Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Nov 24, 2024·The Verge
Microsoft has announced the Zero Day Quest, an in-person hacking event aimed at addressing high-impact security vulnerabilities in cloud and AI technologies. This event will supplement Microsoft's bug bounty program by offering an additional $4 million in rewards for researchers who identify significant flaws. The initiative, beginning now with submission acceptance, culminates in a gathering at Microsoft's headquarters in 2025, where participants can engage directly with AI engineers and the specialized AI Red Team. Microsoft also intends to enhance transparency by sharing information about fixed vulnerabilities to promote industry learning.
Nov 24, 2024·Forbes
The rise in mergers and acquisitions (M&A) post-COVID-19 has underscored the vital role of cybersecurity in these transactions, as companies seek to strengthen their market positions while facing integration challenges. A key risk involves inheriting cybersecurity vulnerabilities from acquired entities, which can lead to significant financial and reputational damage, as exemplified by Verizon's acquisition of Yahoo. Challenges include merging disparate IT systems and security protocols, which can expose organizations to increased cyber threats. Reports of a rise in phishing attempts directed at acquired companies further highlight the importance of prioritizing cybersecurity during M&A. Companies are advised to conduct thorough cybersecurity assessments pre-acquisition and implement strong integration strategies post-acquisition to mitigate potential risks.
Nov 24, 2024·Cyberscoop
CISO professionals can now access specialized liability insurance designed to protect them from claims of negligence or inadequate performance, a coverage previously unavailable to them. This new policy, introduced by New Jersey-based insurer Crum & Forster, fills a critical gap in professional protection for CISOs, who are often held accountable for cybersecurity incidents despite varying circumstances. The coverage includes liability related to organizational consulting and pro bono IT security efforts, offering a financial safety net in light of the increasing scrutiny of CISOs following major security breaches and related lawsuits.
Nov 21, 2024·LinkedIn
CISOs are increasingly seen as essential contributors in board meetings due to the rising significance of cybersecurity in protecting business operations amidst tighter regulatory scrutiny and growing cyber threats, wrote Jigar Shah, Global Head of IT, Identity, Access and Application at Tenet Health. As organizations recognize cybersecurity as a business risk rather than just an IT issue, effective communication between CISOs and boards becomes crucial for aligning cybersecurity strategies with organizational goals. CISOs must educate board members on cyber risks and their implications, using relevant real-world scenarios in their presentations and concluding with a clear request for support or funding to enhance security initiatives.
Nov 21, 2024·Healthcare IT Today
The National Institute of Standards and Technology (NIST) has updated its Cybersecurity Framework with the introduction of NIST 2.0, which includes a new 'govern' function designed to integrate cybersecurity into overall risk management strategies for healthcare organizations. This enhancement emphasizes the role of leadership in shaping cybersecurity policies and strategies, promoting a unified approach that connects the original five functions: identify, protect, detect, respond, and recover. However, healthcare organizations face challenges in accurately maintaining inventories of medical devices, with inaccuracies potentially reaching 40%, which can hinder effective cybersecurity efforts. Addressing these inventory issues is essential for improving overall patient safety and trust.
Nov 21, 2024·Cybersecurity Dive
Microsoft has unveiled enhancements to its Windows Resiliency Initiative in response to a global IT outage caused by a flawed software update from CrowdStrike in July 2024, which affected over 8.5 million devices. Key features include enabling IT administrators to adjust Windows Update settings remotely for unbootable PCs, improving recovery and system management. This new capability will be available to the Windows Insider Program in early 2025. Additionally, Microsoft plans to implement safe deployment practices in partnership with endpoint security providers and will allow developers to create security solutions that function outside of kernel mode, enhancing overall system security.
Nov 20, 2024·PCMag
Microsoft is introducing Quick Machine Recovery, a new recovery mode for Windows aimed at assisting IT administrators in managing large fleets of PCs. This feature is a response to a past incident where a faulty CrowdStrike update caused millions of machines to crash, necessitating manual fixes until an automatic patch was applied. Quick Machine Recovery will enable administrators to remotely execute targeted fixes on unbootable machines, enhancing recovery efficiency and minimizing downtime. Additionally, Microsoft advocates for a shift among cybersecurity vendors away from kernel-level access implementations, proposing a new security layer that allows antivirus software to operate in user mode to reduce the risk of widespread system failures.
