Skip to content
All resources
Cybersecurity Intel · № 05 · 2 – 15 March 2026

Seeded months ago: the fortnight old breaches came due

A healthcare IT breach runs undetected for eleven months before 3.4 million patients are told. Cloud keys stolen in last year's SaaS supply-chain theft unlock a petabyte-scale claim against a Canadian BPO. And 13 KEV additions in a fortnight span browsers, ICS gear and AI tooling.

Published 16 March 2026 By Blacklight Threat Intelligence Classification TLP:CLEAR · Public
3.4M
Patients exposed in a healthcare IT breach undetected for ~11 months
13
CVEs added to CISA KEV in the fortnight, browsers to ICS to AI tooling
48h
From report to emergency patch for two exploited Chrome zero-days
93
Healthcare victims on ransomware leak sites in February, more than double January

Executive summary

  • Dwell time is the story. Cognizant's TriZetto healthcare arm disclosed a breach of 3.4 million patients that ran undetected for roughly eleven months, and a mass-extortion crew spent the fortnight naming victims of an Oracle E-Business Suite zero-day exploited months earlier.
  • Yesterday's SaaS theft is today's cloud intrusion. The claim against Telus Digital, up to a petabyte including client call recordings and source code, began with cloud keys mined from data stolen in last year's Salesloft Drift OAuth incident. Stolen SaaS data is a long-tail initial-access source.
  • The exploited surface is widening. Thirteen KEV additions in a fortnight covered Chrome zero-days, ICS and camera gear, enterprise management tools and, notably, an AI workflow-automation platform.

Key findings

6 March 2026 Healthcare · T1567

TriZetto breach exposes 3.4 million patients after 11 months undetected

Cognizant's TriZetto Provider Solutions confirmed attackers accessed its portal and took personal and health data of more than 3.4 million people, largely insurance eligibility records. Access reportedly began in November 2024 and went undetected for roughly eleven months, with notifications starting over a year after the intrusion began.

12 March 2026 ATT&CK T1550 / T1078

Telus Digital breached with cloud keys mined from last year's SaaS theft

The Canadian BPO confirmed an incident after an extortion crew claimed up to a petabyte of data, including client customer-support records, call recordings and source code, demanding 65 million dollars. The reported path: Google Cloud credentials found inside Salesforce data stolen in the 2025 Salesloft Drift OAuth theft, used months later to enter Telus systems. Figures are attacker claims; the access chain is the lesson.

2 – 11 March 2026 CVE-2025-61882

Mass extortion of Oracle EBS victims rolls on: 29 more named

The Cl0p-linked campaign exploiting an Oracle E-Business Suite zero-day kept naming victims, adding 29 organisations including Michelin, Canon, Mazda and Broadcom, with hundreds of gigabytes published in staged leaks. Exploit-once, extort-many remains the model: one ERP flaw, months of rolling disclosures.

12 – 13 March 2026 CVE-2026-3910 · KEV

Two Chrome zero-days exploited in the wild, patched in 48 hours

Google shipped an emergency update for a V8 JIT type-confusion flaw enabling code execution from a crafted page and a Skia out-of-bounds write, both exploited in the wild. CISA added both to KEV within a day with a two-week federal deadline. Every Chromium-based browser needed the corresponding patch.

2 – 15 March 2026 KEV · OT & AI

KEV fortnight: ICS gear, admin planes and an AI automation platform

Beyond the browser flaws, thirteen KEV additions took in Hikvision cameras and Rockwell industrial credentials, Ivanti Endpoint Manager, VMware Aria and SolarWinds Web Help Desk, and a code-execution flaw in the n8n workflow-automation platform, an early marker that AI-era automation tooling is now on the exploited list.

