Monday report

Monday report

From Washington, DC,

  • The Hill reports,
    • “GOP lawmakers returning to Capitol Hill are facing a health care bind, with Affordable Care Act (ACA) subsidies having expired Dec. 31, and no clear path forward for extending them.
    • “The GOP remains split over whether to extend the subsidies at all. But last month, four Republican centrists, frustrated with party leadership, joined Democrats in backing a discharge petition on legislation to extend the subsidies for three years.
    • “Speaker Mike Johnson (R-La.) told reporters in December he plans to bringthe bill to the floor this week, according to CBS News. It is expected to pass and head to the Senate, where it will likely undergo bipartisan reform to get the necessary 60 votes to advance. 
    • “I think a straight-up extension is a waste of money,” Senate Majority Leader John Thune (R-S.D.) said before the recess. “But if there are reforms and both sides sit down and agree on what that looks like and then there’s a transition that gives people the option of putting money into a [health savings account] … then there could be a path forward.”
  • MedCity News tells us,
    • “According to one expert at Pitchbook, two core issues are likely to dominate healthcare reform discussions in 2026: rising costs and flaws in Medicare Advantage.
    • “Healthcare affordability remains a major systemic issue preventing millions of Americans from accessing care, and Medicare Advantage’s risk-adjustment system is “clearly broken,” creating incentives that pull excess money into the program, explained Brian Wright, lead analyst for healthcare research at Pitchbook.
    • “On the Affordable Care Act and commercial market side of things, reforms will probably aim to improve affordability and risk pooling, he said. With Medicaid eligibility pressures pushing providers to shift costs to commercial payers, Wright suggested that lawmakers may look for ways to make the commercial market function more effectively rather than serve as the system’s subsidizer.”
  • Politico adds,
    • “After a bruising clash last year, funding the government for the remainder of this fiscal year could prove to be the least contentious issue, if today offers any indication. In a bicameral breakthrough, top appropriators this morning released the text of the three-bill funding package to pass ahead of the Jan. 30 shutdown deadline, POLITICO’s Jennifer Scholtes and Meredith Lee Hill report. As GOP leaders start to whip votes, they’re planning to put the package to a vote in the House on Thursday.”
  • The Wall Street Journal points out,
    • “Democrats are increasingly wary of another government shutdown after a 43-day government-funding lapse last year.
    • “A shutdown last year backed by Democrats to force funding for enhanced Affordable Care Act coverage didn’t succeed.
    • “The Congressional Budget Office estimates that extending enhanced ACA benefits for three years would add $83 billion to the federal deficit.”
  • Per an HHS news release,
    • “Deputy Secretary of Health and Human Services Jim O’Neill, in his role as Acting Director of the Centers for Disease Control and Prevention (CDC), today signed a decision memorandum* [PDF, 894 KB] accepting recommendations from a comprehensive scientific assessment [PDF, 1.05 MB] of U.S. childhood immunization practices, following a directive from President Trump to review international best practices from peer, developed countries.”
  • A related HHS fact sheet explains
    • The updated CDC childhood immunization schedule:
      • Recommends all vaccines for which there is consensus among peer nations.
      • Allows for more flexibility and choice, with less coercion, by reassigning non-consensus vaccines to certain high-risk groups or populations and shared clinical decision-making.
      • Ensures that all the diseases covered by the previous immunization schedule will still be available to anyone who wants them through Affordable Care Act insurance plans and federal insurance programs, including Medicaid, the Children’s Health Insurance Program, and the Vaccines for Children program. Families will not have to purchase them out of pocket. Among peer nations, the U.S. will continue to offer the most childhood vaccines for free to those who want them.
      • Is accompanied by a strengthening of vaccine research through HHS’ commitment to double-blind placebo controlled randomized trials as well as more observational studies to evaluate long-term effects of individual vaccines and the vaccine schedule.

From the Food and Drug Administration front,

  • BioPharma Dive reports,
    • “Moderna has filed approval applications for a seasonal flu vaccine it expects to become a critical source of future revenue growth.
    • “The company on Monday said it submitted clearance requests with regulators in the U.S., Europe, Canada and Australia. Moderna is specifically seeking approvals to market the vaccine, dubbed mRNA-1010, for people at least 50 years of age. 
    • “If approved, this potential new product launch and geographic expansion represent an important opportunity to support Moderna’s continued growth in 2027 and beyond,” said Moderna CEO Stéphane Bancel, in a statement.” 
  • Beckers Hospital Review adds,
    • “Axsome Therapeutics received FDA acceptance and priority review designation for its supplemental new drug application for AXS-05, a treatment for agitation associated with Alzheimer’s disease.
    • “The FDA set a Prescription Drug User Fee Act action date of April 30, 2026. AXS-05 is a combination of dextromethorphan hydrobromide and bupropion hydrochloride.
    • “Agitation affects up to 76% of individuals with Alzheimer’s disease, and there are currently few approved treatment options, according to a Dec. 31 news release. The application is supported by data from four randomized, double-blind, controlled phase 3 trials and a long-term safety study.”
  • Fierce Pharma recounts the FDA’s new drug approvals issued in 2025.
    • “There were 46 novel drug approvals in 2025, compared to 55 in 2023 and 50 in 2024. Meanwhile, the FDA’s Center for Biologics Evaluation and Research endorsed 18 new biological treatments in 2025, compared to 25 in 2023 and 18 in 2024.
    • “The surge in December included seven novel approvals, which was the most in any month of 2025. There also were many more novel approvals (30) in the second half of 2025 than in the first half (16), indicating that the U.S. regulator functioned more efficiently as it gained stability through the year.”

From the judicial front,

  • Bloomberg Law offers more details on the Human Rights Campaign’s complaint filed against OPM with the EEOC.
    • Four federal employees represented by the Human Rights Campaign filed a class action discrimination claim against the Trump administration over its near-total ban on gender-affirming care in federal health plans.
    • The notice filed Jan. 1 with the Office of Personnel Management initiates legal proceedings with an Equal Employment Opportunity counselor—who oversees potential resolutions through informal or formal arbitration—and predates a formal complaint with OPM.
  • Bloomberg Law also reports,
    • “A California law imposing fiduciary duties on pharmacy benefit managers intrudes on federally regulated health insurance plans, the Pharmaceutical Care Management Association said in a lawsuit filed Friday [January 2, 2026, in the U.S. District Court for the Central District of California, No. 2:26-cv-00012].
    • “California’s SB 41 requires PBMs—which oversee prescription drugs for health plans—to act in their clients’ interests and disclose all commissions and conflicts of interest. The law was enacted in October 2025 and applies to self-insured employer plans, which are regulated under the federal Employee Retirement Income Security Act.
    • “PCMA’s lawsuit is the latest salvo in an ongoing battle with state governments, which have enacted a range of laws attempting to curb what they say are abusive business practices. Employers are under fire in federal court over drug prices under their PBM contracts, while Congress and the Trump administration take aim at PBM tactics they say increase drug costs for plans and patients.
    • “California’s law is preempted by ERISA because it affects who is considered a plan fiduciary, which is the “first and most fundamental design decision,” PCMA wrote in its complaint filed in the US District Court for the Central District of California.”

From the public health and medical / Rx research front,

  • The New York Times reports,
    • “In 2000, a landmark study claimed to set the record straight on glyphosate, a contentious weedkiller used on hundreds of millions of acres of farmland. The paper found that the chemical, the active ingredient in Roundup, wasn’t a human health risk despite evidence of a cancer link.
    • “Last month, the study was retracted by the scientific journal that published it a quarter century ago, setting off a crisis of confidence in the science behind a weedkiller that has become the backbone of American food production. It is used on soybeans, corn and wheat, on specialty crops like almonds, and on cotton and in home gardens.
    • “The Environmental Protection Agency still considers the herbicide to be safe. But the federal government faces a deadline in 2026 to re-examine glyphosate’s safety after legal action brought by environmental, food-safety and farmworker advocacy groups.
    • “The E.P.A. has also faced pressure to act on glyphosate from the Make America Healthy Again movement, led by supporters of the health secretary, Robert F. Kennedy Jr., who once served as co-counsel in a lawsuit against Monsanto over exposure to Roundup.”
  • Health Day informs us,
    • “Sleep problems might be an early warning sign of dementia, a new study says.
    • “Circadian rhythms that are weaker and more fragmented are tied to an increased risk of dementia, researchers reported Dec. 29 in the journal Neurology.
    • “In fact, people with weak circadian rhythms have a more than doubled risk of dementia, results showed.
    • “Changes in circadian rhythms happen with aging, and evidence suggests that circadian rhythm disturbances may be a risk factor for neurodegenerative diseases like dementia,” said lead researcher Wendy Wang, an assistant professor of epidemiology and internal medicine at UT Southwestern Medical Center in Dallas.”
  • MedPage Today points out,
    • “Melatonin prescribing for young children appears to have been on the rise globally in recent years, despite a dearth of efficacy data for kids with typical development, a systematic review suggested.
    • “There was evidence for improved sleep onset with melatonin use in young children with neurological conditions, such as autism spectrum disorder.
    • “Data on long-term outcomes for other behaviors and health impacts were lacking.”
  • The American Medical Association lets us know “what doctors wish patients knew about ankle sprains and strains.
  • BioPharma Dive calls attention to “10 clinical trials to watch in the first half of 2026. After a lengthy downturn, the biotech industry finally gathered momentum in 2025. Key readouts in obesity, infectious disease and many rare conditions could help it continue.”

From the U.S. healthcare business and artificial intelligence front,

  • The Washington Post reports,
    • “Novo Nordisk launched the first GLP-1 weight-loss pill Monday with a pledge that manufacturing investments will enable the drugmaker to avoid the type of shortages that plagued the rollout of its injectable version.
    • “The company said doctors can now prescribe the new oral version of Wegovy and patients can pick it up at more than 70,000 pharmacies and via mail-order services throughout the country.
    • “The starting dose of the once-daily pill costs $150 a month for patients without insurance coverage, while the largest dose — on which patients lose the most weight — will be available by the end of the week for $300 a month. For those with employer insurance coverage, the company says it will cost as little as $25 a month.
    • “By introducing the semaglutide-based tablet, the Danish drugmaker is aiming to avoid a pitfall that has cut into sales of its two leading injectable drugs, Ozempic and Wegovy: churning out enough of the medicine to keep up with patient demand. Novo Nordisk executives say they are confident they’ll have enough pills, pointing to the scale of the launch: The pill will be available in pharmacies like CVS and Costco, on telehealth platforms that have partnered with the company, and on Novo Nordisk’s own direct-to-consumer service.”
  • Modern Healthcare relates,
    • “Corewell Health and independent laboratory company Quest Diagnostics have completed their agreement to form a joint venture providing laboratory services. 
    • “The venture, Diagnostic Lab of Michigan will be based at the Corewell Health Southfield Center in Southfield, Michigan. The facility is slated to open in the first quarter of 2027. 
    • “Quest Diagnostics owns 51% of Diagnostic Lab of Michigan and Corewell, which has dual headquarters in Southfield and Grand Rapids Michigan, owns 49%, according to a Monday news release. Further financial terms were not disclosed.” 
  • The Wall Street Journal tells us,
    • “Health systems are increasingly adopting AI, with 27% paying for commercial AI licenses, triple the rate across the U.S. economy.
    • “AI tools have significantly reduced report-writing time for radiologists and cut staff time on denied insurance claims by as much as 23%.
    • “Despite efficiency gains, AI can produce fabricated information.”
  • Beckers Health IT adds,
    • More than 40 million Americans use ChatGPT daily to ask questions about healthcare, according to a new report from OpenAI that highlights how patients and clinicians are increasingly turning to AI to navigate a complex and strained U.S. healthcare system.
    • The report, AI as a Healthcare Ally: How Americans Are Navigating the System With ChatGPT, was shared with Becker’s by an OpenAI spokesperson. It is based on anonymized ChatGPT message data and OpenAI-led research.
    • The article offers eight findings from the OpenAI report.
  • Per Beckers Hospital Review,
    • “Nashville, Tenn.-based HCA Healthcare is facing resistance to its expansion efforts across multiple states, as competing health systems challenge the for-profit giant’s push to add new emergency rooms, surgery centers and hospitals in regions where it already has a presence.”
  • and
    • “Patients in Washington, D.C., had the highest median time spent in the emergency department, while patients in North Dakota had the lowest, CMS data shows.
    • “The agency’s “Timely and Effective Care” dataset, updated Nov. 26, tracks the average median time patients spend in the emergency department before leaving. The measures apply to children and adults treated at hospitals paid under the Inpatient Prospective Payment System or the Outpatient Prospective Payment System, as well as those that voluntarily report data on relevant measures for Medicare patients, Medicare managed care patients and non-Medicare patients.” 

Cybersecurity Saturday

Happy New Year!

From the cybersecurity policy and law enforcement front,

  • Federal News Network points out five things to watch in cybersecurity policy at the federal level during 2026.
    • “New national cyber strategy”
    • “AI and cyber”
    • “CISA 2015 reauthorization”
    • “CIRCIA rule” and
    • “Cyber leader gaps”
  • Security Week reports,
    • “Two cybersecurity professionals from the United States have pleaded guilty to charges related to their role in BlackCat/Alphv ransomware attacks, the Justice Department announced this week [December 30].
    • “Three individuals were charged in October for allegedly conducting ransomware attacks against several US-based companies. Two of the suspects, 36-year-old Kevin Martin from Texas and an unnamed individual, were employed as ransomware negotiators at threat intelligence and incident response firm DigitalMint.
    • “The third suspect, 40-year-old Ryan Goldberg from Georgia, worked as an incident response manager at cybersecurity company Sygnia.
    • “The three are accused of hacking into the systems of several companies, stealing valuable information, and deploying BlackCat ransomware. 
    • “Based on the Justice Department’s description of the scheme, the suspects were BlackCat ransomware affiliates, paying 20% of the ransoms they received from victims to the administrators of the ransomware operation in exchange for access to the file-encrypting malware and a platform designed for managing extortions.”

From the cybersecurity breaches and vulnerabilities front,

  • Bleeping Computer points out the 15 biggest cybersecurity and cyber attack stories of 2025.
  • Security Week adds,
    • “Insurance giant Aflac is notifying roughly 22.65 million people that their personal information was stolen from its systems in June 2025.
    • “The company disclosed the intrusion on June 20, saying it had identified suspicious activity on its network in the US on June 12 and blaming it on a sophisticated cybercrime group.
    • “The company said it immediately contained the attack and engaged with third-party cybersecurity experts to help with incident response. Aflac’s operations were not affected, as file-encrypting ransomware was not deployed.
    • “Just before Christmas, the Columbus, Georgia-based company announced it had completed its investigation into the potentially compromised data and had started notifying the affected individuals.
    • “Based on our review of potentially impacted files, we have determined personal information associated with approximately 22.65 million individuals was involved,” the company said.
    • “The compromised information, the insurance giant says, includes names, addresses, Social Security numbers, dates of birth, driver’s license numbers, government ID numbers, medical and health insurance information, and other data.”
  • The Cybersecurity and Infrastructure Security Agency (CISA) added one known exploited vulnerability to its catalog this week.
  • Bleeping Computer informs us,
    • “IBM urged customers to patch a critical authentication bypass vulnerability in its API Connect enterprise platform that could allow attackers to access apps remotely.
    • “API Connect is an application programming interface (API) gateway that enables organizations to develop, test, and manage APIs and provide controlled access to internal services for applications, business partners, and external developers.
    • “Available in on-premises, cloud, or hybrid deployments, API Connect is used by hundreds of companies in banking, healthcare, retail, and telecommunications sectors.
    • “Tracked as CVE-2025-13915 and rated 9.8/10 in severity, this authentication bypass security flaw affects IBM API Connect versions 10.0.11.0 and 10.0.8.0 through 10.0.8.5.
    • “Successful exploitation enables unauthenticated threat actors to remotely access exposed applications by circumventing authentication in low-complexity attacks that don’t require user interaction.”
  • and
    • “Over 10,000 Fortinet firewalls are still exposed online and vulnerable to ongoing attacks exploiting a five-year-old critical two-factor authentication (2FA) bypass vulnerability.
    • “Fortinet released FortiOS versions 6.4.1, 6.2.4, and 6.0.10 in July 2020 to address this flaw (tracked as CVE-2020-12812) and advised admins who couldn’t immediately patch to turn off username-case-sensitivity to block 2FA bypass attempts targeting their devices.
    • “This improper authentication security flaw (rated 9.8/10 in severity) was found in FortiGate SSL VPN and allows attackers to log in to unpatched firewalls without being prompted for the second factor of authentication (FortiToken) when the username’s case is changed.
    • “Last week, Fortinet warned customers that attackers are still exploiting CVE-2020-12812, targeting firewalls with vulnerable configurations that require LDAP (Lightweight Directory Access Protocol) to be enabled.
    • “Fortinet has observed recent abuse of the July 2020 vulnerability FG-IR-19-283 / CVE-2020-12812 in the wild based on specific configurations,” the company said.”
  • and
    • “Trust Wallet believes the compromise of its web browser to steal roughly $8.5 million from over 2,500 crypto wallets is likely related to an “industry-wide” Sha1-Hulud attack in November.
    • “Trust Wallet, a crypto wallet used by over 200 million people, enables users to store, send, and receive Bitcoin, Ethereum, Solana, and thousands of other cryptocurrencies and digital tokens via a web browser extension and free mobile apps.
    • “As BleepingComputer previously reported, this December 24th incident resulted in the theft of millions of dollars in cryptocurrency from the compromised wallets of Trust Wallet users.
    • This happened after attackers added a malicious JavaScript file to version 2.68.0 of Trust Wallet’s Chrome extension, which stole sensitive wallet data and enabled threat actors to execute unauthorized transactions.
    • “Our Developer GitHub secrets were exposed in the attack, which gave the attacker access to our browser extension source code and the Chrome Web Store (CWS) API key,” the company said in a Tuesday [December 30] update.
  • and
    • “A fourth wave of the “GlassWorm” campaign is targeting macOS developers with malicious VSCode/OpenVSX extensions that deliver trojanized versions of crypto wallet applications.
    • “Extensions in the OpenVSX registry and the Microsoft Visual Studio Marketplace expand the capabilities of a VS Code-compatible editor by adding features and productivity enhancements in the form of development tools, language support, or themes.
    • “The Microsoft marketplace is the official extension store for Visual Studio Code, whereas OpenVSX serves as an open, vendor-neutral alternative, primarily used by editors that do not support or choose not to rely on Microsoft’s proprietary marketplace.”
    • “The GlassWorm malware first appeared on the marketplaces in October, hidden inside malicious extensions using “invisible” Unicode characters.”
    • “Once installed, the malware attempted to steal credentials for GitHub, npm, and OpenVSX accounts, as well as cryptocurrency wallet data from multiple extensions. Additionally, it supported remote access through VNC and can route traffic through the victim’s machine via a SOCKS proxy.
    • “Despite the public exposure and increased defenses, GlassWorm returned in early November on OpenVSX and then again in early December on VSCode.”

