Endpoint Security

Proof-of-Concept Prompts Alert on SharePoint Remote Execution Flaw

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency is urging organizations to review a UK National Cyber Security Centre (NCSC) alert for a remote code execution...

CISA Urges Patch of Windows Remote Code Execution TCP/IP Flaw, DoS Risk

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency urged all organizations to apply the patch for a remote code execution (RCE) vulnerability...

Top Strategies for Implementing Multi-Factor Authentication

by Kelsey Waddill

Multi-factor authentication (MFA) can block more than 99 percent of automated cyber attacks, yet healthcare organizations often wait until their security has already been breached before turning to...

FBI, CISA Warn APT Hackers Chaining Vulnerabilities in Cyberattacks

by Jessica Davis

Advanced persistent threat (APT) hackers are targeting government networks, critical infrastructure, and election organizations by chaining vulnerabilities – a method of exploiting multiple...

Report: 72% Orgs Faced Increase in IoT, Endpoint Security Incidents

by Jessica Davis

Two-thirds of organizations saw an increase in the number of IoT and endpoint security incidents in the last year, with US cybersecurity decision makers naming malware, insecure networks, and remote...

61% Microsoft Exchange Servers Are Unpatched, Vulnerable to Attack

by Jessica Davis

The majority of Microsoft Exchange Servers have yet to be updated with a patch for a critical memory corruption vulnerability reported earlier this year, according to Rapid7. These...

Ransomware Reigns, as Cyberattacks Increase in Sophistication, Frequency

by Jessica Davis

From October 2019 to July 2020, Microsoft data shows hackers have rapidly improved the sophistication and increased the frequency of cyberattacks. And when it comes to incident response...

CISA: Hackers Exploiting Unpatched Microsoft NetLogon Vulnerability

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency has urged all organizations to apply the partial patch and to implement mitigation methods for a...

Ransomware Hacking Groups Post Data from 5 Healthcare Entities

by Jessica Davis

The hacking groups behind Pysa, or Mespinoza, SunCrypt, REvil, and NetWalker ransomware variants posted data allegedly stolen from five separate healthcare...

Exploit Code Prompts CISA Alert to Microsoft Netlogon Vulnerability

by Jessica Davis

A recent public exploit for an elevation of privilege vulnerability found in Microsoft’s Netlogon will make unpatched systems a prime target for cybercriminals, according to a recent...

Iranian Hackers Targeting, Exploiting VPN Flaws of US Healthcare, IT Orgs

by Jessica Davis

Hackers with ties to Iran are exploiting flaws found in commonly used Virtual Private Networks (VPNs) across a range of federal agencies and businesses, including those in the healthcare...

5 Top Critical Vulnerabilities In Need of Patch, Software Update

by Jessica Davis

The healthcare sector has remained a crucial target for hackers over the course of the last five years. But despite a heavy reliance upon legacy technologies, industry stakeholders have...

Healthcare’s Password Problem and The Need for Management, Vaults

by Jessica Davis

Digital Shadows recently reported that at least 15 billion compromised credentials and passwords are for sale on the dark web. The data should serve as a warning to...

CISA Shares Incident Detection, Response Playbook for Cyber Activity

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency released guidance to help enterprise organizations detect and remediate malicious cyber activity, which...

Healthcare Key Target of Hacker Selling Access to Compromised RDP

by Jessica Davis

The hacker known as TrueFighter has reemerged with a campaign actively targeting the remote desktop protocol (RDP) across all sectors, with those in the healthcare industry as...

112K Patients Impacted by Utah Pathology Services Email Hack

by Jessica Davis

Utah Pathology Services is notifying 112,000 patients that their data was potentially affected after the hack of an employee email account in June.  Discovered on June 30, a hacker...

Credential Theft Via Spoofed Login Pages Increase, Healthcare Top Target

by Jessica Davis

A new IRONSCALES report found a drastic increase in successful credential theft attempts sent through spoofed login pages and social engineering attacks during the first half of...

FBI, CISA Alert of Surge in Vishing Cyberattacks on Remote Workers

by Jessica Davis

Hackers are targeting employees working remotely amid the COVID-19 pandemic with a voice phishing, or “vishing,” campaign to obtain enterprise login credentials for mining...

Brute-Force P2P Botnet Targeting SSH Servers of Medical Centers, Banks

by Jessica Davis

Guardicore researchers are warning organizations of a sophisticated peer-to-peer botnet, which has been actively breaching SSH servers since January 2020. Known as FritzFrog,...

IBM: Remote Exploit Flaw Found in Millions of Connected IoT Devices

by Jessica Davis

IBM X-Force Red security researchers uncovered a bug in components made by the manufacturer Thales, which are included in millions of connected devices. The IoT...