Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Goat Feed

    Daily MedTech
    cybersecurity feed

    Live: every CISA KEV add, FDA letter, ICS-MA advisory, and 524B move for MedTech manufacturers.

    Coverage:CISA KEV · CISA ICS-MA · FDA Medical Devices · openFDA Recalls · openFDA 510(k) · openFDA MAUDE · MHRA · NVD (MedTech) · AAMI · IMDRFSee full methodology →

    Get the Monday summary

    One short email covering the previous week's notable items. No fluff.

    Activity Pulse

    16 items published in the last 30 days

    Window
    Days since last critical
    3days
    Quiet streak - last critical 3d ago
    Critical
    Notable
    Informational
    Synced just now
    Goat Feed
    2026-08-14
    Pulse

    Friday, August 14, 2026 (UTC)

    No items for this day.

    Try a different day or browse the weekly summary.

    End of day

    Recent · previous 7 days

    9
    infoCVEBGC-RS 5.0

    NVD CVE-2026-73669 (CVSS 4.0 5.3 MEDIUM) - Philips

    The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker (v2.0.22) that listens on all network interfaces with anonymous access enabled and no firewall restriction. An attacker with access to the Bridge's network can read device data and control connected lights

    notableGuidance

    Flow Neuroscience FL-100

    Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to manipulate brain stimulation parameters and override safety limits.

    criticalKEVBGC-RS 5.5Infra · likely in-scope

    CISA KEV: Microsoft Windows Ancillary Function Driver for WinSock CVE-2026-68820 (CVSS 3.1 7.0 HIGH) - Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    notableGuidance

    Pulsetto Vagus Nerve Stimulator

    Successful exploitation of this vulnerability could allow an attacker to use hidden commands to disable electrical safety mechanisms or modify other stimulation output settings.

    notableGuidance

    Mira Hormone Monitor, Mira Android App

    Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token information, and obtain control of user accounts.

    infoCVEBGC-RS 4.6

    NVD CVE-2026-62293 (CVSS 3.1 5.0 MEDIUM) - GE HealthCare

    HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the hidden scan command concatenates attacker-controlled Implementation Guide titles, profile titles, and source references into scan.html without escaping in