Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Jul 29, 2024·Fox News
Security researchers have identified new Mac malware that disguises itself as the legitimate and popular browser, Arc. This malware is distributed through Google Ads that redirect users to a fake download site, prompting users to bypass Mac security measures to install it. Once installed, the malware, named Poseidon, steals sensitive data like passwords and cryptocurrency wallets and sends it to a control panel accessible to cybercriminals. Despite Google's verification processes, bad actors managed to exploit Google Ads to spread this malware. Users are advised to follow security best practices such as bookmarking trusted sites and using strong antivirus protection. In response, Google has suspended the offending advertiser's account for policy violations.
Jul 29, 2024·publication
CrowdStrike experienced a significant issue with a software update for its Falcon sensor, which was live for 78 minutes on July 19, 2024. The faulty update caused widespread IT network disruptions and system crashes on Windows devices running versions 7.11 and above. Despite quickly reverting the update, many systems were already affected, necessitating manual remediation efforts across various sectors. CrowdStrike clarified that the issue was not due to a cyberattack and provided remediation guidance on its blog. This incident highlighted vulnerabilities in automated software deployment and its expansive impact on businesses worldwide.
Jul 29, 2024·NBC News
Warren Buffett's Berkshire Hathaway expressed caution at its annual investor meeting about cyber insurance, advising agents to sell such policies only when necessary due to the unpredictable scale of potential losses. This caution was underscored by a recent global IT outage caused by a CrowdStrike quality control issue, which affected various sectors including transportation and healthcare. While some experts like Gerald Glombicki of Fitch Ratings believe that the industry has largely priced in such risks and can manage the losses, others such as Josephine Wolff of Tufts University foresee significant business interruption claims and potential litigation arising from such incidents. The episode highlights the complexities and evolving nature of the cyber insurance market, emphasizing the need for better risk assessment and potentially more standardized policies.
Jul 29, 2024·Business Insider
The CrowdStrike outage on Friday caused significant disruptions globally, affecting airlines, delivery services, stores, and amusement parks, with potential economic damages reaching tens of billions of dollars. CrowdStrike is liable only for refunding subscription fees and not for business interruption losses. Companies are turning to their cyber insurance policies, though payouts may be slow and less than the actual losses incurred. The incident underscores the increased reliance on and potential risks of cyber insurance, especially for large businesses with negotiated terms. Observers note the irony of the outage resulting from protective software updates and anticipate lasting impacts on the cyber insurance industry.
Jul 29, 2024·artemis.bm
The recent IT outage linked to CrowdStrike has caused significant concern within the US cyber insurance industry, but losses are expected to be contained below $1 billion, with estimates ranging between $270 million and $960 million. Coalition's CEO Joshua Motta detailed that although such cyber events raise concerns about systemic risks, they do not equate to natural catastrophe losses. Modeling insights and adjustments to cyber insurance policies, including coverage limitations and sub-limits, are being accelerated in response to these events. The evolving landscape emphasizes the need for thoughtful management of cyber perils and acknowledges the benefits of technological diversification and rapid organizational responses.
Jul 26, 2024·theguardian
CrowdStrike, a cybersecurity firm, recently offered its employees UberEats vouchers, raising questions about the company's remote work policies and employee benefits. This news highlights the growing trend of companies providing non-traditional perks to support their remote workforce. The move reflects how firms are adapting their incentives to accommodate the changing dynamics of work environments amid ongoing shifts in how and where employees perform their duties.
Jul 26, 2024·Wall Street Journal
CrowdStrike recently experienced a significant global tech outage due to a software bug, impacting various systems and services. The cybersecurity company, known for its cloud-delivered endpoint protection, is addressing the issue and working towards a resolution. The malfunction highlights the vulnerabilities inherent in software dependencies and the widespread effects such disruptions can have on technology ecosystems.
Jul 26, 2024·Becker's Hospital Review
Duke University Health System, along with other healthcare systems globally, experienced a significant IT outage on July 19 due to a faulty update from CrowdStrike, a prominent cybersecurity vendor. The disruption caused tens of thousands of workstations to display blank blue screens, directly impacting hospital operations and patient care systems. By activating incident command protocols and deploying a massive joint effort between IT and operational staff, most affected health systems restored patient services by July 22. The incident highlighted the critical reliance on third-party vendors and underscored the need for rigorous cybersecurity measures, including redundancy, vendor security evaluations, and comprehensive incident response planning. The event's resolution involved detailed manual intervention and coordination to mitigate the impact on healthcare delivery.
Jul 26, 2024·Cybersecurity Dive
The recent congressional testimony by UnitedHealth Group CEO Andrew Witty highlighted the increasing importance of cybersecurity at the executive level following a major cyberattack on Change Healthcare, a UnitedHealth subsidiary. The breach, which impacted millions of Americans, disrupted key healthcare services and exposed the vulnerability of healthcare data systems. This incident underscored that CEOs must play a proactive role in cybersecurity strategy, emphasizing risk mitigation, incident response, and disaster recovery. The implications extend beyond corporate embarrassment; CEOs face potential SEC charges, shareholder lawsuits, and national security concerns. Consequently, executives are urged to deeply engage in their organization's cybersecurity posture to prevent and effectively manage breaches.
Jul 26, 2024·Healthcare IT News
A recent advisory from the Cybersecurity and Infrastructure Security Agency (CISA) highlighted a series of remotely exploitable vulnerabilities in Philips' Vue Picture Archiving and Communication Systems (PACS) versions prior to 12.2.8.410. These vulnerabilities could allow unauthorized data access and system modifications, affecting system integrity and availability. Countries like the U.S. and Brazil are particularly at risk. Philips has issued updates to address these vulnerabilities and recommends healthcare organizations perform risk assessments before deploying defensive measures. The advisory underscores the importance of regular software updates to protect patient data and maintain system integrity.
