// INTEL.DIGEST

Cyber briefing — Morning Fri 4 CT

Sep 4

Coverage window: Wednesday Sep 2, 2026 7:00am CT through Friday Sep 4, 2026 7:00am CT.

Adversary Behaviors

Nothing in-scope this slot.

Major Provider Breaches

Boston Scientific: shipping restored for majority of products; backlog still clearing

Boston Scientific’s incident page was updated 3 Sep 2026 at 4:29 p.m. ET (3:29 p.m. CT). Working with CrowdStrike and other third-party experts, the company says it has growing confidence that unauthorized access was limited to select internal-facing IT infrastructure. The investigation continues.

On shipping, the 3 Sep note states the company has begun restoring shipping capabilities for the majority of its products at major distribution centers globally, and is progressively moving queued customer orders through fulfillment while working through an existing backlog. It is still restoring shipping for additional products and locations as validation completes, and still plans to ramp to full capacity. Customers can continue to submit orders electronically through EDI and local applications. Earlier FAQ points on personal-data investigation and new CRM remote-monitoring activations remain posted; the 3 Sep update does not withdraw them. No public attribution.

Sources: Boston Scientific incident updates, latest 3 Sep 2026 4:29 p.m. ET; Boston Scientific Form 8-K, 26 Aug 2026.

CVEs

Nothing in-scope this slot. CVE-2026-33824 (Windows Server IKE), CVE-2019-1068 (SQL Server), CVE-2026-59310 (vCenter), and CVE-2026-55040 (SharePoint) were first listed in the Aug 30 Morning file and have completed their three-briefing life (Aug 30, Aug 31, Sep 2); they are dropped on this fourth scheduled Morning run. EPSS re-check on 3 Sep 2026 still cleared the cutoff for all four, but no new KEV listing, exploitation write-up, or other in-window activity newly re-qualified them. Cisco Nexus 9000 Silicon One RCE CVE-2026-20212 (CVSS 9.8, advisory 2 Sep 2026) was checked and omitted: FIRST EPSS was 0.00527 on 3 Sep 2026, below the 0.2 cutoff. Other in-scope candidates checked this slot (including Exchange CVE-2026-62911, SharePoint CVE-2026-65663, and Veeam ONE CVE-2026-65641) also failed EPSS >= 0.2. CISA’s 2 Sep 2026 KEV additions were out of product scope for this briefing.