. The malicious emails were received by users across roughly 13,000 organizations in 26 countries, but 92% of the targets were in the US. 
    • “Many of the messages were received by users in the healthcare and life sciences, financial services, professional services, and technology and software sectors.” * * *
    • “Enterprises at risk of being targeted in this and similar phishing campaigns have been provided with recommendations for mitigating attacks, as well as threat-hunting queries and indicators of compromise (IoCs).”
  • Cybersecurity Dive relates,
    • “Hackers could exploit vulnerabilities in Progress Software’s MOVEit Automation tool to improperly access businesses’ data, the software maker said in a recent advisory.
    • “Exploitation of the two flaws — an authentication-bypass vulnerability tracked as CVE-2026-4670 and a privilege-escalation vulnerability tracked as CVE-2026-5174 — could “lead to unauthorized access, administrative control, and data exposure,” according to Progress Software’s advisory.
    • “The newly patched flaws represent serious security weaknesses in a widely used managed-file-transfer program that helps organizations transfer data between self-hosted servers, cloud platforms and third-party vendors.
    • “Progress Software urged customers to upgrade to the latest version of the software, which fixes both vulnerabilities.”
  • Per Dark Reading,
    • “Researchers have spotted a modular cloud worm that will clear you of any infections by the dangerous supply chain attacker “TeamPCP,” free of charge. The catch: It wants your secrets.
    • “SentinelLabs named the program “PCPJack” in a new blog post,and described it as “well developed” — effective, with a few inexplicable but superficial oddities. Affected organizations stand to lose secrets associated with their cloud, container, developer, productivity, and financial services, unless they implement cloud security best practices, concealing passwords and keys behind vaults and multifactor checks.”
  • Per Bleeping Computer,
    • “A fake version for the Claude AI website offers a malicious Claude-Pro Relay download that pushes a previously undocumented backdoor for Windows named Beagle.
    • “The threat actor advertises Claude-Pro as a “high-performance relay service designed specifically for Claude-Code” developers.
    • “The fake website is a simplistic attempt at mimicking the legitimate site for the popular Claude large language model (LLM) and an AI assistant, using similar colors and fonts.
    • “However, the facade falls apart when it comes to links, as they are mere redirects to the front page, researchers at cybersecurity company Sophos say in a report today.”

From the ransomware front,

  • Edscoop reports,
    • “ShinyHunters, the prolific criminal hacker and extortion group, on Thursday [May 7, 2026] provided additional details about its recent breach of Canvas, the learning management system developed by Instructure, with hopes of coaxing payments from some of the nearly 9,000 educational institutions it claims are affected.
    • “After announcing on May 1 that it had exfiltrated several terabytes of data containing the personal information of 275 million users, it announced a deadline of Thursday [May 7] before “everything is leaked and there will be no chance at a negociation for anyone. Instructure has not even bothered speaking to us to understand the situation or to even negociate with us to prevent the release of this data. Our demand was not even as high as you might think it is.”
    • “On Thursday, the group presented to Canvas users a second message and extended the deadline for payment until May 12. “ShinyHunters has breached Instructure (again). Instead of contacting us to resolve it they ignored us and did some ‘security patches’,” the note reads. The group advised affected schools to consult security professionals and use the Tox messaging protocol to negotiate a “settlement.”
    • “The attached list of affected institutions includes many school districts, along with well-known universities, including Cambridge, Columbia, Cornell, Georgetown, Harvard, MIT and UC Berkeley.”
  • The Wall Street Journal adds on May 8, 2026,
    • Canvas, one of the most widely used education apps, said it had restored services after pulling the plug in the middle of finals week at many colleges to deal with a cybersecurity incident.
    • From Berkeley to Harvard, students at thousands of colleges and high schools temporarily lost access to their coursework on Thursday afternoon after a hacking group posted a ransom note on the platform.  
    • The company behind Canvas, Instructure Inc., said the intruders had accessed some customer data, including names, email addresses and student ID numbers, as well as messages between Canvas users. The company said it hasn’t found that passwords or financial information were involved. The investigation is ongoing and it has notified the Federal Bureau of Investigation.
    • “We have since confirmed that the unauthorized actor carried out this activity by exploiting an issue related to our Free-For-Teacher accounts,” the company said on its website. “As a result, we have made the difficult decision to temporarily shut down Free-For-Teacher accounts.” 
  • Security Week relates,
    • “The RansomHouse ransomware group has taken credit for the recent attack on the cybersecurity firm Trellix.
    • “The Trellix hack came to light this week when the company announced on its website that part of its source code repository had been breached.
    • “Based on our investigation to date, we have found no evidence that our source code release or distribution process was affected, or that our source code has been exploited,” the company stated.
    • “No other information has been shared by Trellix, but it has promised to release additional details after it completes its investigation.”
  • Industrial Cyber tells us,
    • “New data from BlackFog shows ransomware activity remaining structurally elevated, with attacks continuing to operate at high volume while expanding their data-centric focus across both disclosed and undisclosed incidents. The analysis highlights that threat actors are increasingly prioritising data theft and extortion over traditional encryption-only disruption, reflecting a broader shift in how ransomware operations monetise compromise. It also underscores that incidents continue to span multiple sectors and geographies, reinforcing that ransomware is no longer episodic but persistent, industrialised, and embedded across the global threat landscape.
    • “A total of 264 publicly disclosed ransomware attacks were recorded, representing a 15% decrease compared to the same period the previous year, BlackFog disclosed in its ‘Q1 2026 Ransomware Report.’ Despite this decline, activity remained steady throughout the first quarter, with 91 attacks in January, 83 in February, and 90 in March. Healthcare remained the most targeted sector, accounting for 72 attacks (27%), reflecting the continued focus on organizations with sensitive data and limited tolerance for operational disruption. Government entities experienced 32 attacks (12%), while the technology sector followed with 28 attacks (11%).” 

From the cybersecurity business and defenses front,

  • The Wall Street Journal reports,
    • “OpenAI said it was previewing a powerful artificial-intelligence model capable of finding software vulnerabilities for a limited group of partners, adding to an industry race to give customers the most advanced cyber capabilities.
    • “The ChatGPT maker said it was releasing GPT-5.5-Cyber, a version of its most capable AI model, to a limited group of users that do vital security work. Other versions of GPT-5.5 are available to customers that do broader cyber work or general queries.
    • “The announcement followed consultation with the White House, which is working with top AI companies on the release of models that present national-security risks. Federal agencies and congressional committees have also been briefed on the latest capabilities.
    • “OpenAI Chief Executive Sam Altman said last week that the company was beginning to roll out the model to trusted cyber partners.”
  • Security Boulevard assesses Anthropic’s Project Glasswing.
  • Security Week relates,
    • “Cisco on Monday announced its intent to acquire Astrix Security, a startup focused on securing non-human identities (NHIs) such as API keys, service accounts, and OAuth tokens increasingly used by applications and AI agents.
    • “In a blog post, Cisco said the acquisition is aimed at extending zero trust principles to the emerging “agentic workforce,” where AI agents and machine identities are rapidly expanding the enterprise attack surface. Astrix’s technology is designed to help organizations discover, govern, and secure these identities, including detecting excessive privileges and real-time threats. 
    • “Astrix provides visibility into non-human identities and the activity of AI-driven agents, along with lifecycle management and automated detection and remediation of over-privileged, unnecessary, or malicious access — including compromised credentials and rogue agent behavior. Cisco plans to integrate these capabilities into its broader security platform, including identity intelligence, secure access, and Duo IAM.”
  • Cybersecurity Dive tells us,
    • “Businesses are confident that AI will improve their cybersecurity posture, even as they neglect more fundamental security tools like identity management and zero-trust networking, according to a “State of Workforce Password Security” report that the business software provider Zoho published on Tuesday.
    • “AI confidence also doesn’t match implementation readiness, the report found, with a massive gap between the share of companies expecting AI to help them with security and the share of companies ready to act on that potential.
    • “The report also contains data on the share of companies that experienced recent cyberattacks and the business world’s security spending plans.”
  • Tech Target identifies “top zero-trust use cases in the enterprise.”
    • “When applied correctly, zero trust can minimize an organization’s attack surface. Experts weigh in on the best use cases where zero trust can deliver results.”
  • Here is a link to Dark Reading’s CISO Corner.

Thursday report

From Washington, DC

  • Federal News Network reports,
    • “In the coming months, the Office of Personnel Management is expected to release a reworked version of its employee viewpoint survey that’s more focused on granular data and delivering realtime feedback.
    • “OPM Director Scott Kupor said his agency has been refining the survey to focus more on micro-level questions in order to more effectively gauge employee opinion.
    • “The goal is to get to a decision on what the kind of new survey format looks like so that we have time to do something over the course of this fiscal year for sure,” Kupor told Federal News Network in an interview Wednesday.”
  • Fedweek outlines the FEHB/PSHB eligibility rules for children.
    • “Both the Federal Employees Health Benefits program and Postal Service Health Benefits program, provide for coverage of spouses and children in their self plus one and family options. While enrollment changes typically happen during the open season each autumn, there are certain life events that involve adding children—for example from self plus one to self and family on the birth or adoption of a child.
    • “In both cases, it’s important to know who qualifies for coverage as a child, and when that may end.’
  • Thompson Reuters notes,
    • QUESTION: We recall that the Affordable Care Act (ACA) requires insured group health plans to satisfy nondiscrimination rules similar to those that apply to self-insured plans under Code § 105(h) (the eligibility and benefit tests). What is the status of those rules? Are employers that sponsor insured plans required to comply with them, and if so, when?
    • ANSWER: Under the ACA, insured group health plans generally must satisfy the nondiscrimination rules of Code § 105(h)(2), including “rules similar to” those in Code § 105(h) regarding nondiscriminatory eligibility, nondiscriminatory benefits, and controlled groups. The Code § 105(h) rules pre-date the ACA, prohibit certain discrimination in favor of highly compensated individuals, and apply only to self-insured health plans. The ACA applied similar requirements to insured plans, other than those that provide only excepted benefits or qualify for grandfathered status.
    • “Although insured group health plans initially were required to comply with the ACA nondiscrimination rules for plan years beginning on or after September 23, 2010, the IRS announced in Notice 2011-1 that compliance is not required until the agencies issue regulations or other guidance regarding how the rules apply to insured plans. To date, the agencies have not issued such regulations or guidance, so sanctions for failure to comply do not yet apply for insured plans. Note that the Code § 105(h) nondiscrimination rules continue to apply to self-insured health plans, including those that provide excepted benefits or are grandfathered. For example, the Code § 105(h) nondiscrimination rules continue to apply to health FSAs”.
  • Per an HHS news release,
    • “Today, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced an Interim Final Rule (IFR) extending, for one-year, the compliance dates that recipients of HHS funding must meet for conforming web content and mobile applications to specific accessibility standards under Section 504 of the Rehabilitation Act of 1973 (Section 504).
    • “Under the revised timeline:
      • “Recipients with 15 or more employees will now have until May 11, 2027, to comply.
      • “Recipients with fewer than 15 employees will now have until May 10, 2028, to comply.

From the Food and Drug Administration front,

  • Fierce Pharma reports,
    • “After a surprise rejection at the beginning of 2026, the FDA has agreed to reconsider a T-cell therapy based on the same single-arm trial that the agency had previously found problematic.
    • “For Pierre Fabre Pharmaceuticals and Atara Biotherapeutics’ Ebvallo, the FDA agreed during a recent meeting that a single-arm study using an appropriate historical control “could serve as an adequate and well controlled study” in support of an application for approval, the two companies said Thursday.
    • “Pierre Fabre and Atara are aiming to get Ebvallo, also known as tabelecleucel or tab-cel, approved for patients with relapsed or refractory Epstein-Barr virus-positive post-transplant lymphoproliferative disease (EBV+PTLD) who have failed on an anti-CD20 regimen. Before the FDA, European regulators had already greenlighted the immunotherapy for the indication in 2022.”
  • MedPage Today adds,
  • and
    • “An investigational trivalent mRNA-based vaccine reduced confirmed flu illness by 26.6% through the end of the flu season compared with approved standard-dose vaccines in a randomized trial among adults ages 50 and older.
    • “The mRNA vaccine led to more adverse events, particularly injection-site pain and fatigue, but most were transient and mild without an excess of more serious risks.
    • “An FDA decision on approval is expected by August.”

From the public health and medical / Rx research front,

  • The Washington Post reports,
    • “Using the blood of a 56-year-old woman vaccinated against measles, scientists have isolated a fighting force of four potent virus-blocking antibodies that could pave the way toward a treatment for people exposed to the highly contagious respiratory disease making a comeback in the United States.
    • “A safe, highly effective vaccine for measles has been available since the 1960s, and the U.S. officially eliminated the disease in 2000, with sporadic cases and outbreaks. But dropping vaccination rates have sparked large outbreaks in multiple states, and the country is edging closer to the virus spreading freely again—which puts more people at risk.
    • “New ways to block or treat measles would be particularly important for people who are immunocompromised and babies under the age of 1, because they are not eligible for the vaccine, leaving them unprotected amid a growing number of cases.
    • “Measles was a problem that was solved. Until it wasn’t solved anymore,” said Erica Ollmann Saphire, president of the La Jolla Institute for Immunology who led the study published Thursday in the journal Cell Host & Microbe. But she and other scientists stressed that this approach was not a substitute for a vaccine.
    • “The treatment is always going to be more expensive than the vaccine. It’s the best bang for your public-health buck — this is for people that couldn’t be vaccinated,” Saphire said.”
  • MedPage Today adds, “A new systematic review in The BMJ reported that current evidence did not support causal associations between aluminium adjuvanted vaccines and serious or long-term health outcomes.
  • Infectious Disease Advisor notes,
    • “HIV pre-exposure prophylaxis (PrEP) uptake remains suboptimal among commercially-insured adolescents and young adults in the United States, highlighting the need for targeted interventions to address access barriers.”
  • The American Medical Association lets us know what doctors wish their patients knew about swimmer’s ear.
    • “Diving into pools or spending the day at the beach or lake can be the epitome of summer fun, but these aquatic adventures can also come with an unwelcome companion: otitis externa, commonly known as swimmer’s ear. This common affliction can sideline even the most dedicated water enthusiasts with its painful consequences. With the incidence of swimmer’s ear rising during the warmer months, understanding its causes, symptoms and prevention methods is essential for water enthusiasts of all ages.” 
  • The National Institute for Health Care Management’s May newletter discusses “Cancer Trends & Treatment Advancements”
  • Per BioPharma Dive,
    • “CellCentric, a biotechnology company developing an experimental drug for multiple myeloma, announced Wednesday it raised a $220 million Series D round to finance mid- and late-stage trials.
    • “Its lead drug, dubbed inobrodib, is an oral medicine that blocks a pair of proteins called “p300” and “CBP,” which in turn prevents the expression of certain key cancer-driving genes. CellCentric believes the treatment might be useful as an additive therapy across different lines of care in multiple myeloma. 
    • “The biotech is testing inobrodib in an all-oral combination involving Bristol Myers Squibb’s Pomalyst, as well as in conjunction with bispecific antibodies for myeloma such as Pfizer’s Elrexfio and Johnson & Johnson’s Tecvayli. It’s also evaluating use in a “maintenance” setting, where treatments are used to keep cancer from returning.”

From the U.S. healthcare business front,

  • Beckers Payer Issues reports,
    • “Blue Shield of California debuted its virtual-first Virtual Blue healthcare plan just over three years ago. Now, the data is rolling in.
    • “The program began in 2023 through a collaboration with tech-enabled healthcare platforms Accolade — now owned by Transcarent — and TeleMed2U. The program has no out-of-pocket costs for visits with virtual-only providers, can often deliver same-day care and now has more than 150,000 members. Blue Shield is even tacking virtual primary care options onto its Trio HMO plan, expanding offerings into the individual market.
    • “Tim Lieb, Blue Shield of California’s senior vice president of commercial markets, recently joined the “Becker’s Payer Issues Podcast” to discuss Virtual Blue’s early strengths and challenges.”
  • Healthcare Dive relates,
    • “Nearly 8 in 10 employers report GLP-1 drugs are driving heightened healthcare costs at their companies, pushing some to consider dropping coverage of the pricey weight loss medications, according to a survey released Tuesday by the Business Group on Health.
    • “Only 72% of employers that cover GLP-1s for weight management said they’d likely maintain that coverage next year, while 10% reported they likely wouldn’t, according to the group, which represents employers that provide health coverage. 
    • “Additionally, 87% of respondents said new oral versions of GLP-1 drugs would result in higher demand for the medications, but only 9% predicted prices would decrease.”
  • and
    •  Providing hospital-level care in patients’ homes was linked to better clinical outcomes, suggesting hospital-at-home programs could serve as a safe and efficient alternative to traditional inpatient care, according to a study published this week in JAMA Network Open. 
    • Hospital at home was associated with decreased emergency department use within 30 days of discharge and lower in-hospital mortality, according to the research. But patients at hospital-at-home programs saw no significant difference in hospital readmissions within 30 days. 
    • Additionally, adoption of hospital at home across the country is uneven, with few rural facilities participating, researchers wrote. The findings “underscore the need to address practical and implementation challenges to broaden equitable access,” they said.
  • Per Healthcare Cost Institute news releases,
    • Health care spending can differ dramatically depending on where Americans live, with costs varying by more than twofold from one metro area to another, according to new findings from the Health Care Cost Institute (HCCI). Charleston, WV, tops the list of the highest spending markets, with annual costs more than twice those in places like Bakersfield, CA, one of the country’s lowest spending areas.
    • The new data comes from the Health Cost Landscape, HCCI’s updated interactive platform that compares health care spending, prices, service use, and market dynamics across 269 metro areas in 45 states. The tool gives a clear, local look at how health care markets function and where consumers are paying the most for care.
  • and
    • “The Transparency in Coverage (TiC) regulations have introduced unprecedented visibility into negotiated health care prices in the United States. By requiring insurers to publish machine-readable files containing payer–provider contracted rates starting in 2022, the policy has created a new data source for studying price variation. However, the scale, inconsistency, and missing information within the TiC data mean that rigorous methodological work is required before it can be used for research. This brief explores the nature of this data, how it is accessed and processed, and how it can be used for analysis, with a detailed walkthrough of a real example examining childbirth prices in Pennsylvania.” * * *
    • “Transparency in Coverage data represent a significant advancement in the availability of information on negotiated health care prices, offering researchers a new lens into variation across payers, providers, and markets. As demonstrated in the childbirth analysis in Pennsylvania, TiC data can be used to replicate and extend findings from traditional claims-based research, particularly in understanding the range and distribution of negotiated rates across payers and providers.
    • “At the same time, the value of TiC data depends heavily on the methods used to create an analytic dataset. The raw data are not inherently research-ready and require substantial processing, including careful service definition, data cleaning, provider and payer entity resolution, and restrictions to ensure comparability. Without these steps, analyses may not be replicable and risk reflecting the messiness of the raw data rather than meaningful differences in prices. Additionally, the absence of utilization data remains a fundamental limitation, requiring integration with external sources to fully assess spending and average prices.
    • “Overall, TiC data should be viewed as a powerful but incomplete resource. When used appropriately, they can provide important insights into health care pricing dynamics and market structure. As data quality improves and methods continue to evolve, TiC data are likely to become an increasingly valuable complement to claims data in health services research.”
  • Per Fierce Healthcare,
    • “Hims & Hers launched an artificial intelligence agent embedded in its platform to help interpret biomarker lab results and provide users personalized insights about their health.
    • “The company launched its direct-to-consumer lab testing program for health biomarker testing back in November. The new agent AI, Labs AI, has been available to some customers in beta testing and will roll out to all Labs customers over time, the company announced Thursday.
    • “Hims & Hers’ Labs offers access to 130 biomarker tests across 10 health areas, including heart health, metabolism, hormones, inflammation and stress, as part of its strategy to extend into prevention and health screening. The new AI care agent makes customers’ lab results clearer, more useful and easier to engage with, according to Patrick Carroll, M.D., Hims & Hers chief medical officer.”
  • and
    • “Ardent Health topped the market’s revenue and earnings estimates, touting Wednesday solid adjusted admission and labor spend numbers despite what has proved to be a tumultuous first quarter for hospitals. 
    • “The publicly traded for-profit logged $1.6 billion of total revenue, which was up 7% year over year and 1.3% above Zacks Investment Research’s consensus estimate. Net income was $40 million, or 28 cents per share, beating the consensus estimate of 18 cents per share. 
    • “Similar to other for-profit health systems’ reports from the past few weeks, executives acknowledged the impacts of a weak respiratory season and severe winter storms on Ardent’s business, particularly in Texas, Oklahoma and New Jersey. That led to a 1.1% year-over-year decline in admissions, though CEO Marty Bonick said during Wednesday’s earnings call that the company “acted swiftly to reschedule surgeries and adjust labor to align with volume, mitigating the impact on our performance.”
  • Per Fierce Pharma,
    • “With an eye on the lucrative U.S. market, Italy’s Angelini Pharma will acquire rare disease specialist Catalyst Pharmaceuticals and its potential blockbuster, Firdapse, for $4.1 billion.
    • “Rome-based Angelini, a family-owned private company established in 1919, is paying $31.50 per share for Florida-based Catalyst. It is a 3% premium on Catalyst’s share price at close yesterday and a 21% premium on its price on April 22 before market activity hinted at public knowledge that a sale was in the offing. Bloomberg reported the potential buyout on April 27, triggering another stock surge.”
  • Per MedTech Dive,
    • “Roche has agreed to acquire PathAI, a Boston-based digital pathology firm, for up to $1.05 billion.
    • “Roche plans to pay $750 million upfront and up to $300 million in additional milestone payments, according to a Thursday announcement. 
    • “The acquisition is expected to close in the second half of 2026, subject to customary closing conditions, including antitrust and regulatory approvals.”

