Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Jan 6, 2025·SC World
Recent security breaches have compromised at least 35 Google Chrome extensions, affecting around 2.6 million users. The malicious code, initially linked to a phishing campaign against the cybersecurity firm Cyberhaven, has been found to exfiltrate sensitive data. The phishing strategy involved deceptive domains to mislead extension developers, who were tricked into granting unauthorized access via a fraudulent authentication request. This breach specifically targeted Facebook accounts, employing sophisticated methods to bypass two-factor authentication, thus allowing attackers to access critical user information.
Jan 5, 2025·Comparitech
Ransomware attacks on U.S. healthcare organizations have caused significant financial harm, amounting to about $20.8 billion since 2018, with 654 successful incidents compromising nearly 89 million patient records. The average daily cost of downtime is estimated at $1.9 million, severely disrupting hospital operations. The problem escalated during the COVID-19 pandemic, culminating in a record 143 attacks in 2023 alone, affecting over 26 million records. For instance, Ascension faced a major ransomware incident in May 2024, causing major disruptions and financial losses between $1.1 billion and $1.6 billion. Ransom demands have ranged from $4,000 to $10 million, averaging around $1.06 million, highlighting the considerable risks facing healthcare facilities.
Jan 5, 2025·BleepingComputer
Apple has reached a $95 million settlement in a class action lawsuit that accused the company of violating privacy laws by allowing its Siri voice assistant to record private conversations and share them with third parties without user consent. The lawsuit, initiated by plaintiffs who argued that this practice led to targeted advertising based on sensitive discussions, alleged breaches of the federal Wiretap Act and California's Invasion of Privacy Act. Under the settlement, affected U.S. users of Siri-enabled devices can claim up to $20 per device for a maximum of five devices, while the plaintiffs may receive up to $10,000 each. Additionally, Apple will delete all Siri audio recordings obtained in violation of privacy laws within six months of finalizing the settlement.
Jan 2, 2025·HHS
The HHS Office for Civil Rights has proposed new measures to enhance cybersecurity in the healthcare sector under HIPAA, addressing the rising incidence of cyberattacks on healthcare organizations. The initiative aims to implement strategies that improve risk assessments, bolster incident response capabilities, and promote advanced security technologies. It also emphasizes the need for training healthcare workers in cybersecurity best practices to reduce risks associated with human error. This comprehensive approach is intended to better protect sensitive patient information and fortify the overall security framework in healthcare.
Jan 2, 2025·Cybersecurity News
Harley-Davidson has reportedly suffered a data breach linked to the cybercriminal group "888," compromising sensitive information of over 66,700 customers. Leaked data includes personal details such as names, addresses, and contact information, raising significant concerns about potential identity theft. While the group claims to have made this database available to subscribers, the authenticity of the leak remains unverified, and Harley-Davidson has yet to release an official statement. The incident has alarmed cybersecurity experts and could threaten the company's reputation.
Jan 2, 2025·Help Net Security
A report by CyberArk indicates that the rapid increase in machine identities, driven by multi-cloud strategies and AI adoption, poses significant security risks due to inadequate identity security controls. Notably, 93% of organizations experienced multiple identity-related breaches in the past year, with machine identities identified as the primary contributors to this growth. Despite many machine identities requiring privileged access, only 38% of organizations classify both human and machine identities with sensitive access as privileged users. Additionally, while 99% of organizations have integrated AI into their cybersecurity defenses, an equal percentage anticipate AI-driven cyber threats in the coming year.
Jan 2, 2025·Educated Guesswork
The article examines the complexities of trusting software, particularly in secure messaging applications, where the integrity of the software and the trustworthiness of manufacturers are critical. It highlights the challenges in verifying authenticity and security, noting that even with promises like end-to-end encryption, the responsibility ultimately lies with the vendor. The limitations of open-source software are discussed, emphasizing that while users can review code, practical challenges arise due to size and the use of precompiled binaries, raising concerns about the alignment between source code and the software used. To enhance software trustworthiness, the article proposes a roadmap that includes establishing reviewable source code, reproducible builds, and binary transparency.