Nov 20, 2024·SecurityWeek
A recent ransomware attack on an Oklahoma medical center has compromised personal information of about 133,000 individuals, underscoring the escalating cyber threats in the healthcare sector. The breach involved unauthorized system access, raising concerns about potential data misuse. In response, the medical center is collaborating with cybersecurity experts to assess the breach and strengthen its systems while notifying affected individuals about protective measures against identity theft. This incident highlights the vulnerability of healthcare organizations to cyberattacks and the necessity for robust cybersecurity strategies to safeguard sensitive patient data.
Nov 19, 2024·Apple News
Jen Easterly, the Director of the Cybersecurity and Infrastructure Security Agency (CISA), is stepping down after serving since 2021, during which she played a key role in enhancing the nation's cybersecurity resilience. Her leadership focused on fostering collaboration between government and private sectors, implementing initiatives to improve security measures across various levels of government and private enterprises, and promoting public awareness of cyber threats. Under her guidance, CISA adopted a proactive approach to cybersecurity, emphasizing advanced technologies and frameworks to counter risks. Easterly's departure raises questions about the future direction of the agency as it strives to maintain the momentum she established.
Nov 14, 2024·Healthcare IT News
The Joint Public Health Cybersecurity Task Group is conducting an anonymous survey to assess cybersecurity needs within public health organizations, with a focus on readiness against evolving cyber threats. This 15-minute survey, developed in collaboration with key health sector councils, aims to gather insights from a wide range of officials and IT leaders to evaluate the impact of cyber incidents on public health services. The findings will inform grant funding and policy recommendations, emphasizing the necessity for high participation rates given the rising cybersecurity threats that target public health agencies.
Nov 14, 2024·SecurityWeek
Citrix and Fortinet have issued critical patches to address serious vulnerabilities in their software, which could allow unauthorized access and other malicious actions. The patches are vital for organizations using these platforms to strengthen their cybersecurity against potential threats. Citrix's update focuses on safeguarding sensitive data, while Fortinet's remedies flaws that could enable arbitrary code execution. Experts highlight the urgency of implementing these updates and stress the importance of ongoing security assessments and employee training to enhance organizational defenses against evolving cyber threats.
Nov 14, 2024·Bleeping Computer
The FBI, NSA, and Five Eyes cybersecurity authorities have issued a joint advisory listing the 15 most exploited vulnerabilities of 2023, many of which were zero-days. This report stresses the necessity for global organizations to address these vulnerabilities promptly and enhance their patch management practices to mitigate cyberattack risks. Particularly concerning is CVE-2023-3519, a code injection vulnerability in Citrix's NetScaler, which has been leveraged by state-sponsored hackers to affect over 2,000 servers. The advisory highlights that despite many of these vulnerabilities being previously addressed, threat actors continue to exploit unpatched flaws, notably affecting major vendors and essential software products.
Nov 14, 2024·CyberNews
Amazon has reported a data leak involving nearly 3 million employee records, including personal contact details, due to a security breach at a third-party property management vendor related to the MOVEit Transfer hack. While Amazon's own systems were not breached, the incident also affected other major companies like HSBC, UBS, and McDonald’s. The consolidated nature of the leaked data increases the risk of social engineering and phishing attacks, prompting concerns about further vulnerabilities among affected organizations. The group claiming responsibility, Nam3L3ss, argues for greater data privacy awareness, yet cybersecurity experts suggest their methods may not be the most effective way to promote compliance and secure data practices.
Nov 14, 2024·LinkedIn
The Healthcare and Public Health Sector Coordinating Council (HSCC) has introduced a Cyber Incident Response Playbook targeted at medical product manufacturers, including medical device and pharmaceutical companies. This resource offers practical guidance for identifying and managing cyber incidents affecting manufacturing operations and operational technology, with adaptable step-by-step recommendations suitable for different organizational sizes. The playbook, shared on LinkedIn by Erik Decker (CISO, Intermountain Health) covers the entire incident response process, from preparation to remediation, and builds on past initiatives, reflecting a collaborative effort to strengthen cybersecurity within the healthcare sector. The HSCC's Joint Cybersecurity Working Group, comprising over 470 members from various fields, focuses on addressing cyber threats to health data and systems.
