Endpoint Security

Dark Web Analysis: Healthcare Risks Tied to Database Leaks, Credentials

by Jessica Davis

A new report from CybelAngel analysts provides insight into just how hackers are getting into healthcare networks, from providers leaving databases wide open to attacks, to credential...

CISA Warns of Accellion FTA Exploit; Centene Among Breach Victims

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency is urging all organizations to be on alert, as threat actors exploited several unpatched vulnerabilities in...

Hospital Recovers from Ransomware; Vendor Incidents Hit Kroger, Provider

by Jessica Davis

In the last few days, three healthcare-related entities reported data breaches or system outages due to ransomware. Kroger informed patients it was part of the massive Accellion data breach, and...

Demand, Sale of Backdoor Access to Healthcare Networks Spiked in 2020

by Jessica Davis

Demand for backdoor access to healthcare networks drastically increased last year, as did the number of hackers gaining and selling backdoor access on the dark web, according to CTIL research. Hackers...

Pharma Key Target of New Phishing Campaign Using Malformed URLs

by Jessica Davis

Threat actors are bypassing traditional URL security defenses with malformed URL protocols to attack end users, according to new data from GreatHorn Threat Intelligence Team. Pharmaceutical companies...

White House: SolarWinds Hack Impacted 9 Fed Agencies, 100 Entities

by Jessica Davis

At a White House press briefing on Wednesday, Deputy National Security Advisor for Cyber and Emerging Technology Anne Neuberger confirmed that the SolarWinds Orion compromise claimed nine federal...

Ransomware Actors Leak Data From 3 More Healthcare-Related Entities

by Jessica Davis

The treat actors behind Avaddon, Conti, and REvil ransomware have yet again leaked more data from healthcare-related entities. The latest data dumps include troves of health information allegedly...

CISA Warns More Critical Flaws Found in Open Source TCP/IP Stacks

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency released an alert, which details further critical vulnerabilities found in a range of open source TCP/IP stacks,...

CISA Alerts to Microsoft Windows Win32K Privilege Escalation Flaw

by Jessica Davis

A privilege escalation flaw in Microsoft Win32k could allow an attacker to take control of the affected system. The Department of Homeland Security Cybersecurity and Infrastructure Security Agency...

How Automation Improved Identity, Access Management at Molina Health

by Jessica Davis

One of the key challenges facing healthcare organizations is a lack of control over access management. With a vast number of vendors and endpoints, visibility into identity governance and an effective...

NCSC: Chinese Threat Actors Targeting US Healthcare, Genomic Data

by Jessica Davis

Threat actors with ties to China are continuing to target US healthcare, genomic, and other valuable data through hacking and other malicious activities, according to a recent alert from the National...

70% Ransomware Attacks Cause Data Exfiltration; Phishing Top Entry Point

by Jessica Davis

Ransomware threat actors are increasingly leveraging email phishing as the leading entry point in these destructive attacks, as Coveware analysis shows data exfiltration occurs in 70 percent of all...

Actor Exploits Beaumont Health’s COVID-19 Vaccine Scheduling Tool

by Jessica Davis

Michigan-based Beaumont Health was forced to shut down its tool for scheduling COVID-19 vaccine appointments over the weekend, after an unauthorized actor exploited a flaw in the Epic platform. The...

CISA Warns of New Malware Threat to Vulnerable SolarWinds Orion Tech

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure and Security Agency released an alert warning of a new malware variant known as SUPERNOVA, which is being used to target vulnerable...

NIST Shares Risk-Based Guide to Information Exchange Security

by Jessica Davis

NIST released a proposed guide designed to support the use of information exchange channels, which provides insights on risk-based considerations to protect data throughout the sharing process and case...

Threat Actors Can Leverage RDP Servers to Amplify DDoS Attacks

by Jessica Davis

A recent report from Netscout revealed that threat actors can abuse the Microsoft remote desktop protocol (RDP) to amplify denial-of-service (DDoS) attacks. Researchers identified over 14,000 servers...

CISA: HPH Cyber Threat Insights, Ransomware Reduction Campaign

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency recently unveiled a campaign designed to tackle ransomware risks and threats across the US. Earlier, CISA shared...

Report: Rise in COVID-19 Vaccine Social Engineering, BEC, Phishing

by Jessica Davis

Recent Proofpoint research shows hackers are continuing to prey on fears tied to the COVID-19 pandemic. And as the vaccine rollout continues, social engineering lures are being leveraged in malware,...

FBI: Spike in Vishing Attacks Seeking Escalated Access, Credential Theft

by Jessica Davis

Threat actors are increasingly using voice phishing, or vishing, in targeted attacks on remote workers in an effort to steal credentials, escalate privileges, and gain proliferated network access,...

COVID-19 Vaccine Data Manipulated Before Leak to Impair Public Trust

by Jessica Davis

The hackers who stole COVID-19 vaccine data belonging to Pfizer and BioNTech from the European Medicines Agency (EMA), a regulatory agency, and leaked the information online in December,...