Cybersecurity Vulnerabilities

3 Cybersecurity Vulnerabilities in OpenEMR Can Lead to Remote Code Execution

by Jill McKeon

Three cybersecurity vulnerabilities in an older version of OpenEMR may leave healthcare organizations open to cyberattacks, HHS warned. HHS urged healthcare organizations using versions of OpenEMR...

Citrix Releases Patches For Cybersecurity Vulnerability Used to Target Healthcare

by Jill McKeon

Citrix released patches for a critical zero-day cybersecurity vulnerability (CVE-2022-27518) in its Application Delivery Controller (ADC) and Gateway platforms. HHS knows of healthcare entities that...

Cybersecurity Resilience Top Priority for 96% of Surveyed Executives

by Sarai Rodriguez

Organization executives are doubling down on investments toward cybersecurity reliance as an uptick in data security breaches jeopardizes business operations and overwhelms industries, including the...

CISA: 3 Steps to Improve Cybersecurity Vulnerability Management

by Jill McKeon

New cybersecurity vulnerabilities are a constant challenge for organizations of all sizes, Eric Goldstein, executive assistant director for cybersecurity at the Cybersecurity and Infrastructure...

HC3 Urges Healthcare to Patch OpenSSL Cybersecurity Vulnerability

by Jill McKeon

UPDATE 11/1/2022 - OpenSSL provided vulnerability guidance for CVE-2022-3786 and CVE-2022-3602. CVE-2022-3602 is no longer labeled as "critical" and was downgraded to "high" after further...

Microsoft Exchange Zero-Day Vulnerabilities May Impact Healthcare Cybersecurity

by Jill McKeon

Two zero-day vulnerabilities are being actively exploited in Microsoft Exchange Servers 2013, 2016, and 2019, and may impact healthcare cybersecurity. The first vulnerability (CVE-2022-41040) is a...

How Cybersecurity Vulnerability Disclosures Help the Healthcare Community

by Jill McKeon

As the healthcare community continues to grapple with cybersecurity challenges, more device manufacturers, independent researchers, and software companies have been prioritizing cybersecurity vulnerability disclosures as a way to mitigate...

FBI: Cyber Criminals Use Social Engineering to Target Healthcare Payment Processors

by Jill McKeon

The Federal Bureau of Investigation (FBI) released its second private industry notification in a single week directed at the healthcare sector, this time warning of social engineering techniques used...

Pen Testing Data Highlights Gaps in Healthcare Cybersecurity

by Jill McKeon

Penetration (“Pen”) testing is a key tool in maintaining healthcare cybersecurity and identifying potential security gaps and vulnerabilities before threat actors can. Security firm...

Apple Issues Urgent Cybersecurity Updates to Fix Zero-Day Vulnerabilities

by Jill McKeon

Apple released security updates to defend against two zero-day vulnerabilities found in macOS Monterey, iOS and iPadOS, and Safari, the Cybersecurity and Infrastructure Security Agency (CISA)...

CISA Alerts Healthcare Sector to OFFIS DCMTK Cybersecurity Vulnerabilities

by Jill McKeon

High-severity cybersecurity vulnerabilities in OFFIS DCMTK software could result in remote code execution (RCE) if exploited, the Cybersecurity and Infrastructure Security Agency (CISA) warned in a...