Cybersecurity Saturday

From the frontier AI / Project Glasswing front

  • Daniel Borish writes in LinkedIn,
    • Anthropic released its fourth threat intelligence report on September 10, 2026, covering activity its Threat Intelligence team disrupted between December 2025 and August 2026. The report documents cases across seven categories of harm: cyber operations, surveillance, influence operations, conventional weapons development, biological misuse, scams and fraud, and illicit distillation. The company assigns each disrupted actor an internal designator, a Generative Threat Group (GTG) number, and publishes case studies detailing how each group used Claude models, along with indicators of compromise for other defenders to act on.
    • “The report’s central claim is not that AI created new categories of attack. Credential theft, phishing, SQL injection, and unpatched edge devices remain the entry points they have always been. What changed is who can run these attacks at what speed. Anthropic’s investigators found a suspected Russian state espionage unit, a network of financially motivated ShinyHunters affiliates, Chinese university students moonlighting in exploit research, and a lone French hacktivist all using functionally similar AI-orchestrated methodologies to run multi-victim campaigns that would previously have required coordinated teams.”
  • The Wall Street Journal reports,
    • “Artificial intelligence agents being tested by OpenAI launched a cyberattack against a popular software service two months before they hacked the AI software company Hugging Face, a new signal of the potential for advanced AI tools to slip out of human control.
    • “The attack overwhelmed maintainers of an online service for coders, called RubyGems, and forced them to shut down new account registrations as they dealt with the chaos it had caused, operators of the service said.
    • “A coalition of AI researchers said it had unearthed evidence that OpenAI agents were behind the May attack and shared its findings with The Wall Street Journal and OpenAI. The AI developer on Friday confirmed that its agents had been involved in an incident involving RubyGems.
    • “Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information. We’ll continue to investigate as part of our broader review of agent activity during training and evaluation,” an OpenAI spokeswoman said in a statement.”
  • and
    • “An Anthropic researcher is quitting the artificial-intelligence industry over fears that the lab and its competitors are racing to build systems they won’t be able to control, a sign of mounting safety concerns within top AI companies.
    • “Jacob Coxon, a researcher who specializes in training new AI models by having them consume vast amounts of data, said Tuesday that he is leaving the company because he doesn’t want to participate in an industrywide rush to build AI systems that can improve themselves, worried such systems could spiral out of control and destroy humanity.
    • “The 27-year old Brit, who previously studied mathematics, said many of his industry colleagues now use phrases like “crunchtime” and “endgame” to describe the trajectory toward self-improving models.” * * *
    • “Anthropic didn’t immediately comment on the departure. Chief Executive Dario Amodei and other company leaders have repeatedly warned about the risks of rogue AI models, and urged the industry to slow development
    • “After Coxon announced his departure, a top scientist at the company, Evan Hubinger, wrote on X that he thought Coxon was correct about the risks of AI development.
    • “We really do earnestly believe AI could kill all humans! I personally think it is >10% within the next decade,” Hubinger wrote. “I believe Anthropic is trying its best, but we do not yet have a plan to solve alignment for superintelligence and are not clearly on track to.” Others also amplified the view.”
  • Per Axios: “Nvidia CEO Jensen Huang: AI fears designed to generate cybersecurity business.”
  • BigGo Finance lets us know,
    • “A bipartisan group of US senators is negotiating legislation that would create a legal duty of care for frontier AI developers, requiring them to prevent catastrophic risks and giving the federal government authority to block unsafe model releases. The proposal, led by John Thune, Ted Cruz and Amy Klobuchar, would apply to advanced models from companies such as OpenAI, Anthropic and Google, with national laboratory experts potentially conducting hands-on testing for nuclear, biological and cyber threats. Companies could appeal government blocking decisions in federal court. The measure would also preempt state AI safety laws. With the House in session only one week before the November 3 midterms, passage remains uncertain despite growing pressure on Congress to address frontier AI risks.”
  • Axios adds,
    • “A letter is circulating among House members urging Speaker Mike Johnson (R-La.) to bring back the House “immediately” and keep it in session until Congress passes AI safeguards, Axios has learned.”
  • The Wall Street Journal notes,
    • “President Trump, who has taken a light touch overseeing the sector, previously said he is in favor of kill switches and other steps to keep AI safe but has warned burdensome regulation could cost the U.S. in the tech race.”
  • and
    • “The leaders of three of the biggest AI companies agreed [September 12] that they needed to slow development of the technology before their advances create a menace that can’t be controlled.
    • “It was a rare display of unity by Elon MuskSam Altman and Dario Amodei, who have been spending tens of billions of dollars to develop evermore powerful artificial intelligence models. Altman even suggested that his company, OpenAI, may need to delay its much-anticipated IPO to focus on safety.”