Midweek update

From Washington, DC,

  • The American Hospital Association News tells us,
    • “The White House May 4 released its National Drug Control Strategy, which, among other efforts, recommends effective primary prevention programs. The initiative increases the implementation of evidence-based prevention strategies; establishes new partnerships with organizations supporting youth health and expanding primary prevention; supports a national media and education campaign against drug use; and supports and enhances the federal drug-free workplace program.”
  • The Centers for Medicare and Medicaid Services announced,
    • “The Centers for Medicare & Medicaid Services (CMS) will provide eligible Medicare beneficiaries access to certain GLP-1 medications for $50 per month beginning July 1, 2026, through December 31, 2027.
    • “Under the Medicare GLP-1 Bridge, a time-limited demonstration, CMS is expanding access to innovative, evidence-based weight-loss treatments. Eligible individuals enrolled in Medicare Part D prescription drug plans will be able to access these medications at a predictable and affordable cost—$50 for a monthly supply. This approach reflects CMS’ continued focus on improving access to high-value treatments that support better long-term health outcomes.
    • * * * “Beginning July 1, Medicare beneficiaries with Part D coverage may be eligible to access certain GLP-1 medications at $50 for a monthly supply. Beneficiaries can talk to their doctor to determine whether a GLP-1 medication is right for them. CMS will share additional information for beneficiaries as the program begins.
    • “In addition, CMS continues to work with stakeholders—including providers, pharmacies, and manufacturers—to support implementation and ensure all partners have the information they need ahead of launch. 
    • “The Medicare GLP-1 Bridge builds on CMS’ broader efforts to improve access to innovative therapies and support healthier outcomes for Medicare beneficiaries. For additional “demonstration details, visit: https://www.cms.gov/medicare/coverage/prescription-drug-coverage/medicare-glp-1-bridge
  • U.S. Office of Personnel Management Director Scott Kupor, writing in his Secrets of OPM blog on Substack, optimistically discusses the state of artificial intelligence.
  • Meanwhile, KFF Health News reviews “Regulation of AI in Prior Authorization and Claims Review: A Look at Federal and State Consumer Protections.”

From the Food and Drug Administation front,

  • Per FDA news releases,
    • “The U.S. Food and Drug Administration today announced major steps in its bold initiative to modernize the agency. The agency launched Elsa 4.0, a significant upgrade to the agency’s internal AI tool available to all FDA staff, from scientific reviewers to investigators.  
    • “The agency also consolidated more than 40 disparate application and submission data sources, systems and portals across all FDA centers into a new platform called HALO (Harmonized AI & Lifecycle Operations for Data).The agency began integrating HALO and Elsa so that FDA staff can query data and build workflows without having to manually upload documents within each chat. The HALO consolidation is expected to enable more penetrating deployment of AI capabilities within agency operations. 
    • “Elsa’s new capabilities once again position FDA as a leader in deploying AI tools that empower staff,” said FDA Commissioner Marty Makary, M.D., M.P.H. “Removing tedious burdens for staff enables them to focus more on science and makes their work streams more efficient and enjoyable. We have some of the best scientists in the world and we need to take good care of them.”
  • and
    • The U.S. Food and Drug Administration today announced that it is piloting one-day inspectional assessments, as part of a broader initiative to make its inspectional resources more targeted and efficient. As part of this pilot, which launched in April, the agency is conducting shorter, focused screening assessments to complement standard FDA inspections. 
    • “One-day inspections can strengthen our inspectional approach by focusing our time and resources where they are most needed—enhancing our overall effectiveness,” said FDA Commissioner Marty Makary, M.D., M.P.H. “For the FDA, the ability to conduct shorter, targeted assessments allows for broader surveillance coverage, enabling the agency to assess more facilities and gather critical insights without compromising regulatory rigor. For industry, these assessments can provide timely feedback while minimizing operational disruption, particularly for lower-risk establishments.”
    • One-day inspectional assessments also support the development of more robust risk models across FDA programs. Data gathered through these assessments—such as recurring compliance themes, facility-specific risk scores, and discrepancies between registered and actual operations—can be used to better target future oversight activities.
  • MedTech Dive tells us,
    • “The Food and Drug Administration added neurosurgical supplies to its medical device shortages list on Wednesday.
    • “The regulator sent a letter to healthcare providers warning about disruptions in availability of neurosurgical patties, sponges and strip devices, which are used to absorb fluids and protect tissue during surgery.
    • “The FDA attributed the problem to recent supplier issues, noting that Medline Industries recently recalled its neuro sponge products. The agency expects the shortage to continue through the end of the year.”

From the public health and medical / Rx research front,

  • The New York Times explains,
    • “Hantaviruses have most likely been around as long as rodents, but little was known about these pathogens before the 20th century. This rare family of viruses that rodents carry has been cited as the source of a deadly outbreak aboard a cruise ship in the Atlantic Ocean.
    • “The virus is zoonotic, meaning it can be transmitted to humans from animals. And while outbreaks have been rare, it is one of the most widely distributed zoonotic viruses on Earth.
    • “Some are Old World hantaviruses and others are New World hantaviruses,” said Sabra Klein, a professor of molecular microbiology and immunology at the Johns Hopkins Bloomberg School of Public Health.
    • “Different species of the virus are carried by different rodents,” Dr. Klein said, adding that European strains cause less severe illnesses than those from Asia.
    • She noted that “there’s no vaccine, there’s no cure, there’s no money” in finding a cure “in part because these are so rare.”
  • The Wall Street Journal adds,
    • “Hantavirus is an unlikely source of contagion on a cruise ship. The virus isn’t as infectious between humans as fast-spreading respiratory illnesses like Covid-19 and the flu. 
    • “It belongs to a family of viruses carried by rodents and spread to humans through contact with infected urine, droppings or saliva. Only one strain—the Andes virus—has shown limited evidence of human-to-human transmission. Researchers in South Africa and Switzerland confirmed this week the virus involved in the suspected outbreak is the Andes strain.
    • “Human-to-human transmission of the Andes strain requires very close contact, like sharing food or living quartersaccording Steven Bradfute, an immunologist at the University of New Mexico Health Sciences Center whose lab has sequenced hantaviruses. “It doesn’t spread into huge outbreaks,” Bradfute said.
    • “WHO and other health authorities say the threat to public health is low. 
    • “Yet the ship’s passengers are at risk, as well as perhaps people they came into close and extended contact with after leaving the ship. That is why Oceanwide Expeditions, the Hondius’s operator, plus health authorities around the world and airlines, are mobilizing to trace the paths of the ship’s travelers.”
  • Fierce Healthcare reports,
    • “The Leapfrog Group highlighted broad improvements across several patient safety measures in this year’s spring release of hospital safety grades, the first reflecting changes made after a court-ordered removal of hospitals that declined to voluntarily submit information to the watchdog group. 
    • “Top marks were handed out to 917 hospitals, with Leapfrog outlining a particularly high share of “A” hospitals in the states of Connecticut (where 64% of hospitals received an “A”), Virginia (59%), South Carolina (51%), Utah (50%) and Montana (44%). 
    • “A hospital’s assigned grade is calculated by reviewing recent data on up to 22 patient safety measures, including a 10-part Medicare composite of reported patient safety and adverse events. Among these, Leapfrog said it saw “significant improvement” in 17 measures, including those related to healthcare-associated infections and medication safety plus multiple items related to patient experience. 
    • “The good news is that hospitals across the country are making meaningful strides in patient safety and helping save countless lives,” Leah Binder, president and CEO of The Leapfrog Group, said. “But not all hospitals are the same. That’s why it’s so important for people to consult Safety Grades and do their research when choosing a hospital.”
    • “Of note, the latest release excludes 450 hospitals that did not participate in Leapfrog’s 2024 or 2025 surveys.” 
  • Beckers Hospital Review points out the “eleven U.S. hospitals have earned consecutive “A” safety grades from The Leapfrog Group since 2012.” You can see “the list of Leapfrog’s five “F” hospitals here.
  • Pulmonary Advisor notes,
    • “While vaccinations showed protective trends, prior viral infections were generally linked to an increased likelihood of future respiratory illnesses.”
  • Per MedPage Today,
    • “Updated findings from a European randomized trial continued to show that colonoscopy screening significantly reduced colorectal cancer (CRC) incidence, but its impact on CRC mortality was less clear.”
  • Following up on recent Wall Street Journal articles, Cardiology Business relates
    • “Three of the leading U.S. cardiovascular health societies have joined forces for a new statement about the importance of multidisciplinary, patient-centered decision-making when managing patients with severe aortic stenosis (AS).
    • “The Society for Cardiovascular Angiography and Interventions (SCAI)American College of Cardiology (ACC) and Society of Thoracic Surgeons (STS) collaborated on the joint statement, calling it a response to “recent media coverage” about transcatheter aortic valve replacement (TAVR) and surgical aortic valve replacement (SAVR). The primary focus of the statement appears to a feature story published by The Wall Street Journal on April 23 that included interviews with patients who experienced significant complications after undergoing TAVR. 
    • “The joint statement highlights the fact that multidisciplinary heart teams are at the center of every treatment decision for patients who present with severe AS and require an aortic valve replacement. This has been the case for many years now, but coverage from The Wall Street Journal and other mainstream news outlets is sure to grab the attention of people unfamiliar with how such treatment decisions are made. 
    • “This statement serves as a fresh reminder for the general public that cardiologists and cardiac surgeons do not take these decisions lightly. The cardiology groups said years of hard work and dedication have gone into developing the framework that is now in place.”
  • Per MedTech Dive,
    • “Neptune Medical’s gastrointestinal robot met both of its primary endpoints in a clinical trial assessing the safety and feasibility of the system to perform colonoscopies.
    • “The study followed 50 adults who underwent screening, surveillance or diagnostic colonoscopy with the robotic endoscopy system at a single center in Poland for 14 days after the procedure.
    • “The results, announced Tuesday, showed no adverse events and a 100% rate of cecal intubation, where the endoscope is guided through the entire colon to the beginning of the large intestine.”
  • and
    • “Johnson & Johnson said Tuesday that a study evaluating the investigational Ottava robotic system in gastric bypass surgery met its safety and efficacy endpoints through 30 days. The average weight loss in that time frame was 30 pounds.
    • “Results from the 30-patient study were among the pre-clinical evidence included in J&J’s submission to the Food and Drug Administration, announced in January, for de novo classification of the robot in multiple procedures in the upper abdomen. 
    • “All procedures in the prospective, multicenter study were completed robotically on Ottava without conversion to a non-robotic approach, the company said. There were no adverse events related to the device.”

From the U.S. healthcare business front,

  • The Wall Street Journal reports,
    • “CVS Health exceeded first-quarter earnings expectations and raised its full-year adjusted-earnings guidance.
    • “The company reported first-quarter net income of $2.96 billion, driven by a turnaround at its Aetna insurance unit.
    • “Aetna’s medical-loss ratio was 84.6%, below analysts’ projections, but 2027 Medicare rates still fall short.”
  • Modern Healthcare relates,
    • “Humana plans to cut Medicare Advantage supplemental benefits in 2027 in a strategic shift for the insurer.
    • “Medicare Advantage payments are not keeping pace with medical costs, President and CEO Jim Rechtin said.
    • “Medicare Advantage membership was 22.6% higher in the first quarter.
    • “Humana downgraded its annual earnings guidance.”
  • Beckers Payers Issues tells us,
    • “Oscar Health reported a net income of $679 million in the first quarter of 2026, according to a May 6 earnings release. This marked the highest quarterly profit in the company’s history, nearly 2.5 times greater than profit in the first quarter of 2025.
    • “Membership reached roughly 3.2 million members, a 56% year-over-year increase. The company’s medical loss ratio was 70.5%, compared to 75.4% during the same period last year.
    • “Total revenue reached $4.6 billion, up 53% year over year. Earnings from operations were $704.1 million, more than double from the first quarter of 2025.
    • “The company also reaffirmed its 2026 guidance. The strong quarter follows a $443 million net loss in 2025.”
  • Fierce Healthcare informs us,
    • “Hinge Health boosted its full-year revenue outlook by $64 million as the company reported a stronger-than-expected first quarter and kicked off an expansion of its business beyond muscle and joint pain.
    • “The digital musculoskeletal (MSK) care provider, which went public nearly a year ago, brought in first-quarter revenue of $182 million, up 47% year-over-year from $123.8 million in Q1 2025. The company posted first-quarter adjusted earnings of 45 cents per share, significantly exceeding Wall Street analyst estimates of 12 cents per share. Hinge Health’s non-GAAP income from operations jumped 208% to $46.2 million compared to non-GAAP income from operations of $15 million during the same quarter a year ago.
    • “The company’s results easily topped Wall Street analyst estimates, with a revenue target of $172 million for the quarter and a Street estimate of $31.2 million for operating income.”
  • and
    • “Amwell, the telehealth platform formerly known as American Well, brought in $54.9 million in first-quarter revenue, down approximately 18% the same period a year ago, as executives discussed artificial intelligence and key contract renewals with investors on Tuesday.
    • “The company is shifting towards subscription revenue, and in Q1, subscription software revenue was 53% of total revenue at $24.9 million, which Chief Financial Officer Mark Hirschhorn said was down “approximately 23%” year-over-year in a May 5 call to discuss Q1 results. 
    • “Encouragingly, renewals and retention were higher than budgeted in the first quarter, providing greater confidence in the stability of our subscription base going forward,” Hirschhorn said.
    • “Amwell’s visit volume was down approximately 19% compared to a year ago, according to Hirschhorn, with 1.1 million visits in Q1. Hirschhorn said the figure is “is in line with the portfolio changes” previously disclosed by the company.”
  • The Wall Street Journal lets us know,
    • “BioNTech plans to shrink its workforce and manufacturing network to cut costs after Covid-19 vaccine demand waned.
    • “The company will affect 1,860 roles, about 22% of its 8,400-person workforce, and exit manufacturing plants.
    • “BioNTech will hand Covid shot supply to Pfizer, pivot to cancer therapies, and projects 500 million euros in annual savings by 2029.”
  • and
    • “Bayer agreed to acquire Perfuse Therapeutics, an eye disease drug specialist, for up to $2.45 billion.
    • “The acquisition aims to complement Bayer’s ophthalmology pipeline, following patent expiration issues with its Eylea drug.
    • ‘Perfuse’s lead drug candidate is an experimental treatment for glaucoma and diabetic retinopathy in mid-stage trials. Bayer will pay $300 million upfront.”
  • Per Fierce Pharma,
    • “Since the start of the decade, Eli Lilly has committed to spend more than $50 billion to bolster its United States manufacturing capabilities. But even that’s not enough to meet the needs of the rapidly growing pharma giant.
    • “On Wednesday, Lilly said that it has earmarked another $4.5 billion to further build up two of three planned production facilities in Lebanon, Indiana, some 28 miles northwest of Lilly’s headquarters in Indianapolis. The company revealed the new investment at a ribbon cutting ceremony for its genetic medicine plant in Lebanon, the first of the three new facilities at the site to become operational.
    • “Of the sum Lilly has pledged to spend for its domestic manufacturing in this decade, more than $21 billion has been allocated for the buildup in its home state. Lilly’s “evolving pipeline” and shifts in the anticipated demand for its products dictated the additional funding, the company said.”





Monday report

From Washington, DC,

  • Per a Senate news release,
    • “The U.S. Senate Health, Education, Labor, and Pensions (HELP) Committee will hold two field hearings in Louisiana this week to discuss how Congress can make health care affordable and improve mental health and substance use disorder treatment. The Committee will hear from a variety of perspectives within the health care system, including patients, providers, and local subject matter experts.” * * *
    • “Title: Making Health Care Affordable Again Part 2: Perspectives from Employers, Patients, and Providers
    • Date: Tuesday, May 5, 2026
    • Time: 9:00 AM CT/10:00 AM ET
    • Location: LSU Foundation Building, 3796 Nicholson Drive, Baton Rouge, LA
    • “Click here to watch this hearing live.”
  • The Wall Street Journal reports,
    • “Health Secretary Robert F. Kennedy Jr. is announcing steps that he said are aimed at helping wean some Americans off psychiatric medications, including antidepressants.
    • “Too many patients begin treatment without a clear understanding of the risks, and how long they will stay on these drugs, or how to come off them,” he said to an audience at an event hosted by the Make America Healthy Again Institute, a nonprofit, on Monday. “We are going to fix it.” 
  • Here is a link to the HHS news release about this announcement.
  • Per U.S. Office of Personnel Management news releases,
    • “The US Office of Personnel Management (OPM) today recognized Public Service Recognition Week, honoring the federal employees who serve the American people every day and highlighting the critical role public servants play in delivering results for taxpayers.
    • “Observed annually during the first full week of May, Public Service Recognition Week celebrates the dedication, professionalism, and impact of public servants across the federal government and at all levels of public service. This recognition also comes as OPM continues its work to strengthen the federal workforce through modern hiring, performance management, and workforce development initiatives.”
  • and
    • “The US Office of Personnel Management (OPM) today announced the expansion of access to USA Class, an artificial intelligence (AI)–enabled tool designed to accelerate the creation of federal position descriptions, to all federal agencies using USA Staffing at no additional cost.
    • “This move integrates USA Class directly into the federal government’s primary hiring platform, providing hiring managers and human resources professionals with modern tools to reduce administrative burdens and speed the hiring process.
    • “USA Class uses AI technology trained on thousands of existing federal position descriptions to help managers quickly generate structured draft duties and assist classifiers in aligning those duties with OPM classification standards. The tool is designed to strengthen collaboration between managers and classifiers, reduce rework, and significantly shorten timelines needed to prepare position descriptions, an essential first step in the hiring process.”
  • OPM Director Scott Kupot discusses the USA Class initiative in the latest post in his Secrets of OPM blog.
    • “Don’t get me wrong – hiring is still hard, and I don’t suspect AI will fully solve that problem in the near term. But we are using AI to streamline the tasks for which computers are very capable and free up time for HR professionals and hiring managers to focus on the people-facing aspects of recruiting and assessing candidates. More to come.”
  • Fierce Healthcare offers “A deeper dive into the ACCESS Model—Who’s participating, potential headwinds and how it could spur health plan adoption.”
    • “The CMS ACCESS Model creates a new category of Medicare Part B providers, ACCESS organizations, that can receive outcome-aligned payments for managing qualifying chronic conditions. The model shifts away from remote patient monitoring (RPM) and chronic care management (CCM) billing codes that offer payments for specific activities.
    • “This access model introduces an alternative approach, which is, you get rid of the billing codes altogether, and you have these new outcomes-aligned payments,” said Aneesh Chopra, chair of the Arcadia Institute.
    • “Chopra, who served as the first U.S. Chief Technology Officer, asserts that the ACCESS model redefines value-based care as it eliminates complexity and makes value-based care scalable.
    • “The use of AI technologies enables companies and providers to take a scarce resource—care management—and make it abundant, Chopra noted, to scale it to more patients living with chronic conditions.”
  • Healthcare Dive relates,
    • “The Department of Justice’s fraud division last week launched a strike force dedicated to rooting out healthcare fraud on the West Coast, as the Trump administration continues to double down on fraud enforcement across the country. 
    • “The West Coast Health Care Fraud Strike Force brings the DOJ’s healthcare fraud unit together with the U.S. attorney’s offices for Arizona, Nevada and the Northern District of California, to coordinate on cases in the region, according to a Thursday press release. 
    • “The strike force will bring increased enforcement resources to Northern California — one of the nation’s hubs for health technology development — and Arizona and Nevada, where the DOJ says healthcare fraud schemes are rising.” 