From the ransomware front,

  • Cybersecurity Insiders recounts the top ransomware attacks of 2025.
  • SC Media tells us,
    • HackRead reports that U.S. automaker Chrysler had over 1 TB of data, including more than 105 GB of Salesforce-related information, claimed to have been exfiltrated by the Everest ransomware gang.
    • “Allegedly included in the stolen data trove spanning between 2021 and 2025 were personal and operational records from customers, internal agents, and dealers, with screenshots revealing internal spreadsheets, structured databases, CRM exports, and directory trees, as well as customer interaction logs with names, physical and email addresses, phone numbers, vehicle details, recall case notes, and call outcomes.” * * *
    • “Everest has warned that it would release not only the entire dataset but also customer service-related audio recordings purportedly stolen from Chrysler should it refuse to fulfill its demands.”
  • Morphisec points out,
    • “In Morphisec’s recent CTO Briefing: The State of Ransomware, CTO Michael Gorelik highlighted one of the most significant and troubling shifts in the ransomware landscape: many ransomware attacks no longer involve encryption at all.   
    • “Instead, attackers quietly steal sensitive data—sometimes over weeks or months—and then extort victims long after the breach. This “ransomware without encryption” model is growing rapidly because it has lower risk for attackers, harder for defenders to detect, and nearly impossible for victims to investigate once logs have aged out.”  

From the cybersecurity defenses front,

  • Dark Reading calls attention to
    • “Cybersecurity Predictions for 2026: Navigating the Future of Digital Threats. Cybersecurity experts discuss 2026 predictions, highlighting the rise of AI-driven threats, the shift to resilience over prevention, and the urgent need for advanced security measures to combat evolving risks”
  • and
    • “5 Threats That Defined Security in 2025. 2025 included a number of monumental threats, from global nation-state attacks to a critical vulnerability under widespread exploitation.”
      • “Salt Typhoon continues its onslaught”
      • “CISA see big layoffs and budget cuts”
      • “React2Shell carries echos of Log4Shell.
      • “Shai-Hulud opens floodgates on self-propagating Open Source Malware.” and
      • “Threat Campaigns Target Salesforce Customers.”
  • and
    • “The Ivanti Endpoint Manager Mobile (EPMM) zero-day attacks, which began last spring and lasted well into the summer as attackers took advantage of patching lag, were one of the top cyber-stories of 2025, sending thousands of victims to the depths of the data exfiltration sea. A recent deep-dive into the wreckage of those attacks highlights the risk inherent in buggy endpoint management systems — a concern that needs to be a higher priority than it typically is, one researcher argues.”
  • SC Media notes,
    • “A whopping 99% of security leaders plan to increase their cybersecurity budgets over the next two to three years, signaling that cybersecurity has become a critical business imperative, according to a KPMG Cybersecurity Survey released earlier this month.
    • “KPMG’s survey, which polled more than 300 C-suite and senior security leaders, found that the projected spending increases come at a time when 83% of organizations report a rise in cyberattacks, which include everything from phishing and ransomware to more advanced AI-powered social-engineering schemes.
    • “The data doesn’t just point to steady growth, it signals a potential boom,” said Michael Isensee, cybersecurity and tech risk leader, KPMG LLP. “We’re seeing a major market pivot where cybersecurity is now a fundamental driver of business strategy.
    • “Leaders are moving beyond reactive defense and are actively investing to build a security posture that can withstand future shocks, especially from AI and other emerging technologies,” continued Isensee. “This isn’t just about spending more, it’s about strategic investment in resilience.”
  • Security Affairs warns,
    • “Your next breach probably won’t start inside your network—it will start with someone you trust. Every supplier, contractor, and service provider needs access to your systems to keep business running, yet each login is a potential doorway for attackers. Access management is meant to control the risks of granting that access, but weak controls and poor hygiene remain the norm. The Thales Digital Trust Index report, Third-Party Edition, highlights that over half of surveyed professionals (51%) keep access to partner systems for days or even a month after they no longer need it, turning everyday collaborations into hidden vulnerabilities that accumulate over time.
    • “Ask yourself: Are you evaluating and managing these risks well enough? If the answer isn’t clear, it’s time to revisit the basics of identity lifecycle management. Supply chain risks are preventable—but only if they aren’t tolerated or ignored. This article is a primer on how to ensure B2B collaboration remains a source of agility and resilience, not your Achilles’ heel.”
  • Here is a link to Dark Reading’s CISO Corner.

Cybersecurity Saturday

From the cybersecurity law enforcement front,

From the cybersecurity policy and law enforcement front,

  • Cyberscoop reports,
    • “The National Institute of Standards and Technology announced that it will partner with The MITRE Corporation on a $20 million project to stand up two new research centers focused on artificial intelligence, including how the technology may impact cybersecurity for U.S. critical infrastructure.
    • “On Monday [December 22], the agency said one center will focus on advanced manufacturing while the second — the AI Economic Security Center to Secure U.S. Critical Infrastructure from Cyberthreats — will focus more directly on how industries that provide water, electricity, internet and other essential services can protect and maintain services in the face of AI-enabled threats. According to NIST, the centers will “drive the development and adoption” of AI-driven tools, including agentic AI solutions.
    • “The centers will develop the technology evaluations and advancements that are necessary to effectively protect U.S. dominance in AI innovation, address threats from adversaries’ use of AI, and reduce risks from reliance on insecure AI,” spokesperson Jennifer Huergo wrote in an agency release.
  • Federal News Network interviewed “a panel of former federal executives for their opinions about 2025 and what federal IT and acquisition storylines stood out over the last 12 months.”
  • Security Week tells us,
    • “The US Justice Department announced on Monday [December 22] the seizure of a web domain and a password database used by a cybercrime group to steal millions of dollars from bank accounts.
    • “According to the DOJ, the seized domain, web3adspanels.org, hosted a backend web panel used by the cybercriminals to store and manipulate thousands of stolen bank login credentials.
    • The threat actor conducted a massive bank account takeover scheme that involved malicious ads on search engines such as Google and Bing in an effort to lure users to fake bank websites.
    • “These phishing sites tricked victims into handing over their login credentials, which the cybercriminals could then use to access and drain their bank accounts.
    • “The FBI has identified nearly 20 victims in the US, including two companies, and has determined that the cybercriminals attempted to steal roughly $28 million, with the actual losses estimated at approximately $14.6 million.” 
  • Bleeping Computer informs us,
    • “An Interpol-coordinated initiative called Operation Sentinel led to the arrest of 574 individuals and the recovery of $3 million linked to business email compromise, extortion, and ransomware incidents.
    • “Between October 27 and November 27, the investigation, which involved law enforcement in 19 countries, took down more than 6,000 malicious links and decrypted six distinct ransomware variants.
    • “Interpol says that the cybercrime cases investigated are connected to more than $21 million in financial losses.”

From the cybersecurity breaches and vulnerabilities front,

  • Cybersecurity Dive reports,
    • “WatchGuard warns that a critical vulnerability in its Firebox devices is facing exploitation as part of a campaign targeting edge devices, according to an advisory from the company
    • “The flaw, tracked as CVE-2025-14733, involves an out-of-bounds write vulnerability in the Fireware OS internet key exchange daemon process. An unauthenticated attacker can achieve remote code execution. 
    • “WatchGuard said it discovered the flaw through an internal process and issued a patch on Thursday. 
    • “Since the fix became available, our partners and end users have been actively patching affected Firebox appliances,” a WatchGuard spokesperson told Cybersecurity Dive. “We continue to strongly encourage timely patching as a core best practice in security hygiene.”
  • Security Week shares information about the Watchguard patch.
  • Dark Reading points out,
    • “Much has been said about IT worker scams in the last few years, but it’s not every day that we get a glimpse into how pervasive the issue has become. 
    • “Stephen Schmidt, senior vice president and chief security officer at Amazon, wrote on LinkedIn over the weekend that the company has prevented “more than 1,800 suspected DPRK operatives from joining [Amazon] since April 2024, and we’ve detected 27% more DPRK-affiliated applications quarter-over-quarter this year.” 
    • “IT worker scams involve operatives working as part of or on behalf of a government try to gain remote IT employment. It is most often associated with North Korea (DPRK), but that’s not the only entity engaging in this practice. While one primary goal may be the worker gaining a foothold in a network for espionage purposes or for sensitive IP theft (and these things do happen), Schmidt, who wrote about North Korean worker scams specifically, highlighted another reason: “Their objective is typically straightforward: get hired, get paid, and funnel wages back to fund the regime’s weapons programs,” he wrote.
  • The Wall Street Journal relates,
    • “AI is making cybercriminals more efficient, enabling them to scale up operations and create more targeted and convincing scams.
    • “Thanks to AI, criminals are getting better at finding targets—for example, by scanning social media to identify people going through big life changes.
    • “Most experts don’t think fully autonomous AI cyberattacks are possible yet in the real world, but research has shown that AI is capable of planning and carrying out an attack on its own in a lab.”
  •  Per SC Media,
    • “A series of campaigns were observed targeting the financial sector across multiple continents worldwide — attacks that exhibited the tradecraft of North Korean-affiliated threat actors.
    • “In a Dec. 18 white paper, Darktrace researchers said the attacks leveraged advanced social engineering focused on job hunters, spear-phishing, React2Shell exploitation, and a new Beavertail malware variant.
    • “While the initial access vector remains unknown, Darktrace said evidence suggests it originated from a malicious npm package hosted on GitHub or GitLab — behavior that aligns with the Lazarus Group’s history of exploiting supply-chain vulnerabilities.
    • “According to Darktrace, the attackers used Beavertail for initial credential theft, followed by heavily obfuscated Python scripts and Tsunami modules, hallmarks of a “well-resourced adversary.”
  • Cyber Insider adds,
    • “A malicious NPM package masquerading as a WhatsApp API library has been discovered exfiltrating users’ messages, credentials, contacts, and media, all while delivering fully functional code.
    • “The package, named lotusbail, had been available on the NPM registry for over six months, amassing more than 56,000 downloads before its true purpose came to light.
    • “The discovery was made by Koi Security, whose researchers published a detailed technical report over the weekend, outlining the package’s behavior. The threat actor behind lotusbail cloned the legitimate @whiskeysockets/baileys WhatsApp Web API library and inserted advanced malware designed to siphon off sensitive user data during normal operation.”

From the ransomware front,

  • Cybersecurity Dive reports,
    • A Cybersecurity and Infrastructure Security Agency program that warns organizations about imminent ransomware attacks has suffered a major setback after its lead staffer left the agency rather than take a forced reassignment.
    • David Stern, the driving force behind CISA’s Pre-Ransomware Notification Initiative (PRNI) — through which the agency alerts organizations that ransomware actors are preparing to encrypt or steal their data — resigned on Dec. 19, according to four people familiar with the matter. The Department of Homeland Security had ordered Stern to take a job at the Federal Emergency Management Agency in Boston or quit, and Stern chose the latter, three of the people said. * * *
    • “The fate of the warning initiative is now unclear. In a statement, CISA Director of Public Affairs Marci McCarthy said the program “has not stopped and continues to operate as a key element in CISA’s efforts to defeat ransomware attacks.” One person familiar with the matter said the agency is preparing several staffers to take over for Stern. But others said the program relied heavily on Stern’s trusted relationships with the organizations that alert CISA to pending ransomware attacks.”
  • InfoSecurity Magazine explores this year’s top ransomware trends.
  • The HIPAA Journal tells us,
    • “Madison, WI-based ARC Community Services, a provider of behavioral health, substance use disorder treatment, and support services to women and children, has experienced a ransomware attack involving the theft of sensitive data from its network.” The attack occurred in November 2024.
  • CSO informs us,
    • “A recent upgrade to the RansomHouse ransomware operation has added new concerns for enterprise defenders, introducing a multi-layered encryption update to the group’s double-extortion RaaS model.
    • “Also tracked under the cluster Jolly Scorpius, the ransomware gang has transitioned from a simple, single-phase encryption routine to a multi-layered dual-key encryption architecture that increases the complexity of its extortion operations.
    • “Detailed by Palo Alto Networks’ threat intelligence team, the update raises the bar for recovery once systems are compromised. The change affects how files are processed and encrypted during an attack, complicating analysis and limiting defenders’ ability to recover data without paying a ransom.”

From the cybersecurity business and defenses front,

  • The Wall Street Journal reports,
    • Artificial-intelligence software company ServiceNow NOW agreed to acquire cybersecurity startup Armis for about $7.75 billion in cash in a move intended to take advantage of growing demand for AI security.
    • Armis recently raised $435 million in a funding round that valued the company at $6.1 billion, and it had been planning for an initial public offering at the end of 2026 or early 2027.
    • ServiceNow said on Tuesday that the acquisition would triple its market opportunity for security and risk solutions and entrench its position in the market for securing AI technology.
    • The increasing integration of AI tools into business workflows has raised worries that companies could become more vulnerable to cyberattacks and hacks.
  • Cyberscoop lets us know,
    • “How to determine if agentic AI browsers are safe enough for your enterprise. Automation is transforming web browsing, enabling AI agents to perform tasks once handled by humans. Yet with greater convenience comes a complex security landscape that enterprises can’t afford to ignore.”
  • Federal News Network discusses “The next cyber battlefield: Preparing federal networks for autonomous malware.”
    • “Recent research from Google’s Threat Intelligence Group has drawn new attention to a long-standing question in cybersecurity: How close are we to malware that can truly think and adapt on its own?
    • “Earlier this month, Google disclosed five experimental code families, including PROMPTFLUX and PROMPTSTEAL, that used large language models (LLMs) during execution to generate commands, rewrite portions of their own code, and adapt to their environment.
    • “While these findings are concerning, it’s important to note that “autonomous” malware is still in the early stages. But that’s precisely the point. Even in this primitive form, these early samples show how the threat landscape is rapidly evolving. Federal agencies now have a narrow window to prepare before those capabilities mature into operational threats.
    • “Autonomous malware represents a fundamental shift in cybersecurity, as this malicious code can reason about its surroundings, make tactical decisions, and evolve its behavior in real time. For federal networks built on complex systems and strict change-control policies, that evolution could eventually collapse traditional defense timelines and upend response models.”
  • Per a CISA news release,
    • “NIST and CISA’s draft Interagency Report Protecting Tokens and Assertions from Forgery, Theft, and Misuse is now available for public comment through January 30, 2026. This report is in response to Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity and Amending Executive Order 13694 and Executive Order 14144, providing implementation guidance to help federal agencies and cloud service providers (CSPs) protect identity tokens and assertions from forgery, theft, and misuse.
    • “This report emphasizes the need for CSPs and cloud consumers, including government agencies, to better define their respective roles and responsibilities in managing identity and access management (IAM) controls in cloud environments. It establishes principles for both CSPs and cloud consumers, calling on CSPs to apply Secure by Designbest practices, and to prioritize transparency, configurability, and interoperability—empowering cloud consumers to better defend their diverse environments. It also calls upon government agencies to understand the architecture and deployment models of their procured CSPs to ensure proper alignment with risk posture and threat environment. 
    • “Comments on the report may be submitted to iam@list.nist.gov. Please visit NIST’s site for more information.” 
  • Per Dark Reading,
    • “As More Coders Adopt AI Agents, Security Pitfalls Lurk in 2026. Developers are leaning more heavily on AI for code generation, but in 2026, the development pipeline and security need to be prioritized.”
  • Here is a link to Dark Reading’s CISO Corner.

Monday report

From Washington, DC,

  • OPM’s leadership posted an end of the year letter to OPM employees.
  • STAT News reports,
    • “Drug manufacturers and pharmacy benefit managers received a holiday gift from President Trump on Friday: They still will not have to publicly post the actual prices of prescription drugs, more than five years after federal law required them to do so.
    • “Net drug prices — the amounts that health insurance companies and PBMs pay to drugmakers, after factoring in rebates — are highly valuable data that undergird the entire economic foundation of the U.S. pharmaceutical industry. But the decision from the Trump administration, rolled out in a new proposed rule, means that drug pricing data will likely remain locked out of public view for the foreseeable future.”
  • Avalere Health shares its perspective about December 2025 Advisory Committee on Immunization Practices Insights and 2026 Emerging Priorities.
    • “The ACIP’s December meeting resulted in a key change to the pediatric immunization schedule and signaled several potential changes to US vaccine coverage and access in 2026.”
  • Per an HHS news release,
    • “Executing on President Trump’s Executive Order (EO) 14192 titled “Unleashing Prosperity through Deregulation” and the President’s mandate to ensure the United States’ continued leadership in artificial intelligence (AI), the U.S. Department of Health and Human Services (HHS), through the Assistant Secretary for Technology Policy/Office of the National Coordinator for Health Information Technology (ASTP/ONC), today released the Health Data, Technology, and Interoperability: ASTP/ONC Deregulatory Actions to Unleash Prosperity (HTI-5) Proposed Rule.
    • “Today’s HTI-5 Proposed Rule has three core goals: (1) reducing burden on health IT developers by streamlining ASTP/ONC’s voluntary Health IT Certification Program by removing redundant requirements; (2) updating the information blocking regulations to better promote electronic health information access, exchange, and use so that patients’ access to their data is not blocked; and (3) advancing a new foundation of Fast Healthcare Interoperability Resources (FHIR®)-based application programming interfaces (APIs) that promote AI-enabled interoperability solutions through modernized standards and certification. The HTI-5 proposed rule is expected to save $1.53 billion in total, including $650 million over the next five years for health IT developers, providers, and other stakeholders.
    • “The HTI-5 proposed rule delivers on President Trump’s directive to reduce regulatory burden and to enable American innovation through artificial intelligence,” said Tom Keane, MD, Assistant Secretary for Technology Policy and National Coordinator for Health IT. “These proposals reflect a commonsense approach that removes redundant requirements on health IT developers, that better ensures seamless patient access to their information and that sets a foundation for AI-based data exchange.” * * *
    • “More information can be found at healthit.gov/hti5 and via ASTP/ONC’s X account, @HHS_TechPolicy
    • “ASTP/ONC is also withdrawing certain proposals not yet finalized from the HTI-2 proposed rule.”

