Risk Management

Disclosed OpenClinic Flaws Pose Remote Code Execution, PHI Risk

by Jessica Davis

Researchers from Bishop Fox Labs discovered four vulnerabilities in the OpenClinic application, an open-source health records management software, which could allow an attacker to read patient...

DHS CISA: Fortinet VPN Vulnerability Poses Password Exposure Risk

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Agency recently released an alert, warning all private sector organizations of a vulnerability found in certain Fortinet devices...

Threat Actors Spoofing Legitimate FBI Site Domains, Poses Cyberattack Risk

by Jessica Davis

The FBI released an alert warning of a new cybercriminal campaign that spoofs the internet domains and email addresses related to the FBI, which poses the risk of future cyberattacks and other...

FBI: Ragnar Locker Ransomware Attacks Increase With Data Theft Risk

by Jessica Davis

The FBI is urging private sector organizations to be on alert for Ragnar Locker ransomware attacks, which frequently lead to data theft, following a rapid increase in cyberattacks. First observed in...

Sanford Health, DSU Launch CyberHealth Innovation Hub

by Jessica Davis

Dakota State University (DSU) and Sanford Health announced the launch of a new initiative, which will create a CyberHealth innovation hub designed to combine the strengths of each organization to...

UPDATE: Luxottica Data Leaked by Hackers After Ransomware Attack

by Jessica Davis

Luxottica of America recently reported a patient data breach, which impacted 829,454 patients. But prior to the security incident, the company faced a ransomware attack, and the Nefilim ransomware...

50% of Advanced Phishing Attacks Evade Leading Secure Email Gateways

by Jessica Davis

Nearly half of all advanced phishing attempts, such as spear-phishing and social engineering attacks, bypass leading secure email gateways (SEGs), as hackers shift into more advanced schemes that...

ASPR Warns Ransomware Threat is Persistent, as Actors Leak More Data

by Jessica Davis

The Department of Health and Human Services, Office of the Assistant Secretary for Preparedness and Response, provided an update on the joint federal alert regarding the imminent wave of ransomware...

Ransomware Groups Team Up, as Hackers Shift into Cloud Operations

by Jessica Davis

Hackers are teaming up with other cybercriminals to increase the impact of attacks and to take advantage of troves of stolen data. Trend Micro and Intel 471 found ransomware groups are teaming up...

SSL-Based Cyberattacks Increase By 260%; Healthcare Most Targeted

by Jessica Davis

The number of cyberattacks leveraging encrypted channels to bypass legacy security controls has rapidly increased by a staggering 260 percent since 2019, with the healthcare sector as the leading...

TrickBot Spear-Phishing Campaign Deploys Malware for Remote Access

by Jessica Davis

Area 1 Security detected a widespread spear-phishing campaign tied to the notorious TrickBot threat actors, which is targeting victims with fake termination emails in an effort to deploy...

BD Discloses Alaris Medical Device Vulnerability, Poses DoS Attack Risk

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Agency released an alert urging organizations to apply mitigations provided by BD to close a vulnerability found in its Alaris...

Profitable Hacking Campaign Targets VoIP SIP Servers, Sells System Access

by Jessica Davis

A massive hacking campaign has recently been observed, targeting the Session initiation Protocol (SIP) servers of Voice over Internet Protocol (VoIP) across the global in what...

Zoom Reaches Settlement with FTC Over Misleading Security Practices

by Jessica Davis

The Federal Trade Commission reached a settlement with Zoom to resolve allegations that the company engaged in misleading security practices. The use of the videoconferencing platform...

Required Actions to Prevent Common Ransomware Exploits, Access Points

by Jessica Davis

Threat actors have made it clear: healthcare will remain a prime target for ransomware attacks, extortion demands, phishing, and whatever nefarious scheme they can use to ensure a...

Ransomware Update: More Data Leaked, NY Health System Recovers

by Jessica Davis

Two of the providers impacted by the recent ransomware wave targeting the healthcare sector have made headway in their recovery efforts, as St. Lawrence Health System restored normal...

Army National Guard Deployed to UVM to Assist Ransomware Recovery

by Jessica Davis

Vermont Governor Phil Scott announced the deployment of the Army National Guard’s Combined Cyber Response Team to the University of Vermont Health...

50% of Ransomware Attacks Lead to Data Exfiltration; Payments Hit $234K

by Jessica Davis

Threat actors are increasing threats to breach victims through extortion attempts, as data exfiltration now occurs in nearly 50 percent of ransomware attacks. Meanwhile, ransom payments rose...

5 Providers Still in Downtime, as Sky Lakes Confirms Ryuk Ransomware

by Jessica Davis

Nearly a week after a reported security incident, Sky Lakes Medical Center in Oregon confirmed Ryuk ransomware actors were behind the cyberattack. In total, five major...

Microsoft: Threat Actors Exploiting Unpatched Windows Zerologon Flaw

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency is urging organizations to review a Microsoft alert, as threat actors, including...