After convincing the help desk to enroll a new device, a threat actor can pivot to a payment system. IT pros: If someone from finance calls and says their phone is busted and they need to start over with authentication, trust but verify. Actually, don’t trust; just verify. Healthcare help desks need to be especiallyContinue reading “HC3 warns healthcare help desks of ‘advanced’ social engineers.”
Category Archives: Security
Cyber Threat: Why We Continue to Get It Wrong.
When are healthcare leaders really going to take cybersecurity seriously? Recently a good friend sent me an article that described analysis performed by an independent organization that performs cybersecurity research and the recommendation they made regarding the paying of ransoms. They make the supposition that stopping the payment of ransoms will end the ransomware threat onceContinue reading “Cyber Threat: Why We Continue to Get It Wrong.”
Small physician practices struggling after cyberattack.
The Change Healthcare cyberattack has stymied cash flow, forcing physician practices to pay out of pocket to keep businesses afloat. Small physician practices are still struggling in the wake of February’s Change Healthcare cyberattack, according to an American Medical Association (AMA) survey released Wednesday. More than half of ~1,400 respondents (55%) reported that they’ve had to use personalContinue reading “Small physician practices struggling after cyberattack.”
Google fixes two Pixel zero-day flaws exploited by forensics firms.
Google has fixed two Google Pixel zero-days exploited by forensic firms to unlock phones without a PIN and gain access to the data stored within them. Although Pixels run Android, they receive separate updates from the standard monthly patches distributed to all Android device OEMs. This is due to their unique hardware platform, over whichContinue reading “Google fixes two Pixel zero-day flaws exploited by forensics firms.”
What to do when you think you got phished.
Security pros share what to do if you took the bait and got phished. So, you clicked a phishing link. Don’t worry—you’re one of many in internet history who have trusted an email that seemed to come from a coworker, have a legitimate URL, or offer a reasonable enough chance to visit Mars. According to cybersecurityContinue reading “What to do when you think you got phished.”
How the Change cyberattack is affecting the healthcare industry.
Experts estimate the attack is costing providers $100 million every day. The cyberattack on Change Healthcare may go down as “the most significant cyberattack on the US healthcare system in American history,” according to trade group American Hospital Association—and one expert says it could take the healthcare industry years to recover. Despite rumors that ChangeContinue reading “How the Change cyberattack is affecting the healthcare industry.”
Ransomware 101: The need-to-knows for healthcare execs.
The Change Healthcare cyberattack may be just the beginning. The cyberattack on Change Healthcare that debilitated health providers and pharmacies across the country last month sent a foreboding message: Your company may be the next big cyberattack victim. You may be thinking, “we’re so careful with our employees. We send out phishing test emails everyContinue reading “Ransomware 101: The need-to-knows for healthcare execs.”
Apple fixes two new iOS zero-days exploited in attacks on iPhones.
Apple released emergency security updates to fix two iOS zero-day vulnerabilities that were exploited in attacks on iPhones. “Apple is aware of a report that this issue may have been exploited,” the company said in an advisory issued on Tuesday. The two bugs were found in the iOS Kernel (CVE-2024-23225) and RTKit (CVE-2024-23296), both allowingContinue reading “Apple fixes two new iOS zero-days exploited in attacks on iPhones.”
US lawmakers vote 50-0 to force sale of TikTok despite angry calls from users.
Lawmaker: TikTok must “sever relationship with the Chinese Communist Party.” The House Commerce Committee today voted 50-0 to approve a bill that would force TikTok owner ByteDance to sell the company or lose access to the US market. The Protecting Americans from Foreign Adversary Controlled Applications Act “addresses the immediate national security risks posed by TikTok andContinue reading “US lawmakers vote 50-0 to force sale of TikTok despite angry calls from users.”
Watch out for weird phishing promises like free transit to Elon Musk’s off-world colonies
Bizarre phishing lures include furious customer service complaints, Uzbek sales opportunities, and complimentary interplanetary voyages. What kind of convincing does it take to dupe your average email sender to engage in risky download behavior? Some scammers’ lists of lures include opportunities to profit off war, angry customer complaints, and even a free trip to theContinue reading “Watch out for weird phishing promises like free transit to Elon Musk’s off-world colonies”

You must be logged in to post a comment.