From the Food and Drug Administration front,

  • The Wall Street Journal reports,
    • “U.S. regulators approved the first GLP-1 weight-loss pill—a tablet formulation of Novo Nordisk’s NOVO.B  Ozempic and Wegovy—ushering in a new era of the obesity-drugs revolution that is expected to broaden their use.
    • “Novo Nordisk said it plans to start selling the new pill in the U.S. soon after the new year, with a cash price of $149 a month for the starting dose.
    • “The Food and Drug Administration approval is a milestone because weekly shots such as Wegovy and Eli Lilly’s LLY Zepbound have dominated the anti-obesity market to date. Yet many people with excess weight don’t take the shots due to costspotty insurance coverage and fear of needles.
    • “Drug companies and analysts say pills will tap in to demand from people who don’t want an injection or would prefer the cadence of a daily dose. Pills also offer the prospect of lower prices and better health-insurance coverage than injections, because pills cost less to make.
    • “Eli Lilly also plans to introduce a new weight-loss pill, potentially within weeks or months.” 
  • Fierce Pharma tells us,
    • “Just two months after reviving its prowess in the idiopathic pulmonary fibrosis (IPF) treatment area with rare lung disease med Jascayd, Boehringer Ingelheim is already unlocking another patient population with a new FDA nod.
    • “The new approval for Jascayd in progressive pulmonary fibrosis (PPF) makes the drug the only preferential phosphodiesterase 4B (PDE4B) inhibitor with immunomodulatory and antifibrotic effects approved in this indication, according to a Dec. 19 company press release.
    • “Progressive pulmonary fibrosis is a life-threatening condition with a high unmet medical need. The U.S. approval of Jascayd is an important step forward to help slow lung function decline for people living with PPF, providing a new, well-tolerated treatment option,” Boehringer’s head of human pharma, Shashank Deshpande, said in a release.”
  • MedTech Dive notes,
    • “Abbott said Monday that it has received Food and Drug Administration approval for its Volt pulsed field ablation system.
    • “The catheter-based device uses targeted, high-energy electrical pulses to treat a common heart arrhythmia called atrial fibrillation. Abbott’s Volt device is indicated for both paroxysmal AFib, where episodes come and go, and persistent AFib, or episodes that last longer than seven days, according to the FDA.
    • “Medtronic, Boston Scientific and Johnson & Johnson have all debuted their own PFA devices in the last two years. The approval allows Abbott to join the fast-growing, competitive market in the U.S.”

From the public health and medical / Rx research front,

  • The American Medical Association lets us know “What doctors wish patients knew about family immunizations.”
    • “Vaccines save millions of lives each year. Two infectious diseases physicians discuss the key role they should play for the loved ones in your family.”
  • Health Day informs us,
    • “Psychiatric conditions as varied as schizophrenia and bipolar disorder might be driven by very similar genetic underpinnings, a new study says. 
    • “Mental health problems can be sorted into five general genetic categories, each with a shared “genetic architecture” driving people’s illness, according to results published in the journal Nature.
    • “Right now, we diagnose psychiatric disorders based on what we see in the room, and many people will be diagnosed with multiple disorders. That can be hard to treat and disheartening for patients,” lead researcher Andrew Grotzinger, an assistant professor of psychology and neuroscience at the University of Colorado-Boulder, said in a news release.
    • “This work provides the best evidence yet that there may be things that we are currently giving different names to that are actually driven by the same biological processes,” he said.”
  • and
    • “A new risk score can help predict which pancreatic cancer survivors are more likely to suffer a recurrence of their cancer, researchers said.
    • “The score could help better manage the follow-up care for patients who’ve had pancreatic tumors surgically removed, and whose cancers have not spread to their lymph nodes, researchers wrote Dec. 17 in JAMA Surgery.
    • “We now have a way to identify patients whose higher risk of recurrence may have been previously overlooked,” senior researcher Dr. Cristina Ferrone, chair of surgery at Cedars-Sinai Medical Center in Los Angeles, said in a news release. “This gives us the opportunity to change the way we care for this patient population in a meaningful way.”
    • “The score helps people with pancreatic neuroendocrine tumors, which are a less common and typically less aggressive form of pancreatic cancer.
    • “Patients whose cancer has not spread outside the pancreas, to either the lymph nodes or surrounding organs, have a 91% five-year survival rate following surgery, researchers said in background notes.”
  • The Wall Street Journal relates
    • “For years, Barbara Schmidt’s family feared an illness was behind a pattern of terrifying falls that repeatedly landed the 83-year-old great-grandmother in surgery with broken bones. Instead, Schmidt’s frequent tumbles might have been tied to something else: medications intended to make her better.
    • “Schmidt, who lives with her husband of 65 years in Lewes, Del., filled prescriptions for more than a dozen different drugs in the past year, according to pharmacy and medical records.
    • “That isn’t unusual for America’s seniors, according to a Wall Street Journal analysis of Medicare data. One in six of the 46 million seniors enrolled in Medicare’s drug benefit, which pays for most drugs taken by older Americans, were prescribed eight or more medications.”
    • * * * “Schmidt’s recent prescriptions came from at least five different healthcare providers. Most were affiliated with the nearby hospital system Beebe Healthcare, including a nurse practitioner whom she sees for primary care and a gastroenterology office. An orthopedic surgeon who has treated her back problems and prescribed medications to help with her pain works for an independent practice, First State Orthopaedics. 
    • “A Beebe spokesman said it has reviewed its prescribing patterns and, this November, added a new electronic medical record that will allow doctors to “view consolidated medical and medication histories” for patients and deliver “safer, more informed care.” First State Orthopaedics said it doesn’t comment on matters of patient care unless it is legally required to do so.
    • “Pharmacists who work with seniors say doctors might not be aware of their patients’ full medication list. Patients don’t always mention what their other doctors have prescribed when a history is taken, and specialists might not have access to a shared medical record.
    • “The Journal analysis found that, among seniors taking eight or more drugs, it was common for the prescriptions to come from a large number of doctors.”

From the U.S. healthcare and artificial intelligence front,

  • Per Beckers Hospital Review,
    • “Houston-based Nutex Health has opened its 26th micro-hospital, Archview ER & Hospital, in St. Louis.
    • “The 16,000-square-foot facility includes 15 emergency room beds, three inpatient suites, a full-service laboratory and advanced imaging technology, according to a Dec. 22 Nutex Health news release.
    • “It replaces Homer G. Phillips Memorial Hospital, which surrendered its license and closed in March. The hospital had been temporarily closed since December 2024, when its license was suspended due to a blood supply shortage.”
  • and
    • “Mark Cuban Cost Plus Drug Co. has added Vegzelma, a biosimilar indicated for six cancer types, to its marketplace for hospitals and other healthcare providers. 
    • “The company plans to expand its biosimilar offerings amid growing demand for biologics among health systems, according to a news release shared with Becker’s. Cost Plus Drugs also offers Starjemza, a biosimilar to Johnson & Johnson’s Stelara (ustekinumab), at a price about $3,000 lower than retail at other pharmacies.
    • “Vegzelma is a biosimilar to Roche’s Avastin (bevacizumab), which is approved for treatment of metastatic colorectal cancer; non-squamous non-small cell lung cancer; recurrent glioblastoma; metastatic renal cell carcinoma; persistent, recurrent or metastatic cervical cancer; and epithelial ovarian, fallopian tube or primary peritoneal cancer.”  

Cybersecurity Saturday

From the cybersecurity policy and law enforcement front,

  • Cyberscoop reports,
    • “With a little more than a month left before a foundational cyber threat information sharing law expires for a second time, Congress might have to do another short-term extension as negotiations on a longer deal aren’t yet bearing fruit, a key lawmaker said Tuesday.
    • “House Homeland Security Chairman Andrew Garbarino, R-N.Y., said the problem with a long-term extension of the Cybersecurity Information Sharing Act of 2015, which provides legal protections to companies to share cyber threat data with the federal government and other companies, is that there are three different views about how to approach it.
    • “The Trump administration and some in the Senate want a clean, 10-year reauthorization of the law, which Congress extended last month until Jan. 30 as part of the legislation that ended the government shutdown, after the information sharing law lapsed in October. But a reauthorization without any changes could run into House opposition, Garbarino said.” * * *
    • “Senate Homeland Security and Governmental Affairs Committee Chairman Rand Paul, R-Ky., also has a version of the bill that focuses largely on language he said is needed to defend free speech. And Garbarino’s version takes yet another approach to tweaking the law.
    • “Unfortunately, I don’t think we’re close enough with the discussions on the Senate to get it to figure out which bill will pass and what will get done,” Garbarino said. That leaves another extension tied to any funding bill that replaces the legislation currently funding the government, which also runs through Jan. 30.”
  • and
    • “Policymakers and companies are reckoning with increased reports over the past few months showing AI tools being leveraged to conduct cyber attacks on a larger and faster scale.
    • “Most notably, Anthropic reported last month that Chinese hackers had jailbroken and tricked its AI model Claude into assisting with a cyberespionage hacking campaign that ultimately targeted more than 30 entities around the world.
    • “The Claude-enabled Chinese hacks have underscored existing concerns among AI companies and policymakers that the technology’s development and relevance to offensive cybersecurity may be outpacing the cybersecurity, legal and policy responses being developed to defend against them.
    • “At a House Homeland Security hearing this week, Logan Graham, head of Anthropic’s red team, said the Chinese spying campaign demonstrates that worries about AI models being used to supercharge hacking are more than theoretical.”
  • Cybersecurity Dive tells us,
    • “A top Senate Republican is pressing the Trump administration for a plan to address the cybersecurity consequences of the U.S.’s dependence on open-source software.
    • “Leaving our reliance on OSS unmonitored is exposing America to increasingly dangerous risks,” Senate Intelligence Committee Chair Tom Cotton, R-Okla., wrote in a Wednesday letter to National Cyber Director Sean Cairncross.
    • “Cotton cited recent incidents that highlighted the unstable and sometimes untrustworthy foundations of the open-source ecosystem, including the XZ Utils crisis, a Russian developer’s control of a package that the U.S. military uses for sensitive applications and the prevalence of code contributions by Chinese companies’ employees, who are bound by Chinese laws that could force them to disclose software flaws to Beijing before fixing them.”
  • and
    • “The National Institute of Standards and Technology has prepared a companion to its widely used Cybersecurity Framework that focuses on how organizations can safely use AI.
    • “NIST’s Cybersecurity Framework Profile for Artificial Intelligence, which the agency released in draft form on Tuesday [December 16], describes how organizations can manage the cybersecurity challenges of different AI systems, improve their cyber defense capabilities with AI and block AI-powered cyberattacks. The document maps components of the Cybersecurity Framework (CSF) onto specific recommendations in each of those three areas, which NIST dubbed “secure,” “defend” and “thwart,” respectively.
    • “The three focus areas reflect the fact that AI is entering organizations’ awareness in different ways,” Barbara Cuthill, one of the profile’s authors, said in a statement. “But ultimately every organization will have to deal with all three.”
  • Cyberscoop tells us,
    • “Federal prosecutors in Michigan say they have dismantled online infrastructure tied to an alleged money laundering operation that moved tens of millions of dollars in proceeds from ransomware and other cybercrime, along with indicting the service’s creator.
    • “The U.S. Attorney’s Office for the Eastern District of Michigan announced a coordinated action with international partners and the Michigan State Police targeting E-Note, a cryptocurrency exchange and payment processing service used to launder illicit funds. The announcement coincided with the unsealing of an indictment charging a Russian national, Mykhalio Petrovich Chudnovets, with one count of money laundering conspiracy.”
  • and
    • “Former cybersecurity professionals Ryan Clifford Goldberg and Kevin Tyler Martin pleaded guilty Thursday to participating in a series of ransomware attacks in 2023 while they were employed at cybersecurity companies tasked with helping organizations respond to ransomware attacks.
    • “Goldberg, who was a manager of incident response at Sygnia, and Martin, a ransomware negotiator at DigitalMint at the time, collaborated with an unnamed co-conspirator to attack victim computers and networks and use ALPHV, also known as BlackCat, ransomware to extort payments.
    • “The plea deals mark a relatively quick turnaround as prosecutors successfully persuaded the pair to cop to their crimes less than three months after they were indicted in the U.S. District Court for the Southern District of Florida. Goldberg was arrested Sept. 22 and Martin was arrested Oct. 14.”
  • and
    • “Artem Aleksandrovych Stryzhak, a 35-year-old Ukrainian national, pleaded guilty Friday to multiple crimes stemming from his involvement in a string of ransomware attacks targeting U.S. and Europe-based organizations from mid 2018 to late 2021. He faces up to 10 years in jail for conspiracy to commit fraud, including extortion. 
    • “Stryzhak was arrested in Spain in June 2024 and extradited to the United States in April. Authorities are still looking for his alleged co-conspirator Volodymyr Tymoshchuk and announced a $11 million reward for information leading to his arrest or conviction.
    • “The defendant used Nefilim ransomware to target high-revenue companies in the United States, steal data and extort victims,” Joseph Nocella, U.S. attorney for the Eastern District of New York, said in a statement.”

From the cybersecurity breaches and vulnerabilities front,

  • Cybersecurity Dive reports,
    • “Apartment owner and developer Rockrose Development Corp. recently found that unauthorized individuals hacked its systems and claimed to have acquired confidential information, according to a letter posted to its website on Dec. 12. 
    • “The security breach occurred on July 4 and affected 47,392 people, according to a data breach notification submitted to Maine’s attorney general’s office. Rockrose discovered the issues on Nov. 14. 
    • “Rockrose determined that personally identifiable information for some individuals may have been impacted, which could indicate that the hackers accessed some sensitive areas of the network. That information could include name, Social Security number, taxpayer identification number, driver’s license number, passport number, bank account and routing numbers, health insurance information, medical information and online account credentials.”
  • Cyberscoop adds,
    • “Fallout from React2Shell — a stubborn vulnerability that impacts wide swaths of the internet’s scaffolding — continues to spread as public exploits and stealth backdoors proliferate and worrying details emerge about the targets attackers are pursuing. 
    • “Threat researchers and incident responders are reacting to swift-moving developments on React2Shell with mounting concern. Cybercriminals, ransomware gangs and nation-state threat groups are all swarming to exploit the maximum-severity vulnerability.
    • Palo Alto Networks’ Unit 42 puts the latest victim count at more than 60 organizations, which have been impacted by attacks involving exploitation of CVE-2025-55182, which Meta and the React team publicly disclosed Dec. 3.
    • “Microsoft said it found “several hundred machines across a diverse set of organizations” that were compromised via exploitation resulting in remote-code execution. Post-exploitation activity in those attacks includes reverse shell implants, lateral movement, data theft and steps that allowed attackers to maintain access to targeted networks, Microsoft said in a research blog Tuesday [December 16]. 
  • The Cybersecurity and Infrastructure Security Agency (“CISA”) added seven known exploited vulnerabilities to its catalog this week.
    • December 15, 2025
      • CVE-2025-14611 Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability
      • CVE-2025-43529 Apple Multiple Products Use-After-Free WebKit Vulnerability 
        • Kubelski Security discusses the Gladinet KVEs here.
        • The Center for Internet Security discusses the Apple KVEs here.
    • December 16, 2025
      • CVE-2025-59718 Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability 
        • Security Affairs discusses this KVE here.
    • December 17, 2025
      • CVE-2025-20393 Cisco Multiple Products Improper Input Validation Vulnerability
      • CVE-2025-40602 SonicWall SMA1000 Missing Authorization Vulnerability
      • CVE-2025-59374 ASUS Live Update Embedded Malicious Code Vulnerability
        • The Hacker News discusses the Cisco KVE here.
        • Security Week discusses the SonicWall KVE here.
        • Malwarebytes discusses the ASUS KVE here.
    • December 19, 2025
      • CVE-2025-14733 WatchGuard Firebox Out-of-Bounds Write Vulnerability 
        • Bleeping Computer discusses this KVE here.
  • Cyberscoop relates,
    • “Cisco customers are confronting a fresh wave of attacks from a Chinese threat group that has actively exploited a critical zero-day vulnerability affecting the vendor’s software for email and web security since at least late November, the company said in an advisory Wednesday. 
    • “Cisco said it became aware of the attacks Dec. 10. The defect CVE-2025-20393, which has a CVSS rating of 10, is an improper input validation vulnerability affecting Cisco AsyncOS software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager that allows attackers to execute commands with unrestricted privileges and implant persistent backdoors on compromised devices.
    • “There is no patch for the vulnerability and Cisco declined to say when one would be made available. Cisco said “non-standard configurations” have been observed in compromised networks, specifically customer systems that are configured with a publicly exposed spam quarantine feature.
    • “Cisco Talos researchers attributed the attacks to a Chinese advanced persistent threat group it tracks as UAT-9686, which has used tooling and infrastructure consistent with other China state-sponsored threat groups such as APT41 and UNC5174.
  • Cybersecurity Dive informs us,
    • “Multiple threat groups have been ramping up attacks using a technique called device code phishing to trick users into granting access to their Microsoft 365 accounts, according to a report Thursday from Proofpoint
    • “Hackers affiliated with China and Russia have used the technique in recent months to launch attacks. A number of criminal groups have used the same method to target M365 users as well. 
    • “This is a social engineering method that abuses a legitimate and trusted workflow for authorized access,” Sarah Sabotka, staff threat researcher at Proofpoint, told Cybersecurity Dive.”
  • and
    • A coordinated, credential-based hacking campaign has been targeting Palo Alto Networks GlobalProtect services, as well as Cisco SSL VPNs, in a surge of mid-December attacks, according to a blog post Wednesday by GreyNoise
    • The threat activity does not involve targeting of any vulnerabilities, but uses automated scripted login attempts over two days. 
    • More than 1.7 million sessions were observed targeting Palo Alto Networks GlobalProtect and PAN-OS profiles over a 16-hour period, according to GreyNoise. More than 10,000 unique IPs were detected trying to log into GlobalProtect portals on Dec. 11.  
  • and
    • “A Russia-linked hacker group has been targeting critical infrastructure organizations using vulnerabilities in their edge devices since at least 2021, highlighting an alarming shift toward exploiting well-known flaws in common networking equipment, Amazon’s threat intelligence team said Monday.
    • “The threat actor’s shift [toward edge devices] represents a concerning evolution,” Amazon researchers wrote in a blog post. “While customer misconfiguration targeting has been ongoing since at least 2022, the actor maintained sustained focus on this activity in 2025 while reducing investment in zero-day and N-day exploitation.”
  • Bleeping Computer points out,
    • “The UEFI firmware implementation in some motherboards from ASUS, Gigabyte, MSI, and ASRock is vulnerable to direct memory access (DMA) attacks that can bypass early-boot memory protections.
    • “The security issue has received multiple identifiers (CVE-2025-11901, CVE-2025‑14302, CVE-2025-14303, and CVE-2025-14304) due to differences in vendor implementations.”

