The Cybersecurity and Infrastructure Security Agency, FBI and National Security Agency released recommendations to help health care and other critical infrastructure organizations prevent, detect and respond to common Russian state-sponsored cyber threats.聽
Cybersecurity News
Latest
A report by the United Kingdom鈥檚 National Health Service is warning of threats leveraging Log4Shell vulnerability in VMware Horizon servers by an unknown cyber actor.
Health and Human Services Secretary Xavier Becerra today in a letter聽to health care and public health leaders urged vigilance against cyber threats posed by a vulnerability within the Apache Log4j software. Exploitation of the software, which exists in thousands of applications, including control systems for medical devices and hardware, can result in data exfiltration or ransomware that can significantly disrupt the delivery of health care.
John Riggi, AHA鈥檚 national advisor for cybersecurity and risk, discusses insights and lessons learned from hospital leaders from Dickinson County Healthcare System in Iron Mountain, Mich, and Sky Lakes Medical Center in Klamath Falls, Ore., after becoming victims of major ransomware attacks in the fall of 2020.
Apache has released a security update to address a second severe vulnerability affecting its Log4j software library, which a remote attacker could exploit to cause a denial-of-service condition, the Cybersecurity and Infrastructure Security Agency announced.
The Cybersecurity and Infrastructure Security Agency has created a webpage聽to provide the latest public information and vendor-supplied advisories on a critical remote code execution vulnerability affecting Apache Log4j software library versions 2.0-beta9 to 2.14.1.
A ransomware attack has impacted several Ultimate Kronos Group services that hospitals and other organizations use to manage their employees and payrolls, the HR management company has confirmed.
Health care organizations should survey their information infrastructure to ensure they are not running vulnerable versions of the Apache Log4j Java library, upgrade any vulnerable systems and identify possible exploitation, the Department of Health and Human Services鈥 Health Sector Cybersecurity Coordination Center advised.
The AHA has developed 鈥淲hat Boards Should Know About Cybersecurity鈥 to assist hospital and health system trustees in asking key questions about their organization鈥檚 cybersecurity protocols.
The Department of Health and Human Services launched a central web resource聽for information on cybersecurity best practices recognized by its 405(d) program.
The Department of Health and Human Services鈥 Health Sector Cybersecurity Coordination Center (HC3) last week advised biotechnology companies specifically and the health care and public health sector generally to review a new report on a malware threat aggressively spreading through the biomanufacturing industry and take appropriation action to protect their information infrastructure.
In this podcast John Riggi, AHA鈥檚 senior advisor for cybersecurity and risk, talks to David Ring, section chief of the FBI's cyber engagement and intelligence section, and Errol Weiss, chief security officer at H-ISAC, about the latest ransomware attacks on hospitals, as well as the partnership between H-ISAC, AHA and the FBI to exchange cyber threat intel and to broadcast and amplify warnings.
Cybersecurity firm [redacted] today announced that it is the newest vendor to earn accreditation by AHA as part of the a
The FBI, Cybersecurity and Infrastructure Security Agency, Australian Cyber Security Centre, and United Kingdom鈥檚 National Cyber Security Centre released an advisory highlighting ongoing malicious cyber activity by Iranian government-sponsored actors targeting U.S. critical infrastructure sectors, including health care.
The AHA urged the Department of Health and Human Services鈥 Office for Civil Rights to quickly initiate rulemaking for a legislative provision (H.R. 7898) enacted by Congress this year to recognize certain recommended security practices when making determinations related to Health Insurance Portability and Accountability Act audits, fines and resolution agreements.
Ransomware actors are very likely using significant financial events, such as mergers and acquisitions, to target and leverage victim companies for ransomware infections, the FBI said in an alert聽this week to the private sector.
The FBI recently raided the Florida offices of Pax Technology, a Chinese-owned company that makes point-of-sale payment terminals, because the devices may have been involved in cyberattacks on U.S. and European organizations, according to news reports.
Microsoft on Sunday posted an update聽on the latest activity by Nobelium, a Russian nation-state actor behind cyberattacks on SolarWinds customers in 2020.
Learn how health care leaders such as Matthew Modica, vice president and chief information security officer at BJC HealthCare, are mitigating cyber risks as they take advantage of rapidly advancing technologies and respond to the pandemic.
The Department of Health and Human Services鈥 Health Sector Cybersecurity Coordination Center (HC3) issued a monthly bulletin聽that consolidates a wide range of cyber security alerts from across government on the latest cybersecurity trends and threats, including guidance聽on hardening remote access virtual private networks.聽