Overview
Severity: CRITICAL | Affected: CogniHealth | Category: breach
CogniHealth, a prominent AI-driven medical diagnostics company, has disclosed a critical security breach affecting approximately two million patients. Attackers gained access to the company's cloud infrastructure by exploiting a vulnerability in a third-party data processing library. The compromised data includes sensitive patient health information (PHI) and, most alarmingly, the proprietary weights and architecture of CogniHealth's flagship cancer detection model. Security experts warn that the theft of the model itself is a major blow, as it could be reverse-engineered to de-anonymize patient data from the training set or be manipulated by adversaries to produce intentionally incorrect diagnoses. The incident underscores the unique security challenges for AI companies handling sensitive data and valuable intellectual property in the form of trained models.