Jan 2, 2025·Security Intelligence
On August 29, 2024, the Cybersecurity and Infrastructure Security Agency (CISA) launched a new cyber-incident Reporting Portal within its CISA Services Portal to simplify the reporting process for cyber incidents. The portal enables users to create accounts, save their reports, and reduce repetitive data entry. CISA underscores the importance of reporting incidents for both individual organizations and the broader community, which aids in response and recovery efforts. As a new presidential administration is expected to take office in January 2025, there may be changes in CISA’s leadership and structure. Despite these uncertainties, CISA plans to continue enhancing the portal's functionality while encouraging compliance with the Cyber Incident Reporting for Critical Infrastructure Act of 2022, even though reporting remains voluntary for now.
Jan 2, 2025·SC World
cyber warfare could streamline recruitment, training, and operational effectiveness. The article highlights the urgency of establishing a dedicated Cyberspace Force to bolster the U.S. military's cyber capabilities, especially in light of the advancements made by rival nations. By merging the NSA with USCYBERCOM, and creating a distinct cyber branch, the U.S. could better prepare for the complexities of modern cyber threats and improve national defense strategies.
Dec 31, 2024·TechCrunch
A roundup of key cybersecurity incidents in 2024 highlights critical events that have influenced digital security practices. AT&T’s $370,000 payout to a hacker to erase stolen records of nearly 110 million customers exposed significant weaknesses in corporate data management. Separately, an investigation revealed automakers’ data sharing with insurance firms was leading to higher premiums for consumers, triggering a congressional inquiry into privacy practices. Furthermore, Cencora, a drug distributor, made headlines for paying $75 million to prevent the release of sensitive data, marking the largest ransom payment recorded and demonstrating the rising financial stakes in ransomware incidents.
Dec 31, 2024·Help Net Security
Machine identities, such as access tokens and service accounts, have emerged as key targets for cyber attackers, with 86% of organizations encountering security issues in their cloud-native environments over the past year. These incidents often result in operational challenges, including launch delays and unauthorized data access, leading 88% of security leaders to view machine identities as the next significant threat. The ongoing friction between security and development teams complicates efforts to foster a security-oriented culture, as 68% of leaders believe these groups will always conflict. Additionally, concerns are rising over AI-related vulnerabilities and supply chain attacks, with 77% anticipating malicious AI usage. Kevin Bocek of Venafi underscores the need for proactive security measures to counteract the evolving tactics of cybercriminals exploiting cloud infrastructure vulnerabilities.
Dec 31, 2024·LinkedIn
Jason Elrod argues for the necessity of integrating cybersecurity into corporate governance, advocating for it to be a regular agenda item at board meetings. He predicts that by 2026, a significant portion of boards will include cybersecurity experts, recognizing it as a critical business risk rather than just an IT issue. Elrod calls on organizations to evaluate the frequency of cybersecurity discussions at the board level and highlights the broader implications of cybersecurity decisions on business operations and resilience. To normalize its importance, he encourages open dialogues among leaders to foster a culture where cybersecurity is a fundamental aspect of business strategy.
Dec 30, 2024·Forbes
A warning has been issued regarding a sophisticated phishing attack targeting Gmail users, which leverages the platform's security features to deceive individuals. Despite precautions, a victim suffered a $500,000 cryptocurrency theft after being manipulated by an attacker posing as Google support, who used authentic-looking alerts and a familiar phone number to create urgency. This incident underscores the effectiveness of phishing tactics that exploit users’ trust and the importance of verification before responding to prompts. In light of these threats, Google has introduced advanced AI-driven defenses to bolster Gmail's security measures.
Dec 30, 2024·The Hacker News
A recent phishing attack has compromised at least 16 Chrome browser extensions, affecting over 600,000 users and exposing them to data theft risks. The campaign began with a cybersecurity firm employee falling for a phishing email that led to the release of a malicious version of their extension, designed to communicate with an external server for stealing user data. The attackers exploited the trust associated with communications from the Chrome Web Store, prompting a false urgency that tricked extension publishers into granting permissions to a malicious application. This incident highlights the security vulnerabilities of browser extensions, which often require extensive user permissions. Further investigations indicate this attack is part of a larger scheme, with links to earlier incidents dating back to April 2023.
