Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Aug 8, 2024·arstechnica
KnowBe4, a US security firm, discovered it had unknowingly hired a North Korean hacker who attempted to install malware within its network. CEO Stu Sjouwerman reported that the intruder used a stolen US-based identity and an AI-enhanced photo to pass standard hiring processes, including video interviews and background checks. Although no data breach occurred, the incident, now under FBI investigation, was detected when the hire's activities triggered security alerts from the company's Security Operations Center (SOC). The infiltrator had logged in remotely, likely from North Korea, using a VPN. KnowBe4 emphasized the importance of this incident as an organizational learning moment.
Aug 8, 2024·Forbes
The cybersecurity industry is currently experiencing a consolidation phase, where high-profile acquisitions and alliances aim to streamline cybersecurity solutions through platformization. While platforms promise simplicity and unified management, experts argue that this approach may not adequately address specialized threats and can lead to vendor lock-in and innovation stagnation. Industry leaders emphasize the enduring value of a modular approach, which allows for flexibility, best-of-breed solutions, and easier adaptation to emerging threats. A balanced strategy that integrates the strengths of both platformization and modularity, focusing on interoperability, can offer a more robust and adaptable cybersecurity ecosystem.
Aug 8, 2024·databreaches.net
In July, the DataBreaches log noted that six U.S. hospitals disclosed breaches, though some incidents received minimal media attention. Fairfield Memorial Hospital in Illinois appeared on LockBit3.0's leak site, acknowledging network issues but omitting details of the ransomware attack. Hospital Auxilio Mutuo in Puerto Rico reported a breach involving patient data, emphasizing ongoing investigations. Northeast Rehabilitation Hospital Network in New Hampshire detailed a ransomware incident affecting 501 patients. Millinocket Regional Hospital in Maine was claimed by RansomHub, without confirmation of a breach. Delhi Hospital in Louisiana faced attempted negotiations with R&D leak group over exfiltrated patient data. Lastly, Schneider Regional Medical Center in the Virgin Islands experienced network blockage and data theft, reported cooperating with authorities.
Aug 7, 2024·The Verge
Microsoft has introduced a new principle called the Security Core Priority, emphasizing that security is the top priority across all levels of the company. This directive, supported by CEO Satya Nadella, requires every employee to integrate security measures into their daily work routines and decision-making processes. The initiative, now accessible through the Connect tool, aims to hold employees accountable and recognize their security efforts. The Security Core Priority includes compulsory elements for all employees, along with optional sections tailored to specific roles. The approach mirrors existing core priorities such as Diversity & Inclusion, with progress reviews included in regular Connect conversations. This initiative underscores Microsoft's commitment to safeguarding its infrastructure, customers, and partners in a complex cyber threat landscape.
Aug 7, 2024·Chief Healthcare Executive
Hospitals are grappling with significant challenges in improving their cybersecurity, primarily due to difficulties in recruiting and retaining skilled professionals. Financial constraints and competition from other sectors offering higher pay and remote work opportunities exacerbate the issue. A HIMSS report indicates that 74% of healthcare IT professionals find hiring qualified cybersecurity staff a major challenge, despite increased IT budget allocations for cybersecurity. Experts highlight the need for hospitals to invest more in attracting top talent and providing growth opportunities to address these staffing shortages and protect sensitive patient data effectively.
Aug 6, 2024·BleepingComputer
A recent cybercriminal campaign has been identified that targets Android devices globally, using thousands of Telegram bots to distribute SMS-stealing malware aimed at intercepting one-time 2FA passwords for over 600 services. Researchers at Zimperium have tracked this operation since February 2022, uncovering 107,000 distinct malware samples linked to the campaign, which is primarily driven by financial motives. The malware is disseminated through deceptive ads and Telegram bots, which lure victims with promises of pirated apps, subsequently hijacking SMS messages to steal OTPs and facilitate authentication for illicit activities. Most victims are in India and Russia, with significant cases also in Brazil, Mexico, and the U.S. Infected devices are unwittingly used to provide anonymization services for online interactions, leading to potential unauthorized charges and legal implications for the victims. Users are advised to exercise caution by avoiding APKs from outside Google Play, restricting app permissions, and keeping Play Protect active.
Aug 6, 2024·IT Brew
A major IT outage caused by enterprise security firm CrowdStrike on July 19 led to massive disruptions across various sectors, including airlines and businesses, triggering substantial direct and indirect costs estimated in the billions. The root cause was identified as a bug in their quality control system, with most affected systems now restored. However, determining financial liability remains uncertain and could take months or years. Legal actions, including potential class suits and individual claims from affected companies like Delta Air Lines, are expected to prolong the resolution process. Industry experts suggest that software liability limitations and insurance negotiations will further complicate compensation payouts. Despite the outage, significant customer losses for CrowdStrike are not anticipated due to the entrenched nature of enterprise software solutions and the high costs associated with switching providers.
