Midweek Update

Midweek Update

From Washington, DC,

  • Meritalk reports,
    • “With the Office of Personnel Management (OPM) on track to lose one-third of its workforce by the end of the year, OPM Director Scott Kupor said on Tuesday that he’s looking to technology to help steady the agency during its ongoing restructuring.
    • “Kupor, who the Senate confirmed as OPM director last month, said that his team is currently conducting a “reprioritization” effort to determine the top critical areas for the agency to focus on – and whether or not they need more headcount to get the job done.
    • “There may be cases where maybe we actually are short people,” Kupor said during an Aug. 26 event hosted by Federal News Network.
    • “We’re not perfect, and I fully acknowledge that there just may be areas where we need to revisit. So, there will be, I’m sure, some places where we have cut deeper than was appropriate, and we’ll have to make some changes,” he said.
    • “Some of those hiring efforts could target fresh talent, but Kupor said the agency may also look to rehire some employees who chose to participate in the deferred resignation program.”
  • The Wall Street Journal reports at 8:35 pm ET Wednesday,
    • “Susan Monarez, the director of the Centers for Disease Control and Prevention, has been pushed out of the job, a senior Trump administration official said Wednesday.
    • “Monarez, who led the agency for less than a month, clashed with Health and Human Services Secretary Robert F. Kennedy Jr. and members of his staff, the official said. President Trump had nominated her to lead the CDC in March after dropping his first pick. Previously the agency’s acting director, Monarez was the first CDC head without a medical degree in more than 70 years.
    • “Lawyers for Monarez said in a statement that she has neither resigned nor received notification from the White House that she has been fired. They also said she will not resign. “When CDC Director Susan Monarez refused to rubber-stamp unscientific, reckless directives and fire dedicated health experts, she chose protecting the public over serving a political agenda,” they said. “For that, she has been targeted.”
    • “Three senior CDC leaders, including Dr. Debra Houry, the agency’s chief medical officer, submitted their resignations Wednesday, according to emails viewed by The Wall Street Journal.”
  • Healthcare Dive tells us,
    • “The process set up by the No Surprises Act to settle disputes between providers and insurers about out-of-network claims is generating billions of dollars in extra costs for the healthcare system — costs that could trickle down in the form of higher consumer premiums, according to a new analysis.
    • “Independent dispute resolution, or IDR, has created an estimated $5 billion in total costs between its inception in 2022 and the end of last year, according to the report published in Health Affairs on Monday. The high amount of claims, significant provider participation and lofty offer amounts are driving the spending, researchers found.
    • “The analysis raises questions for policymakers concerned about curbing healthcare costs. In particular, Washington should consider tackling the high volume of ineligible disputes clogging up the process — and scrutinize the role of private equity, given providers backed by the firms are responsible for an outsized portion of disputes, researchers said.”
  • FEHBlog note — The No Surprises Act arbitration which is supposed to resemble baseball arbitration fails to include the safeguards found in actual baseball arbitration like a hearing at which the parties have access to both offers and can debate them before the decisionmakers.
  • Fierce Healthcare informs us,
    • “The National Committee on Quality Assurance (NCQA) has launched an artificial intelligence working group to determine how to best measure performance of high-risk AI once it has been deployed by health plans and providers. 
    • “The 35-year-old organization runs a spate of quality measurement and reporting programs, like health plan accreditation and the Healthcare Effectiveness Data and Information Set (HEDIS) measures used by 90% of health plans, according to the Office of the Assistant Secretary for Planning and Evaluation. 
    • “The NCQA has convened more than 30 organizations to share their experiences using AI and help create standards for the technology. Some members of its AI working group are the American Academy of Family Physicians, America’s Health Insurance Plans, Blue Cross Blue Shield of Tennessee, the Community Care Plan, Covered California, the Kaiser Foundation Health Plan and United HealthCare.
    • “As the modality of care, as the channels of healthcare delivery continue to evolve, and as we continue to see a very evolving healthcare delivery landscape, we do want to take a very hard look at what additional things we can do to continue putting that lens on quality and putting quality front and center,” Vik Wadhwani, chief transformation officer at NCQA, said in an interview.”
  • Kushner & Co. reminds us that the time for circulating Medicare prescription drug creditable coverage notices is approaching. The deadline is October 15, 2025.
    • For 2025, with the Inflation Reduction Act lowering the out-of-pocket maximum to $2,000 (from $8,000 in 2024), many employer prescription drug plans—and especially those with High-Deductible Health Plans—may find that their plans are no longer creditable. Further, new changes for 2026 may also impact these notices. Be sure to check with your group medical plan insurance carrier or TPA [or PBM] to ensure you’re in compliance in determining whether your prescription drug plan is creditable or noncreditable.
  • The FAR Council today finalized the inflation adjustments to FAR thresholds which take effect on October 1, 2025. The key change for FEHB carriers is the following:
    • “The cost or pricing data threshold at FAR 15.403–4, for contracts awarded before July 1, 2018, increases from $750,000 to $950,000. For contracts issued on or after July 1, 2018, the threshold increases from $2 million to $2.5 million.”
    • 90 Fed. Reg. 41873 (August 27, 2025)
    • OPM’s FEHBAR treats this threshold as the subcontract preapproval threshold for experience rated carriers and the flow down trigger for the significant events clause. 48 C.F.R. Secs. 1652.222-701652.244-70.

From the Food and Drug Administration (FDA) front,

  • The Wall Street Journal reports,
    • “The Food and Drug Administration authorized three new Covid-19 vaccines—from Pfizer and its partner BioNTech, and Moderna and Novavax—that target a variant of the coronavirus known as LP.8.1. This was the dominant circulating strain when FDA advisers picked a target in May. 
    • “The companies are expected to begin shipping doses to pharmacies and other vaccination sites within days. This is the fourth-year companies have updated Covid shots to target the primary variant that is circulating, in hopes the shots will better protect people from severe illness through the fall and winter months.
    • “In a change this year, the FDA cleared use of the updated vaccines in a smaller population. The three vaccines are cleared for everyone 65 and older, and for people in younger populations who have underlying conditions that put them at higher risk of severe Covid-19. 
    • “Pfizer’s vaccine was cleared for at-risk people ages 5 through 64, Moderna’s in at-risk people six months and older, and Novavax for at-risk people 12 and older.
    • “In previous years, U.S. health officials recommended the booster shots in most people six months and older, even if they didn’t have at-risk conditions.” * * *
    • “In deciding on vaccine coverage, health insurers typically follow recommendations by the Advisory Committee on Immunization Practices, or ACIP, which advises the CDC. They may also consider clinical recommendations from medical societies. 
    • “No meeting has been scheduled for ACIP to consider the new updated boosters. Kennedy fired all members of the ACIP in June and replaced them with people including some vaccine skeptics.
    • “A trade group for health-insurance companies, America’s Health Insurance Plans, said health plans will continue to follow requirements for ACIP-recommended vaccines.”
  • FEHBlog note — Indeed, the Affordable Care Act requires that health plans waive cost sharing for in-network administration of vaccines recommended by ACIP and confirmed by the CDC (or the HHS Secretary in the event of a vacancy in the CDC directorship.).
  • Cardiovascular Business adds,
    • “The U.S. Food and Drug Administration (FDA) is warning the public about a new safety issue associated with Johnson & Johnson MedTech’s Automated Impella Controller (AIC)
    • “This latest alert was put in place after Johnson & Johnson MedTech received reports that some of the Pump Driver Circuit Assemblies of its AICs contain 25V-rated tantalum capacitors instead of the expected 35V-related tantalum capacitors. This can cause the pump’s performance to suffer, and there a risk of the pump stopping altogether and triggering an “Impella Failure” or “Impella Stopped. Controller Failure” alarm. 
    • “One patient death has been linked to this issue. 
    • “This alert covers a total of 69 AICs. Full lists of the affected product codes and serial numbers are available as part of the FDA’s advisory. Anyone with one of the affected devices is urged not to use it any longer. Instead, the device should be quarantined until additional information is made available.
    • “The FDA is currently reviewing information about this potentially high-risk device issue and will keep the public informed as significant new information becomes available,” according to the advisory.”

From the judicial front,

  • Bloomberg Law reports,
    • “Cigna Health & Life Insurance Co. reached a class-wide settlement in a family’s lawsuit saying the insurer breached its fiduciary duties by failing to maintain an up-to-date list of in-network medical providers.
    • “The parties reached a preliminary agreement after a mediation session with a retired judge and plan to file details of the deal for court approval by Sept. 19, they said in a status report docketed Monday in the US District Court for the Northern District of Illinois. The filing didn’t include details about the terms of the settlement.” * * *
    • “Judge Manish S. Shah allowed portions of the case to advance in February, saying the family has a viable fiduciary breach claim based on Cigna’s failure to properly resolve the matter in a way that didn’t force them to foot the bill. But Shah dismissed the family’s claim for wrongfully denied benefits under the Employee Retirement Income Security Act because Cigna correctly paid their benefits according to the terms of their health plan.”

From the public health and medical research front,

  • Fierce Healthcare lets us know,
    • “Advancements in technology, testing and imaging have transformed cancer detection and risk assessment, enabling them to be faster and more precise.
    • “But providing patients with a cancer risk score or identifying those at high risk is only one step in cancer prevention. Getting patients to act on their cancer risk and get supplemental screening is the next big leap, and CancerIQ is focused on closing this gap.
    • “The company, which offers healthcare providers a cancer-focused precision health platform, developed new capabilities to provide patients at elevated risk for cancer with “hyper-personalized” patient education, engagement and navigation support. The new features were built on insights from thousands of high-risk patient journeys and backed by behavioral science with the aim to drive sustained follow-through on supplemental screenings that detect cancer earlier, according to executives.
    • “The first release focuses on screening breast MRI, with plans to support additional patient populations, including those eligible for low-dose lung CT.”
  • BioPharma Dive reports,
    • “People with early breast cancer who were treated in a late-stage study with Eli Lilly’s drug Verzenio and standard hormone therapy lived longer than those given hormone therapy alone, the company reported Wednesday.
    • “The summary results come from Lilly’s monarchE study, which began in 2017 and enrolled more than 5,600 adults with high-risk breast cancer that tested positive for hormone receptors but negative for a protein called HER2. Lilly said the improvement in survival was “statistically significant and clinically meaningful.”
    • “The study previously met its main goal, showing the addition of Verzenio improved invasive disease-free survival — data that supported a 2021 approval in this treatment setting. The overall survival findings, which were a secondary endpoint, will be presented at an upcoming medical meeting, Lilly said.”
  • STAT News relates,
    • “Akeso, a Chinese biotech with a drug positioned to rival Merck’s megablockbuster Keytruda, has reported for the first time that the therapy can improve patient survival.
    • “The therapy, ivonescimab, showed a statistically significant survival benefit as a second-line treatment when combined with chemotherapy to treat non-small cell lung cancers. The patients’ cancers had progressed after getting therapies targeting EGFR, a protein that can drive tumor growth. 
    • “The company described the results of the Chinese trial as clinically meaningful in a report for the first half of the year released on Tuesday. But it didn’t delve into details, which Akeso plans to share at an upcoming medical conference.”
  • Per Fierce BioTech,
    • “Amylyx’s withdrawn-from-market Relyvrio has failed to make an impact on primary or secondary endpoints in a rare neurodegenerative disease, prompting the company to discontinue the program.
    • “Oral therapy Relyvrio, which Amylyx is again referring to as AMX0035, was tested in progressive supranuclear palsy (PSP), a fatal and rapidly progressing condition that impacts mobility, eye movements, swallowing and speech. Currently, there aren’t any approved treatments for the disease.”
    • “Amylyx’s phase 2/3b study was measuring AMX0035’s impact on disease progression and severity using a 28-item, condition-specific scale. The phase 2 portion of the trial found no difference in patients receiving AMX0035 compared to placebo at 24 weeks, according to an Aug. 27 company release.
    • “Given the results, the company has discontinued the phase 2b trial, plus a related open-label extension study. Amylyx has also terminated plans for the phase 3 portion of the study.”
  • Per Health Day,
    • ‘Few teens with depression receive treatment, with disparities seen based on residence, gender, and race, according to a study published online Aug. 20 in PLOS Mental Health.
    • “Su Chen Tan, from the University of Tennessee in Knoxville, and colleagues used data from adolescents (aged 12 to 17 years) with major depressive episodes (MDE) participating in the 2022 U.S. National Survey on Drug Use and Health to assess mental health service utilization by rurality, race/ethnicity, gender, age, health insurance coverage, and poverty level.
    • “The researchers found that 19.2 percent of adolescents experienced MDE, but only 47.5 percent received treatment within the past year. There were significantly lower odds of receiving specialist treatment for adolescents in rural areas versus their urban counterparts (adjusted odds ratio [aOR], 0.64). Further, odds of receiving telehealth services were significantly lower for rural adolescents (aOR, 0.64) but were significantly higher for adolescents with insurance (public insurance: aOR, 2.99; private insurance: aOR, 3.82). Compared with younger adolescents, older adolescents had lower odds of utilizing school-based services (aOR, 0.52). Female adolescents had greater odds of utilizing any mental health treatment than male adolescents (aOR, 1.59), while Black adolescents had significantly lower odds of utilizing any mental health treatment versus non-Hispanic White adolescents (aOR, 0.36).”
  • and
    • “Two-thirds of women in their child-bearing years have an increased risk for birth defects due to a lifestyle factor they can change, a new study says.
    • “These risk factors — low levels of vitamin B9 (folate), unmanaged diabetes or exposure to tobacco smoke — increase the odds of a serious birth defect in any child they might have, researchers said.
    • “Heart defects, cleft palates and defects of the brain and spinal cord are among the problems that could be headed off if women took steps to improve their health prior to pregnancy, researchers reported today in the American Journal of Preventive Medicine.”

