Regulatory intelligence for medical device & software security

Know the moment it matters.

GrapeBeaver watches FDA, CISA, NVD, IMDRF, and manufacturer advisories continuously, and tells you exactly what's relevant to the devices you actually ship.

$20 a month. 14-day trial, no card required.

MEDTECH INTELLIGENCE · https://medtechintelligence.com/?post_type=feature_article&p=47946  ·  MEDTECH INTELLIGENCE · https://medtechintelligence.com/?post_type=feature_article&p=47948  ·  MEDTECH INTELLIGENCE · https://medtechintelligence.com/?post_type=feature_article&p=47960  ·  EC NEW MEDICAL DEVICE REGULATIONS · https://health.ec.europa.eu/events/health-technology-assessment-webinar-patients-and-clinical-experts-2026-09-18_en

Every item, scored and sourced

Reverse-chronological, filtered to the device categories you track. Severity is the only thing on the page allowed to be loud — so when something is red, it means something.

grapebeaver.io/app/feed
Low CISA ICS · 14 Aug 2026 /node/25092
CISA ICS: OFFIS DCMTK Toolkit

CISA published ICS Medical Advisory ICSMA-26-181-01 (dated June 30, 2026) covering five vulnerabilities in the OFFIS DCMTK Toolkit, an open-source DICOM library used in healthcare imaging software worldwide. …

Imaging systemsThird-party software components
Low CISA ICS · 14 Aug 2026 /node/23330
CISA ICS: Pixmeo OsiriX MD

CISA published an ICS Medical Advisory (ICSMA-25-128-01, originally released May 8, 2025) describing three vulnerabilities in Pixmeo's OsiriX MD medical imaging software, affecting version 14.0.1 (Build 2024-02-28) and …

Imaging systemsSoftware as a medical device
Low CISA ICS · 14 Aug 2026 /node/23756
CISA ICS: Santesoft Sante PACS Server

CISA published an ICS Medical Advisory (ICSMA-25-224-01) covering five vulnerabilities in Santesoft Sante PACS Server versions prior to 4.2.3: a path traversal flaw (CVE-2025-0572) allowing arbitrary file creation …

Imaging systemsCloud and hosted clinical platforms
Low CISA ICS · 14 Aug 2026 /node/24134
CISA ICS: Vertikal Systems Hospital Manager Backend Services

CISA published an ICS Medical Advisory (ICSMA-25-301-01) for Vertikal Systems' Hospital Manager Backend Services, describing two vulnerabilities present in versions dated September 19, 2025 and prior: an unauthenticated …

Hospital IT and EHR
21
Sources watched continuously
41
Device categories in the taxonomy
100%
Items read by a person before you see them

Gathered, assessed, reviewed, sent

01 · GATHER

Every source, one feed

FDA recalls and MAUDE reports, CISA ICS-CERT, NVD/CVE, IMDRF, EU MDR/IVDR, and manufacturer PSIRT bulletins — normalized and deduplicated as they publish, so a cross-posted advisory reaches you once.

02 · ASSESS

A score you can argue with

Each item gets one summary and a 0–100 impact score weighing exploitability against clinical consequence — with the reasoning shown, so you can disagree on the evidence rather than take it on trust.

03 · REVIEW

A person signs off

Nothing reaches your inbox until someone has read the assessment against the source and approved it. That gate is not optional, and it is why a summary here means something.

Digests that respect your inbox

Daily or weekly, at a time you choose. It leads with a one-line count, groups by severity with the most serious first, and links each item back to the full assessment.

  • Nothing new means nothing sent — an empty digest is just noise.
  • Set a severity floor and never see below it.
  • Every digest is archived and searchable, so "that thing from three weeks ago" is findable without digging through mail.
  • No hero images. A compliance inbox is not the place for one.
See a full sample
GRAPEBEAVER DAILY DIGEST
3 new items, 1 at high or critical severity.
Low
CISA ICS: OFFIS DCMTK Toolkit
CISA ICS · 14 Aug
Low
CISA ICS: Pixmeo OsiriX MD
CISA ICS · 14 Aug
Low
CISA ICS: Santesoft Sante PACS Server
CISA ICS · 14 Aug

One plan. No tiers to decode.

Individual

For a practitioner, consultant or engineer who needs to know what actually affects the devices they work with.

  • Every source — FDA recalls and MAUDE, CISA ICS-CERT, NVD/CVE, IMDRF, EU MDR/IVDR, manufacturer PSIRT
  • Human-reviewed summary and severity score on every item
  • Up to 7 tracked device categories
  • Daily or weekly digest, your choice of time
  • Searchable history of everything you were sent

New accounts are closed while this deployment is being tested. If you were invited, use the link you were sent.

Running a fleet across multiple sites, or need API access, SSO and your own risk framework? Talk to us about Enterprise.

Assessments are AI-assisted and human-reviewed

Every summary and severity score is produced by an analysis agent and then read, corrected where needed, and approved by a person before it is published. GrapeBeaver surfaces intelligence for you to act on — it does not replace your own regulatory judgment, and it makes no compliance guarantee.