From the cybersecurity policy and law enforcement front,

  • Per GovCIO Media,
    • “Federal agencies are looking to deepen their partnership with the private sector to protect critical infrastructure, with joint efforts to identify vulnerabilities, deploy technology and scale solutions.
    • “National Cyber Director Sean Cairncross said Thursday [September 10] at the Billington Cybersecurity Summit in Washington that government and industry need to work “hand in glove” rather than rely on compliance checklists as technology increasingly shapes both critical infrastructure and the threats against it.
    • “We’re in a moment technologically where security and innovation have melded, and in order to move forward, protect critical infrastructure, make sure the systems that our citizens rely on for daily life are protected and secure, we need a relationship that is hand in glove, and that means we cannot be dictating a compliance checklist to industry,” said Cairncross.”
  • Federal News Network reports,
    • “The FBI released its first agency-wide, unclassified cyber strategy on Wednesday, with the goal of unifying efforts across the bureau’s 56 field offices to counter both nation-state threats and cyber criminals.
    • “The 17-page strategy details a four-pillar approach to countering cyber threats across the bureau. Brett Leatherman, assistant director of the FBI’s Cyber Division, said previous cyber strategies for the bureau have either been classified or focused on specific threats, like countering China.
    • “This is a comprehensive strategy that directs our teams, our field offices, our global presence, and how we are to align all our efforts to counter this work,” Leatherman told reporters after speaking at the Billington Cybersecurity Summit in Washington on Wednesday morning [September 9].”
  • and
    • “The CIA is pushing to bring more scientific and technical expertise into its workforce, with a top official touting a big year for hiring despite widespread cuts across the intelligence community over the past year.
    • “Michael Ellis, the deputy director of the CIA, said the spy agency is seeking to recruit more employees with backgrounds in science and technology. Ellis described a STEM background as not a prerequisite for intelligence in work in 2026, but “it sure helps make things easier.”
    • “When I think about, you know, where we want the CIA workforce to be five years from now, it’s an elite workforce,” Ellis said at the Billington Cybersecurity Summit in Washington on Tuesday. “It’s a nimble workforce. It’s one that has more technical background than it has today, and it’s one that is motivated by mission.”
  • Cybersecurity Dive adds,
    • “As the federal government scrambles to protect its own networks and support critical infrastructure operators, CISA is preparing to bring in roughly 250 new employees to rebuild core teams.
    • “We’re looking forward to welcoming hundreds of new CISA employees in the very near future,” acting CISA Director Nick Andersen told reporters after a talk at the Billington Cybersecurity Summit here on Wednesday.
    • “The employees have received tentative job offers and are “waiting to get that official start date,” Andersen said during his speech.”
  • Cyberscoop points out,
    • “The private sector still isn’t sharing enough cyber information with the FBI in part because organizations are operating on false assumptions about what the bureau will do with what it collects, the FBI’s top cyber official said Wednesday.
    • “Brett Leatherman, assistant director of the FBI’s cyber division, said in remarks at the Billington CyberSecurity Summit and in a discussion with reporters that organizations stand to benefit from bringing in the bureau when it’s compromised by hackers from the People’s Republic of China (PRC) and others. But one of the “key misconceptions” is that “the FBI is somehow sharing information with regulators for regulatory purposes, and that’s not the case.”
    • “From my standpoint over the last few years, I think we’ve seen a hesitancy on some companies to engage [with the] FBI,” Leatherman said.”
  • and
    • “The U.S. government is accusing Chinese AI companies of engaging in a deliberate and “systematic” effort to illegally distill U.S. frontier AI models and their capabilities. 
    • “According to a joint cybersecurity advisory from the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI, the sheer scale of these efforts since 2024 indicate that distillation is a critical part of China’s AI industrial policy.
    • “China-based artificial intelligence companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy,” the agencies wrote. 
    • “The advisory names Chinese companies like DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, saying they spent billions of tokens across millions of exchanges and requests with frontier U.S. AI models like Anthropic’s Claude, OpenAI’s ChatGPT, Google Gemini, and xAI’s Grok, since at least late 2024.”
  • The Justice Department made available “Remarks by Deputy Assistant Attorney General Josh Goldfoot of the Justice Department’s Criminal Division at the International Symposium on Cybercrime Response” held in Seoul, Korea.
  • Beckers Health IT notes,
    • “A Ukrainian national who helped deploy Conti ransomware against more than 1,000 victims worldwide has been sentenced to four years in prison for conspiracy to commit wire fraud.
    • “Oleksii Oleksiyovych Lytvynenko, 44, formerly of Cork, Ireland, admitted to joining the Conti operation and coding a “loader” — malware used to deliver other malicious software onto compromised systems, according to a Sept. 10 U.S. Justice Department news release. He pleadedguilty June 10.
    • “Conti attacked computers and networks in 47 states, the District of Columbia, Puerto Rico and 31 countries between 2020 and 2022, and the FBI estimates the group collected more than $150 million in ransom payments. Evidence from Mr. Lytvynenko’s online accounts showed he possessed data stolen from eight U.S. victims and four overseas victims. He was arrested in County Cork, Ireland, in July 2023.”