From the U.S. healthcare business front,

  • Healthcare Dive points out Blue Shield of California names interim CEO Mike Stuart to permanent chief executive.
  • Beckers Payer Issues notes,
    • “AM Best has downgraded its outlook for the health insurance sector from stable to negative, citing escalating medical costs and increased utilization across government, commercial and ACA plans.
    • “The credit rating agency noted higher utilization of specialty drugs, increased physician visits, more inpatient admissions and a surge in behavioral health claims. The coding intensity of medical services has also increased, according to an Aug. 25 news release.”
  • STAT News reports,
    • “Dressed in red and black jackets reminiscent of Star Trek uniforms, the heads of Epic’s data and AI divisions, Phil Lindemann and Seth Hain, described an aspirational vision for artificial intelligence at the end of last week’s Epic UGM keynote. Using the data stored in Cosmos — Epic’s de-identified patient record research database — the company trained an AI model that can generate many possible future timelines for a patient, then tell the doctor which outcomes are most likely, like what might happen during a hospital stay, or if the patient might end up in the emergency department in the next year. 
    • “Just as a large language model can be trained once and then used to generate different kinds of text, like an email or a poem, without being specifically trained on how to write either emails or poems, Epic’s “large medical model,” trained on all sorts of medical events and outcomes, could replace individual predictive medical algorithms. If the model, which Epic calls CoMET — the Cosmos Medical Event Transformer — can achieve performance similar to machine learning algorithms specifically trained to predict readmissions or asthma attacks, “that’s a breakthrough in how we can get risk prediction embedded into clinical care,” said Lindemann.
    • “This idea isn’t entirely new. Researchers like Arkadiusz Sitek at Massachusetts General Hospital have built models that predict future patient medical events before. But, Sitek told STAT, the scale of CoMET is impressive and suggests this approach will work in a large population. Epic trained and evaluated its model on 115 billion medical events from 118 million unique patient records collected from January 2012 to April 2025. The work was detailed in a preprint posted last week with Microsoft and Yale researchers.”
  • FIerce Healthcare informs us,
    • “Four hospitals are sending heart failure patients home with a virtual care support team under a newly unveiled collaboration between the American Heart Association (AHA) and remote chronic disease monitoring platform Cadence.
    • “The American Heart Association Connected Care pilot program aims to reduce 30-day readmissions by addressing “critical gaps in heart failure care” that occur after heart failure patients leave the hospital.
    • “It will see the participating hospitals integrate program referrals into their discharge workflows. Enrolled patients are given and taught to use connected vital sign monitors, which a Cadence virtual care team uses to provide ongoing clinical support, adjust treatments or direct the patient to an in-person provider if necessary.
    • Almost one in four heart failure patients are readmitted to the hospital within 30 days of discharge, and fewer than a fifth receive post-discharge medical therapies in line with clinical guidelines, according to study data cited in the announcement.”
  • Beckers Hospital Review identifies “five new drug shortages and discontinuations, according to drug supply databases from the FDA and the American Society of Health-System Pharmacists.” 

Weekend update

From Washington, DC

  • Congress will return to Capitol Hill for Committee business and floor voting on September 2.
  • JAMA considers Medicare Part D benefit designs following the Inflation Reduction Act.
    • Question How did prescription drug coverage in Medicare Part D plans change after the Inflation Reduction Act (IRA)?
    • “Findings In this cross-sectional study of enrollees in Medicare Part D stand-alone and Medicare Advantage plans, from 2019 to 2025 mean deductibles and the proportion of patients with coinsurance for preferred brand-name drugs increased. For stand-alone plans, these increases were observed before and after the IRA changes took effect in 2025, but for Medicare Advantage plans, the changes were abrupt in 2025.
    • Meaning The IRA limited annual out-of-pocket costs to $2000 for Medicare Part D beneficiaries, but concurrent design changes by Part D insurers, particularly among Medicare Advantage plans, may lead to higher cost sharing for some beneficiaries who do not reach this limit in 2025.

From the public health and medical research front,

  • Medscape informs us,
    • “Among hospitalized children and teens, respiratory syncytial virus (RSV) mostly affects younger, otherwise healthy infants, while the lesser-known human metapneumovirus (HMPV) tends to affect older children, many of whom have preexisting health conditions, according to a study published in Pediatrics.
    • “Researchers and other experts said the findings will hopefully promote the development of HMPV vaccines and affordable rapid diagnostic tests for the virus in outpatient settings.
    • “HPMV is not on people’s radar,” said John V. Williams, MD, chair of the Department of Pediatrics at the University of Wisconsin School of Medicine and Public Health in Madison, Wisconsin. “It was the largest prospective apples-to-apples comparison [on RSV and HMPV]; it has tremendous importance in that sense.”
  • The University of Minnesota’s CIDRAP tells us,
    • A study of more than 4 million children in South Korea found no association between antibiotic exposure during pregnancy or early infancy and increased incidence of autoimmune diseases, researchers reported yesterday in PLOS Medicine.
    • The study, conducted by researchers with Sungkyunkwan University in South Korea, is the latest to examine whether early exposure to antibiotics is associated with increased risk of childhood-onset diseases and neurodevelopmental conditions. Antibiotics are the most commonly prescribed medication in young children and are frequently overused, and animal research suggests antibiotic exposure at an early age may increase the risk of these conditions by disrupting the gut microbiome while it’s still developing.
    • To date, studies exploring potential links between early antibiotic exposure and development of autoimmune diseases have produced conflicting results. But the authors of the new study say previous research has been limited by potential confounding variables, such as infection and genetic factors.
  • Healio lets us know,
    • “The prevalence of certain gut-brain interaction disorders increased significantly during the COVID-19 pandemic, with the largest increase observed in irritable bowel syndrome, according to cross-sectional study results.
    • “Earlier studies focused on people who actually had COVID-19 and found a much higher risk of IBS after infection. Our study is different; we looked at the whole adult population, not just those infected, and still found a big jump in IBS rates,” Christopher V. Almario, MD, MSHPM, associate professor of medicine and co-director of Cedars-Sinai Center for Outcomes Research and Education, told Healio. “This suggests it’s not just the virus itself, but also broader effects of the pandemic — stress, isolation, dietary changes — that additionally likely played a role.”
  • and
    • “Three speakers outlined how AI is likely to have a major impact on the future of preventive cardiology.
    • “At the American Society for Preventive Cardiology Congress on CVD Prevention, the speakers discussed the importance of preventive cardiologists being involved in shaping the direction of AI in medical care, ways in which use of AI can promote health equity and how AI programs can be used for early detection of CV conditions.” * * *
    • :A priority for the future is to develop, validate and deploy AI-based screening for CVD, Pierre Elias, MD, assistant professor of cardiology and biomedical informatics at Columbia University and medical director for artificial intelligence at New York-Presbyterian Hospital, said during a presentation. 
    • “We have mammograms, we have colonoscopies; we have no equivalent for most forms of cardiovascular disease,” he said. “Every doctor in this room has had a patient that makes them think, why am I meeting them so late in the disease course? The way that we diagnose most forms of cardiovascular disease is either too expensive or too invasive to do on a population level.”

From the U.S. healthcare business front,

  • The New York Times explains why “President Trump’s planned pharmaceutical tariffs threaten to hit many of the most common and well-known drugs that Americans take.”
  • Fierce BioTech reports,
    • “Tempus AI has acquired the digital pathology developer Paige, including its FDA-cleared, artificial intelligence-powered programs for spotting the signs of cancer.
    • “The deal totals $81.25 million, which includes Tempus paying out Paige’s remaining commitment to Microsoft Azure for its cloud-computing services. The transaction will also be “paid predominantly” in Tempus stock, according to the company.
    • “Tempus set its eyes on the former Fierce Medtech Fierce 15 winner in part for its massive, anonymized dataset, which encompasses nearly 7 million digitized pathology slides and clinical data licensed from Memorial Sloan Kettering Cancer Center.” 
  • HR Dive shares an attorney’s opinion pointing out “three DEI approaches employers must reconsider to avoid federal ire. The principles set forth in a recent DOJ memo are likely to be applied by the EEOC to all employers under Title VII, attorney Jonathan Segal writes.”

Cybersecurity Saturday

From the cybersecurity policy and law enforcement front,

  • Federal News Network tells us,
    • “The House Homeland Security Committee plans to convene in early September to mark up a reauthorization bill for a soon-to-expire cybersecurity law that’s viewed as critical to cyber collaboration across government and industry.
    • “In a statement, House Homeland Security Committee Chairman Andrew Garbarino (R-N.Y.) confirmed the committee will mark up a reauthorization bill for the Cybersecurity Information Sharing Act of 2015 once Congress returns from August recess.
    • “Reauthorizing the Cybersecurity and Information Sharing Act is essential as the deadline nears and as threats evolve,” Garbarino said. “The House Committee on Homeland Security plans to mark up our legislative text for its reauthorization shortly after Congress returns from recess in September. In a 10-year extension, I will preserve the privacy protections in the law, and I aim to provide enhanced clarity to certain pre-existing provisions to better address the evolving threat landscape.”
    • “CISA 2015, as it’s known, expires at the end of September. The law provides liability protections and privacy guardrails to especially encourage private sector organizations to voluntarily share data with each other and government agencies.”
  • Cybersecurity Dive reports,
    • “The Cybersecurity and Infrastructure Security Agency (CISA) has updated its recommendations for the minimum features of a software bill of materials (SBOM), the latest step in the agency’s campaign to encourage transparency in the software market.
    • “The updates and additions included in this document will better position Federal Government agencies and other SBOM consumers to address a range of use cases, understand the generation process, and improve data quality,” CISA said in the new publication, which it released on Thursday [August 21].” * * *
    • “The publication, which is open for public comment through Oct. 3, is aimed primarily at government agencies but is also designed to help other organizations understand what to expect from their vendors’ SBOMs.”
  • and
    • “The National Institute of Standards and Technology [NIST] wants public feedback on a plan to develop guidance for how companies can implement various types of artificial intelligence systems in a secure manner. 
    • “NIST on Thursday [August 14] released a concept paper about creating control overlays for securing AI systems based on the agency’s widely used SP 800-53 framework. The overlays are designed to help ensure that companies implement AI in a way that maintains the integrity and confidentiality of the technology and the data it uses in a series of different test cases. 
    • “The agency also created a Slack channel to collect community feedback on the development of the overlays.”
  • Per NIST news releases,
  • and
    • “NIST has released the initial public draft (IPD) of Special Publication (SP) 1331, Quick-Start Guide for Using CSF 2.0 to Improve the Management of Emerging Cybersecurity Risksfor public comment. The document highlights the topic of emerging cybersecurity risks and explains how organizations can improve their ability to address such risks through existing practices within the cyber risk discipline in conjunction with the NIST Cybersecurity Framework (CSF) 2.0. The guide also emphasizes the importance of integrating these practices with organizational enterprise risk management (ERM) to proactively address emerging risks before they occur. 
    • “The comment period is open through September 21, 2025, at 11:59 PM. Please send your feedback about this draft publication to csf@nist.gov.”
  • Per an HHS news release,
    • “Today [August 18], the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a settlement with BST & Co. CPAs, LLP (“BST”), a New York public accounting, business advisory, and management consulting firm, concerning a potential violation of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. BST is a HIPAA business associate and receives financial information that also contains protected health information (PHI) from a HIPAA covered entity.” * * *
    • “The settlement resolves an investigation of BST that OCR initiated after receiving a breach report that BST filed on February 16, 2020. BST reported that on December 7, 2019, BST discovered that part of its network was infected with ransomware, impacting the PHI of its covered entity client. OCR’s investigation determined that BST had failed to conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by BST.
    • “Under the terms of the resolution agreement, BST agreed to implement a corrective action plan that will be monitored by OCR for two years and paid $175,000 to OCR.”
  • Cybersecurity Dive informs us,
    • “Federal prosecutors on Tuesday [August 19] charged an Oregon man for allegedly running a global botnet-for-hire operation called Rapper Bot that used hacked IoT devices to conduct large-scale distributed denial-of-service (DDoS) attacks.
    • “Authorities charged Ethan Foltz, 22, with one count of aiding and abetting computer intrusions. Police executed a search warrant at Foltz’s house on Aug. 6, shut down the botnet and took control of its infrastructure, according to the U.S. Department of Justice.
    • “Rapper Bot allegedly used between 65,000 and 95,000 infected devices for DDoS attacks that often measured between two and three terabits per second. The largest attack may have exceeded six terabits per second, prosecutors said.
    • “Rapper Bot was “one of the most powerful DDoS botnets to ever exist,” said Michael Heyman, the U.S. attorney in Alaska, where authorities believe the botnet infected at least five devices.”
  • Cyberscoop adds,
    • “A 20-year-old Florida man received a 10-year federal prison sentence Wednesday for his role in the notorious Scattered Spider cybercrime organization, marking the first conviction of a member from the group responsible for breaching more than 130 major companies.
    • “Noah Michael Urban, 20, of Palm Coast, Fla., pleaded guilty to conspiracy, wire fraud and aggravated identity theft charges in two separate federal cases spanning Florida and California. A federal judge sentenced Urban to 120 months in prison with three years of supervised release and ordered him to pay $13 million in restitution to victims.
    • “The sentence exceeded federal prosecutors’ recommendation of eight years, reflecting the scope of Urban’s criminal activities that investigators say caused between $9.5 million and $25 million in total losses.”

