A Polish Health Platform Breach Reaches 19 Million (08/17/2026)
- › Poland is investigating a breach at MyDr, a supplier connected to the national health platform, with nearly 19 million people and more than 12,000 medical facilities potentially affected.
- › Flashpoint counted 1.7 billion credentials harvested by infostealers in the first half of 2026, from 7.4 million infected devices, a 27% rise over the prior six months.
- › A Unisoc modem exploit chain lets a video call run code in the Android kernel, and no vendor firmware fix has been identified.
- › France confirmed its tax authority breach affected 678,000 individuals and businesses, well below the actor's original claim.
- › GitLab patched CVE-2026-19478, a 9.4 that lets an unauthenticated attacker delete public projects on self-managed installations.
The MyDr breach in Poland is the one to watch, because the vendor sits between 12,000 medical facilities and the national health platform, and the exposure is being counted at 19 million people. Underneath that, Flashpoint’s midyear numbers explain how most of these start: 1.7 billion credentials pulled off 7.4 million machines in six months, by malware that costs the operator almost nothing to run.
Top 5 Critical Security Alerts
1. A Polish Health Software Vendor Breach Reaches 19 Million People
Polish authorities are investigating MyDr, a privately owned company whose software connects healthcare providers to P1, the national electronic health platform handling prescriptions, referrals, and records. Nearly 19 million people and more than 12,000 medical facilities are potentially affected. The company confirms external criminal activity and unauthorized access to historical data reaching back through April 2024, and says there is no evidence anything was published. The specific data types are claims by the actors, supported with screenshots and not yet verified. Poland’s Personal Data Protection Office is planning an inspection. The Record
Operator Note: Two years of undetected access at the vendor that sits between thousands of practices and a national platform. Each of those 12,000 facilities is about to discover that its own breach notification obligation is triggered by a system it does not run and cannot audit. If you are a small provider anywhere, the question is not whether your practice is secure. It is which of your suppliers holds the same position MyDr held.
2. Infostealers Took 1.7 Billion Credentials in Six Months
Flashpoint’s midyear threat report counts 1.7 billion credentials harvested between January and June 2026, from 7.4 million infected devices. That infection count is up 27% over the previous six months, with Vidar, StealC, and Lumma leading the families. Flashpoint describes the result as a fully automated ecosystem processing credentials at machine speed. Infosecurity Magazine
Operator Note: Divide it out and the average infected machine gave up around 230 credentials. That is the browser password store, and it is why the initial access market stays cheap while everything downstream of it gets more expensive. A stronger password does nothing here. The defense is denying the endpoint in the first place, then revoking sessions the moment you suspect one.
3. A Video Call Reaches the Android Kernel Through the Modem
Researcher 0x50594d, working with SSD Secure Disclosure, published a chain against Unisoc modems that uses a Voice over Long Term Evolution video call to land execution in kernel space, letting an attacker modify Android kernel code from modem-level access. Confirmed devices include the Xiaomi Redmi A5, Motorola E13, and Realme C33, and the disclosure explicitly does not present that as a complete list. No vendor firmware update addressing the flaw has been identified. Infosecurity Magazine
Operator Note: The modem is a separate processor running its own firmware that your endpoint tooling cannot see, and the trigger here is an inbound call rather than anything the user does wrong. Unisoc parts sit mostly in budget handsets, so if your field staff, contractors, or overseas offices buy their own phones, this is in your estate whether or not it is on your standards list.
4. France Confirms 678,000 in the Tax Authority Breach
The French Finance Ministry established that 678,000 individuals and professionals had data accessed and extracted from Direction Generale des Finances Publiques systems. Tax reference income, family quotient data, withholding rates, company names, and cadastral property details were taken. User IDs, passwords, and online account credentials were not. The actor ZeroBytes had claimed access to roughly 20 million citizens and says they extracted 252,149 records covering more than 2 million people before stopping. Notifications start next week. BleepingComputer
Operator Note: We carried the 600,000 figure on August 14 as the actor’s claim, and the confirmed number came in at 678,000 with a very different shape underneath it. Worth keeping as a calibration exercise: the criminal’s number described access, the ministry’s number describes extraction, and the two were never measuring the same thing.
5. GitLab Patches a 9.4 That Deletes Public Projects
CVE-2026-19478 carries a 9.4 and lets an unauthenticated attacker remotely modify or delete public projects and user data through a GraphQL directive. It affects Community and Enterprise editions from 18.2 through 18.10, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. GitLab.com and Dedicated customers are already covered, so this is a self-managed problem. No exploitation is known yet, and technical details are held until roughly mid-November. The Hacker News
Operator Note: Destruction rather than theft, which changes what you check. Patch, then confirm your GitLab backups restore, because the failure mode here is projects that are gone rather than projects that leaked. Ninety days of held detail is a countdown, and the recent pattern has been exploitation arriving days after the write-up, not months.
Additional Security Alerts
Threat Intelligence
- A China-nexus actor is exploiting vCenter and dropping Babuk-derived ransomware: The same flaw we flagged on August 13 now has a named operator and a payload behind it. The Hacker News
- Cavern C2 hides in Domain Name System and Google Apps Script traffic: Command and control that rides services already allowed out of your network. The Hacker News
Security Breaches & Incidents
- A crook is selling 3.6 million records claimed from corporate Azure tenants: The listing names major companies, and the claim is unverified. BleepingComputer
- SafePal joins the run on hardware wallet makers with 39,798 customers exposed: Stolen customer data is already advertised for sale, following Trezor last week. BleepingComputer
- A South Carolina debt consolidation firm leaked financial details and Social Security numbers for nearly 750,000 people: Loan applicants hand over everything at once, which makes these files unusually complete. The Record
- Pokemon Center disclosed a breach and cancelled some orders: Customer information was exposed at the official store, which sits alongside the physical burglaries hitting card shops. BleepingComputer
- Philips and GE are investigating Clop data theft claims: Two more names added to the group’s list. BleepingComputer
Security Tools & Best Practices
- Windows Server 2022 leaves mainstream support in 60 days: Extended support continues, and the feature and non-security fix stream stops. BleepingComputer
- Microsoft is working on a Defender patch for the ShieldBreak zero-day: No date given. BleepingComputer
- A Forminator flaw exposes 40,000 WordPress sites to admin takeover: Unauthenticated remote code execution through malicious PHP uploads. Infosecurity Magazine
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.