From the Food and Drug Administration front,

  • Fierce Pharma reports,
    • Incyte is poised to expand the reach of its blockbuster JAK inhibitor Jakafi with a new once-daily, extended-release version that’s soon to hit pharmacy shelves. 
    • “The FDA signed off on Jakafi XR under the same indications as original Jakafi, allowing its use to treat intermediate or high-risk myelofibrosis, polycthemia vera and graft-versus-host disease. In a bioequivalence study, a single 55-mg Jakafi XR tablet exhibited consistent, day-long exposure comparable to a twice-daily 25-mg immediate-release Jakafi dose. 
    • The new version allows for expanded treatment options “without changing the well-established role of Jakafi in clinical practice,” Incyte’s CEO Bill Meury explained in a company release.”
  • and
    • “Along with partner Lannett, a subsidiary of China’s Sunshine Lake Pharma has brought a biosimilar of Sanofi’s insulin glargine Lantus to the U.S., adding a cheaper interchangeable option to the diabetes treatment landscape. 
    • “The green light makes Lannet and Sunshine’s product the first long-acting insulin from a Chinese company to win the FDA’s blessing. 
    • “The biosimilar will be sold under the brand name Langlara and is now FDA-approved to treat adult and pediatric patients with type 1 diabetes as well as adults with type 2 diabetes. Langlara also received an interchangeable designation from the FDA, meaning that it can be distributed by pharmacists in place of Lantus without sign-off from a physician.”   

From the judicial front,

  • Per a Department of Justice news release,
    • “Two men were sentenced today for their roles in a scheme to defraud Medicare, Medicaid, and private health insurance companies by submitting over $522 million in fraudulent claims for medically unnecessary genetic tests that were obtained through the payment of illegal kickbacks and bribes.
    • “Reyad Salahaldeen, 57, of Buford, Georgia, was sentenced to 151 months in prison after pleading guilty to conspiracy to commit health care fraud and wire fraud. Mohamad Mustafa, 28, of Duluth, Georgia, was sentenced to three years in prison after pleading guilty to paying health care kickbacks.
    • “Under the guise of health care, these two fraudsters attempted to steal more than half a billion dollars from taxpayers through a web of sham contracts, lies, and bribes,” said Colin M. McDonald, Assistant Attorney for the National Fraud Enforcement Division. “These schemes deplete America’s pocketbook and destroy the trust in medicine that patients deserve and demand. The Department of Justice will remain vigilant in our efforts to deter those defrauding the American people in the name of health care. I thank the prosecutors and our law enforcement partners at FBI and HHS-OIG who worked tirelessly for this just outcome.”

From the public health and medical / Rx research front,

  • A neurologist, writing in the Washington Post, tells us about “six ways to keep work stress from fueling headaches.”
  • The American Medical Association lets us know what doctors wish their patients knew about Lyme Disease.
    • “An early sign of Lyme disease is a bullseye rash from a tick bite. But symptoms can worsen if left untreated. Three infectious diseases physicians share more.”
  • Cardiovascular Business reports,
    • “Long-term antidepressant use may increase a person’s risk of sudden cardiac death (SCD), according to new findings published in Heart Rhythm.
    • “SCD frequently occurs without warning, often in individuals without previously diagnosed cardiovascular disease,” wrote first author Jasmin Mujkanovic, MD, a cardiologist with Copenhagen University Hospital, and colleagues. “It accounts for a significant proportion of cardiovascular mortality worldwide. Psychiatric disorders have previously been shown to be associated with SCD, with major depressive disorders having a twofold increased risk … Pharmacologic treatment of depression, with antidepressants among the most common pharmaceuticals prescribed, adds another layer of complexity.”
  • MedPage Today relates,
    • “Kids seen by primary care clinicians for acute respiratory tract infections were prescribed antibiotics less often during telemedicine visits versus in-person visits in a cross-sectional study.
    • “The difference was driven by more telemedicine diagnoses of viral infections and sinusitis versus more in-person diagnoses of acute otitis media and streptococcal pharyngitis.
    • “There were no significant differences between groups in antibiotic management guideline concordance, follow-up visits, or antibiotic prescription within 14 days after the initial visit.”
  • and
    • “A 10% increase in ultraprocessed food intake was tied to lower attention scores and greater dementia risk in a cross-sectional study.
    • “The relationships persisted even in people who followed a Mediterranean diet.
    • “No relationship emerged between ultraprocessed food intake and memory scores.”
  • Health Day informs us,
    • “Antibiotics don’t appear to increase a person’s risk of developing celiac disease, a new study says.
    • “Patients with celiac disease had a 24% higher odds of antibiotic use compared to healthy siblings or members of the general public, researchers reported recently in the journal Clinical Gastroenterology and Hepatology
    • “However, the odds of antibiotic use were even higher — 50% — among a group of people whose gut lining was normal, when they were compared to the general public, researchers said.
    • “These results indicate that earlier studies that linked celiac disease to antibiotics reflect a heightened awareness of the disorder, in which the gut becomes inflamed if a person eats gluten.
    • “We do not see a causal link between celiac disease and antibiotics,” said lead researcher Dr. Maria Ulnes, a pediatrician and doctoral student at the University of Gothenburg in Sweden.”
  • Radiology Business points out,
    • “A new 4D mammography technique could diagnose cancer with up to four times the precision of 3D digital breast tomosynthesis (DBT) exams. 
    • “That’s according to early data out of an ongoing first-in-human clinical trial at Baptist Health Hardin in Elizabethtown, Kentucky. The trial is testing the utility of the 4D mammography system developed by Calidar Inc.—a medical technology startup out of North Carolina. Calidar’s 4D system harnesses X-ray diffraction imaging to measure molecular-level signatures of disease; these tissue “fingerprints” could help providers diagnose breast cancer in its earliest stages, but current mammography systems do not have this capability. 
    • “Calidar has indicated that its 4D system also allows for exams to be completed more quickly, and at a reduced radiation dose compared to 2D and 3D scans.” 

From the U.S. healthcare business and artificial intelligence front,

  • Beckers Payer Issues explains,
    • “Healthcare more broadly has been focused on reaching consumers where they are at. Health systems have established virtual care partnerships, and prescription drugs are now more accessible via direct-to-consumer pathways.
    • “But health insurers have also been developing strategies to reach members more directly, such as through transparent pricing and shifts in product offerings.”
    • The article offers several examples.
  • The Wall Street Journal reports,
    • UCB said it agreed to buy Candid Therapeutics [which is based in San Diego, CA] for up to $2.2 billion, in a deal that seeks to bolster the Belgian pharmaceutical company’s pipeline of experimental treatments for autoimmune and inflammatory diseases.
    • Brussels-based UCB said Sunday that it would pay $2 billion upfront and up to $200 million subject to future targets to acquire Candid. Its latest acquisition follows a licensing agreement with China’s Antengene valued at up to $1.18 billion in March, and a deal to buy epilepsy-therapy developer Neurona Therapeutics for up to $1.15 billion last month.
    • Privately held Candid is developing a portfolio of experimental drugs to treat autoimmune and inflammatory diseases and its lead candidate, cizutamig, is a so-called bispecific antibody being tested in multiple early-stage clinical trials across a number of indications, UCB said.
  • Fierce Healthcare relates,
    • “UPMC and CommonSpirit’s talks to hand over a three-hospital system in eastern Ohio have progressed to a definitive agreement between the parties with a transaction expected to close in the fall. 
    • “Financial terms of the deal for CommonSpirit’s Trinity Health System were not disclosed, and a close would require regulatory clearances.
    • “Trinity Health System and UPMC share a commitment to providing top-tier care and serving the most vulnerable members of our community,” Dwayne Richardson, interim president of Trinity Health System, said in a Monday release announcing the agreement. “UPMC’s proven track record of community service and compassionate approach to care were key factors in our decision, and will significantly benefit our patients.”
    • “Trinity Health System includes facilities for urgent care, behavioral health and physician offices alongside its hospitals. The deal reflects a market expansion for UPMC, which is based in Pittsburgh, Pennsylvania and dominates the western half of that state with more than 40 hospitals and 800 outpatient sites.” 
  • Radiology Business notes,
    • “It may be more than anxiety and forgetfulness to blame for women missing their scheduled mammograms, according to new survey data. 
    • “Missed breast imaging appointments are not uncommon. In fact, prior research has suggested that breast imaging appointments account for the largest number of no-shows in imaging. This can be problematic for both practices and patients, experts explain in a new paper in Academic Radiology.” * * *
    •  
  • Healthcare Dive tells us,
    • “Healthcare bankruptcies rose in the first quarter after declining last year, according to a report released last week by restructuring advisory firm Gibbins Advisors.
    • “Twelve healthcare companies with liabilities of at least $10 million filed for Chapter 11 bankruptcy protection in the first quarter, up 33% from the fourth quarter of 2025. 
    • “Senior care firms and physician practices drove bankruptcies in the first quarter, with four filings each.” * * *
    • “The most common reason for missing an exam was forgetting about the appointment, cited by 35% of respondents. Financial and logistical issues, however, also represented a significant barrier for many; 19% indicated that financial hardship prevented them from attending their appointment, while another 20% said they did not have transportation to get to their exam. Notably, respondents who fell under lower income brackets most often cited issues with payments and transportation. Notably, around 30% of the patients who missed their appointment never rescheduled. 
    • “In terms of improving follow through, respondents suggested that more frequent reminders would be beneficial; the majority signaled that text message reminders were the most effective. Other suggestions included some form of payment assistance and transportation services.”  
  • Joanna Stern writing in the Wall Street Journal describes a personal experience with AI enhanced mammography.
  • Per an Institute for Clinical and Economic Review news release,
    • “The Institute for Clinical and Economic Review (ICER) posted a Protocol today outlining how it will conduct its second annual analysis titled the “Launch Price and Access Report,” which will examine launch prices and patient access for new FDA-approved treatments. This protocol was developed with input from a multi-stakeholder working group* consisting of patient and consumer advocates, clinicians, policy experts, payers, and life science companies. 
    • “In the upcoming report, to be released in October 2026, ICER will analyze launch price trends over four years (2022-2025). ICER is also conducting an in-depth review of newly launched drugs (July 2024 to June 2025 novel drug approvals) by:
      • “Evaluating the impact of pricing above ICER’s Health Benefit Price Benchmark (HBPB) for drugs that ICER has previously reviewed.
      • “Evaluating patient access to newly launched drugs using real-world pharmacy and medical claims data, payer coverage policies, and direct patient surveys.
    • “The complete timeline for ICER’s Launch Price and Access report is available here.”
  • Fierce Pharma tells us,
    • “With three weeks of data on Lilly’s oral GLP-1 launch in obesity now on the books, the dimensions of Foundayo’s rollout—and its critical comparison to that of Novo Nordisk’s Wegovy pill—are coming into focus. 
    • “In its third week on the U.S. market, which ended April 24, Foundayo generated some 5,600 prescriptions, analysts at Jefferies wrote in a May 1 note to clients. That level of adoption is numerically lower than the stats recorded by the Wegovy pill in its third week, when prescriptions for the oral obesity med came in at around 26,100, per the note. 
    • “Nevertheless, almost all of Foundayo’s recorded performance stems from cash pay channels, according to the Jefferies team, with commercial access via insurance set to come online by the middle of this month, which will likely give Foundayo a substantial boost in uptake. 
    • “The team acknowledged that Foundayo’s reimbursement “appears to be ramping more slowly vs oral Wegovy’s.” 
    • “Overall, the analysts described Foundayo as “off to a solid start,” and estimate the drug will generate $146 million in the second quarter and $1.6 billion for all of 2026. That compares to consensus forecasts of $134 million and $1.2 billion, respectively.” 

Cybersecurity Saturday

From the Iranian war front,

  • The Center for Strategic and International Studies offers an April 27, 2026, FAQ about “The Iranian Cyber Threat to U.S. Critical Infrastructure.”
  • MedTech Dive tells us,
    • “A cyberattack that shut down ordering, shipping and manufacturing at Stryker for weeks cut into the company’s first-quarter results.
    • “CEO Kevin Lobo told investors Thursday that the cyberattack “meaningfully” affected Stryker’s growth.
    • “The cyber incident had a big impact on our results and affected each of our businesses differently given their varied go-to-market models and processes to record revenue,” Lobo said. “This resulted in distortions in our first-quarter results that will normalize over the course of the year.” * * *
    • “Stryker was hit by the cyberattack on March 11. The company’s global Microsoft environment was disrupted, and ordering, shipping and manufacturing were shut down for weeks. Operations were not restored until the first week of April.
    • “The attack has been claimed by an Iran-linked threat actor tracked as Handala, according to Check Point Research. Along with the operational disruption, the group claims to have wiped thousands of servers and mobile devices, and stolen data.
    • “Lobo said the cyberattack wiped 40,000 laptops. He added that the company lost some procedures due to operations shutting down, and some sales reps were unable to get into hospitals. However, Lobo maintained that the company didn’t lose overall business.”
  • SC Media reports on April 27,
    • “Large medical devices maker Medtronic on April 24 said it was hit by a cyberattack that led to unauthorized access to data in some of its corporate IT systems. 
    • “However, in a statement, Medtronic said it had not identified any impact to its products, patient safety, or connections to its customers, manufacturing and distribution operations, financial reporting systems, or the company’s ability to meet patient needs.
    • “The networks that support our corporate IT systems, our products and our manufacturing and distribution operations are separate,” said the company. “Hospital customer networks remain separate from Medtronic IT networks and are secured and managed by customers’ IT teams.”
    • “The attack raised some eyebrows because it was reportedly claimed by Handala, the same group that was behind the attack on Stryker March 11 that led to service disruptions. This was the second publicly reported attack on a large medical device maker since the war with Iran started Feb. 28.”
    • “Handala didn’t target Medtronic by accident,” said Amir Khayat, co-founder and CEO of Vorlon. “Critical infrastructure, complex vendor networks, sensitive data, and known security gaps make healthcare one of the most attractive targets in the world. The teams that find out their exposure after an incident are the ones who never looked before it.”

From the cybersecurity policy and law enforcement front,

  • Cybersecurity Dive reports,
    • “The U.S. government wants to know how major U.S. technology companies are using AI to protect their computer networks and how they’re preparing for the possibility of an AI-driven cybersecurity crisis.
    • “Officials from the White House’s Office of the National Cyber Director (ONCD) have reached out to tech giants in recent weeks with questions about AI, information sharing, vulnerability patching and how the federal government can help, according to an email and a list of questions shared with Cybersecurity Dive.” * * *
    • “ONCD asked the companies to answer 11 questions on a range of cybersecurity topics by May 1.”
  • and
    • “A group of U.S. government agencies on Wednesday [April 29] offered advice for critical infrastructure organizations on applying zero-trust (ZT) principles to their operational technology (OT) environments.
    • “Taking a zero-trust approach to these industrial systems requires careful consideration, the new government publication says, “because OT systems interact with the physical environment and are constrained by availability and safety requirements, as well as legacy technology with long lifespans.”
    • “The document — co-authored by the Cybersecurity and Infrastructure Security Agency (CISA), the FBI and the departments of Defense, Energy and State — describes the unique challenges that OT environments pose, the importance of clear governance frameworks and supply-chain oversight, and the steps that infrastructure operators should take to implement zero trust.”
  • and
    • “The Australian and U.S. governments, along with other international partners, released guidance on Friday [May 1] for safely deploying agentic AI systems.
    • The automation capabilities of AI agents create unique risks that can lead to “productivity losses, service disruption, privacy breaches or cybersecurity incidents,” the guidance document reads. “Organisations must therefore anticipate what could go wrong, assess how agentic AI risk scenarios might affect operations and establish ongoing visibility and assurance to maintain confidence in their agentic AI investments.”
    • “Safely using AI agents means “never granting it broad or unrestricted access, especially to sensitive data or critical systems,” the document warns. Companies, it says, “should only use agentic AI for low-risk and non-sensitive tasks.”
    • “The publication — co-issued by the Australian Signals Directorate, the U.S.’s Cybersecurity and Infrastructure Security Agency and National Security Agency and their British, Canadian and New Zealand counterparts — comes as businesses race to integrate AI tools into their workflows and increasingly embrace agentic AI for its ability to automate repetitive tasks.”
  • HelpNet Security adds,
    • “AI agents need credentials to work. They authenticate with LLM platforms, connect to databases, call SaaS APIs, access cloud resources, and orchestrate across dozens of external services. Every integration point requires an identity. Most organizations are handling this badly, and the evidence is in the code.
    • “GitGuardian’s State of Secrets Sprawl Report found 28,649,024 new secrets exposed in public GitHub commits across 2025, a 34% year-over-year increase and the largest annual jump in the report’s history.
    • “One of the root causes is authentication design: which credential type gets chosen, what scope it carries, how long it lives, and where it gets stored. In the meantime, AI is creating more credentials that need managing and generating more artifacts where those credentials leak.”
  • Per a National Institute of Standards and Technology news release,
    • “The National Institute of Standards and Technology (NIST) is hosting a virtual event titled “Building Your Small Business Cybersecurity Team: From In-House to Outsourcing” on May 5, 2026, from 2:00 to 3:00 p.m. EDT. The webinar, part of National Small Business Week, focuses on helping small businesses develop cybersecurity teams to manage and reduce risks. It will address different team structures based on factors such as budget, staff capabilities, and organizational needs, including in-house roles, full teams, and outsourced support. Speakers will discuss considerations for hiring, outsourcing, and training employees, as well as available resources such as the National Initiative for Cybersecurity Education Workforce Framework for Cybersecurity.  For additional information and to register for the event refer to the official NIST Event page.”
  • Cyberscoop informs us,
    • “Two former cybersecurity professionals who moonlighted as cybercriminals, committing a series of ransomware attacks in 2023, were each sentenced to four years in prison, the Justice Department said Thursday [April 30].
    • “Ryan Clifford Goldberg and Kevin Tyler Martin previously pleaded guilty to one of three charges brought against them in December and faced up to 20 years behind bars. 
    • “Goldberg, who was a manager of incident response at Sygnia, and Martin, a ransomware negotiator at DigitalMint at the time, collaborated with Angelo John Martino III to attack victim computers and networks and use ALPHV, also known as BlackCat, ransomware to extort payments.
    • “These defendants exploited specialized cybersecurity knowledge not to protect victims, but to extort them,” Jason A. Reding Quiñones, U.S. attorney for the Southern District of Florida, said in a statement. “They used ransomware to lock down critical systems, steal sensitive data, and pressure American businesses into paying to regain access to their own information.”

From the cybersecurity breaches and vulnerabilities front,

  • The Washington Post reports on April 30,
    • “The Trump administration inadvertently exposed the Social Security numbers of health care providers in a database powering a new Medicare portal, The Washington Post found.
    • “The Centers for Medicare and Medicaid Services (CMS) last year created a directory to help seniors look up which doctors and medical providers accept which insurance plans, framing it as an overdue improvement and part of the Trump administration’s initiative to modernize health care technology.
    • “But a publicly accessible database used to populate the directory contains some of the providers’ Social Security numbers, linked to their names and other identifying information. For at least several weeks, CMS made the database available for public use as part of its data transparency efforts. The files are not immediately visible to users who visit the provider directory.
    • “The Post downloaded the database and identified at least dozens of Social Security numbers belonging to health care providers while reviewing a sample of rows.
    • “The Post informed health officials on Tuesday that the numbers had been exposed, giving the agency time to take down the database, and contacted some of the affected providers, who said they were confused and concerned.” * * *
    • “CMS officials said they are working to fix the problem that led to the exposure. A spokesperson said the problem “stems from incorrect entries of provider or provider-representative-supplied information in the wrong places” — essentially, that providers entered information in the wrong place and left their own Social Security numbers exposed.
    • “The agency has taken steps to address it promptly and reinforce safeguards around data submission and validation,” CMS said in a statement.”
  • Cyberscoop relates on April 30,
    • “A pair of persistent and problematic threat groups affiliated with The Com are actively targeting organizations across multiple critical infrastructure sectors for rapid data theft and extortion attacks, according to CrowdStrike.
    • “The financially-motivated attackers, which CrowdStrike tracks as Cordial Spider and Snarky Spider, have used voice-phishing and social engineering attacks to break into victims’ identity platforms and traverse SaaS environments since at least October 2025, the company said in a report Thursday, which it shared exclusively with CyberScoop prior to release. 
    • “Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, said the subgroups composed of native English speakers primarily target U.S.-based organizations in the academic, aviation, retail, hospitality, automotive, financial services, legal and technology sectors.
    • “This “new wave of ecrime threat actors” are closely aligned with Scattered Spider and linked to other subsets of The Com, including SLSH and ShinyHunters, Meyers said.” 
  • Cybersecurity Dive tells us,
    • “Phishing attacks using QR codes to direct victims to malicious links surged in the first quarter of 2026, Microsoft said in a threat report published on Thursday [April 30].
    • “Email-based phishing attacks overwhelmingly used malicious links rather than attachments during the first three months of the year, reflecting the greater range of delivery options for externally hosted threats.
    • “A major phishing-as-a-service (PhaaS) platform is significantly diminished after recent attempts to choke off its infrastructure, the company said.”
  • InfoSecurity Magazine points out,
    • “The threat landscape in 2025 was characterized by a surge in compromised credentials, extortion and vulnerability exploitation, according to a new report from KELA.  
    • “The threat intelligence firm tracked nearly 2.9 billion compromised credentials last year globally, it said in its latest report, The State of Cybercrime 2026: Emerging Threats & Predictions.” * * *
    • “Cybercriminals and APT groups have moved from using AI merely as a supportive tool in attacks to making it an essential component in the complexity, enhancement, and escalation of those attacks,” it warned.
    • “Specifically, attacks have moved on from basic jailbreaking of LLMs to vibe hacking for autonomous execution of entire workflows, the report claimed. AI-assisted malware and prompt injection attacks designed to hijack agents are also increasingly common, KELA said.
    • “We’re seeing a fundamental pivot in adversary behavior with the shift from AI-assisted tools to fully autonomous, agentic malicious workflows, where over 80% of operations require minimal human oversight,” said David Carmiel, CEO of KELA.
    • “Attackers no longer need to break in through a backdoor, they can quickly find the key and walk through the front using stolen credentials. Organizations relying on stale intelligence and legacy defenses instead of AI-powered solutions are leaving the door wide open to attacks.”
  • The Cybersecurity and Infrastructure Security Agency, which beginning yesterday is no longer subject to shutdown, added four known exploited vulnerabilities to its catalog this week.