From the cybersecurity vulnerabilities and breaches front,

  • The American Hospital Association News informs us,
    • “The FBI Aug. 20 released an advisory warning of malicious activity by Russian cyber actors targeting end-of-life devices running an unpatched vulnerability in Cisco Smart Install software. The agency said the actors, attributed to the Russian Federal Security Service’s Center 16, have been detected collecting configuration files for thousands of networking devices associated with U.S. entities across critical infrastructure sectors. On some devices, the files were modified to enable unauthorized access to the devices. The vulnerability was initially publicized in 2018.
    • “If you have vulnerable equipment in your network, please pay particular attention to ensuring that it is patched and running as securely as possible,” said Scott Gee, AHA deputy national advisor of cybersecurity and risk. “It is recommended that hospitals also make this equipment a priority for replacement since it’s no longer supported for updates by Cisco. It is also a good time to review the process for patch management and equipment upgrades, particularly focusing on patching known exploited vulnerabilities. The Cybersecurity Infrastructure and Security Agency maintains a catalog of KEVs.”
  • CISA added two known exploited vulnerabilities to that catalog this week.
  • Cyberscoop adds,
    • “The Chinese state-backed threat group Silk Typhoon has raised the pace of attacks targeting government, technology, legal and professional services in North America since late spring, according to CrowdStrike.
    • “We were calling this jokingly, ‘the summer of Murky Panda,’ because we’ve seen so much activity from them over the last couple of months,” said Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, using the firm’s nomenclature for the cyberespionage group.
    • “CrowdStrike has worked on more than a dozen cases involving Murky Panda during the past few months, including two active incident response cases, Meyers said. The group, which has been active since at least 2023, is “one of the top-tier Chinese threats that we’ve been seeing a lot this summer,” he said.
    • “Murky Panda exemplifies how Chinese attackers are gaining access to victim networks and infrastructure via vulnerabilities, unmanaged devices, the cloud and pivots between cloud services. 
    • “The group’s advanced techniques in cloud environments are evident, as it enables prolonged access and lateral movement to downstream victims by abusing delegated administrative privileges in cloud solution providers, CrowdStrike said in a research report released Thursday. [August 21].
  • Bleeping Computer reports,
    • “Hackers have stolen the personal information of 1.1 million individuals in a Salesforce data theft attack, which impacted U.S. insurance giant Allianz Life in July.
    • “Allianz Life has nearly 2,000 employees in the United States and is a subsidiary of Allianz SE, which has over 128 million customers worldwide and ranks as the world’s 82nd largest company based on revenue.
    • “As the company disclosed last month, information belonging to the “majority” of its 1.4 million customers was stolen by attackers who gained access to a third-party cloud CRM system on July 16th.” * * *
    • “On Monday, data breach notification service Have I Been Pwned revealed the extent of the incident, reporting that the email addresses, names, genders, dates of birth, phone numbers, and physical addresses of 1.1 million Allianz Life customers were stolen during the breach.
    • “Bleeping Computer has also confirmed with multiple people affected by this breach that their data (including their tax IDs, phone numbers, email addresses, and other information) in the leaked files is accurate.
    • “Many other high-profile companies worldwide were also breached in this campaign, including GoogleAdidasQantasLouis VuittonDiorTiffany & Co.Chanel, and, most recently, human resources giant Workday.”
  • Cybersecurity Dive notes,
    • The attack [on WorkDay] follows a string of social-engineering intrusions linked to ShinyHunters, a hacker group associated with an underground cybercrime collective known as The Com. The Com also has ties to the notorious hacker team Scattered Spider, which has targeted companies in multiple industries over the past several months, including retail, insurance and aviation. 
    • ShinyHunters has launched numerous attacks in recent months targeting Salesforce instances, according to researchers at Google. The group targeted one of Google’s own Salesforce instances earlier this month. 
    • Reliaquest recently published evidence of possible collaboration between ShinyHunters and Scattered Spider, including ticket-themed phishing domains and Salesforce credential-harvesting pages. 
  • Per Dark Reading,
    • “In this interview from Black Hat USA 2025, Philippe Laulheret, a senior vulnerability researcher at Cisco Talos, discusses his discovery of the “ReVault” vulnerability affecting millions of Dell business laptops
    • “Laulheret found that the Control Vault (also called a unified secure hub) — a control board connecting peripherals like fingerprint readers and smart card readers to Dell Latitude and Precision laptops — contained multiple security flaws that allow any user to communicate with the board through undocumented APIs, potentially leading to memory corruption, code execution, extraction of secret keys, and permanent firmware modification.”
  • Per Bleeping Computer,
    • “Six major password managers with tens of millions of users are currently vulnerable to unpatched clickjacking flaws that could allow attackers to steal account credentials, 2FA codes, and credit card details.
    • “Threat actors could exploit the security issues when victims visit a malicious page or websites vulnerable to cross-site scripting (XSS) or cache poisoning, where attackers overlay invisible HTML elements over the password manager interface.
    • “While users believe they are interacting with harmless clickable elements, they trigger autofill actions that leak sensitive information.
    • “The flaws were presented during the recent DEF CON 33 hacker conference by independent researcher Marek Tóth. Researchers at cybersecurity company Socket later verified the findings and helped inform impacted vendors and coordinate public disclosure.
    • “The researcher tested his attack on certain versions of 1Password, Bitwarden, Enpass, iCloud Passwords, LastPass, and LogMeOnce, and found that all their browser-based variants could leak sensitive info under certain scenarios.”
  • and
    • “A new infostealer malware targeting Mac devices, called ‘Shamos,’ is targeting Mac devices in ClickFix attacks that impersonate troubleshooting guides and fixes.
    • “The new malware, which is a variant of the Atomic macOS Stealer (AMOS), was developed by the cybercriminal group “COOKIE SPIDER,” and is used to steal data and credentials stored in web browsers, Keychain items, Apple Notes, and cryptocurrency wallets.
    • “CrowdStrike, which detected Shamos, reports that the malware has attempted infections against over three hundred environments worldwide that they monitor since June 2025.”

From the ransomware front,

  • Cybersecurity Dive reports on August 20,
    • “The pharmaceutical and biotechnology company Inotiv Inc. is investigating a cyberattack that led to hackers encrypting the firm’s data, it said in a filing on Monday with the U.S. Securities and Exchange Commission. 
    • “The Aug. 8 attack disrupted access to certain data storage and business applications, according to Innotiv. The company said it is working to bring certain systems back online and has moved some operations to offline alternatives in order to maintain business continuity.  
    • The company has restricted access to its systems, retained third-party experts and notified law enforcement, according to its SEC filing.” * * *
    • “The hackers behind the Qilin ransomware have claimed credit for the attack, according to researchers at Huntress and Kroll.”
  • Bleeping Computer adds on August 22,
    • “Kidney dialysis firm DaVita has confirmed that a ransomware gang that breached its network stole the personal and health information of nearly 2.7 million individuals.
    • “DaVita serves over 265,400 patients across 3,113 outpatient dialysis centers, 2,660 in the United States, and 453 centers in 13 other countries worldwide. The company reported revenues of over $12 billion in 2024 and of $3.3 billion for the second quarter of 2025.
    • “In April, the healthcare provider revealed in a filing with the U.S. Securities and Exchange Commission (SEC) that its operations were disrupted after attackers partially encrypted its network over the weekend.
    • “According to a dedicated website with more information regarding the resulting data breach, the attackers gained access to DaVita’s network on March 24 and were evicted after the company detected the incident on April 12.” * * *
    • “Although the kidney dialysis firm hasn’t linked the attack to a specific ransomware operation, the Interlock ransomware gang claimed responsibility for the breach in late April.
    • “Interlock also leaked the allegedly stolen data on its dark web portal after negotiations with DaVita had failed, claiming it had stolen roughly 1.5 terabytes of data from the company’s compromised systems, or nearly 700,000 files containing what appeared to be sensitive patient records, insurance details, user account information, and financial data.”
  • Dark Reading points out that “Researchers highlight how Warlock, a new ransomware heavyweight, uses its sophisticated capabilities to target on-premises SharePoint instances.”

From the cybersecurity business and defenses front,

  • Cybersecurity Dive reports,
    • “Enterprise software spending will sustain double-digit growth through 2029, according to Forrester projections. Vendor revenues grew 11% on average during the first quarter of the year, the analyst firm said in a July report.
    • “Infrastructure software spend will lead the charge, increasing 13.3% over the next four years, as enterprises stock up on cloud services, security tools and AI capabilities. The market for application software, a category that includes IT operations management, enterprise resource planning, and supply chain tools, will see slower growth of 9.5%, the firm said.
    • “Database management services will help shore up software market growth, as enterprises lay the groundwork for generative AI and agentic automation tools. The firm previously estimated off-the-shelf AI governance software spend to more than quadruple from 2024 to 2030, nearing $16 billion and capturing 7% of the software market.”
  • and
    • “Many business leaders still aren’t following cybersecurity best practices to protect their organizations from costly intrusions, according to a report that the consulting giant Unisys published on Tuesday [August 21].
    • “Only 62% of organizations have or are setting up a zero-trust network architecture, only 61% are prioritizing post-incident recovery and only 45% deploy or plan to deploy managed detection and response software.
    • “Only 42% of organizations said they use or plan to use digital identity and access management services, which are considered essential for stopping attacks that exploit legitimate credentials.”
  • Dark Reading informs us,
    • “Cyber insurers are testing out new ways to hold policyholders accountable for outdated security, limiting payouts when policyholders fall prey to attacks that use older vulnerabilities or take advantage of holes in the organizations’ defenses.
    • “Potential risk-limiting approaches include a sliding scale of accountability — and payouts — based on an unpatched vulnerability’s half-life, or whether a company failed to fix a critical vulnerability within a certain number of days, according to a blog post penned by cyber insurer Coalition, which does not support such approaches. Dubbed CVE exclusions, after the Common Vulnerabilities and Exposures (CVE) system widely used to assign identifiers to software security issues, the tactic is not yet widely adopted, and most examples are from insurers outside the US, the firm stated.
    • The limits could start showing up in companies’ policies, however, if demand for cyber insurance continues to grow, creating a seller’s market, says John Coletti, head of cyber underwriting at Coalition
    • “While we will not name names, there are specific examples of this occurring within the industry,” he says. “A company should be highly skeptical of buying a policy with a CVE exclusion.”
  • Info-Security Magazine relates,
    • “The US National Institute of Standards and Technology (NIST) has published new guidelines it claims will help organizations optimize their efforts to detect face morphing software.
    • “Face morphing is a type of deepfake technology that enables threat actors to blend the photos of two people into a single image. In doing so, it simplifies identity fraud by tricking face recognition systems into erroneously identifying an image as belonging to both original individuals.
    • “In this way, individual A can assume the identity of individual B and vice versa, NIST said.
    • “The new report, Face Analysis Technology Evaluation (FATE) MORPH 4B: Considerations for Implementing Morph Detection in Operations (NISTIR 8584), offers an introduction to the topic and key detection methods.
    • “It focuses mainly on the pros and cons of various investigatory techniques, and ways to prevent morphs from entering operational systems in locations such as passport application offices and border crossings.”
  • Here is a link to Dark Reading’s CISO Corner.