From the cybersecurity breaches and vulnerabilities front,

  • HIPAA Journal released its June 2026 Healthcare Data Breach Report.
    • “In June 2026, 66 large healthcare data breaches – data breaches involving the protected health information of 500 or more individuals – were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) – a slight increase from the 64 data breaches reported in May. More than two large data breaches a day is the new normal. Over the past 12 months, an average of 65 large healthcare data breaches have been reported per day; eight years ago in 2018, large healthcare data breaches occurred at a rate of around one per day.”
  • Beckers Health IT reports,
    • “Houston-based Nutex Health says the hackers behind its August cyberattack have published the data they allegedly stole on their own website.
    • “The publicly traded micro-hospital operator is now downloading, processing and analyzing that data to determine its contents, scope and authenticity, according to a Sept. 10 SEC filing. Nutex said the review could take several weeks given the volume of data involved.” * * *
    • “Nutex said it has not identified any material impact on its business operations or financial reporting systems, and its materiality assessment from the Aug. 31 filing remains unchanged. The company said it continues to evaluate regulatory and legal notification requirements and intends to notify affected patients and employees.
    • “Several purported class action lawsuits have been filed against Nutex in the U.S. District Court for the Southern District of Texas’ Houston Division on behalf of individuals whose personal or health information was allegedly accessed. Nutex said it cannot predict the litigation’s outcome or its potential financial impact.”
  • and
    • “Annapolis, Md.-based Luminis Health’s phone system and MyChart patient portal remain unavailable as the health system continues responding to a cybersecurity incident involving an unauthorized criminal actor.
    • “In a Sept. 10 update, Luminis Health said its investigation is ongoing and teams are working with third-party experts to safely restore affected systems.
    • “The health system said its hospitals remain open and continue providing patient care.”
  • and
    • Recent cybersecurity warnings and incidents are highlighting risks for healthcare organizations that extend beyond ransomware, including cloud authorization abuse, voice phishing, brand impersonation, third-party access and publicly exposed information.
    • [The article describes] five recent cybersecurity developments Becker’s has reported on in September.]
  • Security Week adds,
    • “More than 4.1 million individuals had their personal, health, and insurance information stolen in a data breach at healthcare company AdaptHealth.
    • “Operating over 680 facilities across the US, AdaptHealth describes itself as a network of medical equipment companies that provides patients with healthcare solutions and medical equipment.
    • “The company was hacked in early June, when a threat actor gained access to its cloud-based applications, including internal systems used for patient management and document storage.
    • “After the attacker contacted the company, it confirmed the data breach, including the theft of a password file associated with insurance billing.
    • “The hacker used social engineering to compromise a user session at a third-party contractor, AdaptHealth said.”
  • and
    • “Future phishing campaigns may no longer involve a detectable physical web page.
    • “Barracuda has analyzed a new type of phishing campaign that adds both stealth and flexibility to traditional phishing. Rather than standard social engineering to persuade a target to visit a static compromised web page, this campaign generates a blob URL to render and deliver the phishing page inside the target’s own browser. This reduces the possibility of security scanners detecting either the social engineering email or the static residence of the phishing page.”
  • HIPAA Journal lets us know,