From the ransomware front,

  • Security Week reports,
    • “South Carolina-based healthcare provider Sandhills Medical Foundation has disclosed a data breach affecting nearly 170,000 individuals.
    • “Sandhills Medical said in a data security incident notice on its website that it discovered a ransomware attack on May 8, 2025. 
    • “It has since been working with law enforcement, cybersecurity experts, and a forensics firm to investigate the intrusion and determine its impact.
    • “Now, nearly one year later, the healthcare organization has publicly disclosed the incident and notified affected individuals.
  • Insurance Business Magazine relates
    • “A single ransomware crew exploiting a single brand of firewall is now driving nearly half of all cyber insurance claims, At-Bay has warned, in a finding that recasts how underwriters and brokers should be thinking about risk selection.
    • “The cyber carrier’s 2026 InsurSec Report, drawn from more than 6,500 claims and 100,000 policy years, concluded that ransomware has entered an infrastructure-driven phase.
    • “Attackers, it said, are no longer hunting by industry or company size but by the network appliances their targets happen to run.
    • “Nearly three in four ransomware attacks, or 73%, began with a VPN in 2025 — a share that has almost doubled in two years.
    • “SonicWall topped the list of most-targeted VPNs for the first time, linked to 27% of ransomware claims. Akira alone accounted for more than 40%, the highest concentration of a single strain on At-Bay’s books, with SonicWall appliances present in 86% of its attacks.”
  • Security Affairs tells us,
    • “Symantec researchers report that recent Trigona ransomware attacks used a custom-built data exfiltration tool instead of common utilities like Rclone or MegaSync. This shift, seen in March 2026 incidents, gives attackers more control and helps them evade detection, as standard tools are often flagged by security systems. Researchers believe this move shows a growing investment in proprietary malware to stay stealthy. 
    • “The attacks, which occurred in March 2026, mark a significant shift in tactics for Trigona affiliates. The motivation for moving away from publicly available tools remains unknown.” reads the report published by Symantec. “Many publicly available tools are now so well known that they may be flagged by security solutions.”
    • “Trigona, active since late 2022, operates as a Ransomware-as-a-Service linked to the Rhantus cybercrime group.”
  • Dark Reading informs us,
    • “The latest variant of an emerging ransomware may be far more destructive than its operators intended, acting as a wiper that deletes many of an organization’s captured files instead of encrypting them, as typical ransomware does. This scenario makes recovery impossible for defenders while complicating the possibility of holding files for ransom for the attackers.
    • “The Vect 2.0 variant of the ransomware-as-service (RaaS) operation, which first appeared last December, has a flaw across its versions for Windows, Linux, and VMware ESXi that inadvertently and permanently destroys so-called “large files” rather than encrypting them, according to a report published this week by Check Point Software. 
    • “For all files of only 128KB or higher, “this effectively makes Vect a wiper for virtually any file containing meaningful data, enterprise assets such as VM disks, databases, documents and backups included,” according to the report. Check Point has confirmed that the flaw, which “discards three of four decryption nonces for every file above 131,072 bytes (128 KB),” is identical across all three platform variants.” * * *
    • “For defenders, this makes the situation slightly worse, as they no longer will be able to recover all of their files, even if they agree to pay the ransom to do so, Check Point says. “Victims who pay the ransom cannot receive a working decryptor for their largest files, not through operator deception, but because the information required for decryption was irrecoverably destroyed at the moment of encryption.”
    • “They probably wouldn’t realize they can’t recover files only after the ransom is paid and their decryption key doesn’t work, which is why Check Point found it so important to report the flaw in Vect, Smadja says.”

From the cybersecurity business and defenses front,

  • CRN reports,
    • “Anthropic announced Thursday [April 30] it’s moving Claude Security, formerly known as Claude Code Security, into public beta to enable rapid AI-powered vulnerability discovery and remediation.
    • “The launch follows the widely discussed disclosure about Anthropic’s Claude Mythos Preview earlier this month, though the Claude Security offering does not leverage Mythos.
    • “Today’s models are already highly effective at finding flaws in software code,” Anthropic said in a blog post Thursday. “The next generation will be more capable still, and will be particularly effective at autonomously exploiting these flaws.”
  • Cybersecurity Dive relates,
    • “PwC has launched an AI-driven, unified detection-and-response managed security service, enabled by Google Security Operations.
    • “The recent announcement follows PwC’s three-year, $400 million collaboration investment with Google Cloud to modernize cybersecurity operations, unveiled in January. The offering targets smaller and mid-sized enterprises that wouldn’t typically turn to a big consulting firm for cybersecurity.
    • “This is not an old-school cyber-managed service offering that requires a lot of people, time and infrastructure to set up,” PwC’s Partner, Global and US Managed Services Leader, Tim Canonico told Channel Dive from the Google Cloud Next conference in Las Vegas. “We’re leveraging Google’s SecOps platform and building agents to do a lot of the work that would typically require large-scale teams to operate.” * * *
    • “All this automation has human checkpoints, and Canonico says it helps create an efficient, low-cost cybersecurity service with 24/7 monitoring, detection and response.”
  • Security Week tells us,
    • Cisco on Thursday [April 30] unveiled a new open source tool, named Model Provenance Kit, designed to help organizations address potential issues associated with the use of third-party AI models.
    • Organizations often leverage AI models obtained from model repositories such as HuggingFace, where millions of models are available.
    • While these models can offer many benefits, organizations often don’t track the changes made to them. In addition, although repositories provide guidance on the importance of model cards and metadata, the maintenance work performed by their developers can vary, affecting downstream users. 
  • The Wall Street Journal infoms us
    • “OpenAI and Microsoft MSFT have reached a truce.
    • “The startup and its longtime partner have forged a new deal that offers OpenAI more freedom to partner with Microsoft’s rivals, caps the amount of revenue it must share with the software giant through 2030 and removes a controversial clause in prior agreements. Microsoft, meanwhile, will retain access to the startup’s models and products.”
  • Here is a link to Dark Reading’s CISO Corner.

Monday report

From Washington, DC

  • Beckers Hospital Review reports,
    • “Americans spend more than $1.6 trillion a year on hospital care — roughly one-third of all health spending — and a new paper from the nonprofit think tank Paragon Health Institute argues that government policy is the primary driver of why those costs keep climbing.
    • “The paper, “The Hospital Cost Crisis: How Government Policies Drive Consolidation, Undermine Competition, and Fuel Soaring Prices,” was authored by John Graham, a visiting fellow at Paragon with nearly three decades of health policy experience.” * * *
    • Click here to read the paper in full. FEHBlog note — The article includes ten highlights from the report.
  • and
    • “Johnson & Johnson will begin marketing four prescription drugs on the Trump administration’s TrumpRx website, according to an April 24 report from CBS News.
    • “The drugs include metformin, metformin extended release, Invokana and Xarelto. Pricing on the platform shows Invokana discounted 62% to about $225 from $598.56, Xarelto discounted 68% to about $197 from $611.82, and Invokamet XR — an extended-release combination of canagliflozin and metformin — discounted 62% to about $225 from $598.56, based on listed cash-pay prices.”
  • MedPage Today relates,
    • “Advocates for the LGBTQ+ community claimed a win this week after the Trump administration pledged to reinstate the 988 Suicide and Crisis Lifeline specialized support program tailored to their needs.
    • During a Senate hearing earlier [last] week, HHS Secretary Robert F. Kennedy Jr. was asked whether he would commit to restoring the tailored line for LGBTQ+ callers to 988, as required by law, after the Trump administration removed it last summer.
    • “We are working on getting it up now,” Kennedy said.
    • “While most 988 calls are routed to the nearest call center, callers who press 3 or text PRIDE were once connected to a centralized network of trained crisis counselors who have shared lived experiences or are trained to provide services to LGBTQ+ youth.
    • “Linking callers to local resources is usually best, since support outside of a phone call might be needed. However, for those in states where attacks on LGBTQ+ individuals are widespread, local resources may not be preferred, Hannah Wesolowski, chief advocacy officer for the National Alliance on Mental Illness, told MedPage Today.
  • The American Hospital Association News tells us,
    • “The AHA again is asking the Health Resources and Services Administration to take action after Eli Lilly warned hospitals that they could lose access to discounted drug prices unless they comply with new data submission requirements.
    • “The AHA said Eli Lilly recently issued a letter to hospitals participating in the 340B Drug Pricing Program threatening the “imminent loss” of discounted pricing if claims data are not submitted “without further delay.”
    • “The AHA for months has raised concerns with HRSA about these practices.
    • “Unfortunately, we are not aware of any action that HRSA has taken to address these unlawful drug company claims-data policies, even as more and more companies have announced policies similar to Lilly’s,” the AHA wrote. “HRSA’s inaction here stands in stark contrast to the speed with which it acted in 2024 when the drug companies announced their unlawful rebate policies.”

From the Food and Drug Administration front,

  • Health Exec reports,
    • “Multiple wound and burn gel products are being removed from where they are used or sold, after it was discovered that a packaging failure was leading to the sterile barrier being breached. Unfortunately, this has led to at least 14 serious injuries. 
    • “The manufacturer of the gels, Integra LifeSciences, issued a letter to distributors of the products,  branded as MediHoney and CVS Wound Gel. The products are sold in retail settings, but also may be found in patient care settings. 
    • “In a statement, the U.S. Food and Drug Administration (FDA) said it’s aware of the issue and provided the known details. The agency said it has determined that using wound gels with the defective packaging may “cause temporary or reversible health problems, or—though unlikely—serious health problems.”
    • “Despite the risk of severe infection and the recorded injuries, there are no known deaths associated with the recalled wound gels.” 
  • The American Hospital Association adds,
    • “The Food and Drug Administration has identified a nationwide recall. Arrow International is recommending dialysis catheter kits containing Merit Medical 16F Dual-Valved Splittable Sheath Introducers be taken out of use due to a design defect where the sheath introducer may not split as intended. In addition, the FDA issued an Early Alert for Omnicell i.v.STATION sterile labels. Omnicell recommends customers do not use affected labels. They should verify the accuracy of labels on filled products.”
  • Fierce Pharma tells us,
    • “AstraZeneca’s systemic lupus erythematosus (SLE) med Saphnelo may have earned a considerable convenience edge in the United States, courtesy of an FDA nod clearing the drug for self-administration via a once-weekly autoinjector. 
    • “As with the drug’s original SLE nod in 2021, the self-administration green light covers the use of Saphnelo on top of standard therapy, AZ said in an April 27 release. In its original formulation, Saphnelo, also known as anifrolumab, is given as an intravenous infusion. 
    • “The FDA signed off on the new administration route after reviewing data from the late-stage TULIP-SC study, in which subcutaneous dosing of Saphnelo triggered statistically significant and clinically meaningful disease activity reductions versus placebo, according to AZ.”
  • and
    • “Johnson & Johnson is bolstering the case for its approved schizophrenia med Caplyta to prevent relapses in the disease. 
    • “On Monday, the FDA approved J&J’s supplemental new drug application for the atypical antipsychotic to include long-term data on the med’s schizophrenia relapse-prevention capabilities.
    • “In a press release, J&J clarified that the “label update builds upon the existing clinical data and postmarketing experience across [Caplyta’s] approved uses.” 
    • “Relapses pose a significant challenge for schizophrenia patients and can disrupt stability, undermine functioning and often trigger episodes of psychosis, hallucinations and other symptoms that have the potential to disrupt daily life, according to J&J. On average, adults living with the condition experience nine relapse episodes within a six-year period, the company added.” 

From the public health and medical / Rx research front,

  • NBC News reports
    • “Deaths from rectal cancer are rising rapidly among younger adults, an alarming trend that is confounding scientists trying to understand why millennials are so hard-hit. 
    • “The rate of rectal cancer seems to be increasing more than two to three times compared to colon cancer,” said Mythili Menon Pathiyil, lead author of a new study and a gastroenterology fellow at SUNY Upstate Medical University in Syracuse, New York. 
    • “If the trend continues, rectal cancer deaths will exceed the number of colon cancer deaths — already the nation’s No. 1 cause of cancer death in people under age 50 — by 2035.”
    • “According to the American Cancer Society, 158,850 new colorectal cancers will be diagnosed in 2026. About 55,230 patients will die from the disease, with nearly a third of those deaths in people under age 65. Colon cancer and rectal cancer are similar but form in different parts of the digestive tract. 
    • “The new research, which hasn’t yet been published in a peer-reviewed journal, is scheduled to be presented at Digestive Disease Week, an annual meeting of gastroenterologists, in May. 
    • “The findings, however, strengthen an American Cancer Society study released in March showing that a rise in rectal cancer rates is driving increases in colorectal cancer diagnoses in people younger than age 65. Colorectal cancer rates have been increasing 3% each year for adults under age 50 since the late 1990s and scientists are scrambling to understand why.”
  • STAT News considers what happened to COVID?
    • “There is an ever-shrinking portion of the population that thinks it’s never been infected — the folks who call themselves Novids. Even among that population, many have all but certainly been exposed to the virus but had only asymptomatic infections.”
    • “This, many experts told STAT, explains why the threat from Covid has subsided.” * * *
    • “Most of the experts STAT consulted believe the virus either now qualifies as, or is on its way to becoming, just another one of the viruses that make people sick with cold or flu-like symptoms — with some caveats. For one, the risk remains high for some people — particularly older people, very young children, and people with medical conditions that weaken their immune systems. For another, cold and flu-like viruses trigger symptoms that range from sniffles and coughs to knock-you-off-your-feet illness. A bad case of flu can take a couple of weeks to recover from, even for a healthy person. Same with Covid.” * * *
    • “Marion Koopmans, scientific director of the Pandemic and Disaster Preparedness Center at Erasmus University in Rotterdam, the Netherlands, said at this point, annual boosting is probably not doing much for people who aren’t at high risk.
    • “What we really would need is data on what the effect is of boosting on variant specific responses AND protection from disease over increasing intervals between boosters. That data is virtually impossible to get,” she wrote in an email. (Pfizer recently announced it had halted a clinical trial the Food and Drug Administration asked it to conduct in healthy adults aged 50 to 64, because it couldn’t recruit enough volunteers.) 
    • “But for high-risk individuals, Covid boosters still offered protection against becoming sick enough to require hospitalization, the latest study in the Netherlands concluded, Koopmans said.”  
  • MedPage Today adds,
    • “Two multicenter trials [(PANORAMIC and CanTreatCOVID)] found no change in hospitalization and death rates when antiviral nirmatrelvir-ritonavir (Paxlovid) was given to COVID-19 patients already mostly vaccinated.” * * *
    • “Now, the PANORAMIC and CanTreatCOVID results reflect a COVID-19 landscape that’s shifted since the pandemic’s early period, said H. Clifford Lane, MD, former deputy director for clinical research and special projects at the National Institute of Allergy and Infectious Diseases (NIAID), and Anthony Fauci, MD, the former NIAID director.
    • “These new data indicate that the 89% relative risk reduction seen in the analysis of hospitalizations or death associated with the use of nirmatrelvir-ritonavir in the EPIC-HR trial does not apply to the current circumstances, in which most adults have varying degrees of preexisting immunity and the circulating variants are different,” Lane and Fauci wrote in an accompanying editorialopens in a new tab or window.
    • “That doesn’t mean nirmatrelvir-ritonavir’s therapeutic time has come and gone, they cautioned. PANORAMIC and CanTreatCOVID participants who took the combination drug saw enhanced recovery and faster viral load reductions, they noted, which points to both clinical efficacy and antiviral activity.”
  • Health Day tells us,
    • “The eyes are the windows not only to the soul, but also to a person’s health, a new study says.
    • Premature aging of the retina could be a red flag for major diseases like diabetes or heart disease, researchers recently reported in the journal Communications Medicine.
    • “They found that people had a higher risk of chronic disease if they had advanced aging of their retinas — the light-sensitive layer of cells that lines the back wall of the eye.”
  • Per a National Institutes of Health news release,
    • “A National Institutes of Health (NIH)-funded clinical study shows that a symptom-based treatment for babies with neonatal opioid withdrawal syndrome (NOWS) — a highly prevalent condition wherein opioid exposure during pregnancy leads to withdrawal after birth — could speed up their recovery.
    • “To treat babies with moderate to severe symptoms of NOWS, doctors often administer opioid medication, lowering the dose over time. Many doctors commonly use this scheduled dosing approach, however, the new study found that providing “as-needed” doses of opioid medications based on each baby’s signs of withdrawal helped them stop the medicine sooner and go home earlier.
    • “Scheduled opioid dosing, which includes a taper, is necessary for some infants with NOWS, however it may overtreat others,” said corresponding author Lori Devlin, D.O., a professor of pediatrics at the University of Louisville and Norton Children’s Neonatology. “The idea is that by matching treatment to disease severity, we can accelerate recovery and minimize exposure.”
  • Genetic Engineering and Biotechnology News informs us,
    • “A cellular-resolution molecular map details how Down syndrome alters human brain development before birth. The study analyzed more than 100,000 nuclei from human prenatal neocortex samples collected across 26 pre-genotyped donors during gestational weeks 13 to 23—the only window during which all the cortical neurons a person will carry for their entire life are generated. The findings suggest that Down syndrome disrupts the developmental sequence of that process, creating shifts that may help explain later differences in cognition, learning, and sensory processing.
    • “This work is published in Science in the paper, “A single-cell multiomic analysis identifies molecular and gene-regulatory mechanisms dysregulated in developing Down syndrome neocortex.
    • “There’s a new level of detail here that had never existed before,” said Luis de la Torre-Ubieta, PhD, an assistant professor of psychiatry and biobehavioral sciences at UCLA and a member of the Eli and Edythe Broad Center of Regenerative Medicine and Stem Cell Research. “For the first time, we can really try to understand systematically what’s going on in the developing brain of individuals with Down syndrome.”
  • STAT News points out,
    • “The drugmaker Erasca said Monday that its RAS-targeting pill shrank tumors in 40% of patients with advanced pancreatic cancer and 62% of patients with advanced non-small cell lung cancer, results that the company said exceeded its expectations. 
    • “The new data, collected from studies done in the U.S. and China, are still preliminary. However, Erasca said the clinical benefit and tolerability of its drug, called ERAS-0015, compared favorably to daraxonrasib, a similar RAS-targeting drug from Revolution Medicines that recently showed a doubling of overall survival in patients with advanced pancreatic cancer.
    • “I’m excited about both datasets, but I think lung is more definitive at this point. The pancreatic results are maturing, but are very, very promising,” Erasca CEO Jonathan Lim told STAT. “All options are on the table.” 
  • and
    • “An oral medicine for hair loss successfully spurred hair growth in a late-stage trial, startup Veradermics announced Monday.
    • “Veradermics assessed the pill in two ways: by how many hairs grew within a square centimeter of the scalp, on average, and by how satisfied participants were with the results. Over the course of six months, men who took the drug, known as VDPHL01, either once or twice daily had between 30 and 33 more hairs per square centimeter of scalp. Men in the placebo group grew approximately seven additional hairs.
    • “Between 79% and 86% of men taking VDPHL01 said they saw improvement, along with between 72% and 84% of the clinical trial investigators — results that pleased Reid Waldman, a dermatologist turned Veradermics’ chief executive.” 
  • BioPharma Dive adds,
    • “An experimental gene editing medicine from Intellia Therapeutics has succeeded in a Phase 3 trial, positioning the company to seek approval of what would be the first treatment of its kind for a rare disorder known as hereditary angioedema.
    • “When compared to a placebo, the therapy, “lonvo-z,” reduced the rate of the disease’s hallmark swelling attacks by 87% over the course of about six months, meeting the study’s primary objective. Lonvo-z also helped rid 62% of recipients of disease attacks or the need for other therapies during that follow-up period, versus 11% of placebo patients.
    • “Intellia said, without specifics, that lonvo-z had a “favorable” safety and tolerability profile. The most common treatment-emergent side effects were infusion-related reactions, headache and fatigue, and all reported by a Feb. 10 data cutoff were mild to moderate in degree. The company has begun a “rolling” U.S. approval submission and, assuming a clearance, intends to launch lonvo-z in the first half of 2027.” 