Cybersecurity Saturday

From the cybersecurity policy and law enforcement front,

  • Cybersecurity Dive tells us,
    • “The Trump administration should slash cybersecurity regulations and double down on winning the trust of the private sector, the U.S. tech industry’s largest trade group said in a paper published Tuesday [August 12, 2025].
    • “In a report laying out recommendations for the White House’s Office of the National Cyber Director — now helmed by newly confirmed Trump appointee Sean Cairncross — the Information Technology Industry Council said the government should focus on “results-driven action.”
    • “There is a need to prioritize impactful security outcomes, slash red tape, rethink legacy network architectures, invest in secure modern systems, and strengthen trusted partnerships between the public and private sectors,” ITI said.
    • “Achieving results, the group argued, “means empowering defenders with what they need to win: efficiency, appropriate resourcing, and the freedom to focus on real threats, not on navigating a web of regulatory regimes.”
  • Cyberscoop observes,
    • “Two executive orders President Donald Trump has signed in recent months could prove to have a more dramatic impact on cybersecurity than first thought, for better or for worse.
    • Overall, some of Trump’s executive orders have been more about sending a message than spurring lasting change, as there are limits to their powers. Specifically, some of the provisions of the two executive orders with cyber ramifications — one from March on state and local preparedness generally, and one from June explicitly on cybersecurity — are more puzzling to cyber experts than anything else, while others preserve policies of the prior administration which Trump has criticized in harsh terms. Yet others might fall short of the orders’ intentions, in practice.
    • But amid the flurry of personnel changesbudget cuts and other executive branch activity in the first half of 2025 under Trump, the full scope of the two cyber-related executive orders might have been somewhat overlooked. And the effects of some of those orders could soon begin coming to fruition as key top Trump cyber officials assume their posts.
  • Federal News Network reports,
    • “The Cybersecurity and Infrastructure Security Agency has rolled out new guidance to help deal with what some cyber experts say is a rising concern: a lack of visibility into threats to operational technology.
    • CISA on Wednesday [August 13, 2025] published “Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators.” CISA developed the guidance in conjunction with other agencies, including the Environmental Protection Agency, the National Security Agency, the FBI and several international partners.
    • The guidance focuses on operational technology, which refers to hardware and software that monitor and control physical processes in industrial settings.
    • “OT systems are essential to the daily lives of all Americans and to national security,” Acting CISA Director Madhu Gottumukkala said in a press release. “They power everything from water systems and energy grids to manufacturing and transportation networks. As cyber threats continue to evolve, CISA through this guidance provides deeper visibility into OT assets as a critical first step in reducing risk and ensuring operational resilience.”
  • Federal News Network also interviews Steve Shirley, Executive director, National Defense Information Sharing and Analysis Center, and J.R. Williamson, “Vice president and chief information security officer, Leidos, about the evolution of zero trust. “Federal agencies are learning that implementing Zero Trust means more than deploying new tools. It requires rethinking how users, devices and data interact across every layer of the enterprise.”
  • The American Hospital Association News informs us,
    • “The Department of Justice Aug. 11 announced a series of actions taken against the BlackSuit ransomware group, also known as “Royal,” including the disruption of four servers and nine domains July 24. BlackSuit attacks have targeted health care and other critical infrastructure sectors, DOJ said. 
    • “There is no doubt that the private sector also contributed information to facilitate this disruption, once again highlighting the value of public private operational engagement,” said John Riggi, AHA national advisor for cybersecurity and risk. “The BlackSuit/Royal ransomware group is directly responsible for multiple disruptive attacks against hospitals and health systems, posing a direct risk to patient and community safety. We hope these aggressive law enforcement operations continue at a pace that will meaningfully degrade foreign cyber adversaries’ abilities to harm the American public.”  

From the cybersecurity vulnerabilities and breaches front,

  • Cybersecurity Dive reports,
    • “The Cybersecurity and Infrastructure Security Agency (CISA) and Microsoft on Tuesday [August 12, 2025,] updated their mitigation guidance for a high-severity flaw in Exchange Server.
    • The flaw, tracked as CVE-2025-53786, could allow an attacker with administrative privileges for on-premises versions of Exchange to escalate privileges by exploiting vulnerable hybrid joined configurations, Microsoft and CISA said last week
    • In an update on Tuesday, CISA said it still saw no evidence of hackers exploiting the flaw, but it urged organizations to review Microsoft’s updated guidance on identifying Exchange Servers on a network and running the Microsoft Exchange Health Checker.
    • “In its updated security bulletin, Microsoft said an attacker could potentially escalate privileges from an on-premises server to a connected cloud environment without leaving an “easily detectable and auditable trace.” 
  • Bloomberg Law reports,
    • “Russian government hackers lurked in the records system of the US courts for years and stole sensitive documents that judges had ordered sealed from public view, according to two people familiar with the matter and a report seen by Bloomberg News.
    • “The attackers had access to what was supposed to be protected information for multiple years, the report on the breach shows. They gained access by exploiting stolen user credentials and a cybersecurity vulnerability in an outdated server used by the federal judiciary, according to the report, which says the hackers specifically searched for sealed records. 
    • “The report, which was reviewed in part by Bloomberg, doesn’t identify the attackers. But investigators found evidence that they were a Russian state-sponsored hacking group, according to the people, who spoke on condition that they not be named because they were not authorized to discuss the matter.
    • “It’s unclear exactly when the hackers first penetrated the system and when the courts became aware of the breach. Last fall, the judiciary hired a cybersecurity firm to help address it, said one of the people.” * * *
    • “The intrusion was previously reported by Politico, while the New York Times earlier reported that Russia was at least in part behind the cyberattack.
    • “The hackers targeted sealed documents in espionage and other sensitive cases, including ones involving fraud, money laundering and agents of foreign governments, Bloomberg Law reported on Tuesday [August 12, 2025]. Such records often include sensitive information that, in the wrong hands, could be used to compromise criminal and national security investigations, or to identify people who provide information to law enforcement.”
  • Per Cybersecurity Dive,
  • and
    • Virtually all companies have experienced some type of intrusion due to vulnerable code, application security firm Checkmarx said in a report released Thursday [August 14, 2025.
    • Nearly eight in 10 firms reported experiencing such breaches in 2023, but that figure climbed more than 90% last year and reached 98% this year.
    • At the same time, eight in 10 companies said they sometimes or often released software with code they knew was vulnerable, up from two-thirds in 2024. “This isn’t oversight,” Checkmarx said. “It’s strategy.”
  • CISA added five known exploited vulnerabilities to its catalog this week.
  • Per Bleeping Computer,
    • “Security researchers have created a new FIDO downgrade attack against Microsoft Entra ID that tricks users into authenticating with weaker login methods, making them susceptible to phishing and session hijacking.
    • “These weaker login channels are vulnerable to adversary-in-the-middle phishing attacks that employ tools like Evilginx, enabling attackers to snatch valid session cookies and hijack the accounts.
    • “Although the attack doesn’t prove a vulnerability in FIDO itself, it shows that the system can be bypassed, which is a crucial weakness.
    • “This is especially worrying considering the increased adoption of FIDO-based authentication in critical environments, a consequence of the technology being touted as extremely phishing-resistant.”
  • and
    • “Cisco is warning about a critical remote code execution (RCE) vulnerability in the RADIUS subsystem of its Secure Firewall Management Center (FMC) software.
    • “Cisco FCM is a management platform for the vendor’s Secure Firewall products, which provides a centralized web or SSH-based interface to allow administrators to configure, monitor, and update Cisco firewalls.
    • ‘RADIUS in FMC is an optional external authentication method that permits connecting to a Remote Authentication Dial-In User Service server instead of local accounts.”

From the ransomware front,

  • Halcyon informs us,
    • “Black Hat 2025 had plenty of shiny new toys and buzzword-heavy sessions, but the real story was hiding in plain sight. No ransomware track. No packed panel on the threat that has cost organizations billions and taken down some of the most secure environments on the planet. The only time it truly took center stage was when Mikko Hyppönen made it impossible to ignore. 
    • “For those paying attention, three truths stood out. Agentic AI will accelerate ransomware campaigns to speeds that will overwhelm unprepared defenders. Ransomware is the next stage in the evolution of malware, and it will only become more capable. Modern security stacks, no matter how mature or expensive, are still being bypassed with troubling ease.” 
  • Bleeping Computer adds,
    • Ransomware and infostealer threats are evolving faster than most organizations can adapt. While security teams have invested heavily in ransomware resilience, particularly through backup and recovery systems, Picus Security’s Blue Report 2025 shows that today’s most damaging attacks aren’t always about encryption.
    • Instead, both ransomware operators and infostealer campaigns often focus on credential theft, data exfiltration, and lateral movement, leveraging old-school stealth and persistence to achieve their objectives with minimal disruption.
    • The evolving adversary tactics are clearly visible when comparing the findings from the Blue Report 2025, based on over 160 million real-world attack simulations, and the Red Report 2025, which analyzes the latest trends in malware, threat actors, and exploitation techniques.
    • The overlap between the two reports reveals a clear and concerning signal: defenders are falling behind on detecting the very tactics that adversaries now favor the most.
  • InfoSecurity Magazine reports,
    • “An ongoing data extortion campaign targeting Salesforce customers could soon turn its attention to financial services firms, security experts have warned.
    • “The notorious ShinyHunters group has been blamed for a series of data breaches impacting big names in the fashion (LVMHChanel, PandoraAdidas) and aviation (Qantas, Air France-KLM) sectors. These victims are typically targeted with vishing for logins to their Salesforce accounts and are sometimes also tricked into downloading a malicious app for similar purposes.”
  • Per Dark Reading,
    • “An emerging ransomware actor is using sophisticated techniques in the style of an advanced persistent threat group (APT) to target organizations with customized ransom demands, posing a significant risk to businesses.
    • “Charon is a new ransomware family (named for the ferryman from Greek mythology who carried souls across the River Styx to Hades); Trend Micro observed it being deployed in a targeted attack in the Middle East’s public sector and aviation industry — the first such record of Charon observed in the wild, according to new research from the firm.
    • “The ransomware leverages techniques such as DLL sideloading, process injection, and anti-EDR capabilities, which are typically the hallmark of advanced threat actors and — in this case — reminiscent of campaigns by the group Earth Baxia, according to a Trend Micro blog post published today.
    • “The attack chain leveraged a legitimate browser-related file, Edge.exe (originally named cookie_exporter.exe), to sideload a malicious msedge.dll (SWORDLDR), which subsequently deployed the Charon ransomware payload,” Trend Micro threat researchers wrote in the post.”
  • and
    • “Researchers spotted a new Crypto24 ransomware campaign that they say marks a “dangerous evolution” in the threat landscape.
    • “According to Trend Micro researchers, recent attacks by Crypto24 actors display a combination of advanced evasion techniques and custom tools that can disable EDR solutions — including Trend Micro’s own Vision One platform. Crypto24 was first spotted in 2024 but hadn’t made much of impact until recently, when it became the latest ransomware gang to bypass EDR platforms and security solutions.
    • Trend Micro’s report, published Thursday, details how Crypto24 has demonstrated a high level of skill that sets it apart from other ransomware gangs. For example, researchers noted how “Crypto24 actors deftly deploy a broad range of tools that include legitimate programs like PSExec and AnyDesk for remote access and lateral movement, as well as Google Drive for data exfiltration.
    • “More importantly, Crypto24’s successful deployment of a customized RealBlindingEDR (an open source tool for disabling security solutions) variant that neutralized our security controls shows their capability to maneuver around modern defenses,” the report said. “The threat actor’s customized version employs advanced evasion, likely via unknown vulnerable drivers, showcasing deep technical expertise and ongoing tool refinement.”

From the cybersecurity business and defenses front,

  • Cyberscoop names its Cyberscoop 50 award winners for 2025.
    • “The CyberScoop 50 Awards recognize those who have been honored for their work in protecting vital networks, information and critical infrastructure. Through their hard work, ingenuity, and creativity, they aim to fend off hackers, stay ahead of adversaries and protect American networks.”
  • HelpNet Security lets us know,
    • “Security leaders are rethinking their approach to cybersecurity as digital supply chains expand and generative AI becomes embedded in critical systems. A recent survey of 225 security leaders conducted by Emerald Research found that 68% are concerned about the risks posed by third-party software and components. While most say they are meeting regulatory requirements, 60% admit attackers are evolving too fast to maintain resilience.” * * *
    • Penetration testing is no longer treated as a box to check. It has become a core element of enterprise security programs. Eighty-eight percent of security leaders now consider it vital. Over half say they use pentests to validate their own software. More than half also require third-party pentests before releasing software to customers.
    • “The survey found that 49% plan to use pentesting to identify software supply chain vulnerabilities, and 44% intend to use it to uncover insider threats. The practice is being integrated across the development life cycle and procurement workflows.
    • “Generative AI is emerging as a new and unpredictable risk. Sixty-six percent of respondents say GenAI helps attackers analyze data and evade defenses. More than half worry that AI can automate the entire attack lifecycle, and 62% are concerned that AI development tools may introduce hidden vulnerabilities into codebases.”
  • Dark Reading discusses cybersecurity budgeting here and here.
  • Following the Blackhat Conference, Dark Reading’s CISO Corner is back.

