Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Oct 15, 2025·Google Cloud
the increasing risks posed by cybersecurity threats in healthcare and other sectors that rely on complex software systems like Oracle's E-Business Suite. The exploitation of a zero-day vulnerability has allowed cybercriminals to infiltrate sensitive organizational data, prompting ransom demands and highlighting the urgent need for comprehensive cybersecurity measures. Healthcare professionals and organizations must prioritize timely software updates and proactive security strategies to safeguard patient and operational data amidst evolving cyber threats. As the frequency and sophistication of such attacks grow, collaboration with cybersecurity experts becomes essential for protecting critical healthcare infrastructure.
Oct 15, 2025·BleepingComputer
Microsoft has announced the final cumulative update for Windows 10, designated as KB5066791, coinciding with the operating system's end of support lifecycle. This critical update addresses six zero-day vulnerabilities and 172 additional flaws, highlighting the urgency for users to implement it to maintain security. Healthcare organizations relying on Windows 10 must be aware that after October 14, 2025, Microsoft will cease free updates and support for the OS, although extended security options are available for a fee. This shift emphasizes the need for healthcare professionals to evaluate their technology strategies to ensure compliance and safeguard sensitive patient data.
Oct 14, 2025·The Royal Gazette
Cybercrime has become the third largest global economy by GDP, posing significant threats to the healthcare sector, which is frequently targeted by sophisticated cyberattacks. Experts from Fortified Health Security, speaking at the CIO Connect conference, commended the Bermuda Hospitals Board for its proactive cybersecurity measures but warned that healthcare organizations must remain vigilant, as attackers now operate in highly organized networks. With threat actors often spending an average of 279 days undetected within systems, the imperative for robust data backup solutions—alongside regular testing of these backups—has never been more crucial. This ongoing risk highlights the need for healthcare professionals to prioritize cybersecurity protocols to safeguard sensitive patient data and maintain operational integrity.
Oct 13, 2025·arstechnica.com
Microsoft has alerted healthcare organizations to the "Payroll Pirate" scam, which exploits vulnerabilities in cloud-based HR services to redirect employee paychecks to attacker-controlled accounts. By utilizing phishing tactics to capture login credentials and intercept multi-factor authentication (MFA) codes, scammers can gain unauthorized access to HR portals like Workday. This incident underscores the inadequacies of certain MFA methods, prompting a critical need for stronger security measures, such as FIDO-compliant solutions, to protect sensitive employee data. Healthcare professionals must reassess their cybersecurity protocols to guard against increasingly sophisticated attacks that compromise financial and personal information.
Oct 13, 2025·SecurityWeek
A coordinated cyberattack campaign targeting devices from Cisco, Fortinet, and Palo Alto Networks has revealed significant vulnerabilities that could compromise the security of numerous organizations. This trend of targeting network infrastructure highlights the critical need for timely updates and robust security measures, as attackers can exploit these weaknesses to access sensitive data and disrupt operations. Healthcare professionals must prioritize vulnerability patching and adopt proactive cybersecurity strategies, including continuous monitoring and incident response planning, to protect against potential breaches. Enhanced collaboration and information sharing within the cybersecurity community are essential for mitigating risks and strengthening defenses against evolving threats.
Oct 13, 2025·Healthcare IT News
In 2025, U.S. healthcare organizations face heightened cybersecurity risks, as recent reports underscore an increase in frequency and severity of cyberattacks disrupting patient care and contributing to clinical risks. Key findings indicate that human factors, particularly employee negligence and leadership gaps, play a substantial role in these breaches, underscoring the need for targeted training and governance in healthcare IT. However, advancements in artificial intelligence offer promising solutions by bolstering defenses and optimizing budgetary allocations for security measures. As predictions suggest an escalation in breaches, healthcare professionals must prioritize cybersecurity to safeguard patient safety and protect sensitive data.
Oct 13, 2025·Cybersecurity Dive
Hackers from the Crimson Collective have breached Red Hat, compromising over 28,000 code repositories and threatening to release 570 GB of sensitive data unless a ransom is paid. This includes critical consulting engagement information, access tokens, and reports on major corporate networks, potentially impacting clients like Walmart and American Express. The incident underscores the vulnerabilities present in software supply chains and raises significant concerns for healthcare technology providers, who often rely on such systems for patient data management. With ongoing threats from ransomware groups, healthcare organizations must bolster their cybersecurity measures to protect sensitive information from similar breaches.
