Only 6% of Internet of Medical Things devices surveyed can be upgraded to post-quantum cryptography, Forescout found — a specific, stark gap that leaves lifetime health data exposed to future “harvest-now, decrypt-later” attacks.
Forescout's findings: medical devices and the PQC shortfall
Forescout analyzed more than 2.5 million devices across more than 50 healthcare delivery organizations and reported that just 6% of IoMT devices and 16% of medical OT devices use SSH implementations capable of supporting a transition to post-quantum cryptography, compared with 50% of IT devices. The company also found that only 31% of exposed healthcare systems support TLS 1.3, which it calls “the only TLS version capable of supporting standardized post-quantum cryptography.” Forescout warned this mix of legacy cryptography and long-lived data makes healthcare systems attractive candidates for harvest-now, decrypt-later (HNDL) operations.
Malicious development tools: VS Code themes and poisoned packages
Researchers uncovered multiple developer-focused supply chain threats. Socket reported two suspicious Visual Studio Code themes still available on the Visual Studio Marketplace — Coca-Cola Christmas and Aurora Borealis Studio Theme — that share ties to a previously removed malicious extension named Aurora Nocturne Night Theme. Socket researcher Kirill Boychenko said an analysis of the Visual Studio Marketplace build of Cosmic Nebula Themes revealed a loader that decrypts and executes embedded JavaScript, avoids Russian-language and Russian-timezone systems, and uses Solana transaction memos “as a dead drop resolver” to identify follow-on payload infrastructure; Boychenko added the build “contains the same Solana address, AES key, and execution model previously documented in GlassWorm activity.”
At the same time, StepSecurity reported the npm package "@subql/common" version 5.8.3 had been compromised with a hidden payload that collects credentials and supports remote shell access. SafeDep described 42 malicious RubyGems published from an account named "reqthrottle_3474" targeting cryptocurrency developers, and flagged a cluster of nine npm packages (published by "dirtyblanket") that embed a self-spreading Linux worm which installs a backdoor and attempts to propagate via SSH keys and npm tokens.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildMulti-stage intrusions: WhatsApp-delivered RAT and Power BI-enabled RMM
Morphisec detailed a WhatsApp-delivered lure file named "Statement.exe" that unpacks a chain of components culminating in a WebSocket RAT tracked as VulcanRAT207. The loader screened hosts, attempted elevation, injected a downloader into the LocalSystem Task Scheduler process, used a signed GoFly driver to terminate selected Baidu processes, set up a Vulkan DLL side-loading task, and launched the RAT. Morphisec said the malware can collect metadata, enable interactive shell access, terminate security processes, replace clipboard text, enumerate local accounts, and self-terminate.
Huntress documented a separate phishing campaign that abused legitimate Power BI domains to host fake reference documents. Targeted users were prompted to “Download Reference,” which opened a new tab to an attacker-controlled site that fingerprinted victims and then triggered a rogue ScreenConnect installer download — the page delayed the automatic download before a script programmatically activated a hidden download link.
Exposed infrastructure, predictable cookies, and sloppy choices that matter
ThreatMon found an attacker-controlled staging service at 151.243.232[.]123 containing 17 named post-exploitation tools and traces of activity linked to Mexican airline Viva Aerobus. The environment reportedly included credential-dumping scripts, Mimikatz output, SQL credential-testing utilities, and file-transfer tooling; operators used Microsoft SQL Server xp_cmdshell to run commands and return payloads via chunked, Base64-encoded query output.
Resecurity described an authentication bypass in a yard management system caused by two session-cookie design flaws: the cookie was signed with a hard-coded secret identical to the cookie name ("session_secret_example"), and the signed value was a public database identifier (CUID) instead of a random session ID. Resecurity warned these weaknesses could be combined to forge valid cookies for arbitrary users — including accounts with elevated privileges. Huntress also reported a file-upload vulnerability in web-based recreation management software used by municipalities that allowed attackers to create accounts, upload web shells, and steal payment data.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: watch developer tooling and CI environments for poisoned packages (the "@subql/common" compromise, the RubyGems cluster, and the dirtyblanket worm), and tighten storage and handling of SSH keys and tokens that the SafeDep analysis showed can enable fast lateral propagation.
- Policymakers and regulators: the Forescout numbers — 6% and 16% upward compatibility for PQC and 31% TLS 1.3 support — highlight a concrete upgrade gap in healthcare that will complicate any sector-wide cryptographic transition or regulation tied to post-quantum readiness.
- Affected enterprises and procurement leaders: supply-chain vetting is no longer just about dependencies — developer-facing artifacts, marketplace extensions, and digitally distributed themes can carry loaders or use unconventional channels such as Solana memos to reach follow-on infrastructure, as Socket and Boychenko documented.
Across these items the tension is the same: attackers mix sophistication and opportunism, but many successful intrusions still hinge on old, avoidable design mistakes — hard-coded secrets, predictable identifiers, unpatched cryptographic stacks, and exposed staging servers. The week’s reporting closes on a plain question left by the details themselves: if attackers and defenders alike keep leaving obvious gaps, which side will learn to stop being careless first?