Cybersecurity Saturday

From the cybersecurity policy and law enforcement front,

  • NextGov/FCW tells us,
    • “The Senate confirmed Sean Cairncross to serve as national cyber director in a 59-35 vote on Saturday night [August 2], making him the first Senate-approved cybersecurity official of President Donald Trump’s second term.
    • “Cairncross is a former Republican National Committee official and was CEO of the Millennium Challenge Corporation agency during Trump’s first term. As national cyber director, he will be tasked with overseeing an office first stood up under the Biden administration, which serves as the key White House cyber policy interlocutor across federal agencies and Capitol Hill.” 
  • Cyberscoop adds,
    • “Sean Cairncross took his post this week as national cyber director at what many agree is a “pivotal” time for the office, giving him a chance to shape its future role in the bureaucracy, tackle difficult policy issues, shore up industry relations and take on key threats.
    • “The former White House official, Republican National Committee leader and head of a federal foreign aid agency became just the third Senate-confirmed national cyber director at an office (ONCD) that’s only four years old. He’s the first person President Donald Trump has assigned to the position after the legislation establishing it became law at the end of his first term.”
  • Cybersecurity Dive informs us,
    • “The Cybersecurity and Infrastructure Security Agency [CISA] has continued its work to protect federal networks and support critical infrastructure providers despite massive job cuts and resource constraints, two senior CISA officials said during the Black Hat USA cybersecurity conference here Thursday.
    • “We are not retreating, we’re advancing in a new direction,” CISA CIO Robert Costello said during a panel discussion.
    • “Chris Butera, the acting head of CISA’s Cybersecurity Division, added that, while the agency “did lose people” to the Trump administration’s downsizing program — roughly a third of its employees — CISA still has “a very talented workforce.” He cited the agency’s around-the-clock response to major vulnerabilities in Microsoft SharePoint as an example of CISA’s continued capacity.”
  • and
    • “The U.S. government is still pushing agencies to adopt zero-trust network designs, continuing a project that gained steam during the Biden administration, a senior cybersecurity policy official said on Wednesday.
    • “It must continue to move forward,” Michael Duffy, the acting federal chief information security officer, said during a panel at the Black Hat cybersecurity conference. “That architectural side of it is very important for us to get right as we integrate new technologies [like] artificial intelligence into the ways we operate.”
    • “Zero-trust networking emphasizes the concept of throwing up hurdles to hackers who penetrate a computer system, limiting the damage they can do by sealing off parts of the network and requiring strict user authentication.”
  • Per Dark Reading,
    • “As the Department of Defense (DoD) continues to make deeper strides in implementing its Cybersecurity Maturity Model Certification (currently CMMC 2.0), we find ourselves at the cusp of what feels like its next iteration, CMMC 3.0, marking the next evolution in its efforts to strengthen cybersecurity across the defense industrial base (DIB). While the updated framework builds on the structure of CMMC 2.0, this new update would include clearer expectations and stricter enforcement, particularly for organizations handling controlled unclassified information (CUI). The DoD’s message is clear: Reducing risk and enhancing resilience are now mission-critical for any company supporting national defense.”
  • Cybersecurity Dive adds,
    • “The Chinese government has such vast hacking resources that it’s targeting tiny companies in the U.S. defense industrial base that never imagined they would end up on Beijing’s radar, a National Security Agency official said here Wednesday.
    • “China’s hacking resources outnumber those of the U.S. and [its] allies combined, and China has stolen more corporate data from the United States than any other nation in the world,” Bailey Bickley, chief of DIB defense at the NSA’s Cybersecurity Collaboration Center, said during a session at the Black Hat USA cybersecurity conference.
    • “Although best known for its intelligence-collection role, the NSA is also responsible for helping defense contractors safeguard their systems. Recently, the agency has been doing that through free security services — including classified information sharing and a protective DNS offering — from the Cybersecurity Collaboration Center.
    • “When we engage with small companies” in the defense industrial base, “they often think that what they do is not important enough to be targeted” by China, Bickley said. “But when you have the significant resources like that to conduct mass scanning and mass exploitation, there is no company and no target too small.”
  • and
    • “The Defense Advanced Research Projects Agency on Friday [August 8] unveiled the winners of a competition to spur the development of artificial intelligence tools designed to autonomously find and fix software vulnerabilities.
    • “Team Atlanta, Trail of Bits and Theori claimed the top three spots in DARPA’s AI Cyber Challenge, agency officials said at the DEF CON cybersecurity conference here. They will receive prizes of $4 million, $3 million and $1.5 million, respectively.
    • “All seven finalist teams will open source their AI tools so that the entire world can use them. Four of the tools debuted on Friday, while the remaining three will be released in the next few weeks.’
  • Cyberscoop reports,
    • “BlackSuit’s technical infrastructure was seized in a globally coordinated takedown operation last month that authorities touted as a significant blow in the fight against cybercrime. The ransomware group’s leak site has displayed a seizure notice since July 24.
    • “The takedown followed a long investigation, which allowed authorities to confiscate “considerable amounts of data,” and identify 184 victims, German officials said in a news release last week. The group’s total extortion demands surpassed $500 million by August 2024, with demands typically in the range of $1 million to $10 million, the Cybersecurity and Infrastructure Security Agency said in an advisory last year. 
    • “U.S. authorities were heavily involved in the operation, but have yet to share details about the investigation or its results. BlackSuit’s extortion site was seized by the Department of Homeland Security’s Homeland Security Investigation department, a unit of U.S. Immigration and Customs Enforcement. 
    • “A spokesperson for ICE told CyberScoop the Justice Department has been waiting for court documents to be unsealed before releasing any information about the law enforcement action dubbed “Operation Checkmate.” The FBI, Secret Service, Europol and cyber authorities from the United Kingdom, Germany, France, Ireland, Ukraine, Lithuania and Romania-based cybersecurity firm Bitdefender were also involved in the operation.” 
  • Dark Reading relates,
    • “Two senior executives and founders of the Samourai Wallet cryptocurrency mixer have pleaded guilty to charges involving washing more than $200 million for cybercriminals and other nefarious types.
    • “CEO Keonne Rodriguez and chief technology officer William Lonergan Hill admitted to operating a money-transmitting business that handled criminal proceeds. They have pleaded guilty to conspiracy and face a maximum sentence of five years in prison in addition to the fine.
    • “The US Department of Justice first arrested Rodriguez and Hill in April of last year on two counts of conspiracy: operating an unlicensed money-transmitting business and money laundering, the latter of which carries a maximum sentence of 20 years.”

From the cybersecurity breaches and vulnerabilities front,

  • FedScoop reports,
    • “The U.S. judiciary announced plans to increase security for sensitive information on its case management system following what it described as “recent escalated cyberattacks of a sophisticated and persistent nature.”
    • “In a Thursday [August 7] statement, the federal judiciary said it’s “taking additional steps to strengthen protections for” that information. It also said it’s “further enhancing security of the system and to block future attacks, and it is prioritizing working with courts to mitigate the impact on litigants.”
    • “The statement from the third branch comes one day after a Politico report revealed that its case filing system had recently been breached. That report cited unnamed sources who were concerned that the identities of confidential court informants may have been compromised.”
  • Cyberscoop tells us,
    • “Federal cyber authorities issued an alert Wednesday evening about a high-severity vulnerability affecting on-premises Microsoft Exchange servers shortly after a researcher presented findings of the defect at Black Hat. 
    • “Microsoft also issued an advisory about the vulnerability — CVE-2025-53786 — and said it’s not aware of exploitation in the wild. 
    • “While the public disclosure and advisories about the defect came late in the day amid one of the largest cybersecurity conferences, Tom Gallagher, VP of engineering at Microsoft Security Response Center, told CyberScoop the timing was coordinated for release following Mollema’s presentation.
    • “Gallagher stressed that exploitation requires an attacker to achieve administrative access to an on-premises Exchange server in a hybrid environment.” 
  • and
    • “SonicWall warned customers to disable encryption services on Gen 7 firewalls in the wake of an active attack spree targeting a yet-to-be identified vulnerability affecting a critical firewall service. Attacks have increased notably since Friday, the company said in a blog post.
    • “Threat hunters and incident responders from Arctic Wolf, Google and Huntress have observed a wave of ransomware attacks beginning as early as July 15. Mounting evidence points to a zero-day vulnerability affecting the secure sockets layer (SSL) VPN protocol as the initial attack vector.
    • “A financially motivated threat actor is actively compromising victim environments and deploying Akira ransomware,” Charles Carmakal, CTO at Mandiant Consulting, said in a LinkedIn post Tuesday. “The speed and scale of the compromises suggests a potential zero-day vulnerability in SonicWall Gen 7 firewalls.”
    • “SonicWall said an ongoing investigation has yet to determine if the attacks involve a previously disclosed vulnerability or a zero-day. “If a new vulnerability is confirmed, we will release updated firmware and guidance as quickly as possible,” Bret Fitzgerald, senior director of global communications at SonicWall, told CyberScoop.”
  • Per Bleeping Computer,
    • “Trend Micro has warned customers to immediately secure their systems against an actively exploited remote code execution vulnerability in its Apex One endpoint security platform.
    • Apex One is an endpoint security platform designed to automatically detect and respond to threats, including malicious tools, malware, and vulnerabilities.
    • “This critical security flaw (tracked as CVE-2025-54948 and CVE-2025-54987 depending on the CPU architecture) is due to a command injection weakness in the Apex One Management Console (on-premise) that enables pre-authenticated attackers to execute arbitrary code remotely on systems running unpatched software.
    • “Trend Micro has yet to issue security updates to patch this actively exploited vulnerability, but it has released a mitigation tool that provides short-term mitigation against exploitation attempts.”
  • and
    • “A recently fixed WinRAR vulnerability tracked as CVE-2025-8088 was exploited as a zero-day in phishing attacks to install the RomCom malware.
    • “The flaw is a directory traversal vulnerability that was fixed in WinRAR 7.13, which allows specially crafted archives to extract files into a file path selected by the attacker.
    • “When extracting a file, previous versions of WinRAR, Windows versions of RAR, UnRAR, portable UnRAR source code and UnRAR.dll can be tricked into using a path, defined in a specially crafted archive, instead of user specified path,” reads the WinRAR 7.13 changelog.”
  • CISA added three known exploited vulnerabilities to its catalog this week.
  • Per SC Media,
    • “Dormant service accounts with privileges were found in more than 70% of enterprise environments according to new research released by BeyondTrust on Aug. 4 at BlackHat in Las Vegas.
    • “The researchers also reported that overly permissive Entra Service Principals create direct pathways to Global Admin privileges, exposing entire Microsoft 365 environments to potential takeover.
    • “According to BeyondTrust, credentials reused across multiple service accounts by human administrators can also let a single compromised password hack numerous non-human accounts.”
    • “Our data shows that many organizations lack the complete story when it comes to their identity attack surface,” said Marc Maiffret, chief technology officer at BeyondTrust. “For many, overlooked hygiene issues silently open the door to attackers. And with the rise of Agentic AI, the stakes have never been higher, especially as most organizations lack visibility into how compromised accounts can be leveraged to seize control of application secrets, which often carry elevated privileges.”
  • Security Week points out,
    • “Five vulnerabilities in the ControlVault3 firmware and the associated Windows APIs expose millions of Dell laptops to persistent implants and Windows login bypasses via physical access, Cisco Talos reports.
    • “The issues, tracked as CVE-2025-24311, CVE-2025-25215, CVE-2025-24922, CVE-2025-25050, and CVE-2025-24919, were initially disclosed on June 13, when Dell announced that patches for them were rolled out for over 100 Dell Pro, Latitude, and Precision models.
    • “The affected component, ControlVault3 (and the ControlVault3+ iteration), is a hardware-based system meant to securely store passwords, biometric information, and security codes.”