From the U.S. healthcare and artificial inteliigence front,

  • Beckers Payer Issues reports,
    • “Elevance Health has set aside $935 million to cover potential costs tied to its ongoing risk adjustment data dispute with CMS, which threatens the insurers’ ability to enroll new members into some of its Medicare Advantage plans.
    • “CFO Mark Kaye disclosed the charge during the company’s first quarter earnings call on April 22, saying the figure reflects Elevance’s current best estimate of what the issue could cost as it works toward a resolution with the government.
    • “[Elevance CEO Gail} Boudreaux also characterized the issue as a historical payment dispute rather than a current compliance concern.”
  • and
    • “CenterWell, Humana’s pharmacy branch, is collaborating with Mark Cuban’s Cost Plus Drug Co. for an employer-based program, according to an April 27 news release.
    • “CenterWell will use Cost Plus Drugs’ SwiftyRx, a digital pharmacy software-as-a-service solution, for medication order intake. The platform should enable CenterWell to offer home delivery pharmacy services for the insurer’s eligible workforce in the Humana Associate Benefit Plan.
    • “Along with SwiftyRx, the organizations will harness Cost Plus Drugs’ drug pricing and CenterWell’s distribution strategies. The collaboration aims to ease access and reduce patient cost through smoother onboarding, automated benefit checks, lowered costs to fill prescriptions and operational efficiency.” 
  • Healthcare Dive points out,
    • Nearly three-quarters of U.S. finance leaders rank healthcare among their companies’ five biggest operating expense concerns, consulting firm Mercer found in a recent survey.
    • “The research comes as the rapid rise of GLP-1 weight-loss medications — like Wegovy and Ozempic — is adding to volatility in employer health costs.
    • “The survey results make clear the far-reaching impacts of rising health benefit costs for individual organizations,” Susan Potter, president of Mercer U.S. & Canada, said in an emailed statement. “Only about one in four CFOs said that their organization was able to absorb the cost increases over the past two years without any business impacts, such as slower wage growth, reduced hiring, or higher prices.”
  • Fierce Healthcare relates,
    • “Insurers are putting a growing focus on specialty drugs covered under the medical benefit, and on re-evaluating the efficacy of traditional rebate models, according to a new report.
    • “The Pharmaceutical Strategies Group (PSG) on Monday released its annual Trends in Specialty Drug Benefits report, which offers a look at how payers are responding to rising costs for these products and striking a balance between cost management and access.
    • “PSG surveyed 228 benefits leaders representing employers, health plans and union coverage, and found that 43% ranked managing specialty drug costs as their top goal. By comparison, 37% said their No. 1 goal is to manage total cost of care, per the report.
    • “As more and more of these products come to market and existing drugs gain new indications, managing them across the pharmacy and medical benefits poses significant complexity, the report found. More payers listed this as a top challenge than access to integrated data or member affordability.”
  • The Wall Street Journal reports,
    • “Eli Lilly agreed to acquire Ajax Therapeutics for up to $2.3 billion to bolster its blood-cancer portfolio.
    • “Ajax Therapeutics is developing AJ1-11095, a Type II JAK2 inhibitor for myelofibrosis patients.
    • “Eli Lilly’s deal to buy Ajax adds to a recent spate of pharma acquisitions, including several by Lilly.”
  • and
    • [India’s] Sun Pharmaceutical Industries will acquire U.S.-listed Organon for $11.75 billion, becoming a top three global women’s health player.
    • Organon, a Merck spinoff, has over 70 products in women’s health and general medicines, commercialized across 140 countries.
    • Sun Pharma will fund the all-cash deal through internal cash and bank financing; the acquisition will make it a top seven global biosimilars player.
  • and
    • Ligand Pharmaceuticals LGND said it has reached a deal to acquire Xoma XOMA Royalty, a company that invests in a range of biotech firms, for around $740 million.
    • “Under the terms, Ligand will pay $39 a share in cash for Xoma, a 2.9% premium over the $37.90 closing price on Friday. The deal is expected to close in the third quarter.
    • “Both Ligand and Xoma are known as royalty aggregators for investing in drugs while they are in development and then, if they work out, collecting royalties from their sales.
    • “By absorbing Xoma, Ligand’s total portfolio would more than double in size to more than 200 drugs and experimental treatments, including a handful of medicines on the market and several in late-stage studies.”
  • MedTech Dive adds,
    • “Johnson & Johnson said Friday it has struck a deal to buy Atraverse Medical, an atrial fibrillation ablation device developer founded by the team behind Farapulse.
    • “Atraverse sells a radiofrequency guidewire used to create an atrial septal defect to treat AFib. The Food and Drug Administration cleared the Hotwire device for use in 2024.
    • “Hotwire competes with products including Boston Scientific’s ProTrack RF Anchor Wire, which Atraverse cited as the predicate product in its 510(k) submission.”
  • Beckers Health IT observes,
    • “For years, the conversation about AI in health systems centered on technology adoption: which tools to buy, which pilots to run, which workflows to automate. But as health systems move from isolated AI deployments toward enterprise-wide agentic platforms, the limiting factor is no longer the technology. It’s the people managing it.
    • “That was the central tension running through a panel of health system technology leaders at Becker’s 16th Annual Meeting in Chicago this spring. Across organizations ranging from a large rural integrated delivery network to an urban academic medical center to a national cancer system, the same challenge surfaced: operations leaders have not yet grasped that they are now managing a digital workforce — and the consequences of that gap are starting to show.
    • “The biggest barrier to us moving forward is really getting operations to understand that this fundamentally changes their role in the equation,” said Jeff Gautney, CIO of Rush University Medical Center in Chicago. “They are managing a digital workforce and they need to think that way as opposed to [thinking that] IT is monitoring this, IT is keeping an eye on it, IT is delivering this solution and I don’t really need to think any differently about it.”
  • MedCity News adds,
    • “There are plenty of AI startups on the market promising to bolster hospitals’ finances by increasing revenue. But that’s not the case for San Francisco-based Midstream Health.
    • “For most health systems, the key to unlocking dollars isn’t boosting revenue — it’s decreasing costs, said Venkat Mocherla, Midstream’s co-founder and president.
    • “Midstream, founded in 2023, uses AI to clean up and unify hospitals’ fragmented financial and operational data, which helps leaders spot savings opportunities and make smarter purchasing decisions, he explained. For instance, the platform could help surface insights that help a hospital capture missed rebates or avoid overpaying for supplies and devices.” * * *
    • T”he company’s platform is being used across health systems including Mount SinaiCommonSpirit and Houston Methodist. Midstream primarily makes money by taking a cut of the savings it generates, which Mocherla noted aligns the startup’s incentives directly with hospitals’ financial outcomes.”

Noteworthy Death

  • Cardiovascular Business reports,
    • “Pioneer cardiologist Eugene Braunwald, MD, often referred to as the “father of modern cardiology,” died April 22. He was 96 years old.
    • “Braunwald was born in Vienna, Austria, and immigrated to the United States as a child to flee Nazi persecution. He went on to hold leadership positions with the National Heart, Lung and Blood Institute; the University of California, San Diego; Brigham and Women’s Hospital and Harvard Medical School. He authored or co-authored more than 1,000 publications over the course of his career and helped shape medical education for many years as the longtime editor of Harrison’s Principles of Internal Medicine, a premier textbook for clinicians. 
    • “Braunwald was also a lifelong contributor to a variety of industry societies, including the American College of Cardiology (ACC)American Heart Association (AHA) and European Society of Cardiology (ESC). He earned the highest honors from all of these groups over the course of his career in medicine, and the AHA even started giving out the Eugene Braunwald Academic Mentorship Award annually in 1999.”
  • RIP

Cybersecurity Saturday

From the Iranian war front,

  • Cybersecurity Dive reports on April 23,
    • “Iran, long considered a steady and persistent cyber threat to the U.S., has raised its game in the months since the two nations went to war in February. 
    • “Iranian-backed cyber threat groups, which range from state-sponsored actors to pro-Iranian hacktivists and financially motivated hackers, appear to have evolved some of their motivations and capabilities in cyber, according to analysts and security researchers. 
    • “What we are seeing are attacks that are aiming to have a more destructive effect,” Annie Fixler, director of the Center on Cyber and Technology Innovation (CCTI) at the Foundation for Defense of Democracies told Cybersecurity Dive. 
    • Specifically, Iran-linked actors have increased the use of data wiping malware in recent attacks against Israel and demonstrated greater capability to evade detection, according to researchers at Palo Alto Networks. 
    • “In another alarming development, Darktrace last week published an analysis of a malware strain called ZionSiphon, to potentially tamper with chlorine levels and pressure controls in Israeli water facilities. The malware was embedded with pro-Iran and Palestinian messaging for additional psychological impact.”
  • Federal News Network commentator shares “what federal leaders need to know about Iran’s cyber campaign.”
    • “To understand the cyber implications of this conflict, federal leaders need to understand how Iran uses cyber as a strategic instrument.”

From the cybersecurity policy and law enforcement front,

  • Cyberscoop reports,
    • “Sean Plankey, the long-sidelined nominee to lead the Cybersecurity and Infrastructure Security Agency, asked President Donald Trump on Wednesday to withdraw his nomination.
    • “At this point in time, I am asking the President to remove my nomination from consideration,” he said in a notification letter seen by CyberScoop. “After thirteen months since my initial nomination, it has become clear that the Senate will not confirm me.”
    • “Plankey’s request comes weeks after the Senate confirmed MarkWayne Mullin to lead the Department of Homeland Security, CISA’s parent agency.”
  • and
    • “House Republicans unveiled on Wednesday Congress’ latest effort to tackle comprehensive digital privacy legislation for Americans.
    • “The Secure Data Act would allow consumers to opt out of data collection for individual businesses for the purposes of targeted advertising, selling to third parties or for use in automated decisionmaking.
    • “It would also require companies to inform consumers when their personal data is being collected or used, provide them with a portable version of that data, and give consent rights to parents over the data collection of teenagers.”
  • Per a NIST news release,
    • “The National Institute of Standards and Technology (NIST), in collaboration with the Department of Health and Human Services Office for Civil Rights (HHS OCR), announced the Safeguarding Health Information: Building Assurance through the Health Insurance Portability and Accountability Act (HIPAA) Security 2026 conference, scheduled for September 2–3, 2026, at the NIST campus in Gaithersburg, Maryland. The event will examine the current healthcare cybersecurity landscape and the HIPPA Security Rule, which establishes federal standards to protect the confidentiality, integrity, and availability of electronic protected health information. The conference will highlight practical strategies, tips, and techniques for implementing the HIPAA Security Rule, including required administrative, physical, and technical safeguards for covered entities and their business associates. Sessions will address best practices for managing risks to electronic health information and ensuring technical assurance, along with topics such as cybersecurity risk management, current threats to the healthcare community, and cybersecurity considerations for Internet of Things technologies in healthcare environments. The event will be offered in both in-person and virtual formats, with separate registration fees and timelines for each option. For additional details, visit the Safeguarding Health Information: Building Assurance through HIPAA Security 2026 event page.”
       
  • Per an April 23, 2026, HHS news release,
    • “Today, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced settlements with four regulated entities following separate ransomware investigations under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. Ransomware is malicious software that blocks access to data—typically by encrypting it with a key known only to the attacker—until a ransom is paid. The resolutions announced mark 19 completed investigations from ransomware breaches and 13 completed investigations in OCR’s Risk Analysis Initiative.” * * *
    • “The settlements follow investigations into separate ransomware breaches that collectively affected over 427,000 individuals and involved the exposure of unsecured ePHI. The types of ePHI affected include demographic data, Social Security numbers (SSNs), financial information, lab results, medications, and diagnoses or conditions. Under the settlements, the regulated entities have agreed to implement corrective action plans subject to OCR monitoring for two years and paid a total of $1,165,000 to OCR.”
  • Per an April 20, 2026, Justice Department news release,
    • “A Florida man, formerly employed as a ransomware negotiator, pleaded guilty to conspiring to commit ransomware attacks against U.S. companies in 2023.
    • “According to court documents, Angelo Martino, 41, of Land O’Lakes, Florida, collaborated with the operators of the Blackcat/ALPHV (“BlackCat”) ransomware variant used by cybercriminals to attack and extort institutions and companies. Beginning in April 2023, Martino abused his role at a U.S.-based cyber incident response company to assist BlackCat actors. Working as a negotiator on behalf of five different ransomware victims, Martino provided BlackCat attackers with confidential information about the negotiating position and strategy of his company’s clients without the clients’ or his employer’s knowledge or permission. This confidential information assisted the ransomware actors and maximized the ransoms that the victims were required to pay. The confidential information included the victims’ insurance policy limits and internal negotiation positions. The BlackCat actors paid Martino for this confidential information.” * * *
    • “To date, law enforcement has seized $10 million of assets from Martino, including digital currency, vehicles, a food truck, and a luxury fishing boat that Martino obtained using proceeds of the offense or acquired as a result of the offense.”
  • Cyberscoop adds,
    • “A core leader of the hacker subset of The Com responsible for a series of high-profile phishing attacks and cryptocurrency thefts from September 2021 to April 2023 pleaded guilty to federal charges, the Justice Department said Friday. 
    • “Tyler Robert Buchanan of Dundee, Scotland, pleaded guilty to conspiracy to commit wire fraud and aggravated identity theft. The 24-year-old was arrested by Spanish police in Palma in 2024 as he attempted to board a charter flight to Naples, Italy. 
    • “Buchanan has been in federal custody since April 2025 and faces up to 22 years in federal prison at his sentencing, which is scheduled for August 21. 
    • “The British national and his co-conspirators, including Noah Michael Urban, who was sentenced to a 10-year federal prison sentence last year, harvested thousands of credentials via phishing and stole more than $8 million in cryptocurrency from U.S. residents via SIM-swapping attacks.”

From the cybersecurity breaches and vulnerabilities front,

  • Cybersecurity Dive reports,
    • “The Cybersecurity and Infrastructure Security Agency on Monday [April 20] released guidance related to the axios supply chain compromise originally disclosed in late March. 
    • “A suspected North Korean actor compromised the node package manager account for an axios maintainer last month. Axios is a Javascript library used widely across the software industry with millions of downloads per week. 
    • “CISA is urging security teams to monitor and review code depositories as well as continuous integration/continuous delivery pipelines that ran npm install or npm update on the compromised axios version, according to the guidance released Monday. 
    • “Security teams should search for cached versions of the affected dependencies in artifact repositories along with dependency management tools, according to the guidance. 
    • “If compromised dependencies are found during the search, organizations should revert the environment back to a known safe state, CISA said.” 
  • and
    • “Vercel, a cloud development platform, said that some of its internal systems were accessed after a third-party tool called Context.ai was compromised while being used by one of Vercel’s employees, according to a blog post released Sunday [April 20].
    • “Vercel is widely known as the creator of Next.js, which is the open-source framework for React. 
    • “The attacker was able to take over the employee’s Vercel Google Workspace account and access certain company “environments and environment variables” that were not designated as “sensitive.”
    • “Vercel said that a limited number of customers had their credentials compromised during the attack, and that they have been notified. They were urged to immediately rotate credentials. 
    • “The company said it believes the attacker is highly sophisticated, based on an assessment of their “operational velocity and detailed understanding of Vercel’s systems.”
  • and
    • “Hackers working for the Chinese government are increasingly hiding their attacks behind ready-made networks of hacked routers and other networking equipment, the U.S. and several allies said on Thursday [April 23].
    • “Attackers’ use of these so-called covert networks is not new, the agencies said in a joint advisory, “but China-nexus cyber actors are now using them strategically, and at scale.”
    • “By funneling their activity through compromised networking equipment — mostly small office and home office (SOHO) routers, but also internet of things devices — hackers can obfuscate their origins and make it harder for defenders to spot reconnaissance, malware deployment and data exfiltration.”
  • Cyberscoop adds,
    • “A state-sponsored hacking group has implanted a custom backdoor on Cisco network security devices that can survive firmware updates and standard reboots, U.S. and British cybersecurity authorities disclosed Thursday, marking a significant escalation in a campaign that has targeted government and critical infrastructure networks since at least late 2025.
    • “The Cybersecurity and Infrastructure Security Agency and the United Kingdom’s National Cyber Security Centre jointly published a malware analysis report identifying the backdoor, code-named Firestarter. Cisco’s threat intelligence division, Talos, attributed the malware to a threat actor it tracks as UAT-4356. The company attributed the same group to a 2024 espionage campaign called ArcaneDoor, which focused on compromising network perimeter devices.
    • “CISA confirmed it discovered Firestarter on a U.S. federal civilian agency’s Cisco Firepower device after identifying suspicious connections through continuous network monitoring. The finding prompted an updated emergency directive issued Thursday, requiring all federal civilian agencies to audit their Cisco firewall infrastructure and submit device memory snapshots for analysis by Friday.”
  • CISA added fourteen known exploited vulnerabilities (KVEs) to its catalog this week.
    • April 20, 2026
      • CVE-2023-27351 PaperCut NG/MF Improper Authentication Vulnerability
      • CVE-2024-27199 JetBrains TeamCity Relative Path Traversal Vulnerability
      • CVE-2025-2749 Kentico Xperience Path Traversal Vulnerability
      • CVE-2025-32975 Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability
      • CVE-2025-48700 Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
      • CVE-2026-20122 Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability
      • CVE-2026-20128 Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability
      • CVE-2026-20133 Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
        • The Cybersecurity Express discusses these KVEs here.
        • Cybersecurity Dive discusses the Cisco KVEs here.
    • April 22, 2026
      • CVE-2026-33825 Microsoft Defender Insufficient Granularity of Access Control Vulnerability
        • Bleeping Computer discusses this KVE here.
    • April 23, 2026
      • CVE-2026-39987 Marimo Remote Code Execution Vulnerability
        • Resecurity discusses this KVE here.
    • April 24, 2026
      • CVE-2024-7399 Samsung MagicINFO 9 Server Path Traversal Vulnerability
      • CVE-2024-57726 SimpleHelp Missing Authorization Vulnerability
      • CVE-2024-57728 SimpleHelp Path Traversal Vulnerability
      • CVE-2025-29635 D-Link DIR-823X Command Injection Vulnerability 
        • The Hackers News discusses these KVEs here.
  • Cybersecurity Dive informs us,
    • “Phishing was the most common way hackers breached their targets in the first quarter of 2026, after nearly a year out of the top spot, Cisco’s Talos threat intelligence team said in a report published on Wednesday.
    • “Nearly 20% of Cisco’s incident-response engagements involved the preliminary stages of a ransomware attack, according to the report — significantly lower than in the first two quarters of 2025, when it was 50%.
    • “Cisco also said it saw hackers using AI to improve phishing attacks.”
  • and
    • “Companies using AI to write code are creating serious security risks that not all organizations feel prepared to handle, according to a reportreleased Wednesday by the security testing firm ProjectDiscovery. 
    • “Security personnel want audit trails and access limitations before they integrate AI into their processes, ProjectDiscovery found. “They are not opposed to the technology, but they need it to earn its place.”
    • “The report highlights one of the most fraught aspects of the AI revolution in the corporate world: the tension between AI-assisted coders and the people responsible for protecting their work.”
  • Dark Reading points out,
    • “AI agents can now carry out end-to-end cloud attacks with minimal human guidance, exploiting known misconfigurations and vulnerabilities at a speed no human attacker can match. 
    • “That’s the central finding of a new proof-of-concept (PoC) study by Palo Alto Networks’ Unit 42, where researchers built an autonomous multi-agent system that carried out a complete cloud attack chain in a live environment, using a single natural-language prompt.
    • “The study suggests an intrusion campaign that Anthropic uncovered last year, when a Chinese state-affiliated cyber-espionage group used the company’s Claude AI to automate large portions of an attack chain, was more a preview of things to come rather than an exception.”
  • Cyberscoop notes,
    • “Attackers rarely exploit an edge-device vulnerability indiscriminately. Typically, they first test how widely the flaw can be used and how much access it can provide, then move on to steal data or disrupt operations.
    • “Pre-attack surveillance and planning leaves a lot of noise in its wake. These signals — particularly spikes in traffic that are hitting specific vendors — can act as an early-warning system, often preceding public vulnerability disclosures, according to research GreyNoise shared exclusively with CyberScoop prior to its release. 
    • “Roughly half of every activity surge GreyNoise detected during a 103-day study last winter was followed by a vulnerability disclosure from the same targeted vendor within three weeks, GreyNoise said in its report.
    • “Researchers determined that the median warning of an impending vulnerability disclosure arrived nine days before the targeted vendor issued a public alert to its customers.”