    • “Three high-severity vulnerabilities have been identified in NextGen Healthcare Mirth Connect (Mirth Connect), a cross-platform healthcare integration engine for connecting, routing, transforming, and exchanging clinical and administrative data between different healthcare systems. The vulnerabilities are due to improper neutralization of special elements used in SQL commands and improper restriction of XML External Entity Reference. Successful exploitation of the vulnerabilities could allow denial-of-service attacks and data exfiltration.
    • “The vulnerabilities were identified by security researcher Abhinav Agarwal using autonomous agents running his published methodology on AI-assisted vulnerability discovery. “Mirth Connect is effectively a switchboard between healthcare systems. It can sit between lab systems, imaging systems, databases, and clinical applications, so a vulnerability in the integration layer can expose much more than one isolated application,” Agarwal told The HIPAA Journal. A potential problem is that healthcare organizations may not know that they have a vulnerable component in one of their products. “A hospital may not see the name Mirth anywhere on the product it bought. Integration software can be managed, resold, or embedded inside another product, which is why SBOMs and exact version disclosure matter after vulnerabilities like these,” explained Agarwal.”
  • CISA added 14 known exploited vulnerabilities to its catalog this week.
    • September 8, 2026
      • CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
      • CVE-2026-81963 Microsoft Windows Link Following Vulnerability  
      • CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability 
      • CVE-2026-86218 N-able N-central Static Code Injection Vulnerability
        • SOC Prime discusses the Adobe KVE here.
        • The Hacker News discusses the Microsoft KVEs here.
        • Cybersecurity Dive discusses the N-able KVE here
    • September 9, 2026
      • CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
      • CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
      • CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability
      • CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability 
        • Security Week discusses the Fortinet KVE here.
        • Cybersecurity News discusses the Citrix KVE here.
        • SOC Prime discusses the Google KVE here.
        • The Cybersecurity Hub discusses the Cisco KVE here.
    • September 10, 2026
      • CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
      • CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
        • Bleeping Computer discusses these KVEs here.
    • September 11, 2026 (1)
      • CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability 
      • CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability 
      • CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
        • The Hacker News discusses the JFrog KVEs here.
        • Security Arsenal discusses the ConnectWise KVE here.
    • September 11, 2026 (2)
      • CVE-2026-85706. GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
        • Cyberscoop discusses this KVE here.
  • Dark Reading adds,
    • “A new analysis of public data from Anthropic’s Project Glasswing has highlighted a significant gap between the number of vulnerability findings generated by its Claude frontier model and those that ultimately prove to be real, serious, and worth fixing.
    • “The distinction matters because it suggests that the bottleneck in vulnerability research may increasingly lie in validating new flaws and coordinating their remediation rather than in discovering them.”
  • Security Week tells us,
    • “Anthropic disrupted a cyberespionage operation whose tradecraft and targeting match the Russian state-nexus group tracked as Midnight Blizzard, the company said in a threat intelligence report published this week. 
    • “The report covers activity the company identified and shut down between December 2025 and August 2026.
    • “According to Anthropic, Midnight Blizzard used Claude to monitor how well its malware evaded detection by security products. When a tool was flagged, AI agents automatically modified and rebuilt it, then redeployed it, repeating the process until the malware went undetected again.”