Aug 6, 2024·The Verge
Delta Air Lines CEO Ed Bastian revealed in a CNBC interview that a recent IT outage caused by a CrowdStrike update resulted in costs of half a billion dollars for Delta over five days, leading to over 5,000 flight cancellations and lingering error screens at airports. Bastian criticized Microsoft's platform as fragile, highlighting the need for big tech companies to balance innovation with current stability. Delta's IT department received only free consulting advice as compensation, while the company has since hired attorney David Boies to pursue damages. Moreover, CrowdStrike shareholders have filed a class action lawsuit, alleging false claims about the validation and testing of the faulty update. The incident underscores differences in how Microsoft and Apple handle third-party access to their operating systems and has led to calls for more rigorous testing protocols from vendors with critical access to Delta's systems.
Aug 6, 2024·darkreading
The article discusses a troubling trend where cybersecurity professionals, facing economic pressures and stagnating salaries, are turning to cybercrime for additional income. The Chartered Institute of Information Security (CIISec) has noted a rise in Dark Web advertisements for cybercriminal services, such as developing phishing pages or using AI for malicious coding, by individuals with legitimate cybersecurity day jobs. This shift is driven by mass layoffs and economic uncertainty in the cyber sector, exacerbating stress and employee dissatisfaction. Experts recommend that enterprises improve their understanding of cybersecurity roles, provide professional development, and focus on mental health to combat insider threats and close the skills gap.
Aug 6, 2024·aha.org
OneBlood, a nonprofit blood provider serving several states, is experiencing a ransomware attack that has significantly disrupted its operations. This has led hospitals to implement conservation strategies, impacting patient care. OneBlood continues to operate at reduced capacity without specifying when normal operations will resume. The American Hospital Association (AHA) is coordinating with state and federal bodies, including the Association for the Advancement of Blood & Biotherapies (AABB), to manage the situation. The AHA and Health Information Sharing and Analysis Center released a bulletin highlighting the need for hospitals to integrate third-party suppliers into their risk management plans due to increasing ransomware attacks on critical healthcare providers.
Aug 6, 2024·The Cyber Express
Recent cyberattacks on U.S. healthcare facilities, including a massive ransomware attack on UnitedHealth’s Change Healthcare subsidiary, highlight the sector's urgent need for enhanced cybersecurity measures. A recent report by SecurityScorecard gives the healthcare sector a "B+" rating for cybersecurity, indicating moderate progress but significant areas needing improvement, such as supply chain risks and application security. Chief Technology Officers (CTOs) play a critical role in navigating these challenges, taking on increased responsibilities in strategic decision-making and innovation to protect patient data and maintain operational efficiency. The rise of ransomware groups like BlackCat and BlackSuit underscores the necessity for robust cybersecurity strategies, including regular software updates, network segmentation, and adherence to HIPAA regulations. Advanced AI-driven solutions, like those offered by Cyble, can provide real-time monitoring and vulnerability management to strengthen healthcare defenses.
Aug 6, 2024·Wall Street Journal
CrowdStrike has responded to Delta Air Lines' accusations regarding a recent tech outage that caused significant disruption and financial losses for the airline. In a letter to Delta's legal team, CrowdStrike rejected the claim that it is to blame for Delta's prolonged issues following the outage, asserting that Delta's threats of litigation have created a misleading narrative. The cybersecurity firm, which has its liability capped at single-digit millions, attributed the outage to a bug in its quality-control tool and highlighted that other airlines recovered quickly while Delta struggled for days. The U.S. Department of Transportation is investigating Delta's response to the disruption. Delta CEO Ed Bastian estimated the outage cost the airline $500 million and has initiated an internal review to learn from the incident.
Aug 5, 2024·TechRadar
Cyberattacks on hospitals and healthcare institutions are escalating, with ransomware incidents causing significant disruptions, from cancelled appointments to compromised patient safety. These attacks exploit the healthcare sector's valuable data, often involving high-stakes ransom demands. The cost of cybercrime is projected to reach $10.5 trillion annually by 2025, heavily impacting patients. Persistent use of outdated IT systems and reactive cybersecurity measures exacerbate vulnerabilities. Strategies like network segmentation and an assumed breach approach are recommended to enhance cyber resilience, ensuring continuous operation and increasing response speed to mitigate these threats effectively.