From the ransomware front,

  • Bleeping Computer reports,
    • “Home security giant ADT has confirmed a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid.
    • “In a statement shared today, the company said it detected unauthorized access to customer and prospective customer data on April 20, after which it terminated the intrusion and launched an investigation.
    • “This investigation determined that personal information was stolen during the breach.”
    • “The investigation confirmed that the information involved was limited to names, phone numbers, and addresses,” ADT told BleepingComputer.
    • “In a small percentage of cases, dates of birth and the last four digits of Social Security numbers or Tax IDs were included. Critically, no payment information — including bank accounts or credit cards — was accessed, and customer security systems were not affected or compromised in any way.”
  • and
    • “Recently observed Trigona ransomware attacks are using a custom, command-line tool to steal data from compromised environments faster and more efficiently.
    • “The utility was emplayed in attacks in March that were attributed to a gang affiliate, likely in an effort to avoid publicly available tools, such as Rclone and MegaSync, that typically trigger security solutions.
    • “Researchers at cybersecurity company Symantec believe that the shift to a custom tool may indicate that the attacker is “investing time and effort in proprietary malware in a bid to maintain a lower profile during a critical phase of their attacks.”
  • and
    • “A new Kyber ransomware operation is targeting Windows systems and VMware ESXi endpoints in recent attacks, with one variant implementing Kyber1024 post-quantum encryption.
    • “Cybersecurity firm Rapid7 retrieved and analyzed two distinct Kyber variants in March 2026 during an incident response. Both variants were deployed on the same network, with one targeting VMware ESXi and the other focusing on Windows file servers.
    • “The ESXi variant is specifically built for VMware environments, with capabilities for datastore encryption, optional virtual machine termination, and defacement of management interfaces,” explains Rapid7.”
  • Dark Reading relates,
    • “A ransomware gang known as “The Gentlemen” has made a name for itself, claiming hundreds of victims in a matter of months.
    • “The Gentlemen is a ransomware-as-a-service (RaaS) outfit that first popped up in mid-2025. While it operates fairly typical double extortion attacks (using both encryption and data leaking as extortion levers), The Gentlemen is known for sophisticated tactics, techniques, and procedures (TTPs), such as antivirus killers and complex infection chains.
    • “Check Point Research this week published its latest findings concerning the gang, noting that it has claimed hundreds of victims and uses malware including something called SystemBC, which researchers described as “a proxy malware frequently leveraged in human‑operated ransomware operations for covert tunneling and payload delivery.”

From the cybersecurity defenses front,

  • TechTarget discusses,
    • “Beyond awareness: Human risk management metrics for CISOs
    • “Traditional security training isn’t keeping threat actors out. As employee awareness programs fall short, Forrester Research suggests a better approach.” * * *
    • “With cybersecurity threats evolving so swiftly, organizations cannot afford to rely on outdated security awareness programs that fail to address the root causes of human vulnerabilities. Human risk management offers a transformative approach, shifting the focus from mere awareness to actionable behavior change.”
  • Dark Reading points out,
    • “When Anthropic announced Project Glasswing this month, most coverage landed on the headline numbers: a 27-year-old OpenBSD vulnerability, a 16-year-old FFmpeg flaw, a Linux kernel exploit chain assembled without human steering. The coalition behind it, including AWS, Apple, Cisco, CrowdStrike, Google, Microsoft, Palo Alto Networks, and others, isn’t there for the optics; they’re there because the model’s capabilities are real, and the coordinated disclosure pipeline matters.
    • “The part worth dwelling on is the FFmpeg result specifically. At least five million automated fuzzer testing passes hit that vulnerable line of code and not one caught it. Mythos Preview read the code, understood what it was doing, and found the flaw.
    • That gap highlights a fundamental security misconception of the past two decades.
    • The industry built enumerators. It needed readers.
    • Automated security tooling has almost always worked the same way at its core: define a pattern, scan to identify the pattern, flag the match. SIEMs ingest event logs and match rules. Static analysis tools check code against known signatures. Vulnerability scanners compare software versions against CVE databases, and so on. These are mostly based on enumeration, and enumeration can only find what you already know to look for.
    • “Five million passes with the industry standard tools, zero catches. These tools knew how to count. But they didn’t know how to read.
    • “Mythos Preview succeeded because it approached the code the way a skilled human analyst would: with an understanding of intent, of relationships between components, of what a sequence of operations does, rather than what it superficially looks like. Security at that depth has been the exclusive domain of rare, expensive human expertise. A model that replicates it at scale is genuinely a different kind of thing, and the industry is right to pay attention.”
  • Here is a link to Dark Reading’s CISO Corner.

Midweek report

From Washington, DC,

  • Per a House of Representatives news release,
    • “Today, the House Appropriations Committee met to consider the Fiscal Year 2027 Financial Services and General Government Appropriations Act. The measure was approved by the Committee with a vote of 34 to 28.” * * *
    • “A summary of the bill is available here.” * * *
  • Federal News Network adds,
    • “The prospects of a civilian federal pay raise next year are continuing to diminish, after House appropriators made no mention of a pay increase in their 2027 spending legislation.
    • “The House Appropriations Committee’s financial services and general government (FSGG) bill for fiscal 2027, which advanced along party lines Wednesday evening, says nothing on funding for a civilian pay raise. Although not yet final, that increases the chances federal employees will miss out on a salary increase next year.”
  •  A House Education and Labor subcommittee shared the testimony presented to its members during its PBM business model hearing today.
  • The Wall Street Journal offers seven takeaways from HHS Secretary Robert F. Kennedy Jr.’s numerous recent appearances before Congressional committees.
  • Healthcare Dive informs us,
    • “Prices for some healthcare services after arbitration under the No Surprises Act were much higher than the same in-network commercial prices before the law was passed, according to new research out this week.
    • “In 2024, prices for imaging after arbitration were 767% higher than average prices in Medicare. For comparison, the same imaging prices were roughly 200% higher than Medicare prices before the No Surprises Act was passed, according to an analysis published by the Brookings Center on Health Policy.
    • “Arbitration decisions in emergency care, imaging and pediatric critical care tended to skew more closely to amounts that providers offered during negotiations, rather than those offered by insurers, according to the analysis.” * * *
    • [This] Brookings research compliments other studies that have found the No Surprises arbitration process raises healthcare costs. One study published in Health Affairs last year found that IDR created an estimated $5 billion in costs between 2022 and 2024, which could eventually result in higher insurance premiums for consumers.”
  • Per an HHS news release,
    • “The Advanced Research Projects Agency for Health (ARPA-H), an agency within the U.S. Department of Health and Human Services (HHS), is today announcing the first set of research teams for its Evidence-Based Validation & Innovation for Rapid Therapeutics in Behavioral Health (EVIDENT) initiative, which will collectively fund up to $139.4 million to help spur new, effective therapies for behavioral health. As part of the Trump Administration’s Executive Order to Accelerate Medical Treatments for Serious Mental Illness, EVIDENT will allocate at least $50 million to match state government investments in psychedelic research for populations with serious mental illness.”
  • MedPage Today adds,
    • “From July 2022 [when the 988 mental health line was launched] through December 2024, 35,529 suicides among individuals ages 15 to 34 were observed compared with 39,901 expected suicides based on trends before the launch of the lifeline, corresponding to an 11% reduction (95% CI 8.7-13.1), reported Anupam B. Jena, MD, PhD, of Harvard Medical School in Boston, and co-authors in a research letter in JAMA.
    • “After replacing the previous 10-digit number for suicide and crisis services with the 3-digit number and investing more than $1.5 billion to expand crisis center capacity and workforce nationwide, “988 appears to be working where it matters most, in reducing suicide deaths among the young people who use it the most … saving lives, at scale, within a few years of launch,” said co-author Vishal R. Patel, MD, MPH, also of Harvard Medical School.
    • “Prior evidence for the lifeline was mostly indirect: higher call volumes, positive caller surveys, reductions in same-day distress,” Patel told MedPage Today. In contrast, this study shows that the lifeline actually affects suicide mortality at the population level, he noted.”
  • HR Dive relates,
    • “The U.S. Department of Labor’s Wage and Hour Division on Wednesday announced a proposed rule to streamline joint employer status under the Fair Labor Standards Act, the Family and Medical Leave Act, and the Migrant and Seasonal Agricultural Worker Protection Act, according to a department press release.
    • “The rule would create “a single nationwide standard that both derives from commonalities in federal court precedent where available and resolves significant differences among the circuit courts where they exist,” DOL said, to “ensure employees and employers have a clear, consistent understanding of when multiple employers are jointly responsible for protecting the wages and other rights of an employee.”

From the Food and Drug Administration front,

  • Fierce Pharma reports
    • ‘Merck is carving out its own place in the evolving HIV treatment space with an FDA approval for its Idvynso, a combination regimen that brings its novel islatravir to market for the first time and serves as the cornerstone of what could be a lucrative HIV franchise for the company. 
    • “Idvynso is a once-daily, two-drug oral pairing of Merck’s doravirine and islatravir. Doravirine is a non-nucleoside reverse transcriptase inhibitor (NNRTI) that has been commercialized since 2018 as part of Merck’s Pifeltro and Delstrigo, while islatravir is a newer nucleoside reverse transcriptase translocation inhibitor (NRTTI) that represents the “anchor medicine” in a number of other HIV combos that the company is advancing.
    • “The doravirine and islatravir combo’s debut is specifically targeted at patients who are switching from other HIV treatments and will be available in pharmacies after May 11, Merck said in its April 21 press release.” 
  • STAT News relates,
    • “The Swiss drugmaker Roche on Tuesday presented the latest data for its experimental multiple sclerosis drug, setting the stage for the company to seek approval for a medicine that it believes can cut relapse rates and slow the progressive disability the disease causes.  
    • “Now the test is whether the drug, called fenebrutinib, can win the regulatory green light.
    • “While three late-stage trials of the drug have shown it to be effective, analysts have homed in on some potentially worrying liver safety signals, an issue that previously prompted the Food and Drug Administration to reject an MS therapy developed by Sanofi. In data released Tuesday, researchers also disclosed that there were two drug-related deaths among patients who took fenebrutinib.  
    • “Roche has touted the potential of fenebrutinib — an oral tablet — noting that it hit its efficacy mark across different types of MS and offers a new approach for treating the disease. It’s also sought to differentiate its therapy from Sanofi’s rejected drug, called tolebrutinib.”

From the public health and medical / Rx research front,

  • BioPharma Dive reports,
    • “Revolution Medicines’ closely watched pancreatic cancer drug helped control tumors when administered early in a patient’s disease course, stimulating a response in at least half of those who got it either as a single treatment or alongside chemotherapy, according to trial results unveiled at a medical meeting Tuesday.
    • “The findings disclosed at the American Association for Cancer Research’s annual convention come from studies testing the therapy, daraxonrasib, in first-line pancreatic cancer. They follow, by a week, Phase 3 data showing the drug nearly doubled survival in people whose disease had progressed after an earlier treatment, sparking a share surge that has launched the company’s valuation past $30 billion.
    • “The Food and Drug Administration gave Revolution a special regulatory fast-pass that could lead to a clearance within weeks of an approval submission.”
  • and
    • “A three-drug combination involving Merck & Co.’s Welireg failed to significantly delay tumor progression or extend survival in a Phase 3 trial of patients newly diagnosed with the most common form of kidney cancer, setting back the big drugmaker’s plans to further expand use of the medication.
    • “The study evaluated Welireg alongside Merck’s immunotherapy Keytruda and Eisai’s Lenvima in first-line clear cell renal cell carcinoma and compared that regimen to the Keytruda-Lenvima tandem alone. Merck didn’t provide specifics but said that drug trio — as well as a separate one also tested in the trial — missed the study’s dual main objectives at an interim analysis.
    • “Merck noted how the findings don’t affect other ongoing studies in “Litespark,” the broad program it’s jointly conducting with Eisai and that includes other Welireg tests. The Food and Drug Administration is reviewing an application based on results from one Litespark study that would expand use of Welireg earlier in kidney cancer.”
  • MedPage Today relates,
    • “In a survey of roughly 45,000 U.S. adults representing more than 257 million people, 9% said they had obesity and drank heavily over the past month, while 3.8% said they had both obesity and met criteria for alcohol use disorder (AUD) over the past year, reported researchers led by Bryant Shuey, MD, MPH, of the University of Pittsburgh.
    • “Overlapping heavy drinking and obesity was most common among men ages 35 to 49 (13.6%), women ages 26 to 34 (11.9%), and Black individuals (11.9%). AUD and obesity overlap was highest for men and women ages 26 to 34 (6.2% and 5.1%), people without insurance, and those on Medicaid, the findings in JAMA Internal Medicine showed.
    • “Shuey and colleagues said the findings on this high-risk population call for public health and clinical interventions tailored to younger and middle-age adults, especially the uninsured and those on Medicaid, to prevent liver disease and liver-associated deaths.” * * *
    • “Given the effectiveness of GLP-1 drugs “for weight loss and metabolic dysfunction–associated steatohepatitis, expanding access for patients with co-occurring risky alcohol use and obesity may reduce liver disease burden,” they argued.”
  • Health Day tells us,
    • “Pregnancy-related deaths in the U.S. increased sharply during the COVID-19 pandemic, particularly among Black women, a new study reports.
    • “Deaths remain significantly higher today for Black mothers, even though they’ve returned to pre-pandemic levels for most other groups, researchers reported in the journal Obstetrics & Gynecology.
    • “We saw a dramatic increase in pregnancy-related deaths during the COVID-19 pandemic, but the recovery has not been equal across all groups,” said senior researcher Dr. Lindsay Admon, an associate professor of obstetrics and gynecology at the University of Michigan Medical School.
    • “We need to better understand what’s driving these differences so we can develop solutions that reduce maternal deaths and improve outcomes for everyone,” she said in a news release.”
    • * * * “Results showed that maternal deaths during or just after pregnancy rose more than 60% during the pandemic, from about 20 deaths per 100,000 live births in 2019 to 33 per 100,000 in 2021.
    • “Most of the pandemic increase was linked to COVID-associated deaths, researchers found. Early pregnancy death rates rose by 7.5 per 100,000 live births, and later pregnancy deaths by 3.7 per 100,000.
    • “By 2023 and 2024, early pregnancy deaths had returned to pre-pandemic levels, but those late in pregnancy and after pregnancy remained elevated.
    • “All death rates remained notably higher for Black mothers, researchers found.”
  • Per an NIH news release,
    • “In a National Institutes of Health (NIH)-funded study, researchers developed a cancer assessment tool that can identify high-risk patients and the tumor cells linked to that risk. The model, called scSurvival, uses a machine learning framework designed to analyze large-scale data at single-cell resolution. 
    • “With NIH support, Oregon Health & Science University (OHSU) tested the model on clinical data from more than 150 cancer patients. The tool predicted survival outcomes and linked specific cell populations to higher risk. 
    • “A risk assessment tool that not only tells you who may be at higher risk, but also provides clues as to why, could really help in these difficult cancers” said Anthony  Letai, M.D., Ph.D., director of NIH’s National Cancer Institute (NCI).”  

From the U.S. healthcare business and artificial intelligence front,

  • Beckers Hospital Review relates,
    • “Franklin, Tenn.-based Community Health Systems reported an operating income of $281 million (9.5% margin) on revenues of $3 billion in the first quarter of 2026, down slightly from a $284 million operating gain (9% margin) in the same period last year. 
    • “However, after interest payments on debt and other expenses, CHS reported a net loss of $58 million in the first quarter, compared to a $13 million loss in the first quarter of 2025. 
    • “We are pleased with the continued, tangible progress on our key priorities, demonstrated by improvements in quality scores, patient experience and physician satisfaction measures, and investments in growth opportunities,” CEO Kevin Hammons said in an April 21 news release. “In the face of a dynamic macroeconomic environment, we remain focused on the variables within our control and believe we are positioning the company for long-term success and value creation.”
  • and
    • “Optum Rx — the pharmacy benefit manager for UnitedHealth Group — claims its “PreCheck” prior authorization tool not only cuts prescription approval times but also reduces denials and appeals.
    • “UnitedHealth Group gave an update on the tool in an April 21 earnings call. Optum CEO Patrick Conway, MD, said denials due to missing information dropped by 68% and appeals were down 88%, thanks to PreCheck. He said PreCheck has been “easing interactions for clients, members and providers.”
    • “Dr. Conway reaffirmed that PreCheck has axed prescription approval time from eight hours to fewer than 30 seconds. 
    • “Optum Rx announced an expansion of PreCheck in November, alongside its decision to eliminate reauthorization requirements for 40 medications. In the November release, UnitedHealth Group said, as of this year, the PreCheck platform covers more than 45 medications and is leveraged across 20 health systems.”
  • Healthcare Dive tells us,
    • “Amazon is launching a weight management program with access to GLP-1s through its One Medical primary care chain, in a bid to help consumers more easily access the popular weight loss drugs alongside supportive care, the retail and technology giant said Tuesday. 
    • “Under the program, users work with a dedicated provider to receive a GLP-1 medication as well as follow-up care, so patients can adjust their treatment and address related health concerns like cardiovascular disease and diabetes. 
    • “Patients can also access prescriptions for “transparent pricing” on Amazon Pharmacy, the company said. New GLP-1 pills start at $25 per month with insurance or through cash-pay options as low as $149 per month.”
  • Fierce Pharma informs us,
    • “As pharma giants slash headcounts and routinely strike billion-dollar M&A deals, another trend is steadily playing out at many of the largest drugmakers: adoption of AI on a corporate scale.
    • “Mark Merck as a participant in this movement. On Wednesday, the company revealed a partnership with Google Cloud as it works to undergo an “agentic AI enterprise transformation.”
    • “As part of an investment in Google Cloud valued at up to $1 billion, Merck will get access to the tech giant’s agentic AI platform across its R&D operations, manufacturing, commercial teams and corporate functions.
    • “Notably, the deal involves Google Cloud engineers working directly with Merck’s teams to onboard the tech, according to the April 22 press release. In a statement, Dave Williams, Merck’s chief information and digital officer, noted that the AI push comes “as we enter one of the most significant launch periods in our company’s history.”
  • Beckers Health IT adds,
    • “UnitedHealth Group is betting big on AI in 2026 — $1.5 billion to be exact. 
    • “During the company’s Q1 earnings call, leaders fleshed out how that investment is materializing.
    • “Think about it this way: A third of this is explicitly invested into software products and platforms, accelerating Optum Insight’s transition of business models into an AI-first software and services firm. The remaining two-thirds is spent across signature end-to-end processes and functions across UnitedHealth Group,” Optum Insight CEO Sandeep Dadlani said. 
    • “Optum Insight, the technology-enabled services business under UnitedHealth, will manage internal AI use cases, which could eventually be translated and commercialized beyond the company. UnitedHealth expects a 2-to-1 return, much of it within the next 12 to 18 months.”
  • and
    • “Michael and Susan Dell have surpassed $1 billion in total giving to the University of Texas at Austin, becoming the university’s first billion-dollar donors, according to an April 21 news release.
    • “The latest investment will support development of the UT Dell Campus for Advanced Research, anchored by an AI-focused UT Dell Medical Center expected to open in 2030. The Dells’ investment will also support expanded supercomputing capabilities, student scholarships and housing.
    • “The medical center will integrate Houston-based University of Texas MD Anderson Cancer Center to provide cancer care as part of the new campus.
    • “The university plans to break ground on the medical center later in 2026.”
  • Fierce Pharma points out,
    • “After AbbVie earlier this year pledged a whopping $100 billion in U.S. R&D and capital investments over the next decade, the company is filling in more details on its expansion plans. And like with many other pharma giants, it’s putting down roots in North Carolina.
    • “The North Chicago-based drugmaker on Wednesday revealed its largest-ever capital investment in a single campus, plotting a 185-acre production hub in Durham. The project will cost some $1.4 billion and add more than 730 roles to the company’s headcount, according to an April 22 press release. The site will produce certain AbbVie medicines in its immunology, neuroscience and oncology portfolios.”

