The provided items do not describe a single cohesive cybersecurity incident; they span multiple, unrelated topics. Dark Reading reported on calls for more detailed breach transparency, arguing that organizations often disclose too little about incidents and that the industry lacks structured post-incident feedback loops comparable to aviation and medicine; the piece highlights an upcoming RSAC session by Adam Shostack and Adrian Sanabria advocating for better disclosure and learning from failures.
Separately, Dark Reading covered wireless and drone-related risks for cities hosting major events (e.g., potential disruption to OT and public-safety communications where wireless components are present), and a distinct report described a real-world ransomware incident impacting the University of Mississippi Medical Center (UMMC), including disruption to IT systems and its Epic electronic medical records platform, alongside commentary on a fictional hospital ransomware storyline in HBO’s The Pitt. Other references in the set are not part of these Dark Reading stories: one is a weekly NCSC-themed roundup that briefly mentions an advisory on exploitation of Cisco Catalyst SD-WAN, and another is a conference write-up on Linux filesystem journal forensics tooling (FJTA) rather than an active threat event.

See the actors and campaigns active against you right now.
8 events from the most recent confirmed update back to the earliest known activity.
At RSAC 2026, Adam Shostack and Adrian Sanabria planned to argue for structured, institutionalized breach post-mortems so organizations disclose actionable details about how intrusions succeeded.
UMMC later said it was making significant progress restoring systems, but appointments and elective procedures remained canceled through at least Feb. 27 while phone lines were overwhelmed.
In response to the attack, UMMC shut down all 35 clinics to limit further damage and shifted operations into downtime conditions as systems were taken offline.
UMMC disclosed a ransomware attack that affected IT systems, including its Epic electronic medical records platform, creating operational disruption across the health system.
The board became inactive after its members were fired during the Salt Typhoon-related telecom breach investigation, ending a notable federal mechanism for detailed cyber incident review.
The US Cyber Safety Review Board was conducting an investigation into major telecom breaches attributed to the China-linked APT Salt Typhoon before the effort was disrupted.
Following a 2023 ransomware attack, the British Library publicly shared more detailed information about the incident, providing an example of the kind of breach transparency researchers say helps others learn from attacks.
The 2017 Equifax breach became a frequently cited example of how important technical and organizational lessons often emerge only later through regulatory filings, lawsuits, and congressional reporting rather than initial disclosures.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcedarkreading.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.