Seeded months ago: the fortnight old breaches came due
A healthcare IT breach runs undetected for eleven months before 3.4 million patients are told. Cloud keys stolen in last year's SaaS supply-chain theft unlock a petabyte-scale claim against a Canadian BPO. And 13 KEV additions in a fortnight span browsers, ICS gear and AI tooling.
Executive summary
- Dwell time is the story. Cognizant's TriZetto healthcare arm disclosed a breach of 3.4 million patients that ran undetected for roughly eleven months, and a mass-extortion crew spent the fortnight naming victims of an Oracle E-Business Suite zero-day exploited months earlier.
- Yesterday's SaaS theft is today's cloud intrusion. The claim against Telus Digital, up to a petabyte including client call recordings and source code, began with cloud keys mined from data stolen in last year's Salesloft Drift OAuth incident. Stolen SaaS data is a long-tail initial-access source.
- The exploited surface is widening. Thirteen KEV additions in a fortnight covered Chrome zero-days, ICS and camera gear, enterprise management tools and, notably, an AI workflow-automation platform.
Key findings
TriZetto breach exposes 3.4 million patients after 11 months undetected
Cognizant's TriZetto Provider Solutions confirmed attackers accessed its portal and took personal and health data of more than 3.4 million people, largely insurance eligibility records. Access reportedly began in November 2024 and went undetected for roughly eleven months, with notifications starting over a year after the intrusion began.
Telus Digital breached with cloud keys mined from last year's SaaS theft
The Canadian BPO confirmed an incident after an extortion crew claimed up to a petabyte of data, including client customer-support records, call recordings and source code, demanding 65 million dollars. The reported path: Google Cloud credentials found inside Salesforce data stolen in the 2025 Salesloft Drift OAuth theft, used months later to enter Telus systems. Figures are attacker claims; the access chain is the lesson.
Mass extortion of Oracle EBS victims rolls on: 29 more named
The Cl0p-linked campaign exploiting an Oracle E-Business Suite zero-day kept naming victims, adding 29 organisations including Michelin, Canon, Mazda and Broadcom, with hundreds of gigabytes published in staged leaks. Exploit-once, extort-many remains the model: one ERP flaw, months of rolling disclosures.
Two Chrome zero-days exploited in the wild, patched in 48 hours
Google shipped an emergency update for a V8 JIT type-confusion flaw enabling code execution from a crafted page and a Skia out-of-bounds write, both exploited in the wild. CISA added both to KEV within a day with a two-week federal deadline. Every Chromium-based browser needed the corresponding patch.
KEV fortnight: ICS gear, admin planes and an AI automation platform
Beyond the browser flaws, thirteen KEV additions took in Hikvision cameras and Rockwell industrial credentials, Ivanti Endpoint Manager, VMware Aria and SolarWinds Web Help Desk, and a code-execution flaw in the n8n workflow-automation platform, an early marker that AI-era automation tooling is now on the exploited list.
The broader pattern
- Detection debt compounds. Eleven months of dwell at a healthcare processor and a petabyte-scale claim seeded by year-old stolen SaaS data both argue the same thing: continuous behavioural detection across cloud and SaaS, not point-in-time audits.
- Embedded credentials are the pivot of choice. API keys inside CRM exports, helpdesk attachments and code repositories turn any data breach into a future cloud breach; scan and rotate what lives inside your data, not just your vaults.
- Healthcare pressure keeps climbing. Leak-site healthcare victims more than doubled month-on-month, and one US medical centre faced a public 800,000-dollar demand after its February outage. The sector's margin for slow triage is gone.
Sector lens
Suggested priorities to consider
Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.
Patch Chrome across every Chromium-based browser in the estate. Both zero-days are on KEV with a hard federal deadline; browser updates are the fastest closed window you will get this month.
Hunt your cloud estate for use of credentials embedded in historic SaaS exports. The Telus chain began with keys inside stolen Salesforce data; rotate anything that ever lived in a CRM field, ticket or repository.
Demand dwell-time evidence from healthcare and claims-processing vendors. Eleven months undetected is a detection failure, not bad luck; ask partners what behavioural monitoring they actually run.
Inventory internet-reachable ERP and patch the Oracle EBS chain. The extortion wave is still naming victims months after the zero-day; absence from the leak site is not absence of compromise.
Bring AI and automation platforms into vulnerability management. The n8n KEV entry is the precedent: workflow tools with broad credentials are now exploited infrastructure, not shadow IT.
These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.
Eleven months of dwell is eleven months of anomalies nobody correlated. Blacklight's agents baseline every identity, API key and data flow continuously, so a portal account reading eligibility records at scale, a dormant cloud key waking up in a new project, or an ERP process spawning outbound transfers is investigated the day it deviates, not the year after, with the full reasoning trail ready for regulators.
Sources & methodology
Primary public sources this issue: CISA Known Exploited Vulnerabilities catalog (entries of 3 – 13 March 2026) · Microsoft March 2026 Patch Tuesday release notes · Google Chrome emergency release notes (12 March 2026) · Google Threat Intelligence reporting on the Oracle EBS campaign · public breach disclosures and security-press reporting (BleepingComputer, SecurityWeek, The Record, CBC), 2 – 15 March 2026 · Breachsense ransomware leak-site statistics, February 2026 · MITRE ATT&CK v15. Attacker-claimed figures are labelled as claims.