Oct 12, 2025·Wired
Apple has significantly enhanced its bug bounty program, now offering up to $2 million for identifying critical software exploit chains that could facilitate spyware attacks, with potential payouts reaching $5 million for particularly dangerous vulnerabilities. This initiative, announced by security VP Ivan Krstić at the Hexacon conference, aims to leverage financial incentives to attract top-tier security researchers and addresses escalating concerns over cybersecurity threats within Apple’s ecosystem. The expanded program, which now encompasses more exploit categories, underscores Apple's proactive approach to fortifying its mobile security and protecting user data from malicious entities. As healthcare technology increasingly integrates mobile platforms, this initiative may offer insights into best practices for safeguarding sensitive health information against similar vulnerabilities.
Oct 12, 2025·Cybersecurity Dive
A recent extortion campaign targeting Oracle E-Business Suite customers has been linked to a zero-day vulnerability (CVE-2025-61882) with a critical severity score of 9.8, allowing unauthenticated attackers to remotely control the system’s processing components. The Clop ransomware group has been sending threatening communications to company executives, urging immediate action to mitigate the threat. In response, Oracle emphasized the importance of updating to a critical patch released in July, as the vulnerability is part of a broader, sophisticated attack strategy that exploits multiple weaknesses. This incident underscores the urgent need for healthcare organizations using Oracle systems to prioritize cybersecurity measures to protect sensitive data.
Oct 9, 2025·Cybernews
Microsoft has issued a warning about the exploitation of its Teams platform by hackers, who utilize sophisticated techniques to gather sensitive information and deliver malware through messages and calls. This has raised significant concerns as Teams has become a target for both cybercriminals and state-sponsored attackers due to its widespread use in organizational communications. In response, Microsoft's Threat Intelligence team emphasizes the need for healthcare administrators to bolster security measures across various layers—identity, endpoints, and network—to mitigate these risks. The implications for healthcare professionals are substantial, as breaches can lead to serious consequences including credential theft and extortion, highlighting the critical need for enhanced cybersecurity protocols in digital communication tools.
Oct 9, 2025·Ars Technica
Salesforce has publicly rejected an extortion demand from the Scattered LAPSUS$ Hunters, a criminal group that claims to have stolen around 1 billion records from Salesforce customers, including major companies like Toyota and FedEx. This syndicate, identified by security researchers as a coalition of three previously known data-extortion groups, has exploited social engineering tactics to gain access to Salesforce portals through deceptive voice calls. The incident underscores the escalating threat of sophisticated cyberattacks in healthcare technology, emphasizing the need for robust security measures and heightened awareness among organizations using digital platforms to protect sensitive patient data. As Salesforce and its clients grapple with the repercussions of this breach, it highlights the critical importance of cybersecurity readiness in the healthcare sector.
Oct 9, 2025·The Hacker News
A recent report by LayerX highlights the alarming emergence of artificial intelligence (AI) as the primary channel for data exfiltration in enterprises, overtaking traditional data loss concerns. With nearly half of employees now utilizing generative AI tools—43% specifically using ChatGPT—security governance struggles to keep pace, as 67% of this usage occurs through unmanaged personal accounts, leaving Chief Information Security Officers (CISOs) unable to monitor data flows effectively. Furthermore, the report reveals that 40% of files uploaded to these AI platforms contain sensitive information, underscoring a critical gap in data protection. This scenario signals an urgent need for healthcare professionals to enhance security measures and adapt governance frameworks to safeguard sensitive data in an increasingly AI-driven environment.
Oct 8, 2025·bankinfosecurity.com
The Health Sector Coordinating Council (HSCC) has launched the SMART toolkit, a free resource aimed at helping healthcare organizations manage third-party risks associated with vendors and critical services. Developed over 16 months with input from 80 organizations, this toolkit provides tailored methodologies to measure systemic risks and encourages organizations to define "materiality" specific to their operations. By shifting focus to high-impact third-party relationships, the SMART toolkit aims to improve organizational preparedness for cybersecurity threats and optimize resource allocation. This initiative underscores the critical need for personalized risk assessments in the increasingly complex healthcare landscape.