Jul 26, 2024·hcinnovationgroup.com
A global outage caused by a faulty software update from CrowdStrike affected around 8.5 million Windows devices, leading to significant disruptions in health systems worldwide. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of ongoing cyber threats, including phishing attempts exploiting the outage. Health systems, such as RWJBarnabas Health and Providence, reported progress in restoring systems but faced scheduling delays and reverted to paper charting in some cases. Microsoft provided a recovery tool to aid affected systems, while the American Hospital Association (AHA) released guidelines for hospital IT teams to enhance resilience against such incidents. Nurses across the U.S. indicated widespread impacts, with some hospitals having to redirect ambulances.
A recent article from the Wall Street Journal reports on a software outage experienced by CrowdStrike, a leading cybersecurity firm. The disruption stemmed from a problematic software patch, which impacted the company's Falcon platform and potentially compromised the security operations of multiple clients. The company is working to resolve the issue and has emphasized its commitment to preventing such incidents in the future. Readers are directed to the full story for further details.
Jul 25, 2024·Becker's Hospital Review
On July 19, Penn Medicine experienced a major disruption when a global IT outage from CrowdStrike affected 50,000 of their computers, leaving staff unable to use electronic medical records and greeted with the "blue screen of death." Executives, awakened by early morning calls, held an emergency Zoom meeting to manage the crisis, which led to the cancellation of most nonessential procedures and a switch to paper records for documentation. Critical imaging machines remained operational on a different system. Penn Medicine is extending clinic hours and considering a shift to iOS devices to mitigate future disruptions.
Jul 25, 2024·Insurance Journal
The recent massive technology outage caused by an update from CrowdStrike has raised significant concerns across various industries and the cyber insurance sector. The incident, likened to the NotPetya attack, is expected to lead to substantial business interruption claims due to systems failure from non-malicious acts like human error. Insurers are now reexamining policy wordings and considering tightening their terms, especially around non-malicious events and the extent of business interruption coverage. The event underscores the need for insurers to assess policyholder supply-chain dependencies and manage potential aggregation risks without retracting essential coverage. The widespread impact highlights growing risks associated with single points of failure and the need for redundancy in critical systems.
Jul 24, 2024·CIO
In light of a recent CrowdStrike incident highlighting vulnerabilities in cloud infrastructure, CIOs are reassessing their cloud strategies to mitigate risks associated with single points of failure. This incident has prompted IT leaders to explore multi-cloud and hybrid approaches to enhance resilience and prevent system-wide disruptions.
Jul 24, 2024·cnn
A faulty software update from cybersecurity firm CrowdStrike caused a significant global IT outage, disrupting various industries, including airlines and hospitals, and affecting approximately 8.5 million devices. Although CrowdStrike has apologized, it has not committed to compensating affected customers, who may seek remuneration through lawsuits. Estimates suggest the financial impact could exceed $1 billion. Despite potential legal protections in its contracts, CrowdStrike's reputation has suffered, and its competitors may use this incident to attract its clients. The company's CEO emphasized ongoing efforts to restore systems and maintain customer trust.
Jul 24, 2024·brendangregg.com
The article discusses the importance of eBPF (Extended Berkeley Packet Filter) in preventing catastrophic system crashes caused by problematic software updates, especially those involving kernel code. It follows an incident on July 19th, where a widespread Windows outage affected critical sectors worldwide due to a faulty kernel driver update by a security company. The article highlights how eBPF provides a secure execution environment that mitigates such risks by verifying code before execution, thus preventing system crashes. With Linux systems already leveraging eBPF, upcoming support for Windows is expected to extend these benefits across platforms. The article urges companies to require eBPF-based solutions to enhance system security and reliability.
Jul 24, 2024·Forbes
Microsoft has released a free recovery tool to address a CrowdStrike update issue that caused the "blue screen of death" on 8.5 million Windows machines. The tool offers two repair options and supports various Windows environments, including those hosted on Hyper-V. The first option uses the Windows PE recovery environment and requires a USB drive to delete the corrupt file, although BitLocker users may need to enter recovery keys manually. The second option attempts to recover systems in safe mode and is aimed at specific configurations. Additionally, Fenix24 has developed a set of free, automated recovery scripts for Windows and VMware users to mitigate the issue without manual patching, although drive encryption may still necessitate manual intervention. Full instructions and additional details are available online for both solutions.
Jul 24, 2024·HCINnovationGroup
Health system IT teams are progressively restoring computer systems and EHR access following a global outage caused by a faulty software update by CrowdStrike, which primarily impacted Windows-based computers. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has reported continued malicious activity, including phishing attempts during the outage, and is working closely with CrowdStrike and other partners to monitor threats. Many hospitals, affected in nearly every state, have experienced scheduling delays and reverted to paper charting. Microsoft has released a recovery tool to assist, with endorsements from the American Hospital Association. Health systems and IT teams are praised for their swift and effective response to maintain patient care during the disruption.
Jul 24, 2024·Wired
The article discusses the discovery and implications of FrostyGoop, a new malware that has been identified targeting heating utilities in Ukraine. The malware, likely linked to Russian threat actors, has the potential to disrupt heating services, posing severe risks to public safety, especially during colder months. This development marks an alarming escalation in cyber warfare tactics, highlighting the vulnerabilities in critical infrastructure and the urgent need for improved cybersecurity measures within essential service sectors.