Cybersecurity Saturday

From the Iranian war front,

  • The New York Times reports on April 16,
    • “The exchange of bombs and missiles in the Middle East between Iran and its foes has been paused for more than a week now. Iran’s hackers, however, have remained active on the digital battlefield.
    • “Iran has continued its cyberspace operations since the cease-fire with the United States began on April 8, according to Western cybersecurity experts and former U.S. intelligence officials. In doing so, Tehran is trying to keep up pressure on the United States and Israel but also positioning itself to mount a bigger retaliation if peace talks do not resume.” * * *
    • “This is a time, more than ever, we should worry about Iran,” said Evan Peña, a co-founder of the cybersecurity firm Armadin. “In cyberwarfare there isn’t really a cease-fire.”
    • “Mr. Peña said that if the cease-fire or negotiations collapsed, Iran would want to be in a strong position to retaliate, potentially by attacking critical infrastructure in the United States. Tehran has done so in the past but generally with limited impact. More than a decade ago, Iranian hackers targeted a small dam in upstate New York, but by happenstance the dam’s sluice-gate controls had been taken offline for maintenance, much to the relief of U.S. investigators at the time.
    • “Iran, Mr. Peña said, is going to be more aggressive and devote more resources to trying to get access to American companies as the war rages on.” * * *
    • “Josh Zweig, the chief executive of Zip Security, which secures small and midsize enterprises, said Iran was specifically looking for less well-defended targets, like municipal-run water and energy facilities.
    • “He also said small firms that make investment decisions for wealthy individuals and families have been targeted.”

From the cybersecurity policy and law enforcement front,

  • Cyberscoop reports,
    • “National Cyber Director Sean Cairncross expects more executive orders coming from the White House as part of implementing the national cybersecurity strategy, he said Wednesday [April 15].
    • “Staffers on Capitol Hill and others in the cyber world have been awaiting the implementation guidance the Trump administration had proclaimed would come to accompany the strategy  published last month.
    • “Asked at a Semafor event about whether that would include executive orders, Cairncross answered, “I think that that’s the case.”
    • “Cairncross touted American ingenuity for producing an artificial intelligence model like Anthropic’s Claude Mythos, rather than it developing under U.S. cyber rivals like China or Russia. He acknowledged reports about the administration holding meetings about the cyber risks and benefits of something like Mythos — “the model right now that everyone’s talking about” — adding that the administration is looking to balance the dangers and positive capabilities of AI in cyberspace.”
  • and
    • “The federal agency tasked with analyzing security vulnerabilities is overwhelmed as it and other authorities struggle to keep pace with a flood of defects that grows every year. The National Institute of Standards and Technology announced Wednesday that it has capitulated to that deluge and narrowed the priorities for its National Vulnerability Database.
    • “NIST said it will only prioritize analysis for CVEs that appear in the Cybersecurity and Infrastructure Security Agency’s known exploited vulnerabilities catalog, software used in the federal government and critical software defined under Executive Order 14028.
    • “The federal agency’s goal with the change is to achieve long-term sustainability and stabilize the NVD program, which has encountered previous challenges, notably a funding lapse in early 2024 that forced NIST to temporarily stop providing key metadata for many vulnerabilities in the database.” * * *
    • “NIST said CVEs that don’t fit its more narrow criteria will still be listed in the NVD, but they won’t be automatically enriched with additional details. 
    • “This will allow us to focus on CVEs with the greatest potential for widespread impact,” the agency said. “While CVEs that do not meet these criteria may have a significant impact on affected systems, they generally do not present the same level of systemic risk as those in the prioritized categories.”
  • Dark Reading adds,
    • [C]ybersecurity teams will need to move to make up for the loss of enrichment data, according to Shane Fry, chief technology officer at RunSafe Security. 
    • “Anthropic’s Mythos highlights why NIST is making this move in the first place,” Fry says. “They have already seen a surge in CVE submissions over the past year and have not been able to keep up. Mythos and other tools for AI-assisted vulnerability will only add to the volume of vulnerabilities disclosed. It’s a problem the industry has been aware of for some time.” 
    • “So without the ability to keep up with the sheer volume of CVEs cyber teams need to pivot, Fry adds. 
    • “The way forward will have to emphasize building defenses into software itself to prevent the exploit of bugs and zero-days even before patches are available or the vulnerability is disclosed,” he advises.” 
  • Federal News Network tells us,
    • “The [U.S.] Office of Personnel Management announced this week that it will be expanding its Tech Force hiring program to include opportunities for agencies to hire cybersecurity specialists. That’s on top of the program’s existing recruitment efforts for software engineers, data scientists and product managers.
    • “The newly added cybersecurity roles will focus on “protecting critical systems, strengthening federal cybersecurity capabilities and safeguarding the digital infrastructure relied on by millions of Americans,” OPM said in a press release.
    • “The federal government depends on strong cybersecurity to protect critical systems and maintain public trust,” OPM Director Scott Kupor said Monday. “Through Tech Force, we’re recruiting highly skilled cybersecurity professionals to take on real challenges and strengthen the government’s defenses where it matters most.”
  • Cyberscoop informs us,
    • “Authorities from 21 countries took down 53 domains and arrested four people allegedly involved in distributed denial-of-service operations used by more than 75,000 cybercriminals, Europol said Thursday. 
    • “The globally coordinated effort dubbed “Operation PowerOFF” disrupted booter services and seized and dismantled infrastructure, including servers and databases, that supported the DDoS-for-hire services, officials said.
    • “Law enforcement agencies obtained data on more than 3 million alleged criminal user accounts from the seized databases, and ultimately sent more than 75,000 emails and letters to participants, warning them to halt their activities.”
  • and
    • “Two New Jersey men were sentenced Wednesday for facilitating North Korea’s long-running scheme to plant operatives inside U.S. businesses as employees, generating more than $5 million in illicit revenue for the regime, the Justice Department said. 
    • “The U.S. nationals — Kejia Wang, also known as Tony Wang, and Zhenxing Wang, also known as Danny Wang — were part of a years-long conspiracy that placed operatives in jobs at more than 100 U.S. companies, including many Fortune 500 companies, based in 27 states and the District of Columbia. * * *
    • “Both men previously pleaded guilty to an assortment of crimes. Kejia Wang was sentenced to nine years in prison for conspiracy to commit wire and mail fraud, money laundering and identity theft. Zhenxing Wang was sentenced to 92 months in prison for conspiracy to commit wire and mail fraud and money laundering. 
    • “The pair were also ordered to forfeit a combined $600,000, of which two-thirds has already been paid, officials said.”

From the cybersecurity breaches and vulnerabilities front,

  • Health Exec reports,
    • “Healthcare IT infrastructure and electronic health record company CareCloud confirmed in a regulatory filing that it’s suffered a data breach, said to have impacted one of its six patient record stores, with hackers inside its network for “approximately eight hours.”
    • “The “cybersecurity incident” was disclosed in a filing with the U.S. Securities and Exchange Commission, and said the incident occurred on March 16. The company said that, while intruders did access patient medical records, it wasn’t clear if any data was stolen.
    • “An investigation into the data breach is still ongoing, and CareCloud said it’s working with a third-party cybersecurity organization to gather the details. After some downtime, CareCloud said it believes the invasion has been thwarted and that criminals no longer have a way inside its network.
    • “Systems were taken down and restored the same day. Details such as how the cyberattack was conducted and if any ransomware was deployed was not revealed. It’s also not clear if any notable cybercrime syndicate was behind the data breach, nor whether those responsible made any demands. 
    • “The filing with the SEC was released on March 24, and there hasn’t been any real update from the company since.”
  • The Cybersecurity and Infrastructure Security Agency added ten known exploited vulnerabilities (KVEs) to its catalog this week.
  • Cybersecurity Dive tells us,
    • “Hackers are attempting to exploit a high-severity flaw found in several end-of-life routers from TP-Link, according to a blog post published Friday [April 17] by Palo Alto Networks’ Unit 42. 
    • “Researchers warn the observed payloads share similarities to those found in malware used in Mirai-like botnets. Such activity would involve attempts to download the malware and execute on vulnerable devices, according to researchers. 
    • “The vulnerability was originally disclosed in June 2023, and proof of concept exploits appeared prior to the disclosure, wrote Unit 42 researchers
    • “The Cybersecurity and Infrastructure Security Agency previously added the command injection vulnerability, tracked as CVE-2023-33538, to its Known Exploited Vulnerabilities catalog in July 2025.” 

From the ransomware front,

  • The HIPAA Journal reports,
    • Brockton Hospital in Massachusetts is continuing [as of April 15] to grapple with a cybersecurity incident that took many of its electronic systems offline on April 6, 2026, and forced the hospital to divert ambulances to alternate facilities and cancel scheduled cancer treatments. An investigation into the cyberattack is ongoing, and the hospital is working with federal and state officials. While some systems have been brought back online, the hospital is continuing to use its downtime procedures, with staff members working off paper rather than computers. A Signature Healthcare spokesperson told Boston 25 News that the hospital would continue under downtime procedures for the next two weeks. * * *
    • “The Anubis ransomware-as-a-service group claimed responsibility for the attack. Anubis engages in double extortion, stealing data and encrypting files. A ransom must be paid to prevent the release of stolen data and obtain the keys to recover encrypted files. According to SuspectFile, which was contacted by a member of the Anubis group, files were encrypted in the attack. The Anubis spokesperson told SuspectFile that only non-critical systems were encrypted, and 2TB of data was stolen in the attack, including a large volume of patient data.
    • “Anubis is attempting to pressure Signature Healthcare into paying the ransom by adding the hospital to its data leak site, along with a countdown clock when the stolen data will be published. Signature Healthcare has yet to confirm the extent of data theft, which may not be known for some time. The priority continues to be patient care, remediating the attack, and bringing systems back online when it is safe to do so.”
  • Govtech relates,
    • “Ransomware continues to pose a serious threat to U.S. critical infrastructure, with more than 2,100 related incidents reported to federal authorities in 2025, according to the latest FBI Internet Crime Complaint Center (IC3) report.
    • “To put that number in perspective, IC3 reported roughly 1,100 data breach threats to critical infrastructure, which includes sectors such as health care, critical manufacturing, financial services, energy and agriculture, among others. Ransomware attacks directed at critical infrastructure are serious, possessing as they do the potential to disrupt operations, expose sensitive data and affect the delivery of public services.
    • “Those incidents have implications for state and local government organizations, which operate or support many of these systems. The nation’s critical infrastructure spans 16 sectors whose disruption would have a debilitating effect on the United States. Of these, the health-care and public health services sector reported the highest number of incidents, the report shows.”
  • SC Media adds,
    • “Analysis by Check Point researchers showed that out of the 672 ransomware attacks reported in March 2026, Qilin alone accounted for 20%, followed by Akira, which was responsible for 12% of the attacks, and Dragonforce RaaS, which was responsible for 8% of the incidents, reports Infosecurity News.”
  • and
    • “Suspected former Black Basta ransomware affiliates are ramping up targeting of senior-level executives with social-engineering attacks designed to deploy remote monitoring and management (RMM) software, ReliaQuest reported Tuesday.
    • “Black Basta, a previously notorious Russia-linked ransomware-as-a-service (RaaS), became defunct last year following leaked chats exposing its infrastructure and techniques. However, attacks leveraging the group’s distinct tactics, techniques and procedures (TTPs) have continued into 2026, with ReliaQuest noting an accelerating volume and increased targeting of company leadership.
    • “For example, Microsoft Teams-based phishing — a staple of Black Basta’s playbook — is becoming more prevalent, with 56% of all Teams phishing over the last year occurring within the last quarter, and nearly a third happening in March 2026 alone.”
  • Industrial Cyber notes,
    • “New data from Cyfirma disclosed that ransomware activity in March reflects a continuation of the sector’s shift toward structured, repeatable extortion models, where encryption is paired with data theft to maximize pressure on victims. The findings show that growing fragmentation of extortion groups suggests that smaller or emerging threat actor groups could adopt automation, AI-assisted reconnaissance, and data-driven victim profiling to scale operations efficiently. These campaigns rely heavily on coercive messaging, warning against third-party recovery attempts and reinforcing the risk of permanent data loss, underscoring how psychological pressure remains central to payment conversion strategies. 
    • “At the operational level, ransomware actors in March continue to refine rather than reinvent their tactics, prioritizing efficiency, scalability, and consistency across attacks. Cyfirma assesses that groups are likely to enhance encryption speed, standardize extortion workflows, and expand double extortion practices, while relying on common intrusion vectors such as phishing and exposed services. The broader trajectory points to incremental evolution within a mature ecosystem, where innovation is less about novel techniques and more about optimizing execution and monetization across a globally opportunistic threat landscape.” 
  • Security Boulevard informs us,
    • “Double extortion is bad enough—that’s the current tactic favored by ransomware groups—but the emerging quadruple extortion promises to further complicate mitigation and response by targeted organizations, prompting an escalation in extortion payments.  
    • “Yet that’s just one piece of evidence that ransomware continues to evolve despite high-profile takedowns by law enforcement—they just reincarnate or rebrand as new groups, new research by Akamai shows. Of course, the biggest game-changer is GenAI, as RasS operators like Black Basta and FunkSec press LLMs into service to generate code and greatly improve the social engineering techniques that give bad actors a foot in the door and to scale up attacks, opening the door for even less sophisticated actors to execute damaging attacks. 
    • “Ransomware groups continue to seek additional ways to generate profit, such as by pressuring victims and weaponizing compliance,”  researchers at Akamai note in their Ransomware Report 2025
    • “Noting that ransomware tactics have moved “away from traditional encryption-centric ransomware tactics towards more sophisticated and advanced extortion methods,” Nathaniel Jones, vice president, security and AI strategy and field CISO at Darktrace, says, “rather than relying solely on encrypting a target’s data for ransom, threat actors will increasingly employ double or even triple extortion strategies, encrypting sensitive data but also threatening to leak or sell stolen data unless their ransom demands are met.” 

From the cybersecurity defenses front,

  • The Wall Street Journal reports,
    • “The software bug was capable of crashing an operating system used by firewalls, servers and network appliances. It went undetected for over 27 years.
    • “Last month, it was caught by Mythos, the latest AI model from Anthropic that has spooked the White House, banking executives and cybersecurity professionals around the world.
    • Welcome to the bug armageddon. AI models like Mythos and others are finding bugs in older software at a rate never seen before.
    • “While most of the coding issues may be minor, their sheer volume has amplified the risk that smaller software developers will become overwhelmed with reports of bugs such as the one Mythos found. Thanks to AI, hackers will be able to leverage those bugs more quickly than ever before.
    • “The 1998 bug in the OpenBSD operating system was one of thousands Mythos found last month. Anthropic said last week that it is working with about 50 technology companies and organizations to find and fix bugs and currently has no plans to release Mythos to the general public.
    • “We need to know that we can release it safely, and it’s not exactly clear how we can do that with full confidence,” said Logan Graham, the head of Anthropic’s Frontier Red Team, which evaluates AI for risks.”
  • Security Week relates,
    • “To help security teams prepare for this future, the Cloud Security Alliance has developed and published The ‘AI Vulnerability Storm’: Building a ‘Mythos-ready’ Security Program. The report does not provide a solution, but it will help readers understand what is coming, and what they must do in preparation.
    • “Mythos will not fundamentally change the nature of cybersecurity. It primarily provides a step change in the pace of attacks, and the biggest single change will be the asymmetric advantage to the attacker increasing dramatically. Cybersecurity itself doesn’t change – it just needs to cope with a new ferocious pace. Best practice fundamentally remains the same, but its importance becomes more critical.
    • “Focus on the basics and harden your environment further,” say the CSA report authors. “Segmentation, egress filtering, multifactor authentication, and defense-in-depth/breadth all increase the difficulty for attackers.” Nothing there is new, but many firms have not done it adequately – and must rapidly start doing it effectively”
  • and
    • “OpenAI announced that it’s scaling its Trusted Access for Cyber program to thousands of verified defenders and hundreds of security teams. They will be given access to GPT-5.4-Cyber, a fine-tuned variant of GPT-5.4 that relaxes the usual guardrails for legitimate cybersecurity work. 
    • “GPT-5.4-Cyber also provides new capabilities such as binary reverse engineering, which enables users to analyze compiled executable software for vulnerabilities and malicious behavior.
    • “The new AI model is initially being offered on a limited, iterative basis to vetted security vendors, organizations, and researchers.
    • “Individual defenders who want to enroll into the Trusted Access for Cyber program and test GPT‑5.4‑Cyber can apply through chatgpt.com/cyber via an identity verification process, while enterprise teams must go through their OpenAI account representative.” 
  • Cyberscoop adds,
    • “A joint report from the Cloud Security Alliance (CSA), the SANS Institute and the Open Worldwide Application Security Project (OWASP) concludes that in the near term, organizations are “likely to be overwhelmed” by threat actors using AI to find and exploit vulnerabilities faster than defenders can patch them.
    • “While those organizations can use AI tools to speed up their own defenses, attackers “still face a heavier relative burden due to the inherent limitations of patching. This in turn leads to “asymmetric benefits” for attackers who can afford to adopt the technology without the same caution and bureaucracy as a multi-billion dollar business.
    • “The cost and capability floor to exploit discovery is dropping, the time between disclosure and weaponization is compressing toward zero, and capabilities that previously required nation-state resources are now becoming broadly accessible,” wrote Robert Lee, SANS Institute’s Chief AI Officer, Gadi Evron, CEO of Knostic and Rich Mogull, chief analyst at CSA, who served as the primary authors.”
  • TechTarget tells us, “How CIOs can beat AI challenges: A top researcher’s view.”
    • “CIOs are grappling with moving AI from the pilot stage to genuine implementation, and many are encountering organizational pitfalls that are stalling the delivery of real value.”
  • Healthexec informs us,
    • “Hospitals have always had to rely on multitudes of healthcare vendors to keep operations humming. In recent years the arrangement’s inherent management challenge has only grown more complex. 
    • “That’s largely because myriad AI technologies have changed daily life for provider organizations and industry partners alike. Arguably the biggest single difficulty to emerge from the transformation is the risk of cybersecurity breaches. 
    • “The Health Sector Coordinating Council (HSCC) is taking a crack at helping cybersecurity leaders, teams and stakeholders clear a path through the thicket. The assistance comes in the form of a 109-page document titled Third-Party AI Risk and Supply Chain Transparency Guide.
    • “The guidebook is authored by members of an HSCC working group focused on cybersecurity. The team’s guiding aim for the project was to “address the growing gaps in discovery and disclosure processes that make AI supply chain risk so difficult to manage.”
  • A NIST press release announced
    • “NIST SP 800-133 Rev. 3 (Initial Public Draft) Recommendation for Cryptographic Key Generation
    • “Proposed changes in this revision include the following:
      • “Asymmetric key-pair generation has been expanded to include methods for deriving randomness during key-pair generation.
      • “Key-pair generation now has options for derivation similar to symmetric keys and new methods for “seed expansion,” which allows for the limited use of SHAKE and deterministic random bit generators (DRBGs).
      • “Key-encapsulation mechanisms (KEMs) are discussed as a key-establishment option for symmetric key generation, and post-quantum cryptography (PQC) references have been added throughout (e.g., the new PQC signatures).
      • “Text has been reworded to address random number generation in alignment with SP 800-90C.
    • “Comments are especially requested regarding:
      • “Hardware security module (HSM) design — How do these requirements align with common practice and existing systems using a root seed/secret value?
      • “PQC implementations and protocol — How do these requirements fit with storing keys as seeds (e.g., for ML-KEM) and performing hybrid (i.e., combined classical and post-quantum) implementations?”
  • Here is a link to Dark Reading’s CISO Corner.