The broader pattern

  • Detection debt compounds. Eleven months of dwell at a healthcare processor and a petabyte-scale claim seeded by year-old stolen SaaS data both argue the same thing: continuous behavioural detection across cloud and SaaS, not point-in-time audits.
  • Embedded credentials are the pivot of choice. API keys inside CRM exports, helpdesk attachments and code repositories turn any data breach into a future cloud breach; scan and rotate what lives inside your data, not just your vaults.
  • Healthcare pressure keeps climbing. Leak-site healthcare victims more than doubled month-on-month, and one US medical centre faced a public 800,000-dollar demand after its February outage. The sector's margin for slow triage is gone.

Sector lens

Healthcare
TriZetto's 3.4 million-patient disclosure and a doubled leak-site count in one month: assume claims-processing partners and billing vendors are in the attacker's target set, and demand detection evidence from them, not just certificates.
Manufacturing
Michelin, Canon and Mazda were named in the Oracle EBS wave. If your ERP is internet-reachable, the exploit-once, extort-many model prices your downtime for you.
Energy & industrial
Rockwell credentials and Hikvision cameras entering KEV in the same fortnight is the OT reminder: legacy device flaws from years past are being actively worked right now.
Financial services
The Telus Digital chain shows vendor breaches surfacing customer call recordings and fraud tooling. Third-party risk now includes what your BPO's cloud holds about your customers.

Suggested priorities to consider

Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.

01

Patch Chrome across every Chromium-based browser in the estate. Both zero-days are on KEV with a hard federal deadline; browser updates are the fastest closed window you will get this month.

02

Hunt your cloud estate for use of credentials embedded in historic SaaS exports. The Telus chain began with keys inside stolen Salesforce data; rotate anything that ever lived in a CRM field, ticket or repository.

03

Demand dwell-time evidence from healthcare and claims-processing vendors. Eleven months undetected is a detection failure, not bad luck; ask partners what behavioural monitoring they actually run.

04

Inventory internet-reachable ERP and patch the Oracle EBS chain. The extortion wave is still naming victims months after the zero-day; absence from the leak site is not absence of compromise.

05

Bring AI and automation platforms into vulnerability management. The n8n KEV entry is the precedent: workflow tools with broad credentials are now exploited infrastructure, not shadow IT.

These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.

How Blacklight handles this

Eleven months of dwell is eleven months of anomalies nobody correlated. Blacklight's agents baseline every identity, API key and data flow continuously, so a portal account reading eligibility records at scale, a dormant cloud key waking up in a new project, or an ERP process spawning outbound transfers is investigated the day it deviates, not the year after, with the full reasoning trail ready for regulators.

Book a Demo

Sources & methodology

Primary public sources this issue: CISA Known Exploited Vulnerabilities catalog (entries of 3 – 13 March 2026) · Microsoft March 2026 Patch Tuesday release notes · Google Chrome emergency release notes (12 March 2026) · Google Threat Intelligence reporting on the Oracle EBS campaign · public breach disclosures and security-press reporting (BleepingComputer, SecurityWeek, The Record, CBC), 2 – 15 March 2026 · Breachsense ransomware leak-site statistics, February 2026 · MITRE ATT&CK v15. Attacker-claimed figures are labelled as claims.

Methodology. Findings are compiled from public reporting and Blacklight Threat Intelligence monitoring for the stated window, mapped to MITRE ATT&CK where applicable. Aggregate platform observations, where cited, are anonymised across the Blacklight customer base and never identify a customer environment. Corrections: intel@blacklightai.com.

Related reading

Blacklight AI · Cybersecurity Intel · № 05 TLP:CLEAR
Get started

See what truly predictive
security looks like.

Sixty minutes, under your control. See the platform run on a pre-loaded, anonymised environment, watch one real incident handled end to end, and map it to your sector, without connecting a single data source.

A typical demo
  • 01 A live tour on a pre-loaded, anonymised environment, running from minute one, not slides.
  • 02 One real incident, detected, investigated and contained, written up as a regulator-ready report.
  • 03 Mapped to your world: your sources, your sector's threats and your regulators.
  • 04 The questions your board will ask: deployment, residency, security, integrations and TCO.

No connectors or data required from you. A proof-of-value on your own telemetry is the next step, never the ask on a first call.