Cybercriminals, hacktivists, nation state actors, cyberterrorists, script kiddies, and insider threats are the main types of bad actors that threaten healthcare, according to a new briefing from the Health Sector Cybersecurity Coordination Center (HC3). Top attacks utilized by the above entities include: Social Engineering: The practice of obtaining sensitive information by manipulating legitimate users, often […]
Third Party Web Analytics Causing Big Problems
Third party web analytics software providers are causing a widespread trend in healthcare breaches, according to a bulletin from The Centers for Medicare & Medicaid Services (CMS) Cybersecurity Integration Center (CCIC) Cyber Threat Intelligence (CTI) team. Many healthcare websites, including health-related mobile applications, use web analytics software from third party providers in order to monitor user […]
Study: Majority of CISOs Have Lost Sensitive Data in Past Year
Sixty-three percent of security leaders had to deal with the loss of sensitive information in the past 12 months, according to the annual Voice of the CISO report from Proofpoint. Sixty-eight percent of surveyed CISOs feel at risk of a material cyber-attack, with, 61% feeling unprepared to cope with it. Other findings include: The loss […]
Study: Cyberattacks That Take Out Even a Single Hospital Should be Considered Regional Disasters
Cyberattacks, such as ransomware, “can have real patient care impacts that extend far beyond a single effected hospital,” according to a new University of California San Diego School of Medicine study, causing disruptions at nearby regional hospitals. The study, published in the May 8 online edition of JAMA, analyzed data from two emergency departments that […]
HC3 Warns of New Data Breaches from Cl0p and Lockbit Ransomware Groups
Ransomware-as-a-service (RaaS) groups Cl0p and Lockbit recently conducted several distinct attacks, exploiting three known vulnerabilities (CVE-2023-27351, CVE-2023-27350, and CVE-2023-0669), according to a new sector alert from the Health Sector Cybersecurity Coordination Center (HC3). CISA added the latter two vulnerabilities to its Known Exploited Vulnerabilities Catalog but has not yet added the first. This Sector Alert […]