logo

Leaked data. Continuous glucose monitoring

ID: afafe65f-185d-5f01-a9cf-d1ba4e810b8a

STIX ID: report--afafe65f-185d-5f01-a9cf-d1ba4e810b8a

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2025-07-22

Date Updated: 2026-03-24

Author: Joe Bursell

...
...

A researcher discovered a publicly readable and writable AWS S3 bucket holding real-time glucose data from smart CGM devices in a likely closed-loop insulin dosing trial, creating a severe risk of data tampering that could trigger dangerous automated overdoses. After urgent outreach to the vendor’s CISO, access was promptly restricted, averting potential harm. The report underscores the risks of cloud misconfiguration in healthcare IoT, the need for robust security reviews, threat modeling, and accessible disclosure channels.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.