From the ransomware front,

  • Cyber Press reports,
    • SentinelLABS research indicates that large language models (LLMs) such as ChatGPT, Claude, and open-source alternatives are accelerating every stage of the ransomware lifecycle, from reconnaissance to negotiation. 
    • “However, analysts emphasize that these tools are improving speed and scale rather than introducing fundamentally new attack methods.
    • “By repurposing enterprise-grade AI workflows, ransomware actors are using models to automate tasks such as creating phishing content, drafting multilingual ransom notes, and triaging data across leaked datasets. 
    • “This enables threat actors to identify financially sensitive files and tailor extortion tactics across multiple languages with greater precision.” * * *
    • “The report finds that while law enforcement disruptions have weakened mega cartels such as LockBit, Conti, and REvil, smaller, short-lived groups such as Termite, Punisher, and Obscura are emerging rapidly. 
    • “These groups exploit LLM-driven workflows to emulate more experienced operators, reducing entry barriers and complicating attribution.”
  • Manufacturing Business Technology adds,
    • “Sophos recently announced new findings from the Sophos State of Ransomware in Manufacturing and Production 2025 report which reveals that manufacturers are stopping more ransomware attacks before data can be encrypted.
    • “However, adversaries are increasingly stealing data and using extortion-only tactics to maintain pressure. As a result, more than half of manufacturing organizations impacted by encryption paid the ransom despite progress in defensive measures.”
  • Bleeping Computer relates,
    • “The Clop ransomware gang (also known as Cl0p) is targeting Internet-exposed Gladinet CentreStack file servers in a new data theft extortion campaign.
    • Gladinet CentreStack enables businesses to securely share files hosted on on-premises file servers through web browsers, mobile apps, and mapped drives without requiring a VPN. According to Gladinet, CentreStack “is used by thousands of businesses from over 49 countries.”
    • “Since April, Gladinet has released security updates to address several other security flaws that were exploited in attacks, some of them as zero-days.
    • “The Clop cybercrime gang is now scanning for and breaching CentreStack servers exposed online, with Curated Intel telling BleepingComputer that ransom notes are left on compromised servers.
    • “However, there is currently no information on the vulnerability Clop is exploiting to hack into CentreStack servers. It is unclear whether this is a zero-day flaw or a previously addressed bug that the owners of the hacked systems have yet to patch.”
  • CSO offers advice on how to create a ransomware playbook that works.

From the cybersecurity business and defenses front,

  • The Wall Street Journal reports,
    • “Blackstone is leading a $400 million investment in data-security firm Cyera that values the New York-based company at $9 billion, according to people familiar with the matter. 
    • “Cyera is among a crop of cybersecurity startups leveraging artificial intelligence to protect companies from new security vulnerabilities introduced by AI. The startup, founded in 2021 by former Israeli Defence Forces military intelligence officers Yotam Segev and Tamar Bar-Ilan, raised funding at a $6 billion valuation in June.”
  • and
    • “Kevin Mandia, founder of the cybersecurity firm Mandiant—which was acquired by Alphabet’s GOOGL 0.61%increase; green up pointing triangle Google for $5.4 billion—has formed a new company called Armadin that will take on the imminent threat from AI hacking.
    • “The company aims to use artificial intelligence to supercharge the business of testing networks for vulnerabilities. Armadin raised $24 million in seed funding from Ballistic Ventures, a venture-capital firm co-founded by Mandia, and is in talks with Accel, GV and Kleiner Perkins to raise $100 million or more, people familiar with the matter said. The deal is expected to value the company at more than $600 million. The round isn’t finalized, and the details could still change.
    • “Known as red-teaming, this kind of service will become more important as hackers turn to AI to speed up their attacks, Mandia said in an interview.  
    • “Offense is going to be all-AI in under two years,” he said. “And because that’s going to happen, that means defense has to be autonomous. You can’t have a human in the loop or it’s going to be too slow.”
  • CISA announced,
    • Today [December 19], the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency, and Canadian Centre for Cyber Security released an update to the Malware Analysis Report BRICKSTORM Backdoor with indicators of compromise (IOCs) and detection signatures for additional BRICKSTORM samples. This update provides information on additional samples, including Rust-based samples. These samples demonstrate advanced persistence and defense evasion mechanisms, such as running as background services, and enhanced command and control capabilities through encrypted WebSocket connections.
    • The update includes two new detection signatures in the form of YARA rules, enabling organizations to better identify BRICKSTORM-related activity. Organizations are strongly encouraged to deploy these updated IOCs and signatures, and to follow the detection guidance to scan for and respond to BRICKSTORM infections If BRICKSTORM, similar malware, or potentially related activity is detected, report the incident to CISA’s 24/7 Operations Center at contact@cisa.dhs.gov or (888) 282-0870.
  • Cybersecurity Dive lets us know,
    • “Hybrid infrastructure that includes a mix of public/private cloud environments, on-premises workloads and air-gapped systems are preferred by security leaders as a way to boost resilience and better manage risk, according to a report Thursday by Trellix
    • “About 96% of chief information security officers said a hybrid model is the preferred approach to meet regulatory and compliance requirements, while 97% said such a model will help meet obligations related to data sovereignty and residency. 
    • “Ultimately, a CISO must ensure their teams, technology and business partners understand the specific shared responsibility model for each service they consume and implement the necessary controls to manage the daily risks that remain the customer’s responsibility,” Trellix CISO Michael Green told Cybersecurity Dive. “This often involves leveraging tools and governance processes designed to operate across multicloud and hybrid environments to provide consistent security posture and visibility.”
  • An ISACA expert notes,
    • “Cybersecurity budgets are often built on assumptions, including the assumption that backups will always work, that insurance will cover the losses and that existing controls are “good enough.” Yet, when those assumptions fail, the operational fallout can be staggering. The City of Hamilton in Canada learned this lesson when a ransomware attack crippled nearly 80% of its network and left taxpayers facing a CAD $18.3 million recovery bill. Misplaced assumptions regarding backups, authentication, insurance and system resilience can lead organizations to underestimate risk and drive up the cost of a cyberattack.”
  • Dark Reading offers advice on creating an AI adoption playbook and of course its CISO Corner.

Monday report

From Washington, DC,

  • The American Hospital Association News informs us,
    • “Approximately 950,000 consumers who currently do not have health insurance coverage through the federally facilitated Health Insurance Marketplace have signed up for a 2026 health plan, the Centers for Medicare & Medicaid Services announced Dec. 5. More than 4.8 million returning consumers have selected 2026 plans. The open enrollment period began Nov. 1 and continues through Jan. 15. Today is the final day for consumers to enroll in coverage that would begin Jan. 1. For those enrolling after Dec. 15, coverage would begin Feb. 1.”
  • and
    • “The Centers for Medicare & Medicaid Services Dec. 15 published the Measures Under Consideration List for 2025. These are measures that CMS is considering adopting through the federal rulemaking process for use in Medicare programs. This year’s list comprises 24 unique measures, with some under consideration for multiple CMS programs and others already in use but undergoing substantial change to their specifications. Notably, several measures address topics consistent with the Department of Health and Human Services’ Make America Health Again priority framework, such as chronic illness and nutrition, and all 24 measures rely on data submissions using at least one digital source. In addition, CMS is promoting the early review of five measures that align with the MAHA initiative and are currently in the development stage. 
    • “CMS will convene a consensus-based multidisciplinary group, on which the AHA sits, to provide recommendations to the agency on these measures by Feb. 1. In addition, CMS will seek input through public comments from Dec. 16 through Jan. 6.” 
  • Per a CMS fact sheet,
    • “All seven of CMS’ A/B Medicare Administrative Contractors (MACs) will issue updated Final Local Coverage Determinations (LCDs) for Skin Substitute Grafts/Cellular and Tissue-Based Products for the Treatment of Diabetic Foot Ulcers and Venous Leg Ulcers that will be effective January 1, 2026.”
  • Per HHS news releases,
    • “Ralph Abraham, M.D., was sworn in today as Principal Deputy Director of the Centers for Disease Control and Prevention (CDC) by Health and Human Services Secretary Robert F. Kennedy, Jr. He will begin his duties at CDC headquarters in Atlanta on January 5, 2026.
    • “Dr. Abraham has nearly 30 years of experience as a medical practitioner, most recently as Surgeon General of the state of Louisiana. As CDC Principal Deputy Director, he will help realign the agency with its mission as America’s frontline defender against infectious disease.”
  • and
    • “The U.S. Department of Health and Human Services (HHS) today convened Lyme disease patients, clinicians, and researchers for a roundtable on diagnostics and clinical needs moderated by HHS Secretary Robert F. Kennedy, Jr. The event fulfills commitments made in the Make America Healthy Again Commission Strategy Report [PDF, 21.85 MB] to address chronic and often unseen illnesses that affect millions of Americans.
    • “For decades, Americans suffering from Lyme disease have been denied the accurate diagnostics and meaningful care they deserve,” said Secretary Kennedy. “Today’s actions push us decisively toward reliable testing and treatment grounded in the real-world experiences of patients. We are committed to delivering the tools that families have waited far too long to receive.”
    • “Participants shared their experiences and recommendations on improving care and advancing research. Senator Susan Collins (R-ME) and Representatives Morgan Griffith (R-VA) and Chris Smith (R-NJ) also engaged in the discussions.
    • “As part of today’s event, HHS announced the renewal of the LymeX Innovation Accelerator with the Steven & Alexandra Cohen Foundation that began during President Trump’s first term. Established in 2020, LymeX is the largest public-private partnership ever built to improve Lyme disease diagnostics and care. The $10 million initiative will advance artificial intelligence tools that support earlier and more accurate detection across stages of infection.”
  • Per an OPM news release,
    • “The US Office of Personnel Management (OPM), in coordination with the Office of Management and Budget (OMB), the General Services Administration (GSA), the White House Office of Science Technology and Policy (OSTP), and agency leaders across the administration, today announced the establishment of the United States Tech Force (Tech Force)– a new, cross-government program to recruit top technologists to modernize the federal government.” * * *
    • “OPM is proud to announce the initial private sector partners for Tech Force: Adobe, Amazon Web Services, AMD, Anduril, Apple, Box, C3.ai, Coinbase, Databricks, Dell Technologies, Docusign, Google Public Sector, IBM, Meta, Microsoft, Nvidia, OpenAI, Oracle, Palantir, Robinhood, Salesforce, SAP, ServiceNow, Snowflake, Synopsys, Uber, Workday, xAI, and Zoom. OPM welcomes the opportunity to expand this list of partners over time.
    • “In addition, Tech Force is partnering with NobleReach Foundation – a nonpartisan talent platform that brings together America’s best and brightest across industry, academia, and government via initiatives such as its NobleReach Scholars Program – to recruit technologists and support the program.
    • “Read more of what government and tech world leaders have to say about Tech Force here.
    • “For further information, please see OPM’s memo to agencies here. To learn more or apply for Tech Force and for FAQ’s visit TechForce.govAnd follow US Tech Force on X.”  

From the Food and Drug Administration front,

  • Per FDA news releases,
    • “The U.S. Food and Drug Administration (FDA) today removed a key limitation on the use of real-world evidence (RWE) used in drug and device applications reviews. In new guidance for certain types of medical device submissions, the agency states it will accept RWE without requiring that identifiable individual patient data collected from real-world data sources always be submitted in a marketing submission. The FDA similarly intends to consider updating its guidance for drugs and biologics.”
  • and
    • “The U.S. Food and Drug Administration today reminded industry of its legal responsibilities under the Federal Food, Drug, and Cosmetic Act regarding food recalls and called for industry to increase adoption of best practices in recall implementation, especially for recalls involving foods for our country’s most vulnerable populations –infants and young children. Last week, the FDA sent warning letters to several major retailers for failing to remove recalled ByHeart infant formula from their store shelves despite being notified of the recall. These warning letters highlight a concerning problem with recall effectiveness at the retail level. Last year, the FDA sent a similar warning letter to a retailer who failed to adequately remove recalled lead-contaminated WanaBana apple cinnamon fruit puree pouches from its store shelves.”
  • Fierce Pharma reports,
    • “Clearing clinical and regulatory hurdles in the development of a fast-acting nasal spray for a heart condition has given Milestone Pharmaceuticals its first FDA approval in its 22-year history.
    • “The U.S. regulator has signed off on Cardamyst (etripamil) to quell symptomatic episodes from paroxysmal supraventricular tachycardia (PSVT), which is a type of abnormal heart rhythm. Cardamyst becomes the first self-administered treatment patients can use to manage their PSVT symptoms.
    • “The calcium channel blocker is a convenient alternative to an emergency room visit, where patients receive an intravenous dose of a drug that “basically reboots your heart,” Milestone CEO Joe Oliveto said in an interview.
  • and
    • “LIB Therapeutics has scored an FDA approval for its cholesterol-lowering, third-generation PCSK9 inhibitor, lerodalcibep-liga.
    • “The injected treatment, which will carry the commercial name Lerochol, is approved to be used along with diet and exercise to reduce low-density lipoprotein cholesterol (LDL-C) in adults with hypercholesterolemia, including those with heterozygous familial hypercholesterolemia (HeFH).
    • “Lerochol arrives on the market with a convenience edge over other PCSK9 drugs, as it is self-administered once monthly and doesn’t need refrigeration because it retains its stability for up to three months at room temperature. By comparison, Amgen’s Repatha and Sanofi and Regeneron’s Praluent are dosed between every two to four weeks, depending on patient needs, and have a shorter shelf life at room temperature.”
  • and
    • “Johnson & Johnson’s Akeega is opening new fronts in prostate cancer treatment with a fresh FDA approval, making it the first precision medicine combo for patients with BRCA2-mutated metastatic castration-sensitive prostate cancer (mCSPC).
    • “Akeega, a dual-action tablet made up of J&J’s androgen-directed prostate cancer med Zytiga (abiraterone acetate) and the PARP inhibitor niraparib—sold by GSK as Zejula in other indications—is added to corticosteroid medication prednisone to delay disease progression of the aggressive form of prostate cancer.  
    • “J&J’s Amplitude study was the first showing that a PARP inhibitor-androgen receptor pathway inhibitor treatment combination could delay both radiographic and symptomatic disease progression in the disease type, Dana-Farber Cancer Institute’s Bradley McGregor, M.D., noted in a company press release.
  • and
    • “The FDA has “proactively” granted Johnson & Johnson a coveted speedy review under the Commissioner’s National Priority Voucher pilot (CNPV), the agency said Monday.
    • “The voucher was granted to J&J for its proposed combination of Tecvayli and Darzalex for previously treated multiple myeloma.
    • “With the voucher, the FDA aims to deliver a decision within one to two months following submission of an application. Normally, FDA drug reviews take up to 10 months, starting from the acceptance of an application.”

From the public health and medical / Rx research front,

  • The New York Times reports,
    • “A new drug has been saturating the fentanyl supply in Philadelphia and moving to other cities throughout the East and Midwestern United States: medetomidine, a powerful veterinary sedative that causes almost instantaneous blackouts and, if not used every few hours, brings on life-threatening withdrawal symptoms.
    • “It has created a new type of drug crisis — one that is occasioned not by overdosing on the drug, but by withdrawing from it.
    • “Since the middle of last year, Philadelphia’s hospitals have been strained by patients coming in with what doctors have identified as medetomidine withdrawal. Although the heart rate slows drastically right after use, in withdrawal the opposite occurs: The heart rate and blood pressure become catastrophically high. Patients experience tremors and unstoppable vomiting. Many require intensive care.”
  • The Wall Street Journal relates,
    • “People susceptible to developing heart issues benefit the most from reducing their consumption of saturated fats, according to a review of research that comes as the federal government prepares to revise dietary recommendations.
    • ‘A paper published Monday in the Annals of Internal Medicine found that people at high risk of developing cardiovascular problems saw a reduction in major health issues including heart attack and stroke when they cut back on saturated fats. The picture was different for people without those same cardiovascular risks. Within five years, cutting saturated fats didn’t yield the same benefits for that group, the review said.”
  • The Washington Post tells us,
    • “Why some people experience long-lasting physical and mental effects from covid-19 could be linked to chronic inflammation, according to new research that experts say could help develop new treatments for the confounding condition that continues to afflict millions.
    • “Some early research on the condition has suggested that long covid’s symptoms linger because the virus persists in people’s bodies. But the new study published Friday in Nature Immunology found that people with long covid had activated immune defenses and heightened inflammatory responses for more than six months after initial infection compared with those who fully recovered.
    • “The latest research “leads to a hypothesis that there might be therapeutic targets related to inflammation that might be worth exploring in clinical studies,” said Dan Barouch, the study’s lead author and director of the Center for Virology and Vaccine Research at Beth Israel Deaconess Medical Center.
    • “The study’s findings signal progress in understanding a condition that is estimated to affect more than 400 million individuals around the world as the coronavirus continues to infect people every day, said Ziyad Al-Aly, a clinical epidemiologist at Washington University in St. Louis who studies long covid. There are no drugs approved for treatment of long covid, leaving doctors to tackle individual symptoms with various therapies.”
  • The American Medical Association lets us know “What doctors wish parents knew about fall prevention for kids.
    • “Rabia Nagda, MD, of Texas Children’s Pediatrics, emphasizes that every environment where kids spend time should be built with fall risk in mind.”
  • Per MedPage Today,
    • “Cannabis use in pregnancy is associated with health risks including preeclampsia and low birthweight.
    • “In this secret shopper study, one in five cannabis retailers told callers that cannabis use was safe in pregnancy.
    • “The findings support a need for more public education about the risks of prenatal cannabis use and for guidance to discuss its use with physicians.”
  • Per Health Day,
    • “‘Dual use’ of vaping and smoking might help smokers cut back or quit.
    • “Smokers who also vaped were 4.5 times more likely to quit within a year.
    • “Dual users were also more likely to cut their smoking by half.”
  • and
    • “People could learn within 15 minutes whether they are infected with hepatitis C, thanks to a rapid test developed by Northwestern University.
    • “The test will allow doctors to diagnose infections during an office visit and kickstart patients’ treatment before they leave, researchers said.
    • “This test could revolutionize HCV care in the U.S. and globally by dramatically improving diagnosis, accelerating treatment uptake and enabling more people to be cured faster,” researcher Dr. Claudia Hawkins said in a news release. She’s director of Northwestern’s Institute for Global Health’s Center for Global Communicable and Emerging Infectious Diseases in Chicago.”
  • STAT News reports,
    • “Gene therapy researchers were converging on a holy grail. A few years ago, researchers at labs and companies reported they had engineered viruses that could ferry corrective genes deep into the brain, giving potential entry to a new world of treatments for Alzheimer’s, Parkinson’s, and a slew of rare genetic diseases.
    • “This summer, after years of careful study, the first person underwent gene therapy using one of the new viruses. The patient, a young child, died two and a half days later.
    • “The death has sent concern and uncertainty rippling through labs and companies developing gene therapies for the brain, along with rare disease groups who hoped these tools could deliver long-sought cures. They worry that Capsida Biotherapeutics unearthed a broader risk for other viruses designed to travel like a messenger pigeon to our brains, one that could derail years of progress. 
    • “Capsida has declined to answer questions about the death beyond a brief statement. Its CEO has departed. The information that has leaked out is troubling. The child died of cerebral edema — brain swelling — a clinical course distinct from other deaths tied to gene therapy over the last decade, according to a person familiar with the matter.
    • “Most disturbingly, none of the animal and lab studies Capsida presented indicated such a calamity was possible, making it unclear how other researchers and companies would test for such a risk.” * * *
    • “The best path ahead may be to start new trials in very low doses. But that’s challenging in gene therapy, where patients can only ever receive one dose of a virus in their lifetime, before they develop immunity to it. Still, “we may have to be a bit more conservative,” said Miguel Sena-Esteves, a gene therapy researcher at the UMass Chan Medical School 
    • “Alternatively, companies may have to move forward first in diseases otherwise immediately fatal, where the risk-benefit calculus shifts dramatically. The prion disease that shadows Sonia Vallabh, a researcher at the Broad Institute, is one. 
    • “Whichever way it goes, the gene therapy field has lost the assurance — already tenuous — that tests in animals can predict the toxicities for us. 
    • “In some way,” Vallabh said, “our only safety species is humans.”
  • The Wall Street Journal adds,
    • “Sanofi said its tolebrutinib drug candidate didn’t meet the primary goal in a late-stage clinical trial for multiple sclerosis. It separately said talks with the U.S. Food and Drug Administration had indicated a regulatory review for tolebrutinib in a different form of the disease would take longer than previously expected.
    • “The updates deal a blow to one of the most advanced drugs in Sanofi’s pipeline as the company seeks to move past recent disappointments in clinical trials. Sanofi has turned to dealmaking this year, using funds raised from the sale of a controlling stake in its consumer-healthcare business to replenish its pipeline.”