From the ransomware front,

  • Bleeping Computer reports,
    • “Ransomware gangs have recently joined ongoing attacks targeting a Microsoft SharePoint vulnerability chain, part of a broader exploitation campaign that has already led to the breach of at least 148 organizations worldwide.
    • “Security researchers at Palo Alto Networks’ Unit 42 have discovered a 4L4MD4R ransomware variant, based on open-source Mauri870 code, while analyzing incidents involving this SharePoint exploit chain (dubbed “ToolShell”).
    • “The ransomware was detected on July 27 after discovering a malware loader that downloads and executes the ransomware from theinnovationfactory[.]it (145.239.97[.]206).
    • “The loader was spotted following a failed exploitation attempt that revealed malicious PowerShell commands designed to disable security monitoring on the targeted device.
    • “Analysis of the 4L4MD4R payload revealed that it is UPX-packed and written in GoLang. Upon execution, the sample decrypts an AES-encrypted payload in memory, allocates memory to load the decrypted PE file, and creates a new thread to execute it,” Unit 42 said.”
  • and
    • “A new Endpoint Detection and Response (EDR) killer that is considered to be the evolution of ‘EDRKillShifter,’ developed by RansomHub, has been observed in attacks by eight different ransomware gangs.
    • “Such tools help ransomware operators turn off security products on breached systems so they can deploy payloads, escalate privileges, attempt lateral movement, and ultimately encrypt devices on the network without being detected. 
    • “According to Sophos security researchers, the new tool, which wasn’t given a specific name, is used by RansomHub, Blacksuit, Medusa, Qilin, Dragonforce, Crytox, Lynx, and INC.”
  • CISA issued an Analysis report about Exploitation of SharePoint Vulnerabilities on August 6.
  • InfoSecurity Magazine explains how ransomware actors have expanded tactics beyond encryption and exfiltration.
  • Halcyon warns us,
    • “Ransomware remains one of the most destructive and expensive threats facing organizations today. With average ransom demands hitting $3.5M, victims are forced into high-stakes decisions under intense pressure: pay up or risk catastrophic disruption. 
    • “Nearly half of all targeted organizations end up paying, even after negotiations. The impact doesn’t end with encryption: recovery takes weeks, services stall, regulators circle, and trust erodes. Ransomware isn’t just a cybersecurity problem; it’s a full-blown operational crisis.  
    • “The Halcyon team of ransomware experts has put together this extortion group power rankings guide as a quick reference for the extortion threat landscape based on data from throughout Q2-2025, which can be reviewed along with earlier reports here: Power Rankings: Ransomware Malicious Quartile.”
  • MSPP Alert adds,
    • “Ransomware doesn’t play fair—and now, neither are the defenders. Sophos and Halcyon are teaming up with a direct integration that goes far beyond traditional intel feeds or industry sharing forums. This partnership isn’t about exchanging threat data after the fact. It’s about coordinating active defenses in real time, within live customer environments.
    • “What makes this different? According to Simon Reed, Chief Research and Scientific Officer at Sophos, it’s not just another “threat feed” dropped into a dashboard. “Sophos and Halcyon’s approach to threat intelligence sharing shifts the status quo from out-of-context threat intelligence (which is still hugely useful as an industry standard approach) to sharing coordinated, real-time defense that meets attackers head-on,” he told MSSP Alert.
    • “Instead of piecing together siloed signals, both companies are now synchronizing responses against a common adversary.”

From the cybersecurity business and reporting front,

  • Dark Reading reports,
    • “It was a memorable Black Hat 2025 USA for the founders of Prime Security, the winners of this year’s Startup Spotlight competition.
    • “The Startup Spotlight Competition is a pitch competition for cybersecurity startup companies to present their products and solutions in front of a live audience at Black Hat. In the first phase of the competition, startups of all stripes submitted a pitch describing the company and the products and solutions. A panel of judges reviewed submissions for the competition, looking for companies that fit the bill of “most innovative emerging companies in cybersecurity,” before narrowing down to four: FireTail, Keep Aware, Prime Security, and Twine Security. 
    • “Representatives from each of the four companies pitched their companies and products for the final time to a panel of judges at the Black Hat USA conference in Las Vegas, in a Shark Tank-style competition. While the judges deliberated on the winner, the audience also voted on their favorite. Prime Security won both the judges’ votes as well as the audience’s.”
  • Here is a link to Dark Reading’s round up of Black Hat conference news.
  • Also per Dark Reading,
    • “Investing in building a human-centric defense involves a combination of adaptive security awareness training, a vigilant and skeptical culture, and the deployment of layered technical controls.”
  • and
    • “Data Dump from APT Actor Yields Clues to Attacker Capabilities. The tranche of information includes data on recent campaigns, attack tools, compromised credentials, and command files used by a threat actor believed to be acting on behalf of China or North Korea.”

Door prize from the artificial intelligence front

  • Per Security Week,
    • “Red Teams Jailbreak GPT-5 With Ease, Warn It’s ‘Nearly Unusable’ for Enterprise
    • “Researchers demonstrate how multi-turn “storytelling” attacks bypass prompt-level filters, exposing systemic weaknesses in GPT-5’s defenses.”

Thursday report

From Washington, DC,

  • MedPage Today tells us,
    • “HHS Secretary Robert F. Kennedy Jr. last month quietly endorsed recommendations from his handpicked vaccine advisors that everyone in the U.S. ages 6 months and older receive a flu shot for the upcoming season.” * * *
    • “ACIP reaffirms the recommendations for routine annual influenza vaccination of all persons aged ≥6 months who do not have contraindications for the 2025-2026 season,” the ACIP page states. “With no current CDC Director and pending confirmation of a new CDC Director, this recommendation was adopted by the HHS Secretary on July 22, 2025, and is now an official recommendation of the CDC.”
    • “A new CDC director, Susan Monarez, PhD, is now in place. * * *
    • “Another ACIP recommendation from the June meeting earned an endorsement Aug. 4 from Monarez. ACIP called for infants younger than 8 months who were born during or entering their first respiratory syncytial virus (RSV) season who are not protected by maternal vaccination to receive one dose of clesrovimab (Enflonsia)opens in a new tab or window. The monoclonal antibody joins a similar long-acting shot, nirsevimab (Beyfortus),opens in a new tab or window as an option for this population.”
  • Beckers Hospital Reviews lets us know six things about the tariffs that took effect today.
  • Federal News Network informs us,
    • “The Postal Service’s board of governors is urging its regulator not to put limits on its ability to set higher mail prices, after posting another multibillion-dollar quarterly net loss.
    • “USPS posted a $3.1 billion net loss for the third quarter of fiscal 2025 — a greater loss than the $2.5 billion net loss it saw for the same period last year.
    • “But Postmaster General David Steiner said USPS is “on the right path,” under a 10-year reform plan launched by his predecessor, former Postmaster General Louis DeJoy.
    • “The strategy is sound. Now we have to execute,” Steiner said during a public meeting of the USPS Board of Governors on Thursday. “But we can’t execute unless all of our team is working together. We all need to be rowing the oars in the same direction.”
  • Healthcare Dive relates,
    • “Amwell has extended a contract with the Defense Health Agency to support virtual care at the military health system, one of the company’s most significant growth initiatives, for another year, the telehealth vendor said Tuesday. 
    • “However, the deal cut out deployments for Amwell’s behavioral health and automated care programs “due to budget restrictions being broadly enforced by the Department of Defense,” CEO Ido Schoenberg said during a second quarter earnings call on Tuesday. 
    • “The contract change led the telehealth firm to revise its guidance for 2025. Amwell now expects revenue from $245 million to $250 million this year, down from its previous outlook of $250 million to $260 million.”

From the Food and Drug Administration front,

  • The American Hospital Association News reports,
    • “The Food and Drug Administration Aug. 7 announced a new program to help improve the domestic pharmaceutical supply chain by increasing regulatory predictability and facilitating the construction of drug manufacturing facilities in the U.S. The program, called FDA PreCheck, was created in response to a May 5 executive order, “Regulatory Relief to Promote Domestic Production of Critical Medicines,” which directs the FDA to streamline and accelerate the development of domestic pharmaceutical manufacturing by eliminating unnecessary or duplicative regulations and improving inspection processes. 
    • “The program consists of a two-phase approach to facilitate new manufacturing facilities. The first provides manufacturers with more frequent FDA communication during stages such as facility design, construction and pre-production. The second focuses on streamlining development of the chemistry, manufacturing and controls section of the drug application through pre-application meetings and early feedback.” 
  • Per BioPharma Dive,
    • “The Food and Drug Administration on Thursday lifted its recommendation to pause use of Valenva’s chikungunya vaccine Ixchiq in older adults but added new warnings about the shot’s risks and limited who is eligible to receive it.
    • “The FDA’s action follows a similar move by the European Medicines Agency, which had paused use along similar lines as the FDA. However, the U.S. regulator’s changes to Ixchiq’s labeling appear likely to curtail how broadly its used in the future.
    • “Vaccination with Ixchiq is not advisable for most U.S. travelers. For most U.S. travelers, the risk of exposure to chikungunya is low,” the updated label says.”
  • Per MedTech Dive,
    • “Tandem Diabetes Care flagged a problem with certain t:slim X2 insulin pumps where a wiring issue with certain devices’ speakers can cause them to malfunction and stop delivering insulin. 
    • “Tandem said it has received reports of 700 adverse events and 59 injuries. There have been no reports of death. The problem, if not addressed, presents the risk of hyperglycemia in people with diabetes. The company said in a Thursday announcement that it has also alerted the Food and Drug Administration and regulators outside of the U.S. 
    • “The company sent a letter to customers in July. The FDA has not yet posted the device correction in its recall database.”
  • Fierce Pharma adds,
    • “When Jazz Pharmaceuticals’ incoming CEO Renee Gala takes the reins at the drugmaker next week, she’ll have a brand-new launch to manage.
    • “Wednesday, the FDA approved Jazz’s Modeyso (dordaviprone) for patients ages 1 and older with H3 K27M-mutant diffuse midline glioma who have progressive disease following prior therapy. The drug, picked up in the company’s $935 million buyout of Chimerix earlier this year, is the first systemic therapy for those with the aggressive brain cancer.”

From the judicial front,

  • Healthcare Dive reports,
    • “UnitedHealth and Amedisys have agreed to a settlement with the Department of Justice, clearing the path for their $3.3 billion merger to go through.
    • The settlement, filed with the Maryland district court on Thursday, requires UnitedHealth and Amedisys to divest certain businesses in order to placate the DOJ’s concerns that the merger is anticompetitive. Amedisys has also agreed to pay a $1.1 million civil penalty to the U.S. for not fully complying with regulators during the merger review process.
    • “Regulators’ tentative greenlight of the multibillion-dollar deal is a win for UnitedHealth, which originally proposed plans to acquire the home health and hospice provider in 2023. However, the merger has been tied up in litigation after the DOJ and four states sued to block it in November.”
  • Per Fierce Healthcare,
    • “The drug price negotiation program has withstood another procedural effort in striking down one of the Inflation Reduction Act’s most significant provisions.
    • “In the U.S. Court of Appeals for the 6th Circuit, a panel of judges upheld (PDF) a lower court’s decision to dismiss the lawsuit.
    • “A judge dismissed the lawsuit last year, saying most of the plaintiffs lacked standing to bring the case, but the U.S. Chamber of Commerce was able to file a new suit. The U.S. Chamber could now appeal to the Supreme Court, reported The Hill.”
  • The Hill adds,
    • “Federal judges in Texas and Connecticut on Thursday ruled against arguments challenging the constitutionality of the Medicare Drug Price Negotiation Program, delivering two more blows to the pharmaceutical industry this week after an appeals court upheld the dismissal of a similar case.
    • “In Connecticut, the U.S. 2nd Circuit Court of Appeals upheld (PDF) a decision granted by U.S. District Judge Michael P. Shea last year against pharmaceutical company Boehringer Ingelheim. The company’s diabetes medication Jardiance was among the first 10 drugs chosen for Medicare negotiations, and two more of its products were chosen for the following round of negotiations.”
    • “In Texas, U.S. District Judge David Alan Ezra dismissed the lawsuit brought forward by the trade group PhRMA with prejudice, closing the case.”

