Infrastructure Security

DOJ Indicts WannaCry Creators, as Global Feds Impact Egregor Efforts

by Jessica Davis

In two separate actions this week, federal efforts have stymied global cybercriminal activities. The Department of Justice indicted the creators of WannaCry, while transnational government cyber...

CISA Warns More Critical Flaws Found in Open Source TCP/IP Stacks

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency released an alert, which details further critical vulnerabilities found in a range of open source TCP/IP stacks,...

CISA Alerts to Microsoft Windows Win32K Privilege Escalation Flaw

by Jessica Davis

A privilege escalation flaw in Microsoft Win32k could allow an attacker to take control of the affected system. The Department of Homeland Security Cybersecurity and Infrastructure Security Agency...

How Automation Improved Identity, Access Management at Molina Health

by Jessica Davis

One of the key challenges facing healthcare organizations is a lack of control over access management. With a vast number of vendors and endpoints, visibility into identity governance and an effective...

CISA Warns of New Malware Threat to Vulnerable SolarWinds Orion Tech

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure and Security Agency released an alert warning of a new malware variant known as SUPERNOVA, which is being used to target vulnerable...

Netwalker Ransomware Site, Emotet Botnet Taken Down in Global Effort

by Jessica Davis

Two of the most prolific cyber threats have been disrupted by global Federal efforts this week. The notorious Emotet botnet was taken down through a global collaboration, while the FBI and the...

560 Healthcare Providers Fell Victim to Ransomware Attacks in 2020

by Jessica Davis

In the midst of responding to COVID-19, the healthcare sector faced a significant number of ransomware attacks in 2020 with 560 healthcare provider facilities falling victim to the malware variant,...

Top Health IT Security Challenges? Medical Devices, Cloud Security

by Jessica Davis

Cloud security and connected medical device security are the biggest IT challenges healthcare entities are facing under the current landscape, according to 46 percent of IT leaders surveyed...

CISA: Poor Cyber Hygiene Exploited to Compromise Cloud Security Services

by Jessica Davis

Threat actors are successfully exploiting organizations with poor cyber hygiene to compromise cloud security services, according to a new Department of Homeland Security Cybersecurity and...

COVID-19 Vaccine Distribution Spurs 51% Rise in Health Web App Attacks

by Jessica Davis

Cyberattacks on web applications tied to the healthcare sector increased by 51 percent, since the start of COVID-19 vaccine distribution in December, according to a new report from Imperva Research...

CISA Insights on APT Compromise of Microsoft 365 Via Password Exploits

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency released an alert, warning that the advanced persistent threat (APT) actors behind the SolarWinds cyberattack...

Threat Actors Targeting Serious Zyxel Networking Tech Vulnerability

by Jessica Davis

A host of security researchers are warning private sector organizations that threat actors are actively targeting a critical vulnerability found in Zyxel Communication platforms, in an effort to take...

NSA Shares Guide to Eliminating Obsolete TLS Protocol Configurations

by Jessica Davis

The NSA released insights designed to help organizations eliminate obsolete Transport Layer Security (TLS) protocol configurations. The guide comes on the heels of a report that found a staggering...

NIST Shares Best Practice Security Guidance for Vulnerable PACS

by Jessica Davis

The Office for Civil Rights is urging healthcare organizations to review recently released NIST cybersecurity guidance for Picture Archiving and Communication System (PACS). The best practice insights...

Fed Cybersecurity Advisory Alerts to Abuse of Authentication Mechanisms

by Jessica Davis

The Department of Homeland Security is again urging organizations to review insights around the ongoing cyberattacks based around the SolarWinds' hack. The latest alert provides NSA guidance on the...

OCR Warns of Global Supply-Chain Cyberattacks Via SolarWinds Orion

by Jessica Davis

The Office for Civil Rights urges all healthcare organizations to review a Department of Homeland Security alert, warning of ongoing global supply-chain cyberattacks. Nation-state actors trojanized...

NSA Warns Nation-State Actors Exploiting Remote Work Endpoints

by Jessica Davis

The NSA released an alert that warns all organizations to apply recommended mitigation measures for a vulnerability found in certain VMWare Workspace platforms. Nation-state actors with ties to Russia...

AMA Warns of Telehealth Cyber Risks, Insider Threats Tied to COVID-19

by Jessica Davis

Hospitals, health systems, and other providers should reassess their security posture in light of the COVID-19 pandemic, which has increased the number of cyber risks within the sector, such as...

DHS CISA: Fortinet VPN Vulnerability Poses Password Exposure Risk

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Agency recently released an alert, warning all private sector organizations of a vulnerability found in certain Fortinet devices...

Profitable Hacking Campaign Targets VoIP SIP Servers, Sells System Access

by Jessica Davis

A massive hacking campaign has recently been observed, targeting the Session initiation Protocol (SIP) servers of Voice over Internet Protocol (VoIP) across the global in what...