From the U.S. healthcare business front,

  • Fierce Healthcare reports,
    • “Highmark released its third quarter earnings report on Monday, where its top brass said the insurer expects to see elevated utilization trends persist into 2026.
    • “The Pittsburgh-based organization, which includes Highmark Health Plans and health system Allegheny Health Network, reported a $69 million net loss and a $204 million operating loss alongside $24.6 billion in revenue through the first nine months of 2025. The bulk of that loss came from the health insurance unit, which is continuing to be pressured by care use.
    • “Carl Daley, chief financial officer and treasurer at Highmark Health, told Fierce Healthcare that the company had expected utilization to normalize over the course of the year, and priced plans accordingly. It’s made adjustments in its pricing strategy for 2026 to adapt to the expectation that utilization remains high.”
  • MedTech Dive tells us,
    • “Philips has agreed to acquire SpectraWAVE, a firm making tools to help diagnose and guide treatment of coronary artery disease, the companies announced Monday. They did not disclose the terms of the deal.
    • “SpectraWAVE makes an intravascular imaging system for the coronary arteries. The Bedford, Massachusetts-based company also makes an AI-enabled solution that calculates fractional flow reserve from a single coronary angiogram to support treatment decisions. 
    • “Philips expects the acquisition will expand its portfolio of intravascular imaging and physiological assessment devices. CEO Roy Jakobs said in a statement that the company is “doubling down on image-guided therapy” and expanding its coronary intervention portfolio with the planned purchase.”
  • Cardiovascular Business adds,
    • “Ambulatory surgical centers (ASCs) and office-based labs (OBLs) are poised to play a growing role in cardiovascular care as payment policies shift and health systems look for more efficient ways to manage procedural volume. That trend, and the guardrails needed to ensure patient safety, was the focus of an educational session at TCT 2025 in San Francisco. 
    • “Cardiovascular Business spoke with one of the presenters, Arnold Seto, MD, cath lab director at the Long Beach VA Medical Center, professor of medicine at Charles Drew University, Society for Cardiovascular Angiography and Interventions (SCAI) treasurer and chair of the SCAI Advocacy Committee, to find out more.
    • “Seto said there is wide expectation that lower-acuity interventional cardiology and peripheral procedures will migrate into the ASC environment. This is partly due to better cost effectiveness and the fact that larger centers want to expand into more complex and structural heart procedures without building out their hospital cath labs to be bigger.
    • “The consultants tell us that as many as 25% to 50% of cardiology procedures will be migrating to the ASC environment. The government would prefer that because they pay about two-thirds of the hospital outpatient costs compared with an ASC reimbursement,” he said. He added that the Center of Medicare and Medicaid Services (CMS) is clearly signaling interest in this shift. “We’ve already seen CMS effectively remove all the PCI codes from the inpatient only list, and actually talk about removing everything from the inpatient only list.”
  • Per a Leapfrog news release,
    • “Today, The Leapfrog Group, a national watchdog organization of employers and other purchasers focused on health care safety and quality, announced the 2025 recipients for their elite annual Top Hospital Award and Top Ambulatory Surgery Center (ASC) Award. This national recognition is one of the most competitive honors U.S. hospitals and surgery centers can earn for excellence in patient safety and quality of care. Selected hospitals and ASCs will be celebrated today as part of Leapfrog’s 2025 Annual Meeting and Awards Dinner.” * * *
    • “The award honors hospitals and ASCs that demonstrate the highest performance in the nation on quality and patient safety, including ethical billing and informed patient consent procedures, lower infection rates, prevention of medication errors and surgical safety. To see the full methodology and list of institutions honored as 2025 Top Hospitals, please visit www.leapfroggroup.org/tophospitals. To see the full list of institutions honored as 2025 Top ASCs, please visit www.leapfroggroup.org/ratings-report/top-ascs.” 
  • Genetic Engineering and Biotechnology News points out,
    • “As Eli Lilly (NYSE: LLY) and Novo Nordisk (Nasdaq Copenhagen: NOVO-B) scramble to bring an oral glucagon-like peptide 1 (GLP-1) receptor agonist to market for obesity, a much smaller potential rival spotlighted positive mid-stage clinical data that captivated investors enough to send its share price more than doubling this past week.
    • “Structure Therapeutics (NASDAQ: GPCR) shares soared 102% after it reported positive data from its Phase II ACCESS clinical program assessing its oral GLP-1 candidate aleniglipron in people with obesity and/or overweight with at least one weight-related co-morbidity. Aleniglipron (formerly GSBR-1290) is designed to be a biased G protein-coupled receptor (GPCR) agonist, which selectively activates the G-protein signaling pathway.”
    • “If approved, Structure would compete with oral GLP-1s for weight management by the leading obesity drug developers, whose candidates could both win FDA approval in the new year.”
  • MedCity News notes,
    • “This Year’s Hottest Healthcare Company Isn’t Even a Healthcare Company
    • “Nvidia has quietly become one of the most influential players in healthcare technology by supplying the accelerated computing and AI infrastructure that powers everything from imaging to drug discovery. The company’s restraint — focusing on enabling the ecosystem rather than owning it — has helped cement its role as the indispensable backbone of the healthcare industry’s AI transformation.”

Cybersecurity Saturday

From the cybersecurity policy and law enforcement front,

  • Cyberscoop reports,
    • “The Defense Department would require that senior leaders have secure mobile phones, that personnel would get cybersecurity training that includes a focus on artificial intelligence and that cyber troops would have access to mental health services under a compromise annual defense policy bill released over the weekend.
    • The deal between House and Senate negotiators on the fiscal 2026 National Defense Authorization Act (NDAA) [reached last weekend] is a massive piece of legislation that runs the gamut of the Pentagon, including a record-breaking $901 billion topline figure. It also has a grab bag of cybersecurity policy provisions.”
  • Roll Call adds,
    • “Senate leaders plan for the chamber to vote next week to clear the bicameral compromise National Defense Authorization Act for President Donald Trump’s signature.
    • “As the fiscal 2026 bill edges closer to enactment, one of the few last-minute controversies shadowing it concerns whether the measure goes far enough to restrict military aircraft operations in close proximity to Ronald Reagan Washington National Airport.
    • “The Senate on Thursday [Decmber 11] voted 75-22 to take one procedural step closer to voting on the measure — agreeing to proceed to the legislation — which would authorize $900.6 billion for defense programs, mostly at the Pentagon.
    • “The chamber still plans to cast another procedural vote — set for Monday evening — and is expected to vote to clear the NDAA soon thereafter next week.
    • “The House passed the bill Wednesday [December 10} by a vote of 312-112.”
  • The American Hospital Association News tells us,
    • “The Cybersecurity and Infrastructure Security Agency Dec. 11 released an update to its voluntary Cybersecurity Performance Goals, which includes measurable actions for critical infrastructure, including health care. The update aligns with the latest cybersecurity standards outlined by the National Institute of Standards and Technology and addresses the most common and impactful threats facing critical infrastructure. The guidance also highlights the role of governance in cybersecurity management, emphasizing accountability, risk management and strategic integration of cybersecurity into day-to-day operations.” 
  • The HIPAA Journal relates,
    • “The College of Healthcare Information Management Executives (CHIME) and more than 100 U.S. hospital systems, healthcare provider organizations, and provider associations have called for the Department of Health and Human Services (HHS) to withdraw its proposed updates to the HIPAA Security Rule.
    • “The HIPAA Security Rule was enacted in 2002, nine years after HIPAA was signed into law, to establish security standards for electronic protected health information created, received, used, or maintained by a covered entity, with the requirements subsequently expanded to cover business associates of HIPAA-regulated entities. The Security Rule was written to be technology agnostic to avoid frequent rule changes in response to advances in technology; however, 22 years after its initial release, the HHS proposed a substantial update that specified many new cybersecurity requirements.” * * *
    • “While few healthcare industry stakeholders would disagree with the main purpose of the update – to improve healthcare cybersecurity and prevent costly and damaging cyberattacks that threaten patient safety – the proposed update attracted considerable criticism from healthcare and provider organizations. In February 2025, 8 industry associations, including CHIME, co-signed a letter to President Trump calling for the proposed update to be rescinded, pointing out that under the previous Trump administration, healthcare organizations were incentivized to adopt recognized cybersecurity best practices, and that was a better approach than imposing unreasonable cybersecurity mandates that would be costly and difficult to implement.
    • “In the December 8, 2025, joint stakeholder letter to HHS Secretary Robert F. Kennedy, Jr., the signatories called for the proposed update to be immediately withdrawn, and for the HHS to instead “conduct a collaborative outreach initiative with our organizations and other regulated entities that are impacted to develop practical and actionable cybersecurity standards for more robust protections of individuals’ health information, without the extreme and unnecessary regulatory burden that health care providers and other stakeholders would face under the crushing and unprecedented provisions of this Proposed Rule.”
  • Per a National Institute of Standards and Technology news release,
    • “NIST Special Publication (SP) 800-70r5 ipd (Revision 5, initial public draft), National Checklist Program for IT Products – Guidelines for Checklist Users and Developers, is now available for public comment through January 16, 2026, at 11:59 PM (EST).
    • “NIST established the National Checklist Program (NCP) to facilitate the generation of security checklists from authoritative sources, centralize the location of checklists, and make checklists broadly accessible. SP 800-70r5 ipd describes the uses, benefits, and management of checklists and checklist control catalogs, as well as the policies, procedures, and general requirements for participation in the NCP.”
  • Security Weeks informs us,
    • “The US government has announced rewards of up to $10 million for information on members of the Iranian hacking group known as Emennet Pasargad.
    • “The reward offers come roughly a year after a US-Israel joint advisory described the activities of the group, which was then identified by the name of its front company, Aria Sepehr Ayandehsazan (ASA).
    • “Noting that the group was previously identified as Emennet Pasargad, Ayandeh Sazan Sepehr Arya (ASSA), Eeleyanet Gostar, and Net Peygard Samavat Company, the US now calls it Shahid Shushtari.
    • “In the private sector, the threat group has been known as Cotton Sandstorm, Marnanbridge, and Haywire Kitten.”
  • Cyberscoop adds,
    • “The Justice Department has charged a Ukrainian national with conducting cyberattacks on critical infrastructure worldwide as part of two Russian state-sponsored hacking operations that targeted water systems, food processing facilities and government networks across the United States and allied nations.
    • “Victoria Eduardovna Dubranova, 33, was arraigned on a second indictment Tuesday [December 9] after being extradited to the U.S. earlier this year. She faces charges related to her alleged work with CyberArmyofRussia_Reborn, known as CARR, and NoName057(16), two groups federal prosecutors say received backing from Moscow to advance Russian geopolitical interests. 
    • “Dubranova pleaded not guilty in both cases.”

From the cybersecurity breaches and vulnerabilities front,

  • Bleeping Computer reports,
    • “MITRE has shared this year’s top 25 list of the most dangerous software weaknesses behind over 39,000 security vulnerabilities disclosed between June 2024 and June 2025.
    • “The list was released in cooperation with the Homeland Security Systems Engineering and Development Institute (HSSEDI) and the Cybersecurity and Infrastructure Security Agency (CISA), which manage and sponsor the Common Weakness Enumeration (CWE) program.
    • “Software weaknesses can be flaws, bugs, vulnerabilities, or errors found in a software’s code, implementation, architecture, or design, and attackers can abuse them to breach systems running the vulnerable software. Successful exploitation allows threat actors to gain control over compromised devices and trigger denial-of-service attacks or access sensitive data.
  • Cyberscoop relates,
    • “Security experts have observed a steady increase in malicious activity from a widening pool of attackers seeking to exploit React2Shell, a critical vulnerability disclosed last week in React Server Components.
    • “Authorities are also responding to heightened concern about the defect, with the Cybersecurity and Infrastructure Security Agency shortening the deadline for agencies to patch the vulnerability to Friday [December 12] . The agency previously set a deadline of Dec. 26 when it added CVE-2025-55182 to its known exploited vulnerabilities catalog last week.
    • “Palo Alto Networks Unit 42 said more than 50 organizations are impacted by attacks involving exploitation of the vulnerability with victims observed in the United States, Asia, South America and the Middle East.” 
  • Cybrsecurity Dive adds,
    • “React on Thursday [December 11] warned that customers will need to apply new upgrades amid the React2Shell crisis, after researchers discovered additional vulnerabilities, including a denial of service flaw and a source code exposure. 
    • “A denial of service vulnerability, tracked as CVE-2025-55184 and CVE-2025-67779, allows an attacker to craft a malicious HTTP request and send it to a Server Functions endpoint, which can lead to an infinite loop. The flaw has a severity score of 7.5. 
    • “The source code exposure, tracked as CVE-2025-55183, allows a malicious HTTP request sent to a vulnerable Server Function to unsafely return the source code of any Server Function.”
  • The American Hospital Association News lets us know,
    • “U.S. and international agencies are warning of potential cyberattacks on health care and other critical infrastructure from state-sponsored cyber actors in Russia and China.
    • “An advisory released yesterday [December 11] warns of incidents by Russian hackers using internet-facing desktop-sharing systems to access operational technology and industrial control systems for malicious activity. A Dec. 4 report warns of Chinese state-sponsored cyber actors using BRICKSTORM malware to attack VMware vSphere and Windows cloud platforms.
    • “These nation-state level threats may be difficult for civilian network defenders to counter,” said John Riggi, AHA national advisor for cybersecurity and risk. “However, robust cyber threat information sharing between the private sector and the federal government, implementation of recommended practices, and the commendable and aggressive enforcement operations by the FBI and other agencies will help mitigate the threat. Organizations should also update, integrate and routinely test emergency preparedness, cyber incident response and clinical continuity plans should there be an extended technology outage affecting hospitals directly or indirectly through a cyberattack against mission-critical third parties.”
  • CISA added seven known exploited vulnerabilities to its catalog this week.
    • December 8, 2025
      • CVE-2022-37055 D-Link Routers Buffer Overflow Vulnerability
      • CVE-2025-66644 Array Networks ArrayOS AG OS Command Injection Vulnerability
        • Cyber Press discusses the D-Link KVE here
        • F5 discusses the Array Networks KVE here.
    • December 9, 2025,
      • CVE-2025-6218 RARLAB WinRAR Path Traversal Vulnerability
      • CVE-2025-62221 Microsoft Windows Use After Free Vulnerability 
        • Cybersecurity News discusses the RARLAB KVE here.
        • Bleeping Computer discusses the Microsoft KVE here.
    • December 11, 2025
      • CVE-2025-58360 OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability 
        • Bleeping Computer discusses this KVE here.
    • December 12, 2025
      • CVE-2025-14174 Google Chromium Out-of-Bounds Memory Access Vulnerability
        • The Hacker News discusses this KVE here.
    • December 12, 2025 (double shot day, not a typo)
      • CVE-2018-4063 Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability
        • Windows Forum discusses this KVE here
  • Bleeping Computer adds,
    • “Apple has released emergency updates to patch two zero-day vulnerabilities that were exploited in an “extremely sophisticated attack” targeting specific individuals.
    • “The zero-days are tracked as CVE-2025-43529 and CVE-2025-14174 and were both issued in response to the same reported exploitation.
    • “Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26,” reads Apple’s security bulletin.”
  • Cybersecurity Dive notes,
    • “Utility-scale battery energy storage systems are facing heightened risks of attack from nation-state and criminal threat groups, and immediate action needs to be taken to secure critical industries from potential disruption, according to a white paper from Brattle Group and Dragos. 
    • BESS deployments are expected to grow between 20% and 45% over the next five years, driven by increased demand for data centers and other power requirements. At the same time, state-linked actors have turned their attention toward disrupting critical industries, such as utilities and rival nations competing with the U.S. for dominance in AI and clean energy.”
  • Per Infosecurity Magazine,
    • “A new iteration of the ClayRat Android spyware featuring expanded surveillance and device-control functions has been identified by cybersecurity researchers.
    • First seen in October, ClayRat was originally capable of stealing SMS messages, call logs and photos, as well as sending mass texts.
    • “The latest version introduces far broader capabilities by combining Default SMS privileges with extensive abuse of Accessibility Services.”