From the public health and medical research,

  • The Wall Street Journal reports,
    • “Ultraprocessed foods make up the majority of calories Americans are eating, according to a report released Thursday by the federal government. But there are signs this consumption might be declining.
    • “Sandwiches, baked goods, salty snacks and other ultraprocessed foods accounted for 55% of the calories Americans age 1 and older consumed from August 2021 to August 2023, according to the Centers for Disease Control and Prevention’s National Center for Health Statistics study. 
    • “That proportion is getting smaller. For adults, the mean percentage of calories consumed from ultraprocessed foods fell 3 percentage points to 53% since 2018 and for children and teens, it fell nearly 4 percentage points to 61.9%, the report found.
    • “Statistically, the decline is significant,” said Anne Williams, a senior service fellow at the CDC and lead author of the report. For adults consuming around 2,000 calories a day, the drop between the 2017 to 2018 figures and the latest report translates to around 60 fewer calories a day coming from ultraprocessed foods on average, said Williams.
    • “Ultraprocessed foods have been linked to an array of health issues, including obesity, Type 2 diabetes, cancer, cardiovascular disease and depression. There isn’t a set definition for ultraprocessed foods but researchers consider them foods made with ingredients not normally found in a home kitchen, including high-fructose corn syrup and emulsifiers such as soy lecithin.”
  • MedPage Today adds,
    • “Eating French fries multiple times a week was associated with a higher risk of type 2 diabetes, though this wasn’t the case for baked, boiled, or mashed potatoes, researchers said.
    • “For every increment of three servings weekly of French fries, the rate of type 2 diabetes increased by 20% (95% CI 1.12-1.28), and for every increment of three servings weekly of total potato, the rate increased by 5% (95% CI 1.02-1.08), reported Walter Willett, MD, of the Harvard T.H. Chan School of Public Health in Boston, and colleagues.
    • “However, consumption of combined baked, boiled, or mashed potatoes was not significantly associated with risk of type 2 diabetes (pooled HR 1.01, 95% CI 0.98-1.05), they noted in The BMJ.
    • “Importantly, our substitution analysis showed that replacing all forms of potatoes — especially fries — with whole grains was linked to a lower risk of type 2 diabetes, whereas swapping them for white rice was associated with the opposite effect,” co-author Seyed Mohammad Mousavi, PhD, also of the Harvard T.H. Chan School of Public Health, told MedPage Today. “This reinforces that it’s not just about the potato itself, it’s about how it’s prepared and what foods it’s replacing in the diet.”
  • Genetic Engineering and BioTechnology News reports,
    • “Parkinson’s disease (PD) is the second-most common neurodegenerative disorder after Alzheimer’s and is caused by the degeneration of dopamine-producing neurons in the brain, leading to motor dysfunction, such as tremors and slowed movements.  
    • “Vamsi Mootha, MD, institute member at the Broad Institute, explains that a striking epidemiological association exists between heavy smoking and lowered PD risk. As smoking causes elevated carbon monoxide exposure which disrupts oxygen delivery by hemoglobin, he speculates that a low oxygen state in the brain may offer an unexpected protective mechanism against this incurable neurological disease that affects more than 10 million people worldwide. 
    • “In a new study published in Nature Neuroscience titled, “Hypoxia ameliorates neurodegeneration and movement disorder in a mouse model of Parkinson’s disease,” Mootha’s lab has now shown that low oxygen environments, similar to the thin air found at Mont Blanc, which reaches an elevation of approximately 16,000 feet, can successfully recover neuron function and alleviate motor symptoms in mice with Parkinson’s-like disease.:
    • * * * “The fact that we actually saw some reversal of neurological damage is really exciting,” said Mootha in a public release. “It tells us that there is a window during which some neurons are dysfunctional but not yet dead—and that we can restore their function if we intervene early enough.”
  • Health Day relates,
    • “Vaccination with the updated COVID-19 mRNA vaccine containing the severe acute respiratory syndrome coronavirus-2 Omicron JN.1 lineage [the fall 2024 vaccine] was not associated with an increased risk for 29 adverse events, according to a study published online July 28 in JAMA Network Open.
    • “Niklas Worm Andersson, M.D., Ph.D., from Statens Serum Institut in Copenhagen, Denmark, and colleagues examined the association between vaccination with JN.1-containing vaccines and the risk for 29 serious adverse events adapted from prioritized lists of adverse events of special interest to COVID-19 vaccines. Outcome rates during the first 28 days after JN.1-containing vaccine administration (i.e., the risk period) were compared to outcome rates during the remaining period.”
  • Per MedPage Today,
    • “Superagers — a group of adults over age 80 with the memory capacity of much younger people — maintained good brain morphology, tended to be gregarious, and appeared to be resistant to neurofibrillary degeneration and resilient to its consequences, more than two decades of research showed.
    • “In contrast to neurotypical peers who had age-related brain shrinkage, this group had a region in the cingulate gyrus that was thicker than younger adults, reported Sandra Weintraub, PhD, of Northwestern University Feinberg School of Medicine in Chicago, and colleagues.
    • “Superagers also had fewer Alzheimer’s-related brain changes, greater size of entorhinal neurons, fewer inflammatory microglia in white matter, better preserved cholinergic innervation, and a greater density of evolutionarily progressive von Economo neurons, Weintraub and colleagues wrote in a perspective piece in Alzheimer’s & Dementia.
    • “No particular lifestyle was conducive to superaging, the researchers said. Some superagers appeared to follow all conceivable recommendations for a healthy life. Others did not eat well, enjoyed smoking and drinking, shunned exercise, suffered stressful life situations, and did not sleep well.
    • “Superagers also did not seem to be medically healthier than their peers and took similar medications as they did. However, the superager group was notably sociable, relishing extracurricular activities. Compared with their cognitively average peers, they rated their relationships with others more positively. On a self-reported questionnaire of personality traits, they tended to endorse high levels of extraversion.
    • “It wasn’t the social and lifestyles aspects of superaging that surprised the researchers; it was “really what we’ve found in their brains that’s been so earth-shattering for us,” Weintraub said in a statement.”

From the healthcare artificial intelligence front,

  • Fierce Healthcare informs us,
    • “OpenAI released its most advanced reasoning model, GPT-5, which it touts as its most useful model for healthcare.
    • “The application of ChatGPT for healthcare played a leading role in the company’s Summer Update meeting on Thursday, during which it did live demos of the upgraded model. 
    • “Sam Altman, CEO of OpenAI, said health is one of the top reasons consumers use ChatGPT, saying it “empowers you to be more in control of your healthcare journey.” The company prioritized improving its healthcare features for this version of the product, Altman said. 
    • “GPT-5 will be available on the free version of the ChatGPT app, which means more consumers could start to rely on the product for assistance in making treatment decisions, understanding test results and determining what questions they should ask their doctors in the clinic.” 
  • Beckers Health IT points out,
    • “Oakland, Calif.-based Kaiser Permanente has been experimenting with AI in its patient portal, increasing patient engagement and experience in the process.
    • “The health system’s Southern California Permanente Medical Group, headquartered in Pasadena, launched the Kaiser Permanente Intelligent Navigator for its 4.9 million patients in October. The platform allows patients to chat with AI via a text box to book appointments and connect with the care they need.
    • “Care is local, but at the same time it’s virtual and it’s become a global commodity,” Khang Nguyen, MD, assistant executive medical director for care transformation at Southern California Permanente Medical Group and chief medical officer of care navigation for the Permanente Federation, told Becker’s. “So patients are really expecting artificial intelligence to support healthcare in a way that is supporting other industries, in the sense that people are able to describe what they want versus being given choices.” * * *
    • “In a study that evaluated nearly 3 million patient encounters using the AI between October and March, the tool detected urgent medical issues with 97.7% accuracy and recommended appropriate care paths with 88.9% accuracy. Patients successfully booked appointments more than half the time, compared to the industry average of 30%. The portal’s patient satisfaction scores went up by about 9%.”

From the U.S. healthcare business front,

  • The Wall Street Journal reports,
    • Eli Lilly shares plunged about 14% in midday trading Thursday after the company reported less-than-stellar results of a new study of an experimental anti-obesity pill that is expected to become a blockbuster.
    • “The pill helped people lose up to about 12% of their body weight after more than a year of treatment. The results could clear the way for the shot alternative to be on the market next year, but the magnitude of weight loss fell short of Wall Street expectations.
    • “The drugmaker also raised its earnings outlook for the year after revenue surged in its latest quarter on continued demand for its weight-loss and diabetes treatments.”
    • “The Lilly pill, orforglipron, is expected to become a big seller if regulators approve it for sale. Morgan Stanley analysts had said that under their bull-case scenario, the drug’s use for both obesity and diabetes could generate annual sales of up to $40 billion by 2033.
    • “Yet the latest clinical-trial results may dent some of that enthusiasm. The magnitude of weight loss fell short of what some analysts were predicting: 13% to 15% or more. 
    • “The Lilly pill is one of two that could hit the market within the next year or so, ushering in a new chapter of the weight-loss drug boom. Novo Nordisk has applied for regulatory approval of an anti-obesity pill version of its Ozempic and Wegovy, which could become available by the end of this year.”
  • Modern Healthcare relates,
    • “Aetna will end nearly 90 Medicare Advantage plans across 34 states in 2026, the company notified third-party sellers this week.
    • “The CVS Health subsidiary’s financial performance has represented a bright spot in the Medicare Advantage market compared with competitors such as UnitedHealth Group. This month, CVS Health raised its annual earnings guidance amid a $2 billion turnaround plan. The company cut the second-most plans in 2025, after Humana.
    • “The majority of the Medicare Advantage plans Aetna plans to eliminate next year are PPOs. Beginning in September, Aetna will stop paying commissions to brokers that enroll new members in these plans, according to a notice the company distributed to brokers on Monday.”
  • and
    • “UPMC and GoHealth Urgent Care have rebranded 81 urgent care centers as part of a joint venture between the two organizations. 
    • “The centers span Pennsylvania and West Virginia and offer care for non-life-threatening ailments, including flu, fever, earaches, insect bites, sprains, simple fractures and cuts requiring stitches. They will also offer virtual care options and are staffed with UPMC clinicians, according to a Thursday news release.
    • “The centers were previously owned by UPMC, including sites it acquired last month from MedExpress, another urgent care provider. Financial details of the joint venture were not disclosed.” 
  • Beckers Payer Issues adds,
    • “As major insurers pull back on their Medicare Advantage offerings, health system-owned plans told Becker’s they’re eyeing an opportunity to regain ground ahead of the annual enrollment season.” * * *
    • “I do think it’s an opportunity. Over time, the playing field is going to level somewhat, which is going to be a challenge for the nationals. For the community health plans, I think it’s going to be a benefit,” Rob Hitchcock, president and CEO of Intermountain’s Select Health, said.
    • “What you want is a healthy mix. You do want the national players to be strong, but you also want the community health plans to be strong,” he added.
  • NFP, an Aon company, discusses pharmacy deserts.
    • “A pharmacy desert is more than just a rural problem. It’s any area, urban, suburban or rural, where people lack reasonable access to a pharmacy. That usually means:
      • “More than one mile away in urban areas.
      • “Two miles in suburban areas.
      • “10 miles in rural regions.
    • “However, distance isn’t the only factor. Even if a pharmacy technically exists nearby, lack of public transportation, limited hours or closures of independent stores can make access nearly impossible, particularly for lower-income communities or those with mobility challenges.” * * *
    • “Pharmacy deserts are growing, and they have real consequences for employee health, equity and cost. While benefit consultants cannot control the closures, clients can guide their employees toward solutions that help their people stay healthy and protected, no matter where they live.”

Tuesday report

From Washington, DC

  • The Wall Street Journal reports,
    • “Many seniors enjoy the perks that come with Medicare Advantage. But those extras—like dental coverage and free gym memberships—are being scaled back.
    • “Insurers are cutting benefits and exiting from unprofitable markets, and Wall Street is cheering them on. Once rewarded by investors for rapid expansion in the lucrative privatized Medicare program, companies are now being applauded for showing restraint amid rising medical costs and lower government payments.” * * *
    • “To be clear, major insurers aren’t exiting Medicare Advantage. Apart from Cigna, which sold its Medicare business last year, the big players are still betting on the program—some are likely to take advantage of the turmoil to increase their market share. And the market is arguably still well served and competitive, especially in densely populated areas. Even after some moderation last year, the average beneficiary this year had 42 plan options from which to choose, according to health-research nonprofit KFF. 
    • “As the industry pivots to leaner operations, Wall Street may regain confidence. But the era of red-hot Medicare Advantage growth is over, at least for now. While Democrats have led efforts to cut overpayments, Republicans also face mounting pressure to curb spending—especially after recent tax cuts, notes Deutsche’s [George] Hill. He warns that more regulatory shifts may be coming, including a potential overhaul of the star ratings system, which governs billions in bonus payments tied to plan quality and patient satisfaction.
    • “Until that picture clears, investors will continue to reward restraint and tightly managed risk. In today’s Medicare Advantage market, and across government insurance programs, growth is taking a back seat to profitability.
  • BiioPharma Dive tells us,
    • “The U.S. plans to put tariffs of up to 250% on pharmaceutical imports over the next year and a half, President Donald Trump said in a Tuesday interview with CNBC.
    • “Trump said he would put a “small tariff” on such imports initially but added that he would raise the duties to 150% and then 250% in “one and a half years maximum.” The president indicated that announcements of pharmaceutical tariffs, as well as duties on semiconductors, would be announced “within the next week or so.”
  • Per an HHS news release,
    • “The U.S. Department of Health and Human Services (HHS) today announced the beginning of a coordinated wind-down of its mRNA vaccine development activities under the Biomedical Advanced Research and Development Authority (BARDA), including the cancellation and de-scoping of various contracts and solicitations. The decision follows a comprehensive review of mRNA-related investments initiated during the COVID-19 public health emergency.
    • “We reviewed the science, listened to the experts, and acted,” said HHS Secretary Robert F. Kennedy, Jr. “BARDA is terminating 22 mRNA vaccine development investments because the data show these vaccines fail to protect effectively against upper respiratory infections like COVID and flu. We’re shifting that funding toward safer, broader vaccine platforms that remain effective even as viruses mutate.” * * *
    • “While some final-stage contracts (e.g., Arcturus and Amplitude) will be allowed to run their course to preserve prior taxpayer investment, no new mRNA-based projects will be initiated. HHS has also instructed its partner, Global Health Investment Corporation (GHIC), which manages BARDA Ventures, to cease all mRNA-based equity investments. In total, this affects 22 projects worth nearly $500 million. Other uses of mRNA technology within the department are not impacted by this announcement.” * * *
    • “The move signals a broader shift in federal vaccine development priorities. Going forward, BARDA will focus on platforms with stronger safety records and transparent clinical and manufacturing data practices. Technologies that were funded during the emergency phase but failed to meet current scientific standards will be phased out in favor of evidence-based, ethically grounded solutions – like whole-virus vaccines and novel platforms.”
  • Roll Call lets us know,
    • “The Trump administration is escalating its push against what has become a key part of the way states, localities and communities respond to the overdose epidemic: harm reduction. 
    • “A public health approach aimed at mitigating the negative health effects associated with drug use, harm reduction aims to prevent overdoses and infectious disease transmission.
    • “Methods can involve the use of opioid overdose reversal medications such as naloxone, providing sterile needles to limit the transmission of infectious diseases, test strips that detect fentanyl in drugs, and “safe consumption sites,” where people can use drugs under supervision in case they need intervention.” * * *
    • “In a “Dear Colleague” letter sent to states last week, Art Kleinschmidt, principal deputy assistant secretary at SAMHSA, said he doesn’t consider naloxone a harm reduction method and as such it would continue to be funded by the government. Kleinschmidt said test kits and other services can also be funded through grants.
    • “But the letter stated that federal funding can’t be used to “purchase pipes or other supplies for safer smoking kits nor syringes or needles used to inject illicit drugs” or “any other supplies to promote or facilitate drug use.” 
    • “Moving forward, SAMHSA funds will no longer be used to support poorly defined so-called “harm reduction” activities; rather, SAMHSA is providing guidance to state agency leadership and to grantees through new award terms and conditions that provide clarity on what supplies and services previously defined under the umbrella of harm reduction can be supported with SAMHSA funding,” Kleinschmidt wrote.” 

