Risk Management

Fed Joint Advisory: Patch These 5 Vulnerabilities Under Active Attack

by Jessica Davis

The National Security Agency, the Department of Homeland Security Cybersecurity and Infrastructure Security Agency, and the FBI released a joint alert, warning that nation-state threat actors from...

H-ISAC Supply-Chain Insights Aim to Prevent Next SolarWinds Cyberattack

by Jessica Davis

The Health-ISAC recently published supply-chain cyberattack insights in collaboration with the American Hospital Association, meant to support healthcare provider organizations prevent and respond to...

COVID-19 Vaccine Cold Chain Entities Remain Key Spear-Phishing Target

by Jessica Davis

Threat actors are continuing to target the COVID-19 vaccine cold chain, the means of delivering and storing vaccines at safe temperatures, with spear-phishing campaigns that leverage pharma and...

DOJ: FBI Removed Web Shells From Exploited Microsoft Exchange Servers

by Jessica Davis

In a rare move, a court-authorized FBI operation removed web shells from a host of exploited on-prem Microsoft Exchange Servers. Many of the victims may have been unaware their systems were...

NSA Finds, Urges Patch of 4 New Critical Microsoft Exchange Flaws

by Jessica Davis

Microsoft disclosed and issued patches for four newly detected vulnerabilities found in on-prem Microsoft Exchange Servers version 2016 and 2019. The Department of Homeland Security is urging all...

DNS Flaws in Millions of IoT Devices Pose Remote Attack, Exfiltration Risk

by Jessica Davis

A group of nine DNS vulnerabilities in four popular TCP/IP stacks used in more than 100 million enterprise, consumer, and industrial IoT devices pose a critical risk of hacking or remote code execution...

Healthcare’s Data Extortion Problem, and How to Prepare for Ransomware

by Jessica Davis

Data extortion was once seen as a rare, or potential threat, rather than a pressing issue, while ransomware and subsequent downtime were greater concerns for healthcare cybersecurity. But...

GAO Audit Finds HHS Information Security Program “Not Effective”

by Jessica Davis

An evaluation of the Department of Health and Human Services against Federal Information Security Modernization Act of 2014 (FISMA) principles found the agency’s information security program...

DHS CISA Shares SolarWinds Post-Threat Compromise Activity Tool

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency shared another tool to support remediation of threats posed by the SolarWinds supply-chain attack. The new dashboard...

COVID-19, Info Blocking Provisions: Time for HIPAA Compliance Checkup

by Jessica Davis

The information blocking provisions of the 21st Century Cures Act officially went into effect this week, putting into focus the Department of Health and Human Services’ regulatory and compliance...

CISA: SAP Vulnerabilities Under Active Attack, Poses Data Theft Risk

by Jessica Davis

An active cyberattack campaign was spotted in the wild, targeting systems running unpatched or misconfigured SAP systems. Threat actors are exploiting these vulnerabilities to gain full control of the...

FBI, CISA: APT Actors Exploiting Unpatched Fortinet Vulnerabilities

by Jessica Davis

Advanced persistent threat actors are actively exploiting unpatched vulnerabilities in Fortinet FortiOS platforms belonging to technology services, government agencies, and other private sector...

VMware Issues Patch for 2 Severe Flaws Posing Credential Theft Risk

by Jessica Davis

VMware issued a software update for its vRealize Operations, Cloud Foundation, and Lifecycle Manage to address two severe flaws that could allow an attacker to steal admin credentials and manipulate or...

DHS CISA Shares More Microsoft Exchange Vulnerability Guidance

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency released another emergency directive designed to further mitigate vulnerabilities in on-prem Microsoft Exchange...

Feds Seize Fraudulent COVID-19 Vaccine, Pharmacy, Pfizer Websites

by Jessica Davis

Multiple fraudulent COVID-19 vaccine, pharmacy, and other pandemic-related websites have been taken down, as a result of a federal government enforcement effort to combat fraud schemes and attacks...

Attackers Target Medical Research Staff with Credential Phishing Attacks

by Jessica Davis

Senior medical research personnel in the US and Israel are being targeted by a credential phishing campaign launched by a nation-state hacking group with ties to Iran, according to a new Proofpoint...

The Risk and Challenge of Bad Bot Traffic on Healthcare Sites, Apps

by Jessica Davis

Around the world, healthcare entities are steadily making progress on vaccinating individuals against COVID-19. Many of these providers are relying on technology for vaccine appointment scheduling and...

FBI: Mamba Ransomware Actors Weaponizing Freeware Encryption Tool

by Jessica Davis

The threat actors behind Mamba ransomware are weaponizing DiskCryptor, an open source full disk encryption software. The malware encrypts the entire drive, including the operating system, to restrict...

Brute-Force Campaign on Windows SMBs Spreads Worming Malware

by Jessica Davis

Internet-facing Windows devices are being targeted by an active malware campaign known as Purple Fox. Hackers are leveraging brute-force attempts against SMBs to deploy the malware, which has worming...

FBI Alerts to Rise in BEC Cyberattacks on US Orgs, Impacting Resources

by Jessica Davis

The FBI recently warned private sector entities that cybercriminals are increasingly leveraging business email compromise attacks against federal government agencies, which has hindered...