Risk Management

FBI: $4.2B Lost to Cybercrime in 2020, Led By Phishing, BEC, Extortion

by Jessica Davis

The latest FBI IC3 Internet Crime Report shows that cybercrime cost individuals and US businesses about $4.2 billion in losses in 2020, up 69 percent from $3.5 billion in 2019. Phishing, non-payment...

Hackers Successfully Exploiting Older, Unpatched Microsoft Vulnerabilities

by Jessica Davis

The most frequent exploit in the last three months caught by HP Sure Click was against an older, unpatched memory corruption vulnerability in Microsoft Office, accounting for nearly 75 percent of all...

Microsoft Shares One-Click Mitigation Tool for Exchange Server Flaws

by Jessica Davis

Microsoft unveiled a mitigation tool for small entities and others operating without a designated IT or security team, which is designed to automatically mitigate the recently...

Healthcare Hacking Incidents Rose 42% in 2020, 31M Patients Impacted

by Jessica Davis

Hacking incidents on the healthcare sector rose 42 percent from 2019, impacting a combined total of nearly 31 million patient records in 470 security incidents in the last year, according to the latest...

APT Hackers Targeting Unpatched, On-Prem Microsoft Exchange Servers

by Jessica Davis

At least 10 advanced persistent threat (APT) hacking groups are targeting unpatched, on-prem Microsoft Exchange servers, in an effort to exploit the vulnerability and take control of the impacted...

Verkada Security Camera Hack Allows Access, Leak of Hospital Live Feeds

by Jessica Davis

A report from Bloomberg shows hackers were able to gain access to the live feeds from at least 150,000 security cameras, including those belonging to several hospitals, health clinics, Tesla, and...

DHS CISA Shares Remediation, Risk Guidance for SolarWinds Compromise

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency released new guidance to help support security leaders and administrators with risk decisions and remediation of...

Microsoft Shares IOC Scan Tool, as Attacks on Exchange Servers Expand

by Jessica Davis

The Assistant Secretary for Preparedness and Response is urging healthcare entities to path the four critical vulnerabilities found in certain Microsoft Exchange Servers, under active exploit....

FBI Probing 2 Hospital Ransomware Attacks; Hackers Remove Health Data

by Jessica Davis

The FBI is currently investigating at least two separate ransomware incidents: one attack on Rehoboth McKinley Christian Health Care in New Mexico and another on Allergy Partners care sites in North...

MITRE Unveils Ransomware Resource for Hospitals, Healthcare Providers

by Jessica Davis

MITRE recently unveiled a newly created ransomware resource, which is designed to help hospitals and other healthcare providers develop and maintain resilient security processes and policies in...

CISA Urges Patch, as Hackers Exploit Zero-Day Flaws in Microsoft Exchange

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency alerted to an out-of-band software update issued by Microsoft, which will patch four zero-day vulnerabilities found...

Update to Ryuk Ransomware Variant Adds Network Worming Capability

by Jessica Davis

The notorious Ryuk ransomware variant has been spotted in the wild by CERT-FR, the French government’s cybersecurity agency, updated with worming capabilities that allow it to automatically...

UHS Ransomware Attack Cost $67M in Lost Revenue, Recovery Efforts

by Jessica Davis

The ransomware attack that resulted in EHR outages at all 400 Universal Healthcare Services’ care sites for about three weeks last year, resulted in about $67 million in lost operating...

NSA Shares Zero Trust Security Model Guide, Recommendations

by Jessica Davis

The NSA unveiled guidance for implementing a zero trust security model across the enterprise infrastructure, which includes recommendations. The system management strategy is designed to bolster...

How to Mitigate COVID-19’s Impact on Device Security and Patient Safety

by Jessica Davis

It’s been long established that the healthcare threat landscape, in terms of its prime targeted nature and the vast number of connected supply chain vendors and medical devices, poses an equal amount of risk and network security...

Healthcare Cyberattacks Doubled in 2020, with 28% Tied to Ransomware

by Jessica Davis

Cyberattacks on healthcare more than doubled in 2020, with ransomware accounting for 28 percent of all attacks. COVID-19 response efforts, including personal protective equipment and the vaccine supply...

Dark Web Analysis: Healthcare Risks Tied to Database Leaks, Credentials

by Jessica Davis

A new report from CybelAngel analysts provides insight into just how hackers are getting into healthcare networks, from providers leaving databases wide open to attacks, to credential...

CISA Warns of Accellion FTA Exploit; Centene Among Breach Victims

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency is urging all organizations to be on alert, as threat actors exploited several unpatched vulnerabilities in...

CIS Offers All US Hospitals Free Ransomware Protection Service

by Jessica Davis

Private hospitals in need of ransomware assistance can now leverage a free malicious domain blocking and reporting (MDBR) service from the Center for Internet Security and Akamai, offered...

Demand, Sale of Backdoor Access to Healthcare Networks Spiked in 2020

by Jessica Davis

Demand for backdoor access to healthcare networks drastically increased last year, as did the number of hackers gaining and selling backdoor access on the dark web, according to CTIL research. Hackers...