From the ransomware front,

  • Cybersecurity Dive reports,
    • “Ransomware activity reached an all-time high in 2023, totaling more than 1,500 incidents and $1.1 billion in reported payments, before dropping the following year after two high-profile law enforcement takedowns.
    • “The two critical law enforcement actions were the 2023 U.S.-led takedown of AlphV/BlackCat and the 2024 disruption of LockBit by U.S. and U.K. authorities, according to a new U.S. government study.
    • “The report by the U.S. Treasury’s Financial Crimes Enforcement Networkshows ransomware fell to 1,476 incidents in 2024, with reported payments reaching $734 million. 
    • ‘More than $2.1 billion in ransomware payments were reported between 2022 and 2024, according to the report. 
    • “The medium amount of a single ransomware transaction rose from $122,097 in 2022 to $155,257 in 2024, according to the report. The most common payment amount was less than $250,000 during the period. 
    • ‘AlphV/BlackCat was the most prevalent ransomware variant during the 2022–2024 period, according to the report. The other most reported variants included Akira, LockBit, Phobos and Black Basta.” 
  • Dark Reading adds,
    • “You may be familiar with ransomware-as-a-service (RaaS), but now there’s also packer-as-a-service.
    • “Security vendor Sophos on Dec. 6 published research on “Shanya,” a packer-as-a-service family that augments ransomware so it can avoid anti-malware software. While ransomware-as-a-service provides low-level attackers with extortion malware they might not be able to create otherwise, packers-as-a-service (PaaS) provide a shell around pre-existing ransomware that acts as an extra layer of obfuscation.
    • “Shanya covers ground previously paved by PaaS operation HeartCrypt, which over the past year has firmly entrenched itself in the modern ransomware ecosystem. Sophos’ Gabor Szappanos and Steeve Gaudreault say Shanya is “already favored by ransomware groups and taking over (to some degree) the role that HeartCrypt has played in the ransomware toolkit.”
  • and
    • “Initial access broker Storm‑0249 has shifted from noisy, easily detected phishing attacks to highly targeted campaigns that are much harder to detect and stop. 
    • “According to ReliaQuest, Storm-0249, which is known for brokering network access to ransomware operators, is increasingly weaponizing legitimate endpoint detection and response (EDR) processes as well as built-in Windows utilities to carry out post-compromise activities. This includes poking around compromised systems to gather information, setting up command-and-control (C2) channels, and staying persistent in the environment. These new tactics let Storm‑0249 slip past defenses, get deep into networks, and operate almost completely under the radar, the security vendor said.”
  • and
    • “A new attack uses SEO poisoning and popular AI models to deliver infostealer malware, all while leveraging legitimate domains. 
    • ClickFix attacks have gained significant popularity over the past year, using otherwise benign CAPTCHA-style prompts to lure users into a false sense of security and then tricking them into executing malicious prompts against themselves. These prompts are often delivered through SEO poisoning and phishing campaigns, representing one of the fancier applications of social engineering in cybercrime to date.” 
  • The Register points out,
    • “Researchers at security software vendor Huntress say they’ve noticed a huge increase in ransomware attacks on hypervisors and urged users to ensure they’re as secure as can be and properly backed up.
    • “Huntress case data revealed a stunning surge in hypervisor ransomware: its role in malicious encryption rocketed from just three percent in the first half of the year to 25 percent so far in the second half,” wrote Senior Hunt & Response Analyst Anna Pham, Technical Account Manager Ben Bernstein, and Senior Manager for Hunt & Response, Dray Agha in a Monday [December 8] post.
    • “The primary actor driving this trend is the Akira ransomware group,” the trio warned, adding that the gang, and other attackers, are going after hypervisors “in an attempt to circumvent endpoint and network security controls.”

From the cybersecurity business and defenses front,

  • Security Week reports,
    • “Enterprise cybersecurity giant Proofpoint has completed the acquisition of Germany-based Microsoft 365 security solutions provider Hornetsecurity.
    • “Financial details were not officially disclosed when news of the transaction came to light, but it was reported that Proofpoint would be paying $1 billion for its European competitor. SecurityWeek learned at the time that the deal size well exceeded $1 billion.
    • Proofpoint has now revealed that the transaction has been valued at $1.8 billion. 
    • “Through the acquisition of Hornetsecurity, Proofpoint is aggressively expanding its reach into the SMB market and strengthening its foothold in Europe.”
  • Info Bank Security adds,
    • “An identity security stalwart led by the company’s longtime founder raised $700 million to support the management of non-human identities and agentic artificial intelligence.
    • “Los Angeles-based Saviynt plans to use the Series B proceeds to invest in core platform capabilities, AI governance protocols and deep integrations with the likes of AWS, Google and CrowdStrike, said Saviynt President Paul Zolfaghari. What was once about on premise human access is now a multidimensional challenge involving extended workforces, robotic accounts and AI-driven agents, Zolfaghari said.
    • “It was an opportunity to put in place the resources necessary to deliver on the vision for the future. The interest in identity security and AI has gone up quite a bit,” he said. “The amount is just a function of the resources that we think that we need for the foreseeable future. It’s an opportunity for us to have the resources we need while still maintaining the control and the culture that has gotten us to this point.”
  • Cyberscoop relates,
    • “Global cybersecurity agencies have issued the first unified guidance on applying artificial intelligence (AI) within critical infrastructure, signaling a major shift from theoretical debate to practical guardrails for safety and reliability.
    • “The release of joint guidance on Principles for the Secure Integration of Artificial Intelligence in Operational Technology marks a meaningful milestone for critical infrastructure security because major global cybersecurity agencies, including CISA, the FBI, the NSA, the Australian Signals Directorate’s Australian Cyber Security Centre, and other partners, have aligned on a shared direction. As AI adoption accelerates across operational environments, this document moves us from theory to practice. It acknowledges AI’s promise while making clear that it also “introduces significant risks—such as operational technology (OT) process models drifting over time or safety-process bypasses” that operators must actively manage to ensure reliability.”
  • Here is a link to Dark Reading’s CISO Corner.

Friday report

From Washington, DC,

  • The Washington Post reports,
    • “House Republicans unveiled a new health care proposal Friday as they aim to address concerns about rising health insurance costs just weeks before enhanced Affordable Care Act subsidies expire.
    • “The legislation would codify and expand health plans for small businesses, fund reductions of premiums for low-income people in the individual health insurance market and increase transparency in prescription drug pricing, according to House Republican leadership aides.
    • “The proposal would also allow for a separate vote on an extension of the premium ACA tax credits, which subsidize health insurance for most of the 24 million Americans who buy their coverage from the Obamacare Marketplace — the central demand Democrats and moderate Republicans have made in the recent health care debate.
    • “The House is expected to vote on the proposal next week before leaving Washington for a two-week holiday break. If passed, it is unclear if the proposal could succeed in the Senate, where it would require 60 votes to overcome a filibuster.”
  • FEHBlog observation — This week, the Democrat leadship in the Senate offered a three year extension extension of the Biden subsidies while the Republican leadership offered a new approach with no transistion period. Both offerings were doomed to fail. The FEHBlog hopes that cooler heads prevail over the next week.
  • Govexec relates,
    • “The House voted 231-195 on Thursday to pass legislation that would nullify President Trump’s efforts to strip more than 1 million federal workers of their collective bargaining rights, sending the measure over to the Senate, where its prospects are less rosy.
    • “Twenty Republican lawmakers broke ranks to support the Protect America’s Workforce Act (H.R. 2550) on the floor. Introduced by Reps. Jared Golden, D-Maine, and Brian Fitzpatrick, R-Pa., the measure effectively nullifies Trump’s March executive order barring unions at more than 40 federal agencies under the guise of national security and bars federal agencies from terminating any union contracts that were in place prior to the edict’s signature.”
  • The American Hospital Association News lets us know,
    • “The Centers for Medicare & Medicaid Services Dec. 11 announced the launch of the Make America Healthy Again: Enhancing Lifestyle and Evaluating Value-based Approaches Through Evidence Model, a voluntary payment model that will fund up to 30 chronic disease prevention and health promotion proposals. The proposals must include evidence-based functional or lifestyle medicine interventions not covered by Original Medicare. Under the MAHA ELEVATE Model, CMS said it will evaluate necessary data on the cost and quality of such interventions to inform future decisions on the feasibility of including them in Original Medicare. The agency will release a funding notice in early 2026 for the first cohort, which will begin Sept. 1, 2026. The second cohort will begin one year later.”
  • The U.S. Office of Personnel Management announced today that it is seeking public comments on its plan to resurrect its FEHB and now also PSHB health claims data warehouse.
    • “OPM is collecting service use and cost data from FEHB and PSHB Carriers, including medical claims, pharmacy claims, encounter data, and provider data. This data will enable OPM to oversee health benefits programs and ensure they provide competitive, quality, and affordable plans. OPM requires Carriers to report necessary information and permit audits and examinations to manage the FEHB Program effectively. The Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule permits covered entities, including carriers, to disclose protected health information (PHI), including service use and cost data, to health oversight agencies, such as OPM, for oversight activities authorized under 45 CFR 165.512(d)(1).”
    • This is a legally flawed analysis. The FEHB Act, 5 U.S.C. Sec. 8910(b), states
      • “(b) Each contract entered into under section 8902 of this title shall contain provisions requiring carriers to—
      • (1) furnish such reasonable reports as the Office determines to be necessary to enable it to carry out its functions under this chapter; and
      • (2) permit the Office and representatives of the Government Accountability Office to examine records of the carriers as may be necessary to carry out the purposes of this chapter.”
    • Furnishing all claims data to OPM is a not a reasonable report in any sense of the English language, and the HIPAA Privacy Rule does not give health oversight agencies new data access rights. See Fed. Reg. 82,462, 82,528 (Dec. 28, 2000). OPM should head back to the drawing board for consultations with carriers.
    • The public comment deadline is February 10, 2026.
  • On a related note, per a CMS news release,
    • “The Centers for Medicare & Medicaid Services (CMS) is pleased to announce the 2026 CMS Burden Reduction Conference taking place February 25, 2026, from 9:00 a.m. to 1:00 p.m. ET. This year’s conference will be a hybrid event, with in-person programming at the Hubert H. Humphrey (HHH) Building in Washington, DC, and a fully supported virtual option for remote attendees. In-person attendance will be limited due to space.”
  • OPM should hold a similar event for overburdened FEHB and PSHB carriers.

From the Food and Drug Adminstration front,

  • Per Fierce Pharma,
    • “Amid a swell of regulatory successes in the myasthenia gravis arena this decade, Amgen is wading into the fray with a new indication for its monoclonal antibody Uplizna.
    • “Thursday, the FDA greenlighted Uplizna (inebilizumab) to treat generalized myasthenia gravis (gMG) in adults who are anti-acetylcholine receptor (AChR) and anti-muscle specific tyrosine kinase (MuSK) antibody positive. After two loading doses, Uplizna for gMG is administered just twice a year, Amgen noted in a Dec. 11 press release.”
  • and
    • “After a three-decade drought of new antibiotics to treat gonorrhea, the FDA has signed off on two first-in-class oral treatments for the sexually transmitted infection (STI), which affects more than 80 million people around the world each year. 
    • “On Friday, the U.S. regulator green lit Innoviva’s Nuzolvence (zoliflodacin) for uncomplicated urogenital gonorrhea. The nod comes less than 24 hours after the agency granted an approval in the same indication to GSK’s Blujepa, which was already on the market for uncomplicated urinary tract infections following its approval in March.
    • “The endorsements are similar in that both therapies are indicated for those ages 12 and older where standard of care treatment is contraindicated or where patients are intolerant or unwilling to use the first line of treatment.”
  • Cardiovascular Business tells us,
    • “The U.S. Food and Drug Administration (FDA) has granted 510(k) market clearance to the enVast mechanical thrombectomy system from Texas-based Vesalio.
    • “The company said the system offers a new approach to clot capture and the removal of large thrombus burden (LTB) in patients undergoing primary percutaneous coronary intervention (PCI). Thrombectomy is used in the coronary arteries to quickly remove clots to restore blood flow following a heart attack to minimizing myocardial damage.
    • “With FDA clearance and the upcoming U.S. launch of enVast, we are proud to introduce a device that we truly believe redefines coronary thrombectomy,” Steve Rybka, CEO of Vesalio, said in a statement. “Clinical experience internationally has consistently demonstrated its safety and effectiveness in managing complex LTB situations.”

From the public health and medical / Rx research front,

  • The Centers for Disease Control and Prevention announced today,
    • “RSV activity is increasing in the Southeastern, Southern, and Mid-Atlantic areas of the country with emergency department visits and hospitalizations increasing among children 0-4 years old. Seasonal influenza activity continues to increase in most areas of the country. COVID-19 activity is low nationally.
    • “COVID-19
      • “COVID-19 activity is low nationally.
    • “Influenza
    • “RSV
      • “RSV activity is increasing in the Southeastern, Southern, and Mid-Atlantic areas of the country with emergency department visits and hospitalizations increasing among children 0-4 years old.
    • “Vaccination
      • “It is not too late to get vaccinated ahead of the holidays. Talk to your doctor or trusted healthcare provider about what vaccines are recommended for you and your family.”
  • The American Hospital Association News adds,
    • “The Centers for Disease Control and Prevention Dec. 11 released a report that found last year’s version of the COVID-19 vaccine was 76% effective in preventing emergency department or urgent care visits for children ages 9 months to 4 years. It was 56% effective for those ages 5-17 years old. “These findings suggest that vaccination with a 2024–2025 COVID-19 vaccine dose provided children with additional protection against COVID-19–associated ED/UC encounters compared with no 2024–2025 dose,” the CDC wrote.”
  • The New York Times reports,
    • “To treat their pain, anxiety and sleep problems, millions of Americans turn to cannabis, which is now legal in 40 states for medical use. But a new review of 15 years of research concludes that the evidence of its benefits is often weak or inconclusive, and that nearly 30 percent of medical cannabis patients meet criteria for cannabis use disorder.
    • “The evidence does not support the use of cannabis or cannabinoids at this point for most of the indications that folks are using it for,” said Dr. Michael Hsu, an addiction psychiatrist and clinical instructor at the University of California, Los Angeles, and the lead author of the review, which was published last month in the medical journal JAMA. (Cannabis refers to the entire plant; cannabinoids are its many compounds.)”
  • The AP informs us,
    • “The U.S. suicide rate dropped slightly last year from some of the highest levels ever reported, preliminary data suggests. Experts say it’s hard to know exactly why, or whether the decline will continue.
    • “A little over 48,800 suicide deaths were reported in 2024, according to provisional data from the Centers for Disease Control and Prevention, roughly 500 fewer than the year before.
    • “The overall suicide rate fell to 13.7 per 100,000 people.”
  • The Washington Post relates,
    • “Solving a technical challenge that has stymied science for 40 years, researchers have built a robot with an onboard computer, sensors and a motor, the whole assembly less than 1 millimeter in size — smaller than a grain of salt.
    • “The feat, accomplished by a partnership of researchers at the University of Pennsylvania and University of Michigan, advances medicine toward a future that might see tiny robots sent into the human body to rewire damaged nerves, deliver medicines to precise areas, and determine the health of a patient’s cells without surgery.”
  • Per Healio,
    • “GLP-1 receptor agonists are not associated with increased risks for dry age-related macular degeneration or cataract development, according to two recently published studies.
    • “The data instead showed significantly reduced risk for cataracts, as well as lower risk for dry AMD, linked with the use of GLP-1s, according to Abhimanyu Ahuja, MD, an ophthalmology resident at the Oregon Health & Science University Casey Eye Institute, and colleagues.
    • “Other studies have demonstrated that these medications have anti-inflammatory and neuroprotective properties,” Ahuja told Healio. “We wondered whether they might influence the risk of conditions like macular degeneration or cataracts in older adults.”
  • Per MedTech Dive,
    • “AtriCure, whose devices are used to treat atrial fibrillation and related conditions, said Thursday the first procedures were performed in patients with its new dual energy platform.
    • “The system integrates pulsed field ablation with a radiofrequency ablation approach using the company’s cardiac clamp technology. Surgeons can use either method independently or in combination.
    • “The platform is not yet approved for use in any market. AtriCure said it expects to initiate a clinical trial in the coming year.”
  • Per Biopharma Dive,
    • “Arcus Biosciences will terminate work on a TIGIT-targeting cancer drug following a decision to cancel a Phase 3 trial because it didn’t appear likely to improve patients’ survival, the company said in a statement Friday.
    • “Called domvanalimab, the drug was being tested in combination with the immunotherapy zimberelimab and chemotherapy against Bristol Myers Squibb’s Opdivo and chemo in gastric and esophageal cancers that haven’t been treated before. Arcus said an independent data committee recommended ending the trial because the domvanalimab combination wasn’t likely to help patients live longer.
    • “The domvanalimab-based combination was the centerpiece of a partnership with Gilead Sciences that led the bigger company to buy a 33% stake in Arcus and pay $900 million just to secure rights.”

From the U.S. healthcare business and artificial intelligence front,

  • Healthcare Dive reports,
    • “Hospitals are managing series of cost, workforce and reimbursement challenges as they navigate uncertainty at the close of 2025 and beyond, according to a new report from Kaufman Hall.
    • “Health systems are attempting to mitigate the impact of tariffs and increasingly expensive supplies, according to Kaufman Hall’s 2025 Health System Performance Outlook report. At the same time, hospitals are trying to retain clinical staff and outsource other functions, according to the report.
    • “Only 30% of hospital leaders surveyed expect balance sheets to improve in 2026, while 30% expect them to lower and 40% projected little change. The split highlights how uncertain health systems feel about the future, especially from recent regulatory changes in the “Big Beautiful Bill” and the likely expiration of Affordable Care Act subsidies.”
  • Beckers Hospital Review relates,
    • “Dallas-based Tenet Healthcare reached a record high stock price of $218 on Nov. 25, capping off a transformative year that highlights investor confidence in the system’s ongoing shift toward specialty and outpatient care.
    • “As of Dec. 12, Tenet stock remained elevated at $199, up nearly 60% from $125 on Jan. 2. The spike reflects investor optimism around Tenet’s long-term strategy to transform into a value-based care enterprise anchored by its ambulatory business, United Surgical Partners International.
    • “In 2024, Tenet sold 14 hospitals for a combined $4.8 billion as part of a sweeping overhaul. The system now operates 50 acute-care hospitals while aggressively expanding its ambulatory surgery center footprint through USPI.”
  • Beckers Payer Issues tells us about 14 payer AI moves this year and “Turquoise Health has detailed its first comprehensive payer price transparency scores in its 2025 impact report, evaluating machine-readable file quality across 97 payers.” 