Aug 5, 2024·The Record Media
IBM's annual report on cybersecurity has revealed that the average cost of a data breach has risen to $4.88 million, a 10% increase from last year’s $4.45 million. Conducted with the Ponemon Institute, the study analyzed 604 organizations across 17 industries and 16 countries. This rise was noted as the largest since the pandemic began, with more than half of the organizations passing on the increased costs to customers through higher prices. Significant breach-related costs include lost business and post-breach activities, amounting to $2.8 million. In the healthcare sector, breaches cost an average of $9.77 million, marking it the most affected industry since 2011. The analysis covered various breach causes, including phishing and compromised credentials, with ransomware attack-related breaches showing cost savings when law enforcement was involved. The U.S. led in average breach costs at $9.36 million.
Aug 5, 2024·Fox News
OneBlood, a significant nonprofit blood donation service for over 300 hospitals in the southeastern U.S., has experienced a ransomware attack compromising its software systems and reducing its operational capacity. Despite this, OneBlood continues to collect, test, and distribute blood through manual processes, which are slower and affect inventory availability. The organization is collaborating with cybersecurity experts and law enforcement to address the incident and restore system functionality. In response to the situation, OneBlood has requested that partner hospitals activate critical blood shortage protocols and has called for urgent blood donations, particularly of O positive, O negative, and platelets. National coordination through the AABB Disaster Task Force and contributions from blood centers across the country are aiding OneBlood's efforts. Founded in 2012, OneBlood has grown to become the second-largest blood center in the U.S., distributing over a million blood products annually.
Aug 5, 2024·KrebsOnSecurity
An international prisoner swap between Russia and Western countries resulted in the release of 24 prisoners, including notable cybercriminals and political detainees. Among those repatriated to Russia were Roman Seleznev, convicted of extensive payment card data theft, and Vladislav Klyushin, involved in a $93 million insider trading scam. In exchange, Russia freed 16 prisoners, including Wall Street Journal reporter Evan Gershkovich and ex-U.S. Marine Paul Whelan, both previously accused of espionage. The swap also saw the release of other Americans, several German nationals, and four individuals accused of being Russian spies by Slovenia, Norway, and Poland.
Aug 5, 2024·Cybersecurity Dive
A recent global IT outage caused by a faulty CrowdStrike software update has reignited concerns about the security of the software supply chain, echoing issues from the 2020 SolarWinds attack. The U.S. Government Accountability Office highlighted the event, which impacted 8.5 million Microsoft Windows systems, in a new report. The White House emphasized persistent vulnerabilities related to memory safety in software development and called for industry-wide adoption of memory-safe programming languages. Microsoft and CrowdStrike are investigating the incident, attributed to a memory safety error in the CSagent.sys driver, and are exploring prevention strategies. The Cybersecurity and Infrastructure Security Agency is collaborating with partners to assess and mitigate the repercussions of the outage.
Aug 5, 2024·ciodive.com
The recent software update failure in CrowdStrike's platform caused significant disruptions worldwide, highlighting the risks associated with automatic updates in IT systems. The incident, which led to the Blue Screen of Death on millions of Windows computers, impacted various sectors, including airlines and banking, and resulted in financial losses exceeding $5.4 billion for Fortune 500 companies. This event underscored the need for IT leaders to adopt more stringent quality assurance and risk mitigation practices, such as canary deployments and staggered updates, to prevent widespread issues from faulty software updates in the future.
Aug 2, 2024·The Guardian
CrowdStrike, a cybersecurity firm, is facing an investor lawsuit filed by Plymouth County Retirement Association in Texas, following a significant global computer outage linked to its software in July. The lawsuit alleges that CrowdStrike misled investors by falsely claiming that its technology was rigorously tested and validated. The plaintiffs argue that inadequate software testing led to the widespread outage, damaging CrowdStrike's reputation and legal standing. Additionally, the company faces other legal actions, including from Delta Air Lines, which estimates a $500 million loss due to the disruption. Despite the fallout, CrowdStrike maintains that the lawsuit is baseless. The outage's overall cost to major companies is estimated at $5 billion, and the company's response included giving $10 UberEats vouchers to team members, which were subsequently blocked by Uber.
Aug 2, 2024·cnn.com
A cyberattack has compromised OneBlood, a key blood-donation nonprofit that supports over 250 hospitals in the southeastern US. Reported initially by CNN, the incident is suspected to be a ransomware attack, leading to significant service disruptions. OneBlood’s software outage is affecting blood product distribution, forcing the organization to manually label products and operate at a reduced capacity. Hospitals in Alabama, Florida, Georgia, and the Carolinas are impacted, and emergency blood shortage protocols have been activated. The nonprofit is collaborating with cybersecurity experts and law enforcement to resolve the issue.