Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Aug 30, 2024·Bleeping Computer
A recently identified large-scale QR code phishing campaign has exploited Microsoft Sway to deceive Microsoft 365 users into revealing their credentials. Detected by Netskope Threat Labs in July 2024, the campaign marked a 2,000-fold increase in attacks primarily targeting users in Asia and North America, especially in the technology, manufacturing, and finance sectors. The phishing emails guided potential victims to Microsoft Sway-hosted pages that prompted them to scan QR codes, leading to malicious sites. This approach bypasses security scanners and preys on the weaker security of mobile devices. Attackers further enhanced the campaign’s effectiveness by using transparent phishing tactics and Cloudflare Turnstile to evade detection. This method mirrors the tactics used in the PerSwaysion campaign five years ago, which also targeted Office 365 credentials of high-ranking individuals in various sectors.
Aug 30, 2024·Becker's Hospital Review
McLaren Port Huron Hospital reverted to using paper records following a ransomware attack on Aug. 6 that disrupted the IT systems of McLaren Health Care, impacting 13 of its facilities. Although IT systems are now restored, the hospital faces delays in patient care and is working to catch up on missed appointments by the end of the week. The transfer of patient information from paper back into electronic systems is expected to take several weeks.
Aug 30, 2024·CSO Online
A recent report from Sophos has highlighted significant updates to the Poortry/BurntCigar toolkit, a tool used by ransomware groups to compromise endpoint protection software. Originally identified for terminating endpoint detection and response (EDR) processes, the toolkit now has the capability to completely wipe EDR software from systems. The toolkit uses a malicious kernel driver and loader, heavily obfuscated to evade detection, and it has been utilized by ransomware gangs such as Cuba, BlackCat, and LockBit. Following Microsoft's closure of a loophole allowing custom kernel-level driver signing, developers have adapted by using methods like Signature Timestamp Forging and obtaining valid leaked certificates. These adaptations have enabled the toolkit to function akin to a rootkit, enhancing its evasion capabilities and making it a more formidable threat to IT defenses.
Aug 30, 2024·publication
In his article, Jon Oltsik outlines "5 Best Practices for Running a Successful Threat-Informed Defense in Cybersecurity," emphasizing the importance of tailoring cybersecurity strategies to specific threats. He discusses the need for establishing a threat intelligence lifecycle, using threat intelligence for exposure management, driving detection engineering, promoting threat hunting, and pursuing continuous testing. These practices involve continuous improvement and alignment of resources to manage vulnerabilities effectively, write and refine detection rules, automate compromise detection, and conduct ongoing testing to identify gaps in defenses. Oltsik highlights that while challenging, adopting a threat-informed defense can lead to improved security efficacy and organizational efficiency.
Aug 29, 2024·HealthcareInfoSecurity
McLaren Health Care successfully restored its IT systems days ahead of schedule after an August 6 ransomware attack, allowing it to resume normal operations across its 13 Michigan hospitals and associated centers. The incident initially forced the diversion of emergency care patients and the implementation of temporary procedures. As of now, all departments, including emergency, diagnostic, cancer, and specialty care facilities, are fully operational, and surgeries postponed due to the outage are being rescheduled. The task of manually inputting patient data recorded during the disruption is ongoing. The cybercriminal group Inc Ransom has claimed responsibility for the attack, and McLaren is still determining if any patient or employee data was compromised. This marks the second ransomware attack on McLaren within a year.
Aug 28, 2024·paulconnelly
In cybersecurity, while technical skills are crucial, strong writing abilities are equally important for leaders. Writing enhances clarity of thought and communication, helping to articulate complex ideas, build trust, influence stakeholders, and establish thought leadership. Effective writing can set cybersecurity professionals apart, leading to career advancement. Practical advice for improving writing skills includes reading widely, storytelling, practicing regularly, using simple language, incorporating humor, and seeking feedback. Investing in writing skills can significantly boost a cybersecurity leader's influence and impact.
Aug 28, 2024·CSO Online
Proofpoint's 2024 "Voice of the CISO" report indicates that ransomware remains a top concern for Chief Information Security Officers (CISOs) worldwide, with 62% stating they would likely pay a ransom to restore access to systems. The willingness to pay is notably high in Saudi Arabia, Canada, and South Korea. CISOs cite cost-benefit analyses, downtime avoidance, and legal implications as primary reasons for considering ransom payments. However, ethical considerations, legal risks, and potential penalties for paying sanctioned entities complicate these decisions. CISOs ultimately don't have the final say, but they act as key advisors to organizational leadership. The dilemma reflects a complex balance between immediate operational continuity and long-term ethical and regulatory consequences.