Tuesday report

From Washington, DC,

  • MedPage Today reports,
    • “The number of Americans signing up for Affordable Care Act (ACA) health insurance for 2026 is moderately higher than it was at a similar time last year, initial new federal data show, even as subsidies set to expireopens in a new tab or window at the end of 2025 will make the coverage more expensiveopens in a new tab or window for many.
    • “Seen at face value, the data from the Centers for Medicare and Medicaid Services seem to defy predictions that many Americans facing pricier plans would drop out of marketplace coverage altogether next year. But experts caution that the numbers are an incomplete snapshot of total enrollment, which could still show a decline by the end of the open enrollment period.
    • “Overall, it’s just too early to know what any of this means,” said Jason Levitis, a senior fellow in the health policy division at the Urban Institute.
    • “The data released Friday show that by day 29 of the window for Americans to shop for ACA plans this year, nearly 5.8 million people had picked one. That’s nearly 400,000 more enrollments than by day 30 of the open enrollment period last year.
    • Meanwhile, this year’s enrollment numbers are about 1.5 million lower than the 7.3 million or so people who had signed up 32 days into the open enrollment period 2 years ago, showing there is some fluctuation year to year in when people sign up for coverage.
    • “In most states, for Americans who want coverage to start Jan. 1, the window to shop for ACA coverage began Nov. 1 and ends Dec. 15. People who want their coverage to start later can continue to select plans through Jan. 15.”
  • The Wall Street Journal adds,
    • “Senate Majority Leader John Thune (R., S.D.) said he would hold a vote later this week on a Republican measure aimed at controlling healthcare costs, amid party division over how best to head off big price increases next year for millions of households.
    • “Thune said Republicans have coalesced around legislation from Sens. Bill Cassidy (R., La.) and Mike Crapo (R., Idaho) [discussed in yesterday’s FEHBlog post] that would put as much as $1,500 a year into tax-advantaged health savings accounts when paired with lower-priced insurance plans in 2026 and 2027. The proposal doesn’t extend enhanced Affordable Care Act subsidies, which are due to expire after this year.
    • “The measure aims to provide an alternative to a Democratic proposal that extends the ACA subsidies for three more years. Votes on the two plans in the GOP-controlled Senate are set for Thursday, as Thune follows through on a promise made to Democrats as a condition for ending the government shutdown last month.
    • “So there will be something out there that Republicans will be able to talk about and support and vote for, and then we’ll see what happens Thursday,” Thune said. If neither proposal gets the 60 votes required to advance in the Senate, he said, “then we’ll see where it goes from there.”
  • Per a Senate news release,
    • “U.S. Senator Bill Cassidy, M.D. (R-LA), chair of the Senate Health, Education, Labor, and Pensions (HELP) Committee, is seeking information from stakeholders regarding the American Medical Association’s (AMA) monopoly of Current Procedural Terminology (CPT®) codes and its impact on patients, providers, and health care costs. Cassidy is asking stakeholders with relevant experience and knowledge of CPT ® coding contracts with the AMA to inform the Committee’s inquiry by responding to this questionnaire.
    • “As chair of the HELP Committee, Cassidy is using all tools at his disposal to lower costs for American patients. Thus far, the AMA evaded questions and failed to cooperate with Cassidy’s inquiry. If the AMA does not respond in a fulsome and transparent manner by December 15, 2025, the Chairman is committed to finding answers by other means.
    • “The federal government mandated the use of CPT codes. This creates the potential for abuse in that if someone has to buy your product, you can charge them what you want,” said Dr. Cassidy. “There may be nothing wrong here, but we should get answers to make sure the CPT system is working for the American patient and for the American health care system.”
  • Beckers Hospital Review tells us,
    • “Nearly 4 million Medicare-eligible Americans face heightened risk of disrupted medication access as restructuring efforts by the U.S. Postal Service slow mail delivery in rural and underserved communities reliant on mail-order prescriptions, according to a Dec. 4 analysis from The Brookings Institution
    • “In 2024, USPS launched its Regional Transportation Optimization initiative, which consolidates mail processing into regional hubs. While the initiative aims to improve efficiency, early analyses suggest it has exacerbated delivery slowdowns in rural areas, according to the report.”
  • The American Hospital Association News informs us,
    • “The Centers for Medicare & Medicaid Services Dec. 9 issued a proposed rule that would make changes to the Increasing Organ Transplant Access Model beginning July 1, 2026. IOTA is a six-year mandatory model for certain kidney transplant hospitals that began July 1 of this year. To comply with statutory requirements, CMS proposes to modify the eligible kidney transplant hospital criteria to exclude Department of Veterans Affairs medical facilities and military medical treatment facilities. The agency also proposes to raise the low-volume threshold from 11 kidney transplants performed annually during each of the baseline years to 15. Regarding IOTA participant performance, CMS proposes updates to the composite graft survival rate metric, including adding a risk-adjustment methodology that includes several transplant recipient and donor characteristics. In addition, CMS proposes other policy changes related to repayments, the extreme and uncontrollable circumstances policy, transparency and public posting of information, voluntary health equity plans, beneficiary protections, monitoring activities, and remedial actions and termination.” 
  • Modern Healthcare relates,
    • “Health insurance companies spent two years getting ready for a new Medicare Advantage quality metric intended to tackle health disparities. Then the government pulled the plug.
    • “The Excellent Health Outcomes for All measure — also known as EHO4All and formerly known as the health equity index— likely won’t be part of the Medicare Advantage Star Ratings program in 2027 after all, the Centers for Medicare and Medicaid proposed in a draft regulation last month.
    • “It’s a mixed bag for the insurance sector. In conjunction with implementing EHO4All, CMS also planned to scrap the Star Ratings program’s so-called reward factor, which benefits companies that demonstrate high quality scores over multiple years. But other companies stood to gain from an emphasis on health equity. 
    • “Moreover, the industry at large carried out intensive preparations to boost their performance on EHO4All measures, which were intended to boost insurers that cover large numbers of beneficiaries who qualify for both Medicare and Medicaid, are eligible for low-income subsidies, or have disabilities.”

From the Food and Drug Administration front,

  • Beckers Hospital Review reports,
    • “The FDA has launched a safety review of approved respiratory syncytial virus therapies for infants, including Beyfortus from Sanofi and AstraZeneca and Enflonsia from Merck, Reuters reported Dec. 9.
    • “Senior executives from the three companies were informed last week that the agency would seek further data on the therapies following internal concerns raised by FDA officials appointed under Health and Human Services Secretary Robert F. Kennedy Jr. Tracy Høeg, MD, PhD, recently namedacting director of the FDA’s Center for Drug Evaluation and Research, initiated the safety inquiry over the summer. As a noted vaccine skeptic, the appointment of Dr. Høeg has raised serious concerns among healthcare experts.”
  • Bloomberg Law lets us know,
    • “The FDA’s effort to curb high drug costs by accelerating approvals of cheaper medicines similar to expensive biologics will need other policy reforms to boost access to the biosimilars, drug pricing experts say. 
    • “The Food and Drug Administration is seeking to lower drug costs by simplifying the development of biosimilars, products that are highly similar to FDA-approved biologics, have no clinically meaningful differences, and can treat patients the same way. Biologics, such as AbbVie Inc.‘s blockbuster treatment Humira for rheumatoid arthritis and Merck & Co.‘s cancer medicine Keytruda, are complex drugs made from sources such as plant or animal cells. 
    • “Biosimilars are often available at a lower cost compared to biologics. While insurance varies for patients, the list price of Humira can run above $6,000 a dose. Amgen Inc.‘s Amjevita, a biosimilar to the inflammatory drug, can be purchased at either 55% or 5% below Humira’s list price.
    • “The FDA action, however, might not immediately yield patient access to the cheaper medicines without reforming other policies that seek to make biosimilars available upon approval, drug pricing experts say. Biosimilars often face hurdles before hitting the market, frequently due to patent litigation, agreements between drug companies to defer entry, and how they’re treated in health insurers’ prescription drug plans.”
  • Per an FDA news release,
    • “The U.S. Food and Drug Administration today approved Augmentin XR (amoxicillin-clavulanate potassium) under the Commissioner’s National Priority Voucher (CNPV) pilot program, marking the first approval achieved through this review pathway. The approval was completed in just two months, representing a major reduction of the review timeline for this type of application.
    • “Over the last few decades, America lost control of supply chains for key medicines we depend on. That chapter is over – we’re entering a new era of manufacturing here at home,” said FDA Commissioner Marty Makary, M.D., M.P.H. “This first drug approval under the CNPV pilot program will strengthen domestic manufacturing and increase our national security.”
    • “The Augmentin XR application demonstrated clear alignment with the CNPV program’s national health priorities by strengthening the U.S. drug supply chain through enhanced domestic manufacturing capacity at a U.S. facility. This approval will also help address antibiotic shortages in the U.S. that have plagued the healthcare system over the past two decades.”
  • and
    • “The U.S. Food and Drug Administration today approved Waskyra (etuvetidigene autotemcel), the first cell-based gene therapy for the treatment of Wiskott-Aldrich syndrome (WAS). Waskyra is indicated for pediatric patients six months and older and adults with WAS who have a mutation in the WAS gene and for whom hematopoietic stem cell transplantation (HSCT) is appropriate and no suitable human leukocyte antigen (HLA)-matched related stem cell donor is available.
    • “Today’s approval is a transformative milestone for patients with Wiskott-Aldrich syndrome, offering the first FDA-approved gene therapy that uses the patient’s own genetically corrected hematopoietic stem cells to treat the disease,” Vinay Prasad, M.D., M.P.H., Chief Medical and Scientific Officer and Director of the FDA’s Center for Biologics Evaluation and Research. “The FDA continues to exercise flexibility in the regulatory approach for rare diseases by considering all available data sources, including as appropriate data from expanded access programs, to facilitate the advancement of life-changing treatments while ensuring scientific requirements are satisfied.”
  • Per MedTech Dive,
    • “Sometimes, the line between medical and wellness products can blur. Regulators’ pushback on a blood pressure feature that Whoop incorporated into its wellness wristband illustrates the challenges wearables developers face as they add increasingly sophisticated features.
    • “Whoop received a warning letter from the Food and Drug Administration this summer after rolling out the blood pressure offering without regulatory authorization.
    • “The company has pushed back on the warning letter, however, arguing that blood pressure is a wellness feature. The FDA disagreed, saying blood pressure is inherently related to a medical diagnosis. 
    • “The FDA isn’t likely to concede on its challenge, experts said. Whoop’s skirmish with the FDA offers lessons on where to draw the line between wellness and medical features.”

From the judicial front,

  • Bloomberg Law reports,
    • “The US Justice Department is weighing a challenge to a deal between two of the largest companies offering software to small, independent pharmacies, as antitrust enforcers step up their focus on the health-care industry.
    • “The deal, which the companies didn’t publicly announce, involves the acquisition ofMicro Merchants Systems, the operator of pharmacy management software platform PrimeRx, by RedSail Technologies, said the people, who asked not to be named discussing a confidential matter. Micro Merchants is backed by TA Associates Management, while RedSail is the result of multiple acquisitions backed by investment firms including Francisco Partners. 
    • “Representatives of the companies met with DOJ antitrust chief Gail Slater in late November, said the people. Such meetings indicate significant government opposition to a deal, although they don’t always precede a federal lawsuit if the companies are able to make proposals that allay the agency’s concerns. Companies submit confidential filings to US authorities as part of a merger review process.”
  • STAT News relates,
    • “In a closely watched case, the U.S. solicitor general has urged the Supreme Court to review a controversy over so-called skinny labels for medicines, arguing that an appeals court finding threatens the availability of lower-cost generic drugs.
    • “Skinny labeling refers to a process in which a generic drug company seeks regulatory approval to market its medicine for a specific use, but not other patented uses for which a brand-name drug is prescribed. For instance, a generic drug could be marketed to treat one type of heart problem, but not another. In doing so, the generic company seeks to avoid lawsuits claiming patent infringement.” * * *
    • “Doubts were raised about the maneuver, however, when the Supreme Court two years ago declined to hear an appeal of a lower court ruling, which questioned the practice. Now, this second case is being seen as a test for whether skinny labeling can survive as a way for generic companies to market medicines, according to legal experts following the issue.”
  • The Wall Street Journal brings us to date on Luigi Mangione’s evidence hearing in New York state court.

From the public health and medical / Rx research front,

  • ABC News reports,
    • “Concerns about the flu spreading in the U.S. are growing as the U.K. continues to see a spike in cases among children and young adults.
    • “The increased number of cases in the U.K., could be a predictor for the flu season in the U.S., according to ABC News chief medical correspondent Dr. Tara Narula.
    • “We know that England or other places can be a marker for what is going to happen here, because their flu season happens a few weeks earlier than ours,” Narula said on “Good Morning America” Monday, adding, “We have low numbers of cases so far but they are increasing.”
    • “Some hospitals are starting to implement flu season visitor restrictions, including the Detroit Medical Center and Children’s Hospital of Michigan, which are allowing, as of Monday, up to two visitors per patient and only those 13 years of age and older are permitted on inpatient hospital floors or in observation units.
    • “According to data from the Centers for Disease Control and Prevention, flu activity in the U.S. is up at least 7% in the last week, and so far, there have been nearly 2 million illnesses, 19,000 hospitalizations, and 730 deaths from the flu.”
  • The Green Science Policy Institute tells us,
    • “New research led by the California Department of Public Health and partners found that replacing foam-containing furniture made before 2014 would cut in half levels of certain harmful flame retardants in people’s bodies in just over a year. Published today in the peer-reviewed journal Environmental Pollution, the study is the first to show measurable health benefits from California’s 2014 furniture flammability standard update, which made it possible for manufacturers to comply without adding chemical flame retardants.
    • “Specifically, volunteers who swapped their old sofas and living room chairs for new, flame-retardant-free versions saw their blood concentrations of polybrominated diphenyl ethers (PBDEs) drop by half in just 1.4 years. Due to the overall declining use of these chemicals, levels in participants who did not replace furniture dropped as well, but two to four times more slowly. PBDEs are linked to cancer risk, hormone disruption, and neurodevelopmental effects. Epidemiological studies have shown that the average U.S. child has lost three to five IQ points from exposure to one PBDE. Further, a recent research paper estimated those with highest levels of this flame retardant in their blood had about four times the risk of dying from cancercompared with people with the lowest levels.
    • “This study shows that the update to California’s flammability standard not only changed what goes into furniture—it changed what goes into people’s bodies,” said co-lead author Kathleen Attfield, a Research Scientist Supervisor with the California Department of Public Health. “Through biomonitoring, we can assess how policy changes and consumer choices can work together to lower exposures to toxic chemicals.”
  • NBC News reports,
    • “Despite previous excitement around a potential link between GLP-1 drugs and a reduced risk of cancer, new research suggests the popular medications “probably have little or no effect” on a person’s risk of developing one of the 13 obesity-related cancers.
    • “The findings, published Monday in the Annals of Internal Medicine, may seem counterintuitive, said co-author Dr. Cho-Han Chiang, who conducted the study earlier this year as an internal medicine resident at Mount Auburn Hospital, a Harvard Medical School teaching hospital in Cambridge, Massachusetts.” * * *
    • “The new study has two major limitations, Chiang said. One is that none of the nearly 50 trials his team analyzed was designed to measure cancer outcomes.
    • “Dr. Kandace McGuire, chief of breast surgery at the Massey Comprehensive Cancer Center at Virginia Commonwealth University, said that might explain the counterintuitive nature of the findings.
    • “When you take a bunch of studies that weren’t looking at cancer risk and you throw them together, sometimes you find things that are contrary to what you would hypothesize,” said McGuire, who wasn’t involved in the research. “Some of that may be just the makeup of the studies, rather than the actual data itself.”
    • “From a cancer prevention perspective, I think more data is needed,” Chiang said, noting that there’s also a lack of data on GLP-1 usage among patients who already have cancer.”
  • Health Day points out,
    • “Laughing gas might live up to its name for people struggling with depression, a major new study says.
    • “Treatment with nitrous oxide can provide rapid relief for people with depression, especially those who aren’t helped by antidepressants, researchers reported recently in the journal eBioMedicine.
    • “This is a significant milestone in understanding the potential of nitrous oxide as an added treatment option for patients with depression who have been failed by current treatments,” senior researcher Dr. Steven Marwaha, an academic psychiatrist with the University of Birmingham in the U.K., said in a news release.
    • “This population has often lost hope of recovery, making the results of this study particularly exciting,” Marwaha added.”
  • Today was the last day of the 2025 American Society for Hematology conference.
    • Per BioPharma Dive,
      • “A regimen involving Johnson & Johnson’s dual-acting drug Tecvayli could be curative when used early in the disease course of people with multiple myeloma, according to data disclosed Tuesday.
      • “Released at the annual meeting of the American Society of Hematology in Orlando, the results come from a trial called MajesTEC-3. J&J in October claimed early success for the study, which evaluated Tecvayli alongside another J&J drug called Darzalex, against Darzalex and a standard combination in people whose disease had advanced after one to three treatment lines. But it didn’t provide specific details, saving them for a spotlighted presentation at ASH on Tuesday.
      • “According to those results, the Tecvayli-Darzalex combination cut the relative risk of disease progression or death by 83% when compared to Darzalex and other therapies. Progression was also uncommon for treatment recipients who went six months without relapsing. According to J&J, 90% of those enrollees were still progression-free three years after the study’s start, leading researchers to suggest the combination could have curative potential.
      • “The efficacy is truly remarkable with this combination,” said Surbhi Sidana, an associate medical professor at Stanford University and a trial investigator. “We can see a light at the end of our tunnel with all of these therapies for our patients, having maybe a functional cure in the future.”
  • BioPharma Dive adds,
    • “An experimental Novartis drug helped bring an autoimmune condition causing low platelet counts under control in a Phase 3 trial, further lifting the prospects of a therapy the company acquired in a multibillion-dollar deal last year.
    • “The drug, ianalumab, acts by destroying misfiring immune cells and blocking signaling that creates new ones. Novartis has been testing it in a disorder called immune thrombocytopenia, in which the body erroneously wipes out blood-clotting platelets. The company intends for the drug to work hand-in-hand with another therapy, Promacta, that it sells for the condition.”