Dec 29, 2024·Help Net Security
Cybercriminals are increasingly utilizing advanced artificial intelligence technologies to perpetrate sophisticated scams, according to McAfee's 2025 predictions. The report highlights the emergence of AI-driven threats such as hyper-realistic deepfakes, live video scams, and personalized phishing attacks, which significantly erode trust in online interactions. Abhishek Karnik from McAfee notes that the accessibility of AI tools allows even non-experts to craft convincing scams, complicating detection efforts. Additionally, the proliferation of mobile applications has led to new vulnerabilities, as scammers embed harmful software in seemingly legitimate apps, particularly from unofficial sources, increasing the risk to users.
Dec 29, 2024·BankInfoSecurity
In 2024, the healthcare sector faced a dramatic increase in cyberattacks, reporting 677 significant data breaches affecting over 182.4 million individuals, with hacking incidents representing the largest threat. A notable ransomware attack on Change Healthcare by the group BlackCat compromised the data of 100 million people, disrupting patient services and leading to a record ransom payment of $22 million. Additionally, Ascension Health experienced a ransomware attack in May, impacting 5.6 million patients and causing substantial operational challenges, underscoring the critical vulnerabilities faced by healthcare organizations in safeguarding sensitive information.
Dec 29, 2024·HHS.gov
The Department of Health and Human Services (HHS) has released a Notice of Proposed Rulemaking intended to enhance cybersecurity protocols for electronic protected health information (ePHI) under the HIPAA Security Rule. This initiative addresses the rising cyber threats facing healthcare organizations by advocating for stronger cybersecurity practices, including comprehensive risk assessments and the adoption of advanced security technologies. Additionally, the proposed rule emphasizes the necessity of training healthcare staff on cybersecurity risks and best practices to mitigate the impact of human error. Overall, HHS aims to promote a culture of security within healthcare organizations to better protect patient information against emerging threats.
Dec 26, 2024·Dark Reading
Cybersecurity experts warn that organizations face increased risks when their security teams are reduced during holidays or vacations, as attackers often exploit these times to target corporate communication platforms and impersonate trusted colleagues. This vulnerability is exacerbated by junior staff being less acquainted with security protocols and the challenges of maintaining service-level agreements. Notable incidents, such as the Log4j vulnerability discovery during a holiday, highlight the importance of timely responses and operational safeguards. To mitigate these risks, organizations should develop detailed staffing plans, train employees on verification methods for urgent requests, and consider automation and restrictions on changes to critical systems during low-resource periods.
Dec 26, 2024·BleepingComputer
Ascension, a major U.S. healthcare system, reported a data breach affecting around 5.6 million patients and employees due to a ransomware attack attributed to the Black Basta group. The attack, which occurred in May, compromised sensitive personal and health information, prompting Ascension to notify affected individuals and offer two years of free identity theft protection. The breach, linked to an employee's accidental download of malware, disrupted their MyChart electronic health records system, while Ascension has initiated investigations and notified law enforcement agencies.
Dec 26, 2024·BankInfoSecurity
The U.S. Department of Health and Human Services (HHS) has issued a warning for healthcare organizations to improve the cybersecurity of operational technology (OT) and Internet of Medical Things (IoMT) devices, which are increasingly targeted by cybercriminals. The advisory highlights that while regulatory focus has been on medical devices, other connected systems such as HVAC and elevators also present security risks due to outdated software and insufficient cybersecurity measures. HHS notes that many of these devices lack vendor support and operate in environments that hinder necessary updates, making them vulnerable to attacks that could compromise patient safety and sensitive data. Recent analyses indicate that both targeted and non-targeted attacks exploit these vulnerabilities, raising concerns about the potential for ransomware incidents involving OT and IoMT devices.