Nov 14, 2024·NSA
A recent Cybersecurity Advisory (CSA) co-authored by CISA and NSA reveals that cybercriminals are increasingly leveraging zero-day vulnerabilities to breach enterprise networks. The report titled "2023 Top Routinely Exploited Vulnerabilities" identifies 15 Common Vulnerabilities and Exposures (CVEs) that have been exploited over the past year, with a notable rise in the initial exploitation of zero-day vulnerabilities—from two last year to eleven this year. NSA's cybersecurity technical director, Jeffrey Dickerson, calls for heightened vigilance and prompt mitigation efforts among network defenders. The report also highlights that many listed vulnerabilities are appearing for the first time, signaling an evolving cyber threat landscape and underscoring the necessity for proactive cybersecurity strategies as exploitation is expected to persist into 2024 and 2025.
Nov 13, 2024·Cyberscoop
President-elect Donald Trump's nomination of Kristi Noem to lead the Department of Homeland Security raises questions about the future of cybersecurity funding for states. Noem, who as South Dakota's governor opposed federal cybersecurity grants and did not apply for them in 2022 or 2023, argued that the conditions attached to these funds often outweigh their benefits. Despite her opposition to federal funding, she has championed the cybersecurity sector in South Dakota, signing legislation to bolster the state's capabilities and establishing initiatives to protect local digital infrastructure, including a $7 million allocation for cybersecurity services.
Nov 13, 2024·Forbes
Amazon has confirmed a significant data breach involving 2.8 million lines of employee data, attributed to a vulnerability in the MOVEit Transfer software used by a third-party property management vendor. The breach, disclosed by a cybercriminal known as "Nam3L3ss," highlights ongoing security risks in supply chain relationships, particularly due to weaknesses in third-party systems. The vulnerability, CVE-2023-34362, permitted unauthorized access via a SQL injection flaw. Nam3L3ss has published Amazon's employee data on BreachForums and claims to possess large amounts of data from various organizations, raising concerns about future disclosures. Compromised information includes employee work contact details, although Amazon maintains that its primary systems, including AWS, remain secure.
Nov 13, 2024·BIPC
Healthcare organizations are confronting a challenging decision regarding whether to pay ransomware demands after cyberattacks that risk sensitive patient data and critical services. The urgency to restore operations must be weighed against ethical and financial ramifications, as paying a ransom does not guarantee data recovery or future protection. Many providers experience severe operational disruptions and financial burdens from such incidents, prompting a search for best practices in cybersecurity. Experts recommend proactive strategies, including strong cybersecurity measures, staff training, and regular data backups, to minimize risks and reduce the likelihood of facing ransom demands in the first place. Collaborating with law enforcement and cybersecurity experts is also suggested to navigate the complexities associated with these attacks.
Nov 12, 2024·BleepingComputer
CISA has issued a warning about a critical vulnerability, CVE-2024-5910, in Palo Alto Networks Expedition, a tool for migrating firewall configurations. This flaw allows attackers to remotely reset admin credentials on internet-exposed servers, potentially granting unauthorized access to sensitive information. Although a patch was released in July, ongoing exploits have been reported, with a vulnerability researcher demonstrating a proof-of-concept that combines this issue with another vulnerability, leading to unauthorized command execution. CISA advises administrators to limit network access to authorized users and to rotate credentials after applying the patch, highlighting the urgency due to a lack of updated security advisories from Palo Alto Networks.
Nov 12, 2024·The Hacker News
INTERPOL's Operation Synergia II, conducted from April to August 2024, led to the disruption of over 22,000 malicious servers and targeted various cyber threats including phishing and ransomware. The operation resulted in nearly 30,000 suspicious IP addresses being identified, with 76% taken down, alongside the seizure of 43 electronic devices and 41 arrests. Significant actions took place across multiple countries, including over 1,000 server disruptions in Hong Kong and additional cyber activity in Mongolia and Madagascar. Private sector partners like Group-IB and Kaspersky supported these efforts, highlighting the collaborative approach to tackling global cybercrime.