From the U.S.healthcare business front,

  • Fierce Healthcare reports,
    • “Healthcare giant CVS Health boosted its outlook for the year as part of its investor day on Tuesday.
    • “The company said it now expects full-year revenues of at least $400 billion and earnings per share (EPS) between $6.60 and $6.70. Previous estimates projected at least $397.3 billion in revenue and EPS of $6.55 to $6.65.
    • “CVS also projects its compound annual growth rate to be in the mid-teens for the next three years, reflecting the efforts it’s made to improve performance at multiple units. For example, CVS said it’s on track to return to target margins at Aetna, and it’s driving sustained earnings at CVS Pharmacy.
    • “We are closing out 2025 with meaningful momentum across our businesses and we expect another year of strong earnings growth in 2026,” said Chief Financial Officer Brian Newman in a press release. “We are committed to doing what we say.”
  • Fierce Pharma tells us,
    • “Eli Lilly has unveiled the location of the third of its four large-scale manufacturing facilities that it plans to build in the U.S.
    • “The drugmaker has selected Huntsville, Alabama, as the site of a $6 billion plant that will produce active pharmaceutical ingredients (APIs) for peptide and small-molecule medicines, including the highly anticipated GLP-1 weight-loss pill, orforglipron.
    • “Lilly plans to employ 450 at the complex, including engineers, scientists, operations personnel and lab technicians. The Indianapolis-based company expects to begin construction in 2026 and complete the facility in 2032. Lilly estimated that the project will also generate 3,000 construction jobs.”
  • Beckers Hospital Review informs us,
    • “Pfizer has entered into a global collaboration and license agreement with YaoPharma for the development, manufacturing and commercialization of YP05002, a small-molecule GLP-1 receptor agonist currently in phase 1 development for chronic weight management.
    • “YaoPharma, a subsidiary of Shanghai Fosun Pharmaceutical Group, will complete the ongoing phase 1 clinical trial and grant Pfizer exclusive worldwide rights to further develop and commercialize the therapy, according to a Dec. 9 news release.
    • “Pfizer will pay $150 million upfront and may pay up to $1.935 billion in development, regulatory and commercial milestone payments, along with tiered royalties on sales if the therapy is approved.”
    • Fierce Health relates,
      • “Artificial intelligence was a key theme in a session on how digital tools are changing the payer industry at this year’s Fierce Health Payer Summit.
      • “The panel took place last Thursday at the annual event and was moderated by Staff Writer Emma Beavins. The panelists spoke about the importance of improving payer-provider relationships and the member experience through AI and data-sharing.
      • “Consumers are used to the convenience offered by platforms like Netflix and Amazon, yet healthcare is lagging. AI can help streamline the member experience, including by surfacing transparent pricing. Doing so carries a high return on investment, Brittany Poche, director of solutions at revenue cycle management company Norwood, said. “Having that whole transparency and that experience, that is going to really move us,” Poche said on the panel.”

    Cybersecurity Saturday

    From the cybersecurity policy and law enforcement front,

    • Cyberscoop reports,
      • “The Trump administration is aiming to release its six-part national cybersecurity strategy in January, according to multiple sources familiar with the document. The document, which is a mere five pages long, will possibly be followed by an executive order to implement the new strategy.
      • “The administration has been soliciting feedback in recent days, which one source considered more of a “messaging” document than anything, with more important work to follow.
      • “According to sources familiar with the strategy, the six “pillars” focus on cyber offense and deterrence; aligning regulations to make them more uniform; bolstering the cyber workforce; federal procurement; critical infrastructure protection; and emerging technologies.”
    • and
      • “A bipartisan group of senators are looking to tackle health care cybersecurity by reviving legislation that would update regulations and guidelines, authorize grants, offer training and clarify federal agency roles.
      • “It’s a subset of cybersecurity where Congress hasn’t enacted any sweeping changes to date. The resurrected Health Care Cybersecurity and Resiliency Act from Health, Education Labor and Pension Committee Chairman Bill Cassidy, R-La., and his colleagues on both sides of the aisle emerges from a 2023 bipartisan health care cybersecurity working group.
      • “Cassidy and his cosponsors — Mark Warner, D-Va., Maggie Hassan, D-N.H., and John Cornyn, R-Tex. — first introduced the bill in late November last year, with little time left in the session to take action on it before Congress adjourned at the beginning of 2025.
      • “Cyberattacks in the health care sector can have a wide range of devastating consequences, from exposing private medical information to disrupting care in ERs — and it can be particularly difficult for medical providers in rural communities with fewer resources to prevent and respond to these attacks,” Hassan said in a news release Thursday.”
    • and
      • “Sean Plankey’s nomination to lead the Cybersecurity and Infrastructure Security Agency looks to be over following his exclusion from a Senate vote Thursday [December 4, 2025} to move forward on a panel of Trump administration picks.
      • “Multiple senators placed holds or threatened holds on his nomination, some related to cybersecurity. But the hold from Sen. Rick Scott, R-Fla., appeared to be the biggest hurdle. With Plankey’s exclusion from the resolution to advance a bevy of nominees that got a key vote Thursday, procedural issues make it unlikely that he will be the nominee going forward, sources told CyberScoop. The administration would have to re-submit his name for nomination next year.
      • “Scott’s hold was related to Department of Homeland Security Secretary Kristi Noem partially terminating a Coast Guard cutter program contract with Florida-based Eastern Shipbuilding Group, multiple sources told CyberScoop. The Government Accountability Office issued a critical report on the program.
      • “While awaiting confirmation, Plankey, a 13-year Coast Guard officer, has been serving as senior adviser to the secretary for the Coast Guard.” 
    • Cybersecurity Dive tells us,
      • “A pair of U.S. senators wants to know how the government is tracking and responding to hackers’ use of AI platforms to conduct cyberattacks.
      • “The emerging threat to U.S. cybersecurity posed by foreign adversaries deploying autonomous AI systems requires a robust response from your office and other federal agencies,” Sens. Maggie Hassan, D-N.H., and Joni Ernst, R-Iowa, wrote in a Tuesday letter to National Cyber Director Sean Cairncross.
      • “The bipartisan letter comes several weeks after Anthropic revealed that Chinese government-linked hackers had manipulated the company’s Claude platform into breaching companies and government agencies around the world. The attack, which Anthropic called “the first documented case of a large-scale cyberattack executed without substantial human intervention,” has exacerbated worries within the security community about the growing offensive capabilities of AI tools.”
    • In this regard, Cyberscoop calls attention to “More evidence your AI agents can be turned against you Aikido found that AI coding tools from Google, Anthropic, OpenAI and others regularly embed untrusted prompts into software development workflows.”
    • Dark Reading relates,
      • “[On December 3, 2025,] [a] collection of agencies published guidance on the best way to defend AI deployments in operational technology (OT)
      • “Such guidance seems necessary, given that on their own, AI and OT environments are two of the most sensitive, high-profile attack surfaces. AI is a prime target, due to the wide range of attack techniques emerging constantly, and OT because of its use in critical and industrial settings.
      • “The guidance was authored by the US’s CISA, FBI, and NSA Artificial Intelligence Security Center; the Australian Signals Directorate’s Australian Cyber Security Centre; the Canadian Centre for Cyber Security; the German Federal Office for Information Security; the Netherlands National Cyber Security Centre; the New Zealand National Cyber Security Centre; and the UK’s National Cyber Security Centre.”
    • Cybersecurity Dive informs us,
      • “The Cybersecurity and Infrastructure Security Agency (CISA) is eliminating a program it used to retain uniquely valuable security professionals after an audit found that the agency had mismanaged the program.
      • “In 2015, CISA’s predecessor inside the Department of Homeland Security created the Cybersecurity Retention Incentive (CRI) program to offer extra money to employees who were likely to leave the government for higher-paying private-sector jobs. CRI incentives were intended to apply only to a narrow subset of CISA employees with specialized cybersecurity skills. But, in September, the DHS inspector general found that CISA was offering the incentives too broadly.
      • “In a statement to Cybersecurity Dive, CISA said it would soon end the CRI program.”
    • Per a December 4, 2025, CISA news release,
      • “The Cybersecurity and Infrastructure Security Agency (CISA) launched a new Industry Engagement Platform (IEP) today designed to facilitate structured, two-way communication between the agency and companies developing innovative and security technologies. The IEP enables CISA to better understand emerging solutions across the technology ecosystem while giving industry a clear, transparent pathway to engage with the agency.
      • “With the launch of this new platform, we’re opening the door wider to innovation—giving industry a direct line to share the tools and technologies that can help CISA stay ahead of evolving threats,” said CISA Acting Director Madhu Gottumukkala. “The private sector drives innovation and this collaboration is essential to our national resilience.”
      • “The IEP allows organizations – including industry, non-profits, academia, government partners at all and the research community – with a structured process to request conversations with CISA subject matter experts to describe new technologies and capabilities. These engagements give innovators the opportunity to present solutions that may strengthen our nation’s cyber and infrastructure security.”
    • Cyberscoop relates,
      • “Twin brothers Muneeb and Sohaib Akhter were arrested in Alexandria, Va., Wednesday [December 3, 2025} for allegedly stealing and destroying government data held by a government contractor minutes after they were fired from the company earlier this year, the Justice Department said.
      • “Prosecutors accuse the 34-year-old brothers of the crimes during a weeklong spree in February, compromising data from multiple federal agencies including the Department of Homeland Security, Internal Revenue Service and the Equal Employment Opportunity Commission.
      • “Authorities did not name the federal government contractor, which provides services and hosts data for more than 45 federal agencies, but the company was previously identified as Washington-based Opexus in a Bloomberg report about the insider attack earlier this year. Opexus did not immediately respond to a request for comment.”
    • Security Week notes,
      • “The cryptocurrency mixer Cryptomixer has been shut down by law enforcement agencies in Europe for facilitating cybercrime and money laundering, Europol announced on Monday [December 1, 2025}.
      • “Accessible both from the clear and the dark web, Cryptomixer was a mixing service (tumbler) designed to help customers obscure the trail of their cryptocurrency by combining their deposits with those from other users into a large, pooled fund before sending back an equivalent amount of untraceable coins to a wallet specified by the customer.”

    From the cybersecurity breaches and vulnerabilities front,

    • Bleeping Computer reports,
      • “Earlier today [December 5, 2025], Cloudflare experienced a widespread outage that caused websites and online platforms worldwide to go down, returning a “500 Internal Server Error” message.
      • “The internet infrastructure company has now blamed the incident on the rollout of emergency mitigations designed to address a critical remote code execution vulnerability in React Server Components, which is now actively exploited in attacks.
      • “The issue was not caused, directly or indirectly, by a cyber attack on Cloudflare’s systems or malicious activity of any kind. Instead, it was triggered by changes being made to our body parsing logic while attempting to detect and mitigate an industry-wide vulnerability disclosed this week in React Server Components,” Cloudflare CTO Dane Knecht noted in a post-mortem.
      • “A subset of customers were impacted, accounting for approximately 28% of all HTTP traffic served by Cloudflare.”
    • and
      • “Financial software provider Marquis Software Solutions is warning that it suffered a data breach that impacted dozens of banks and credit unions across the US.
      • “Marquis Software Solutions provides data analytics, CRM tools, compliance reporting, and digital marketing services to over 700 banks, credit unions, and mortgage lenders.
      • “In data breach notifications filed with US Attorney General offices, Marquis says it suffered a ransomware attack on August 14, 2025, after its network was breached through its SonicWall firewall.
      • “This allowed the hackers to steal “certain files from its systems” during the attack.
      • “The review determined that the files contained personal information received from certain business customers,” reads a notification filed with Maine’s AG office.”
    • Cyberscoop relates,
      • “Cybersecurity authorities and threat analysts unveiled alarming details Thursday [December 4, 2025] about a suspected China state-sponsored espionage and data theft campaign that Google previously warned about in September. The outlook based on their limited visibility into China’s sustained ability to burrow into critical infrastructure and government agency networks undetected, dating back to at least 2022, is grim.
      • “State-sponsored actors are not just infiltrating networks, they are embedding themselves to enable long-term access, disruptions and potential sabotage,” Nick Andersen, executive assistant director for cybersecurity at the Cybersecurity and Infrastructure Security Agency, said during a media briefing.
      • “Brickstorm, a backdoor which Andersen described as a “terribly sophisticated piece of malware,” has allowed the attackers to achieve persistent access with an average duration of 393 days to support immediate data theft and follow-on pivots to other malicious activity, Austin Larsen, principal analyst at Google Threat Intelligence Group, told CyberScoop.
      • “We believe dozens of organizations in the United States have been impacted by Brickstorm, not including downstream victims,” Larsen said.
      • “CISA, the National Security Agency and the Canadian Centre for Cyber Security released an analysis report on Brickstorm, which targets VMware vSphere and Windows environments to conceal activity, achieve lateral movement and tunnel into victim networks while also automatically reinstalling or restarting the malware if disrupted. CISA provided indicators of compromise based on eight Brickstorm samples it obtained from victim organizations.”
    • Cybersecurity Dive adds,
      • “A China-nexus threat actor hacked into VMware vCenter environments at U.S.-based companies before deploying Brickstorm malware, security firm CrowdStrike warned in a blog post published Thursday.
      • “The threat actor, tracked under the name Warp Panda, targeted multiple industries during the summer of 2025, including legal, technology and manufacturing firms. 
      • “Warp Panda has targeted entities mainly in North America and Asia Pacific in an effort to support strategic objectives of the Chinese Communist Party, according to CrowdStrike. These include economic competition, advancing their technology and growing regional influence.”
    • CISA added four known exploited vulnerabilities to its catalog this week.
    • Per Bleeping Computer,
      • An ongoing phishing campaign impersonates popular brands, such as Unilever, Disney, MasterCard, LVMH, and Uber, in Calendly-themed lures to steal Google Workspace and Facebook business account credentials.
      • Although threat actors targeting business ad manager accounts isn’t new, the campaign discovered by Push Security is highly targeted, with professionally crafted lures that create conditions for high success rates.
      • Access to marketing accounts gives threat actors a springboard to launch malvertising campaigns for AiTM phishing, malware distribution, and ClickFix attacks.
    • Cybersecurity Dive notes,
      • “Distributed denial of service attacks rose sharply during the third-quarter, fueled by record-level attacks from the Aisuru botnet, comprising between one and four million hosts across the globe, according to a report released Wednesday by Cloudflare. 
      • “The number of attacks rose 54% quarter over quarter, averaging about 14 hyper-volumetric attacks daily, according to Cloudflare. Researchers called the scale of these attacks “unprecedented,” reaching 29.7 terabits per second and 14.1 billion packets per second. 
      • “The record-breaking 29.7 Tbps attack was a User Datagram Protocol carpet-bombing attack that hit an average of 15,000 destination ports per second, according to Cloudflare. 
      • “Aisuru targeted a number of critical industries, including telecommunications, financial services, hosting providers and gaming companies.” 

    From the ransomware front,

    • Dark Reading warns us,
      • “The Ransomware Holiday Bind: Burnout or Be Vulnerable
      • “Ransomware groups target enterprises during off-hours, weekends, and holidays when security teams are stretched thin and response times lag.”
    • Per Bleeping Computer,
      • “American pharmaceutical firm Inotiv is notifying thousands of people that they’re personal information was stolen in an August 2025 ransomware attack.
      • “Inotiv is an Indiana-based contract research organization specializing in drug development, discovery, and safety assessment, as well as live-animal research modeling. The company has about 2,000 employees and an annual revenue exceeding $500 million.
      • “When it disclosed the incident, Inotiv said that the attack had disrupted business operations after some of its networks and systems (including databases and internal applications) were taken down.
      • “Earlier this week, the company revealed in a filing with the U.S. Securities and Exchange Commission (SEC) that it has “restored availability and access” to impacted networks and systems and that it’s now sending data breach notifications to 9,542 individuals whose data was stolen in the August ransomware attack.
      • “Our investigation determined that between approximately August 5-8, 2025, a threat actor gained unauthorized access to Inotiv’s systems and may have acquired certain data,” it says in letter samples filed with Maine’s attorney general.”
    • Help Net Security explains “how a noisy ransomware intrusion exposed a long-term espionage foothold.”
      • “Getting breached by two separate and likely unconnected cyber attack groups is a nightmare scenario for any organization, but can result in an unexpected silver lining: the noisier intrusion can draw attention to a far stealthier threat that might otherwise linger undetected for months.”
    • CXO Revolutionaries offers management lessons from the ransomware attack against the State of Nevada this past summer.

    From the cybersecurity business and defenses front,

    • SC Media reports,
      • “Cybersecurity startup 7AI announced Dec. 4 that it raised $130 million in Series A funding 10 months after emerging from stealth in February. 
      • “The funding round is the largest Series A in history for cybersecurity, the company stated in its announcement, and brings its total amount raised to $166 million. 7AI was founded by two former executives and founders of the security firm Cybereason, former CEO Lior Div and former CTO Yonatan Striem-Amit.
      • “We’re at an agentic security inflection point that changes the equation entirely. Instead of security teams drowning in investigations that take hours, our AI agents complete them in minutes at a speed, accuracy, and consistency that’s difficult for humans and automation to match,” Div said. “… We have the proof, and it’s in production right now: our AI agents do the investigation work so security teams can finally do human work: strategic threat hunting, proactive security and innovation through AI transformation.”
      • “Over the last 10 months, the company said its AI agents processed more than 2.5 million alerts and completed over 650,000 security investigations for its clients. Customers reported saving between 30 minutes and 2.5 hours per investigation, and eliminated up to 99% of false positives in production.”
    • Dark Reading discusses “How Agentic AI Can Boost Cyber Defense. Transurban head of cyber defense Muhammad Ali Paracha shares how his team is automating the triaging and scoring of security threats as part of the Black Hat Middle East conference.”
    • The American Hospital Association News relates,
      • “The FBI has public resources available to help prevent exploitation by cybercriminals, who use artificial intelligence for deception. An infographic by the FBI and the American Bankers Association Foundation highlights how AI-generated or manipulated media, also known as “deep fakes,” can be used to impersonate trusted individuals. It details signs of a deep fake scam and how such content can depict public figures, friends and family members. An FBI announcement further explains how criminals use AI-generated text, images, audio and video for fraud schemes. The alert includes tips to help protect against suspected schemes.
      • “The information provided by the FBI and the ABA is relevant for health care as criminals are increasingly using AI-generated deep fake audio and video content — often in combination — to deceive health care staff,” said John Riggi, AHA national advisor for cybersecurity and risk. “Deep fakes are used to manipulate unwitting individuals by having them click on phishing emails, provide their credentials, hire malicious remote IT workers or transfer funds to criminal accounts. Constant vigilance and multi-layered human verification processes are needed, especially as AI-synthetic video and audio capabilities continue to advance.”
    • Here is a link to Dark Reading’s CISO Corner.