Aug 28, 2024·cio.com
The article discusses the aftermath of the Y2K bug and its parallels to the current situation with CrowdStrike. It highlights how the IT industry's quick response to Y2K led to accusations of it being an exaggerated threat, diverting attention away from systemic issues. In the present, CrowdStrike faces blame for cybersecurity vulnerabilities, particularly due to Microsoft's mandated kernel access and the broader pressure on security vendors to release rapid, untested patches. The author emphasizes the importance of understanding and managing the inevitable trade-offs in IT, particularly in balancing speed and risk in cybersecurity efforts, while urging IT leaders to educate their executive teams on these critical dynamics.
Aug 27, 2024·Data Protection Report
On August 13, 2024, Enzo Biochem Inc. and its subsidiary Enzo Clinical Labs, Inc. settled with the New York, Connecticut, and New Jersey Attorneys General for a $4.5 million payment after a security incident in April 2023. The settlement followed findings that Enzo failed to implement security measures recommended in a 2021 vendor HIPAA risk assessment, leading to violations of both the HIPAA Security and Breach Notification Rules and New York’s SHIELD Act. Enzo did not admit liability as part of the settlement. This case emphasizes the importance of promptly addressing security vulnerabilities and indicates potential enforcement actions for HIPAA-covered entities under the SHIELD Act.
Aug 27, 2024·LinkedIn
The article discusses the challenge cybersecurity professionals face in proving their value, given that their successes are often characterized by the absence of attacks. To address this, cybersecurity efforts should translate risk reduction into tangible financial terms and align with business continuity metrics like Recovery Time Objective (RTO) and Recovery Point Objective (RPO). Highlighting proactive threat detection and the cost of inaction can justify investments. Regular scenario-based simulations, threat intelligence metrics, post-incident reviews, and business impact assessments can demonstrate preparedness and savings. These efforts elevate cybersecurity from a cost center to a strategic asset, as emphasized by the author, Dr. Dennis E. Leber.
Aug 26, 2024·thehackernews
SolarWinds has released patches for a critical vulnerability in its Web Help Desk software (CVE-2024-28987) that allows unauthenticated remote users to gain unauthorized access and modify data. Rated 9.1 on the CVSS scale, the flaw was discovered by Horizon3.ai's Zach Hanley. Users are advised to update to version 12.8.3 Hotfix 2, which requires prior installation of versions 12.8.3.1813 or 12.8.3 HF1. This follows a recent patch for another severe vulnerability (CVE-2024-28986) with a CVSS score of 9.8 that has been actively exploited, though specific attack details remain unknown. Further information on CVE-2024-28987 is anticipated next month, underscoring the urgency for timely updates.
Aug 26, 2024·krebsonsecurity.com
The escalation of top-level domains (TLDs) has intensified a security issue where many organizations inadvertently send Microsoft Windows usernames and passwords to domains they do not own, due to previously non-existent TLDs now being available for registration. This flaw, known as "namespace collision," exposes sensitive data because organizations set up their internal authentication systems using what they thought were private domains. Security researcher Philippe Caturegli has been mapping this vulnerability by examining self-signed security certificates, uncovering more than 9,000 suspect domains. A significant portion of these are now registered, potentially allowing third parties to intercept credentials. Caturegli's findings highlight the scale of the issue, revealing that even critical infrastructures and government entities are affected. His research underscores the persistent and pervasive risk posed by outdated network configurations and the need for organizations to adopt more secure internal domain naming practices.
Aug 22, 2024·StackAware
The author expresses skepticism about the value of cyber insurance after engaging in a frustrating process with their carrier to establish a response plan. Despite purchasing the insurance for contractual reasons, the carrier showed little proactive interest in preparing the client for incidents. Challenges included delays in securing a non-disclosure agreement (NDA) and business associate agreement (BAA), inadequate onboarding support, and the need to manually remove former employees from communication channels. The author also questions the efficacy of cyber insurance, citing instances of low claims payouts and industry struggles to quantify cyber risk, suggesting some organizations might be better off investing in improved preventative controls rather than insurance premiums.