Oct 8, 2025·Los Angeles Times
Newport Beach Police responded to a 911 call about a shooting at Hoag Hospital, which was later determined to be a swatting incident with no actual emergency. Swatting not only leads to excessive police resources being deployed but can also incite chaos, fear, and significant disruptions in healthcare settings, as seen in previous incidents at Loma Linda University and Claremont McKenna College. This highlights the urgent need for improved emergency response protocols and public awareness to mitigate the risks associated with such dangerous pranks. The serious consequences of swatting, including potential casualties, call for healthcare professionals and authorities to enhance their preparedness for these deceptive threats.
Oct 7, 2025·AHA
The American Hospital Association (AHA) has updated its Cybersecurity and Risk Advisory webpage to address a critical vulnerability in the Oracle E-Business Suite that can be exploited remotely, presenting significant risks to healthcare organizations. This initiative reflects an urgent need for enhanced cybersecurity measures in a sector increasingly targeted by cyber threats, including a new LockBit 5.0 ransomware variant that poses serious operational risks. Additionally, efforts in Texas demonstrate a collaborative approach among healthcare entities to bolster regional cybersecurity resilience. These developments highlight the importance of proactive risk management and information sharing to safeguard sensitive patient data and maintain operational integrity in healthcare systems.
Oct 7, 2025·Cyber Insider
The hacking collective LAPSUS$ has established a new online portal to claim responsibility for a substantial data breach affecting Salesforce products, impacting over 50 prominent companies, including Toyota and FedEx. They allege to have extracted several terabytes of sensitive data, including personal identifiers and corporate information, by exploiting vulnerabilities such as weak OAuth protections and improper two-factor authentication. This incident raises serious concerns about the security of cloud-based services and highlights the need for healthcare organizations, which often use similar systems, to enhance their data protection measures. Failure to address these vulnerabilities could result in significant data exposure and regulatory repercussions as hackers threaten full disclosure of the data by October 2025.
Oct 7, 2025·BleepingComputer
Hackers breached Discord's data by compromising a third-party customer service provider, stealing sensitive information including partial payment details and personally identifiable information from users. This incident, impacting individuals who interacted with Discord’s support teams, underscores vulnerabilities in how healthcare and other industries manage third-party vendor relationships. The stolen data, if leaked, could not only jeopardize user privacy but potentially aid in criminal investigations, raising alarms about the security measures in place to protect against such breaches. Discord's swift response, involving isolation of the compromised provider and law enforcement engagement, highlights the critical need for robust cybersecurity strategies in managing customer data.
Oct 7, 2025·BankInfoSecurity
Jigar Kadakia, Chief Information Security Officer at GeneDx, warns that genomic testing companies are increasingly vulnerable to cyberattacks due to the sensitive data they manage, particularly regarding children’s health. He advocates for a reevaluation of authentication strategies as traditional methods, including two-factor authentication, are being circumvented by advanced tactics such as AI-driven social engineering. The rise of AI algorithms and complex digital identities necessitates healthcare organizations to adopt comprehensive security measures that evolve alongside these threats. As digital identities become more intertwined with healthcare operations, effective identity and access management is essential to safeguard patient data.
Oct 6, 2025·Cybersecurity Dive
The recent expiration of federal funding for the Multi-State Information Sharing and Analysis Center (MS-ISAC) has severely impacted state and local governments' cybersecurity capabilities, particularly for smaller jurisdictions that rely on its resources. The loss of this funding, initiated by the Trump administration, ends a 21-year partnership with the Department of Homeland Security that provided essential services to mitigate local cyber threats. As a result, MS-ISAC expects to lose two-thirds of its state members and thousands of local governments, which could jeopardize the cybersecurity of critical infrastructure, including schools and hospitals. The shift to higher membership fees could further exclude financially constrained local entities from accessing necessary cybersecurity support.
Oct 5, 2025·DH Insights
A recent study from NYU Tandon School of Engineering reveals that advanced ransomware, termed Ransomware 3.0, can now operate autonomously using large language models (LLMs). This capability allows attackers to execute a full ransomware attack—including reconnaissance, file scanning, and personalized notifications—without human input, significantly raising the sophistication and adaptability of such threats. The findings highlight a troubling shift in the cybersecurity landscape, as this autonomous approach makes it increasingly challenging for traditional security measures, which rely on static signatures, to effectively detect these threats. Healthcare professionals should be aware that this evolution could lead to more frequent and diversified attacks on healthcare systems, underscoring the need for enhanced cybersecurity strategies.