From the ransomware front,

  • The Hacker News reports,
    • “Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities.
    • “The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
    • “The second flaw under exploitation is CVE-2026-20316 (CVSS score: 5.3), which could allow an unauthenticated, remote attacker to log in to an affected device using a low-privilege account to access sensitive data within susceptible systems. It can be paired with other Cisco Secure FMC vulnerabilities to elevate privileges.” * * *
  • Cybersecurity Insiders relates,
    • “Ransomware attacks are becoming increasingly common, posing a serious threat to businesses across industries. A recent study conducted by Object First in collaboration with technology research firm Omdia highlights not only the growing frequency of these attacks, but also the increasing difficulty businesses face in recovering their data after an incident.
    • “According to the study, ransomware is having a significant impact on business operations. Over the past 24 months, around 84 percent of businesses surveyed admitted that file-encrypting malware had severely disrupted their operations. This represents a considerable increase from the previous year, when only 64 percent of businesses reported experiencing such disruption.
    • “The findings become even more concerning when it comes to data recovery. Only 39 percent of ransomware victims said they were able to recover at least 80 percent of their data following an attack. This is a sharp decline from the 57 percent reported the previous year. The figures indicate that businesses are not only encountering ransomware more frequently but are also finding it increasingly difficult to restore their systems and recover critical information.” * * *
    • “The decline in successful data recovery also highlights the importance of preparedness. Simply preventing an attack is no longer enough. Organizations need comprehensive backup and recovery strategies that can help them restore critical systems quickly in the event of a successful breach. Regularly tested backups, robust access controls, employee awareness training and well-defined incident-response plans can all play an important role in reducing the damage caused by ransomware.
    • “The latest findings suggest that ransomware has evolved into a broader business continuity challenge. As attacks become more frequent and sophisticated, organizations must focus equally on prevention, detection and recovery. Investing in resilient infrastructure and reliable data protection could prove crucial in ensuring that a ransomware incident does not turn into a prolonged business crisis.”
  • Help Net Security adds,
    • “In this Help Net Security video, Kerri Shafer-Page, VP of Incident Response at Arctic Wolf, walks through the ransomware decision tree in this video. She covers four areas where decisions need settling in advance, starting with containment.
    • “Someone has to know the network well enough to judge what pulling a system offline does to client data, a manufacturing line, or a website. Then comes the extortion demand. Who is authorized to negotiate, and what is the ceiling?
    • “Shafer-Page treats paying as a business decision, noting that a demand can cost less than an insurance retention and higher renewal rates. She argues law enforcement belongs in the playbook, since agencies may know the threat actor and can help you avoid sanctions problems.
    • “Communication matters too, from cyber legal counsel on disclosure deadlines to a spokesperson and a prepared help desk. Her advice: make these decisions on a Tuesday afternoon, not at 2 a.m. on a holiday weekend.”
  • and
    • “In this Help Net Security video, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, explains what happens behind the scenes during ransomware negotiations.
    • “Ross walks through the tactics groups use once an attack begins, from research on a victim’s revenue and insurance coverage to test decryptions that prove they hold a working key.
    • “He describes how demands are often set at roughly 1% to 5% of annual revenue, why deadlines move depending on how a victim responds, and how some groups split work between researchers, negotiators, and staff who apply public pressure.”