Aug 22, 2024·wsj.com
The article discusses the growing threat of cyberattacks on hospitals and the broader healthcare industry. It highlights various incidents of security breaches, explores the consequences these attacks have on medical facilities and patient care, and emphasizes the urgent need for improved cybersecurity measures. Strategies such as adopting comprehensive security frameworks, investing in advanced technology, and conducting regular training for healthcare staff are recommended to mitigate these risks and protect sensitive health information from cyber threats.
Aug 22, 2024·defensescoop.com
The article advocates for the establishment of an independent U.S. Cyber Force, emphasizing that current distributed cyber defense efforts are insufficient in facing the sophisticated and frequent cyber threats from adversaries like China, Russia, and Iran. It argues that a dedicated cyber force would fill gaps in capabilities, training, and innovation, while providing streamlined command, specialized recruitment, and enhanced adaptability. Comparisons to the recently established U.S. Space Force are made to illustrate the need for specialized military branches to address unique operational challenges. The article counters concerns about redundancy and cost by noting potential efficiencies and long-term benefits, asserting the necessity of a robust cyber force to safeguard national security.
Aug 21, 2024·FedTech Magazine
The U.S. Department of Veterans Affairs (VA) is increasingly incorporating Internet of Medical Things (IoMT) devices into its healthcare delivery system to enhance patient data collection and streamline clinical operations. These connected medical devices present significant benefits but also pose cybersecurity risks such as potential data breaches and ransomware attacks. To mitigate these risks, the VA and other federal agencies are adopting zero-trust architectures, emphasizing continuous monitoring, encryption, and segmented network access. Legacy devices with outdated security controls further complicate the landscape, prompting the FDA to advocate for stronger collaboration and updated regulatory measures among manufacturers and healthcare providers. Organizations are advised to employ comprehensive security solutions and proactive management strategies to safeguard these critical devices in the complex healthcare environment.
Aug 21, 2024·KrebsOnSecurity
A recent breach at National Public Data (NPD) has exposed the personal information, including Social Security Numbers, addresses, and phone numbers, of hundreds of millions of Americans. The exposure was exacerbated by a related data broker inadvertently publishing database passwords online. The breach, initially sold by a cybercriminal in April, became public in July, compromising information of over 272 million people. Additionally, it was discovered that credentials for users of NPD’s sister site recordscheck.net were exposed via an accessible archive. This breach highlights the importance of credit file freezes, as detailed personal information is now more accessible to identity thieves.
Aug 21, 2024·The HIPAA Journal
The editorial by Josh Ablett emphasizes the critical need for healthcare organizations to conduct cyber fire drills to effectively handle breaches. Despite significant investments in preventive measures, breaches continue to occur, causing severe operational disruptions and financial consequences. Ablett explains the concept of "dwell time" and argues that early detection and swift response are crucial to minimizing damage. He advocates for regular, realistic cybersecurity simulations to build employee muscle memory, ensuring they know how to act promptly and appropriately during an attack. Implementing these drills can mean the difference between a minor incident and a major operational crisis.
Aug 21, 2024·azure.microsoft.com
Microsoft is introducing mandatory multifactor authentication (MFA) for all Azure sign-ins starting in the second half of 2024. This move is part of its $20 billion investment in security and the Secure Future Initiative to protect identities and digital assets from increasingly sophisticated cyberattacks. The phased rollout aims to provide customers with time to implement the changes and will involve notifications via email, Azure portals, and the Microsoft 365 message center. Customers will also have various MFA options, including Microsoft Authenticator, FIDO2 security keys, and certificate-based authentication, with extended timeframes available for complex environments. More details can be found in Microsoft's documentation.
Aug 21, 2024·TechCrunch
Earlier this year, Change Healthcare, a UnitedHealth-owned health tech company, suffered a significant ransomware attack, resulting in what is likely one of the largest data breaches of U.S. health and medical data. The attack, attributed to the ALPHV/BlackCat ransomware gang, caused widespread outages across the healthcare sector, disrupting billing and prescription services. Although UnitedHealth paid a $22 million ransom for a "safe" copy of the stolen data, issues persisted as affected individuals began receiving breach notifications. UnitedHealth confirmed the breach impacted a substantial portion of the U.S. population, with potentially over 100 million individuals affected. The incident, rooted in compromised security protocols, highlights vulnerabilities in handling sensitive healthcare data and has prompted increased bounty efforts from the U.S. government to locate those responsible.