Monday report

From Washington, DC,

  • The Washington Post lets us know,
    • “The White House will make the case Monday to Congress — and to voters — that it has developed a strategy to address frequent frustrations involving U.S. medical care, such as too few physicians and too much paperwork.
    • “The Trump administration casts its physician-focused agenda as a fix for a strained health care system — pointing to a $50 billion funding program for rural health it contends will boost the number of doctors in remote areas, efforts to reduce payment distortions that favor hospitals rather than doctors, and regulatory changes intended to speed insurance approvals for tests and follow-up care.
    • “Together, these reforms will enable faster, more affordable, and higher-quality physician services for Americans,” the White House writes in the Economic Report of the President [WhiteHouse.gov link], an annual document previewed with The Washington Post and set to be transmitted to Congress on Monday.
    • “The economic report, which does not offer new proposals, is best understood as a distillation of White House economists’ thinking ahead of this year’s midterm elections, in which voters’ frustrations regarding health care costs and access are set to play a central role. Past administrations have often used the report, which is written by the president’s Council of Economic Advisers, as a messaging document to rally support for their initiatives. This year’s report addresses health care affordability, a key focus for President Donald Trump and his advisers, and says it is working to “unleash” more competition in health care markets to lower costs and improve quality.”
  • Bloomberg Law informs us,
    • “Senate Republicans aren’t planning to include Medicare and Medicaid changes in the next partisan spending package—instead focusing it largely on ending the partial government shutdown.
    • “Top Republicans plan to use a bill that advances through the simple-majority budget reconciliation process to fund immigration enforcement and US Border Patrol and would not require Democrats’ support.
    • “Though some Republicans have been pushing for including Medicare and Medicaid policies in the package, the narrow focus does not leave room for other priorities, Senate Majority Leader John Thune (R-S.D.) said Monday. He said budget instructions will not be sent to the Senate Finance Committee.” * * *
    • “But he didn’t rule out returning to other health care policies. For instance, he mentioned a provision blocking federal Medicaid payments from going to Planned Parenthood, which was included in the 2025 tax-and-spending law and sunsets in July, as a possible candidate for inclusion.”
  • Beckers Hospital Review reports,
    • “CMS on April 10 proposed a 2.4% pay increase for hospitals under the fiscal 2027 Inpatient Prospective Payment System, but hospitals are concerned that the update does not keep pace with the mounting financial challenges.
    • “CMS has proposed another inadequate update to inpatient payment rates, another extremely high productivity cut, and reductions to disproportionate share payments — in the face of rising need for care and higher uninsured rates,” Ashley Thompson, the American Hospital Association’s vice president of public policy analysis and development, said in an April 10 statement. 
    • “Beth Feldpush, America’s Essential Hospitals’ senior vice president of policy and advocacy told Becker’s in an April 11 statement that the proposed DSH payment cuts “fails to acknowledge the growing number of uninsured individuals due to recent Congressional actions.” 
    • ‘Charlene McDonald, president and CEO of the Federation of American Hospitals, said in an April 10 statement that CMS’ proposal is a step in the right direction, but added it “does not negate the compounding effects of rising inflation, record levels of uncompensated care and a growing uninsured population.”
    • “National hospital group leaders also raised concerns about another aspect of the proposal: the introduction of the first mandatory nationwide episode-based payment model.”
  • Fierce Healthcare informs us,
    • “The Centers for Medicare and Medicaid Services picked 150 digital health companies and healthcare providers to participate in the launch of its tech-enabled chronic care model.
    • “The Center for Medicare and Medicaid Innovation (CMMI) announced in December the Advancing Chronic Care with Effective Scalable Solutions (ACCESS) Model as a 10-year payment program to encourage the use of technology to treat chronic diseases. CMS aims for the ACCESS Model to provide stable, recurring payments for technology used to treat diabetes, hypertension, chronic kidney disease, obesity, depression and anxiety. The model will help pay for telehealth software, wearables and wellness apps that address the conditions.
    • “The CMMI plans to use outcome-aligned payments to cover the cost of technology for Medicare providers if a patient with a qualifying chronic condition achieves clinically significant outcomes, such as lowering their blood pressure.” 
  • Citeline points out,
    • An April 1, 2026, proposal [Federal Register link] from the US Treasury Department would allow whistleblowers who alert the government to certain financial crimes to collect 10%-30% of any monetary penalties collected, creating a new risk for healthcare firms – especially those with overseas business partners. The public comment period ends on June 1, 2026.

From the Food and Drug Administration front,

  • Fierce Pharma reports,
    • “For the first time, the FDA has approved generics for AstraZeneca’s Type 2 diabetes blockbuster Farxiga. The U.S. regulator has given thumbs up to 14 companies, including Teva, Sandoz and a host of Indian drugmakers including Aurobindo, Biocon, Cipla, Lupin and Zydus to produce 5 mg and 10 mg tablets of dapagliflozin.
    • “The treatment is indicated for glycemic control and to reduce the risk of hospitalization for heart failure for those with Type 2 diabetes who also have established cardiovascular disease or multiple cardiovascular risk factors.Farxiga generated sales of $8.5 billion last year, including $1.7 billion in the U.S.
    • “The FDA originally approved the SGLT2 inhibitor in 2014. Generic versions of Farxiga became available (PDF) in the U.K. and Japan in the second half of last year.”
  • and
    • “From a negative phase 3 readout and a seemingly tightening regulatory climate to a grueling three-month review extension, the path for Travere Therapeutics in its first-in-disease bid was anything but certain. Yet, the company has defied the odds, securing Filspari a landmark FDA approval in focal segmental glomerulosclerosis (FSGS) and delivering the first treatment for the rare kidney disease.
    • “Monday’s FDA approval makes Filspari the first therapy specifically indicated for FSGS, a condition that represents a $1 billion-plus sales opportunity, according to Leerink Partners analysts. The drug was originally approved in 2023 for the treatment of IgA nephropathy, another kidney disease.
    • “FSGS is estimated to affect more than 40,000 patients in the U.S. The disorder is characterized by scarring in the kidney’s filtering units as protein keeps leaking into the urine, often leading to further disease progression and kidney failure, sometimes quite rapidly.” 
  • Cardiovascular Business relates,
    • “Anumana, a Massachusetts-based artificial intelligence (AI) company co-founded by nference and Mayo Clinic, has received U.S. Food and Drug Administration (FDA) clearance for a new algorithm designed to detect signs of cardiac amyloidosis (CA). This represents Anumana’s second FDA clearance in just two weeks, highlighting the company’s growing impact in the world of cardiovascular care. 
    • “CA is a life-threatening condition that often leads to heart failure complications, but it remains critically underdiagnosed. Anumana sees this clearance as a way to help care teams identify CA early so patients can receive timely treatment.
    • “The newly cleared algorithm, which previously received the FDA’s breakthrough device designation, was designed to evaluate standard 12-lead electrocardiograms (ECGs) and flag patients at increased risk of CA. 
    • “Each of our FDA-cleared algorithms addresses a specific and frequently missed cardiovascular condition, and cardiac amyloidosis represents an important addition to that portfolio,” Maulik Nanavaty, CEO of Anumana, said in a prepared statement. “The more conditions we can identify from a single ECG, the more valuable the test becomes in clinical practice. That’s what Anumana is working toward with each new clearance as we continue to advance our rigorous clinical evidence approach.”

From the census front,

  • The Wall Street Journal reports,
    • “The first of the youth-obsessed baby boomers turn 80 this year, including President Trump, and they want to shake up old age.
    • “Having reached octogenarian levels, a generation that shaped much of our past is shaping the future of aging for themselves and those who follow. They want better healthcare and housing, cures for dementia and a say in when to die. New professions and products will appear. Their massive spending will shift and innovators will follow.
    • “They are reinventing old age,” says Joseph Coughlin, director of the Massachusetts Institute of Technology AgeLab. Unlike the patient Silent Generation, boomers had high expectations and used their sheer numbers as well as financial and political clout to make them happen, which isn’t necessarily a bad thing.
    • “If you don’t have expectations of getting better, then you simply become satisfied with what is,” says Coughlin.”

From the public health and medical / Rx research front,

  • NBC News reports,
    • “Protein-hungry shoppers are buying more meat with their health top of mind. Health experts, however, wish they’d think beyond the butcher counter.” * * *
    • “Meat is indeed packed with protein, but it comes with some well-established health drawbacks.
    • “Saturated fat we’ve known about for decades,” said Dr. Sarah C. Hull, a cardiologist at Yale Medicine. It’s common in red meat and contributes to increasing LDL cholesterol levels, hardening the blood vessels and, in turn, raising the risk of heart attack or stroke.” * * *
    • “Hull said that many common plant-based proteins are particularly high in fiber, which 95% of Americans don’t get enough of, and they’re generally associated with better overall health outcomes than animal proteins. Her research suggests that increased consumption of certain plant-derived nutrients may help counter some negative effects of red meat and ultra-processed foods.”
  • Health Day relates,
    • “Influenza vaccination may offer cardiovascular protection even when it does not prevent infection, according to a study published online April 2 in Eurosurveillance.” * * *
    • “Hospital admissions for heart attack and stroke were more frequent in the first week after testing positive for influenza than during any other period in the year before and after their test,” the authors write. “This increased risk was about half as high among people who tested positive for influenza but had received the influenza vaccine that season.”
  • and
    • “Children with ADHD are more apt to have a bright future if they’re diagnosed in their early elementary years rather than as high schoolers, a new study says.
    • “Kids diagnosed with ADHD at an earlier age are more likely to have better grades and go on to college, researchers reported April 8 in JAMA Psychiatry. They’re also less likely to drop out of school.
    • “ADHD diagnosis during the first years of school was associated with better school performance, more academic track choices and lower probability of school dropout,” concluded the research team led by Lotta Volotinen, a doctoral researcher at the University of Helsinki in Finland.
    • “The findings support the recommendations for earlier diagnosis, and screening for ADHD before age 12 years should be considered,” the team wrote.”
  • The American Medical Association lets us know “what doctors wish patients knew about managing food allergies.”
    • Once a food allergy is diagnosed, learning how to avoid triggers, recognize warning signs and when to seek medical care are key. Two physicians share more.
  • Per Cardiology Advisor,
    • “Maternal stroke is associated with significantly higher rates of maternal mortality and severe delivery complications, including cardiac arrest and acute renal failure.”
  • Per Pulmonology Advisor,
    • “The increased risk for asthma attacks among those using marijuana was consistent regardless of whether individuals vaped or smoked cannabis or did both.”
  • Per an Oregon State University news release,
    • “Researchers at Oregon Health & Science University have uncovered a key reason why immunotherapy has largely failed in pancreatic cancer — and identified a promising strategy to overcome that resistance. 
    • “The study, published in the journal Immunity, shows that pancreatic tumors actively reshape their immune environment by co‑opting regulatory immune cells that normally shut down tumor-killing cells. By reprogramming those cells, the research reveals a potential pathway to make immunotherapy effective against one of the deadliest and most treatment‑resistant cancers. 
    • “Pancreatic cancer is incredibly resistant to most therapies,” said the study’s senior author, Katelyn Byrne, Ph.D., assistant professor of cell, developmental and cancer biology in the OHSU School of Medicine and member of the OHSU Brenden‑Colson Center for Pancreatic Care. “Even when we know the immune system is capable of long‑lasting protection, it’s been very difficult to get that response to work in this disease.” 
    • “In the new study, Byrne and team tested an experimental immunotherapy in mouse models known as agonistic CD40, which works differently from standard checkpoint inhibitors. Rather than targeting a single immune signal, the therapy broadly activates the immune response upstream. 
    • “Byrne said the researchers were surprised to find out that activating the immune system this way didn’t just stimulate tumor‑killing cells — it also reprogrammed regulatory T cells, converting them from immune suppressors into cells that support anti‑tumor activity. 
    • “We didn’t expect this,” Byrne said. “The therapy doesn’t directly target Tregs, but as a secondary effect of turning on the immune response, those Tregs changed their behavior. Cells that were shutting down the immune reaction suddenly started supporting tumor killing.” 
    • “The team’s findings help explain one reason why many immunotherapies haven’t worked in pancreatic cancer and point to a possible solution: Treatments may need to both turn on the immune system and overcome the tumor’s own ability to shut it down.” 
  • Per an NIH news release,
    • “A National Institutes of Health (NIH)-funded research team has discovered an enhanced CRISPR gene-editing system that could enable targeted delivery inside the human body — a key step toward broader clinical use. Researchers identified a naturally occurring enzyme, Al3Cas12f, that is small enough to fit into adeno-associated virus vectors, a leading targeted delivery method for gene therapies. They then engineered an enhanced version that dramatically improved gene-editing performance in human cells. 
    • “The advance addresses a major limitation in CRISPR technology. Commonly used gene-editing proteins are too large for targeted delivery systems, restricting clinical applications to cells modified outside the body, such as blood and bone marrow. 
    • “Smart delivery of gene editing systems is a powerful notion with broad clinical implications, and this basic science finding takes us a significant step toward that future,” said Erica Brown, Ph.D., acting director of NIH’s National Institute of General Medical Sciences (NIGMS).” 
  • BioPharma Dive adds,
    • “Revolution Medicines said Monday its experimental pancreatic cancer drug hit every goal at an early checkpoint in a Phase 3 trial, helping people who got it live nearly twice as long as those who got standard chemotherapy.
    • “Enrollees who got daraxonrasib lived a median of 13.2 months after treatment, compared with 6.7 months for those who got chemo, a finding that equates to a 60% reduction in the risk of death among those who got the experimental drug. Daraxonrasib achieved its other objectives at an interim look at the results, findings so striking that the company ended the trial early. Revolution enrolled people whose metastatic pancreatic cancer had returned after an earlier treatment.
    • “The Food and Drug Administration has already awarded daraxonrasib a “national priority” voucher that could help Revolution gain an approval within weeks of an official submission. Revolution shares rose nearly 40% in early trading, adding $7 billion to the company’s already hefty valuation.”
  • BioPharma Dive also informs us,
    • “An experimental therapy from Allogene helped eliminate signs of cancer better than standard treatment in a Phase 3 trial in first-line large B-cell lymphoma, results suggesting the biotechnology company may have found a role to use donor-derived cell therapy against the deadly blood cancer.  
    • “After 45 days of treatment, seven of the 12 patients given Allogene’s therapy in the study were negative for “minimal residual disease,” meaning that diagnostic tests could no longer detect signs of cancer. By comparison, only 2 of 12 placebo recipients hit that mark, a roughly 42-percentage-point difference that clears an important bar published literature has suggested is crucial for delaying a relapse. 
    • “The results come from an early “futility” analysis. Allogene is enrolling 220 people in the study and expects to report in 2027 results showing whether treatment staved off cancer’s return.
  • and
    • “In experimental drug from Spyre Therapeutics helped lower signs of disease activity and improve remission rates in a Phase 2 study of people with ulcerative colitis. 
    • After 12 weeks of treatment, patients who received “SPY001” in the trial had a statistically significant, 9.2-point reduction on a scoring system that assesses the severity of their disease, meeting the study’s primary objective. Notably, treatment was also associated with a 40% remission rate and a 51% improvement on endoscopic imaging. One severe adverse event was reported — chest pain in a 68-year-old male with a history of cardiovascular disease — but was deemed unrelated to treatment.
    • Spyre said the findings were “clinically meaningful” and support SPY001’s “best-in-class profile.” The drug is one of multiple therapies the company is evaluating in Phase 2 trials in inflammatory bowel disease. Proof-of-concept data for two other therapies in the trial are expected later this year. Data from a placebo-controlled portion of the study are on track for 2027.” 
  • Per Fierce Pharma,
    • “Eli Lilly has chalked up another victory in the chronic lymphocytic leukemia (CLL) space, as its BTK inhibitor Jaypirca delivered its fourth positive phase 3 readout in the blood cancer. 
    • “Monday, Lilly said its phase 3 Bruin CLL-322 trial in patients with previously treated CLL or small lymphocytic lymphoma (SLL) has met its primary endpoint. In an industry first, the study showed that adding Jaypirca to a fixed-duration regimen of venetoclax and rituximab significantly extended progression-free survival (PFS) compared with the standard combo alone. 
    • “As Lilly pointed out, Bruin CLL-322 is the first phase 3 in CLL to utilize and outperform a venetoclax-based regimen. Roche and AbbVie sell venetoclax, an oral BCL-2 inhibitor, under the brand name Venclexta.” 

From the U.S. healthcare business and artificial intelligence front,

  • Beckers Payer Issues reports,
    • “Houston-based Memorial Hermann Health System and BCBS Texas agreed on a contract April 11, bringing the health system back in network.
    • “The agreement ensures “access to quality care at cost-effective prices,” BCBS Texas said in an April 13 statement shared with Becker’s. It covers both commercial and Medicare Advantage members. The previous contract expired April 1, affecting commercial members. The health system had beenout of network for Medicare Advantage plans since Jan. 1.”
  • Fierce Healthcare offers a look at how Evernorth’s new Delaware specialty pharmacy facility highlights a broader care coordination approach.
  • Beckers Hospital Reports ranks 83 health systems by their most recent revenue.
    • “Revenue growth continued across the hospital industry in 2025, with many of the nation’s largest health systems posting mid- to high-single-digit gains fueled by stronger patient volumes, improved payment rates and the expansion of ambulatory and pharmacy operations. 
    • “But the gains were far from uniform. Some systems grew revenue by double digits through mergers, acquisitions and new payer arrangements, while others saw declines as they shed hospitals and restructured their portfolios.”
  • and tells us,
    • “The world’s two main GLP-1 drug manufacturers, Eli Lilly and Novo Nordisk, are taking different approaches with rolling out their recently approved GLP-1 pills for weight loss. 
    • “Two oral GLP-1s, two very different commercial strategies. Health systems operating metabolic programs or making formulary decisions need to understand both.
    • “While both companies offer their recently approved GLP-1 pills through pharmacies and direct-to-consumer platforms that circumvent pharmacy benefit managers, they are diverging in other routes. 
    • “Eli Lilly is betting on retail and digital access, as it’s offering its weight loss GLP-1 pill through GoodRx, telehealth firm Ro and same-day delivery with Amazon Pharmacy
    • “By contrast, Novo Nordisk launched a Wegovy subscription program through WeightWatchers, LifeMD, Ro and Hims & Hers — with which the drugmaker previously had a strained relationship. With the 12-month subscription plan, Novo Nordisk said patients can save up to $600 per year on the Wegovy pill.” 
  • and informs us,
    • “Large language models may help identify drug safety signals in clinical notes, though their performance remains below thresholds required for clinical decision support.
    • “Researchers evaluated three models — GPT-3.5, GPT-4 and GPT-4o — using clinical notes from 100 patients at Nashville, Tenn.-based Vanderbilt Health, 70 patients at the University of California—San Francisco and 272 patients from seven Roche-sponsored trials, according to an April 6 Vanderbilt news release.
    • “For detecting immune-related adverse events at the patient level, GPT-4o achieved F1 scores of 56%, 66% and 62% across the respective datasets. The F1 score reflects how well a model balances correctly identifying real safety issues while avoiding false alarms. At the individual note level, the model reached an average F1 score of 57% across 667 notes.
    • “An F1 score of 90% or more is considered excellent, while 80% or higher may support clinical decision-making.”
  • STAT News points out,
    • “Every day, more than 40 million people ask ChatGPT about health care, according to OpenAI. They’re asking questions about diet, exercise, insurance — and in some cases, serious symptoms that would typically get discussed on a 911 call or in a doctor’s office.
    • “For some health systems, that’s creating an imperative. A small number of hospitals are trying to recapture some of those clinical conversations from commercial large language models like ChatGPT, Claude, and Gemini. They’re implementing their own patient-facing chatbots, ones that draw directly from their existing medical records and can funnel patients toward care in their own system. 
    • “Hartford HealthCare this week will launch PatientGPT, a chatbot engineered by clinical AI company K Health, to its patients in Connecticut. Two health systems — California-based Sutter Health and Reid Health, serving Indiana and Ohio — have announced pilot versions of Emmie, the chatbot built by medical record mammoth Epic. The list is likely to grow rapidly.
    • “Health systems need to do this, either through a vendor or building it themselves,” said Mount Sinai chief AI officer Girish Nadkarni, the senior author of a recent study that found ChatGPT Health missed high-risk emergencies when used to triage patients.”
  • The Wall Street Journal cautions,
    • “The artificial intelligence gold rush is rapidly drying up the supply of computing power, leading to product issues and reliability problems.
    • “Anthropic experiences frequent outages and limits user token usage, while OpenAI scrapped its Sora app to free up compute.
    • “CoreWeave raised prices over 20% and extended contracts, as spot-market Nvidia GPU rental costs rose 48% in two months.” * * *
    • “All of it points to a classic problem that has popped up in technology booms throughout history, from the 19th-century railroad expansion to the telecom and internet explosion of the early 2000s. Demand is growing far faster than companies are able to access resources and build out infrastructure. Historically, price increases have been among the only ways to address a supply crunch, but such a move could be perilous for frontier AI companies, which are in a ferocious competition to gain users.”
  • Per MedTech Dive,
    • “Stryker said Monday that it has agreed to buy intravascular lithotripsy firm Amplitude Vascular Systems. The companies did not disclose the terms of the acquisition. 
    • “Intravascular lithotripsy is a procedure to treat artery disease. Boston-based Amplitude Vascular Systems, or AVS, uses pressure waves generated by carbon dioxide through a balloon catheter to break up calcified plaque.
    • “The acquisition is expected to bolster Stryker’s peripheral vascular portfolio once AVS’ device is cleared in key markets.”
  • and
    • “GE HealthCare has provided an update on the integration of its bkActiv intraoperative ultrasound technology with Medtronic’s Stealth AXiS surgical navigation system.
    • “The integrated product is now available commercially, GE HealthCare said Thursday. Medtronic said it had integrated bkActiv into Stealth AXiS when the surgical system received regulatory clearance last month.
    • “Integrating the technologies gives surgeons real-time ultrasound images, helping them to assess mid-procedure anatomy changes that could affect the preoperative plan.”