From the cybersecurity business and defenses front,

  • Cryptobriefing reports,
    • “Tenable Holdings is embedding Anthropic’s Claude Mythos 5 directly into its flagship cybersecurity product, betting that frontier AI models can fundamentally change how organizations spot and neutralize threats before attackers exploit them.
    • “The integration, announced on September 8, 2026, will bring AI-driven exposure analysis and attack-path discovery into the Tenable One Exposure Management Platform. The first concrete feature shipping under this effort is called Tenable One Adversary View, which uses Claude Mythos 5 to reconstruct how an attacker could move from an initial foothold all the way to an organization’s most critical systems.”
  • Per MedTech Dive,
    • “Boston Scientific disclosed Tuesday the cyberattack that recently hit the company is likely to affect third-quarter and full-year results.
    • “The medical device maker believes it is unlikely to meet net sales growth and adjusted earnings per share guidance ranges provided in July for the third quarter and full year, according to a new filing with the Securities and Exchange Commission.
    • “The Company anticipates recovering some portion of the impacted revenue as it continues to ramp operations globally, fulfill customer orders and reduce remaining backlogs, however the full impacts are not yet known,” Boston Scientific said in the filing.”
  • Cybersecurity Dive relates,
    • “After suffering a series of high-profile cyberattacks over the past decade, Microsoft says a new initiative to reinvigorate its security culture is bearing fruit.”
  • and
    • “Chief information security officers are largely expected to ensure the security of AI across the enterprise, but many say they are not receiving adequate support, according to findings from Proofpoint. 
    • “About 85% of CISOs said ensuring the safe use of AI assistants, copilots and automation is a top priority over the next two years, according to Proofpoint’s annual Voice of the CISO report. Eight of every 10 CISOs said they are expected to manage AI-related security risks without receiving a proportional increase in resources or expertise. 
    • “CISOs have a significant role to play in securing AI adoption, but they can’t own the risk alone,” Patrick Joyce, global resident CISO at Proofpoint, told Cybersecurity Dive. “AI is being adopted across the business, often faster than traditional governance models can keep up.”
  • and
    • “Advances in artificial intelligence aren’t changing the fact that simple cybersecurity failures remain the most consequential, government and industry leaders warned on Tuesday.
    • “What will prevent the attacks in the next 18 months are the same things that would have prevented the attacks of yesterday,” Jason Bilnoski, a deputy assistant director in the FBI’s Cyber Division, said during a panel here at the Billington Cybersecurity Summit.
    • “Core practices such as identity management, perimeter monitoring, cyber hygiene and strong multifactor authentication remain as essential as ever, Bilnoski said.
    • “Speed and capability is certainly increasing with the use of AI, but the end state is still the same,” he said. “How actors are compromising, whether it’s criminal or nation-state, still stays the same.”
  • HIPAA Journal tells us,
    • “The HHS has released an updated version of the Security Risk Assessment (SRA) Tool (v3.7). The tool is ideally suited for small- and medium-sized entities to guide them through the risk analysis process, help them identify risks and vulnerabilities to electronic protected health information (ePHI), and comply with the risk analysis implementation specification of the Security Management Process standard of the HIPAA Security Rule.”
  • CISA has released the 2026 edition of its Insider Threat Mitigation Guide.
    • “The Cybersecurity and Infrastructure Security Agency’s Insider Threat Mitigation Guide aids critical infrastructure stakeholders in comprehending the concept of insider threats, identifying the various forms these threats can take, and implementing best practices to establish or enhance an insider threat mitigation program. Such a program is essential for protecting critical assets, deterring violence, countering unintentional incidents, preventing loss of revenue or intellectual property, averting the compromise of sensitive data, and ultimately saving lives.”
  • Healthcare IT News informs us,
    • “Devices and sensors that collect heart rate and other health data and rely on applications to share information with third parties pose serious questions about data protection for patients and the health systems that care for them.
    • “While smart ring and watch data might help doctors treat patients, security experts say low security standards in consumer tech and improperly configured APIs present potential security risks for providers.
    • “Hackers can exploit such flaws, using consumer devices as entry points to breach receiving electronic health record systems and access centralized databases.
    • “To mitigate these threats, security experts say healthcare organizations must establish strict security protocols, including mandatory transit encryption, multi-factor authentication and account monitoring. They recommend zero-trust approaches to catch rogue traffic and implementation of rigorous engineering frameworks.”
  • Here’s a link to Dark Reading’s CISO Corner.

Leave a Reply

Your email address will not be published. Required fields are marked *