From the public health and medical research front,

  • The American Hospital Association News informs us,
    • “Patients in the hospital for surgeries had better outcomes in 2024 than they did in 2019, according to a new report released today by the AHA and Vizient. 
    • “The significant improvement aligned not only with better performance on patient safety metrics — such as reductions in infections and falls — but also with marked declines in three major surgical patient safety indicators: severe bleeding, sepsis and respiratory failure. * * *
    • “The new findings build on a report AHA released in collaboration with Vizient last year showing that hospitals and health systems performed better on key patient safety and quality measures in the first quarter of 2024 than they did before the COVID-19 pandemic. In fact, hospitals’ efforts to improve safety led to 200,000 Americans hospitalized between April 2023 and March 2024 surviving episodes of care they wouldn’t have in 2019.” 
  • MedPage Today reports,
    • “Unhealthy alcohol use is a leading cause of death and serious illness among U.S. adults.
    • “In new draft guidance, the USPSTF reaffirmed that all adults should be screened for unhealthy alcohol use and [newly] recommended brief behavioral counseling interventions when appropriate.
    • “The task force found insufficient evidence to make the same recommendation in adolescents.”
    • The public comment period ends on September 2, 2025.
  • Healio adds,
    • “Testing for hepatitis C virus infection every 6 to 12 months — or even more frequently — among people who inject drugs could be a beneficial, cost-effective strategy, according to a study published in JAMA Health Forum.
    • USPSTF recommends hepatitis c screening for adults aged 18 to 79 without known liver disease.
      • “Most adults need to be screened only once. Persons with continued risk for HCV infection (e.g., PWID) should be screened periodically. There is limited information about the specific screening interval that should occur in persons who continue to be at risk for new HCV infection or how pregnancy changes the need for additional screening.”
        • The JAMA Health Forum study fills in the screening interval information gap.
  • Per STAT News,
    • “Nathan Young, a community neurologist at the Mayo Clinic, recently saw a patient whose diagnosis he couldn’t quite nail down. Parkinson’s seemed a likely possibility, but Young was concerned she might instead have a rare neurological disorder called progressive supranuclear palsy, or PSP, which can progress much more rapidly. 
    • “I opened a can of worms,” said Young: He ordered a PET scan of the patient’s brain, but the radiology report only confused matters. Instead of ruling out PSP, it suggested yet a third diagnosis: Alzheimer’s. 
    • “Normally at this point, Young would call in other specialists as reinforcements, including Mayo’s renowned experts. But this time he had something different to help: a new AI tool called StateViewer.”
    • “Developed by Mayo’s Neurology AI program, StateViewer takes scans like the one Young ordered — they’re called FDG-PET scans, named for the radioactive tracer they use — and spits out a report of similar brains that have been scanned in Mayo’s clinical and research networks. The output: a differential diagnosis of nine potential types of dementia. In development over the last several years, StateViewer hit the rails at all three Mayo campuses four months ago, and it’s been run thousands of times on patients’ brain scans.”
  • and
    • “Vertex Pharmaceuticals said Monday afternoon that its next-generation non-opioid pain reliever failed to significantly outperform placebo in a Phase 2 trial.
    • “The experimental drug, codenamed VX-993, is similar to the company’s recently approved pill Journavx but could potentially be given at higher doses and formulated as an IV infusion. The hope is that it could thus provide superior relief or offer an alternative to IV opioids. But after Monday’s results, the company said it would discontinue efforts to develop the drug as a single-agent medicine for acute pain.”
    • “We do not plan to advance VX-993 as monotherapy in acute pain, because we do not expect that it will be superior to our [existing] NaV1.8 inhibitors,” said CEO Reshma Kewalramani during a Monday afternoon earnings call with investors, using a scientific shorthand for the class of drugs. She noted that the company will continue a trial testing the drug in patients with diabetes who have chronic nerve pain.”
  • Cardiovascular Business points out,
    • “A surgeon at Cleveland Clinic has performed the world’s first robotic-assisted heart surgery of its kind, using CardioPrecision’s CoreVista Robot Enabling Platform to implant Corcym’s Perceval Plus aortic heart valve through a small incision in the patient’s neck.
    • “The successful operation, known as AVATAR (Advanced Videoscopic Aortic valve surgery by Transcervical Approach using Robot assistance), was performed by Marijan Koprivanac, MD, a cardiovascular surgeon with Cleveland Clinic’s Heart, Vascular and Thoracic Institute. Other robotic techniques for aortic valve replacement have already been in use, including the robotic aortic valve replacement procedures developed at the WVU Heart and Vascular Institute, what sets this approach apart is the fact that everything is done through that small incision in the neck. 
    • “Combining the artificial heart valve with this new surgical technology means patients should experience less pain and time in the hospital following heart surgery,” Koprivanac said in a statement. “In fact, we believe that this may be one of the least invasive surgical heart valve replacement options now available.”
  • Per Genetic Engineering and Biotechnology News,
    • “Amyotrophic lateral sclerosis (ALS) is an incurable neurological disorder affecting motor neurons (MNs), which are nerve cells in the brain and spinal cord that control voluntary muscle movement and breathing. Many ALS clinical trials, including those testing promising drugs, have fallen short of expectations, commonly because the extent of the disease can vary, and not all patients respond the same way to medications.
    • “Scientists at Case Western Reserve University now report new insights into one type of ALS, that may point towards a therapeutic approach for different types of the disorder. The team studied inducible pluripotent stem cell (iPSC)-motor neurons (MNs) carrying the P56S mutation in a protein called vesicle-associated membrane protein-associated protein-B (VAPB), which is responsible for a familial form of ALS. Their findings provided evidence that the mutation activates integrated stress response (ISR) via mitochondrial dysfunction in motor neurons and also indicated that pharmacological inhibition of ISR using ISRIB helped to rescue ALS-associated phenotypes in both VAPB P56S and patient-derived IPSC-MNs.
    • “Although the research centered on this rare form type of ALS, the investigators are optimistic the positive results could provide clues for potentially treating the devastating disorder more broadly. Study lead Helen Cristina Miranda, PhD, an associate professor of genetics and genome sciences at Case Western Reserve’s School of Medicine, suggested, “This work could help lay the foundation for genetically informed clinical trials.”
    • “Miranda and colleagues reported on their study in EMBO Molecular Medicine, in a paper titled “Convergent activation of the integrated stress response and ER–mitochondria uncoupling in VAPB-associated ALS,” concluding, “This is the first study to mechanistically connect a known ALS mutation with ISR activation, highlighting the potential for mutation-specific therapeutic targeting and patient stratification in ISR-modulating clinical trials.”
  • The National Institutes of Health announced a “new study to test if mothers’ diet prevents early sign of food allergy in babies. NIH trial to assess if eating peanuts, eggs during pregnancy, breastfeeding protects infants.”
    • “The study, called Expecting Mother’s Study of Consumption or Avoidance of Peanut and Egg (ESCAPE), will be led by Kirsi Järvinen-Seppo, M.D., Ph.D., chief of Pediatric Allergy and Immunology and Founders’ Distinguished Professor in Pediatric Allergy at University of Rochester Medicine. Results are expected in 2029. 
    • “More information about the trial, including contacts for people who are interested in participating, is available at ClinicalTrials.gov under study identifier NCT06260956.”
  • NIH Research Matters covers the following topics this week: “Treating CoQ10 deficiency | Specialized blood vessels in organoids | Fat-fueled neurons.”
  • Beckers Hospital Review identifies “seven new drug shortages and discontinuations, according to drug supply databases from the FDA and the American Society of Health-System Pharmacists.” 
  • CIGNA, writing in LinkedIn, discusses the importance of access to mental health services.
    • “Virtual care appointments have emerged as a valuable tool in providing mental health services, particularly in remote or underserved areas. Connecting with mental health professionals via telephone, video calls, and even smart phone apps, make it easier to access care without the need for travel. Additionally, virtual care often reduces wait times, providing quicker access to necessary care.
    • “Community-based mental health programs are another effective approach. These programs use the strengths and resources of local communities to provide support and care. Community health workers, peer support groups, and local organizations can play a vital role in delivering mental health services and promoting mental well-being.
    • “Integrating mental health services into primary care is also promising. By training primary care providers to recognize and address mental health issues, individuals can receive holistic care that addresses both their physical and mental health needs. This integration can help improve overall health outcomes.”

From the U.S. healthcare business front,

  • BioPharma Dive reports,
    • “Pfizer and other large pharmaceutical companies are taking seriously President Donald Trump’s demand that drugmakers make more of their medicines available direct to consumers in the U.S. at lower cost, Pfizer CEO Albert Bourla said Tuesday.
    • “We have serious discussions in the industry,” Bourla told investors on a conference call Pfizer held to discuss its earnings for the second quarter. “I’m connected very often individually with all the major companies, and they are all ready to roll up their sleeves and execute something like that.”
  • MedTech Dive relates,
    • “Alcon has agreed to buy implantable lens maker STAAR Surgical for about $1.5 billion in total equity value, the companies said Tuesday.
    • “Alcon, which will purchase all outstanding shares of STAAR for $28 per share in cash, expects STAAR’s refractive surgery offerings to complement Alcon’s laser vision correction business.
    • “BTIG analyst Ryan Zimmerman said Alcon is getting “a solid deal” given STAAR’s setbacks in the China market. The company is betting on a recovery in China and the longer-term health of lens-based refractive surgery, said the analyst.”
  • Per Fierce Healthcare,
    • “Shares of Hims & Hers tumbled 12% in after-hours trading Monday after the company’s second-quarter revenue missed Wall Street analysts’ expectations.
    • “The company faces headwinds in its compounded GLP-1 drug business after pharma giant Novo Nordisk pulled the plug on a monthlong collaboration to make its weight loss drug Wegovy available on the telehealth company’s platform. The company had to off-board GLP-1 subscribers from the branded version of the drug, executives said.
    • “Hims & Hers continues to sell compounded semaglutide, the active ingredient in Novo’s Wegovy and Ozempic drugs, and these generic versions are more affordable than the branded drugs.
    • “Analysts, however, seem pleased by what they see as strong results and the online health and wellness company’s growth plans, including international expansion, new hormone health offerings and building out standalone lab testing.”
  • and
    • “Online therapy provider Talkspace continues to make big investments in artificial intelligence, seeing opportunities to improve the experience for patients and cut down on paperwork for providers.
    • “Talkspace connects people via an app with therapists who provide counseling remotely, either over the phone, by video chat or by text.
    • “The company is building out foundational large language models specifically for behavioral health using its internal, de-identified clinical data sets, as it claims to have the “largest behavioral health datasets in the industry,” consisting of millions of therapeutic interactions on the Talkspace platform over the past 12 years.
    • “Unlike existing, horizontal, general-purpose LLMs, we are working closely with mental health clinicians experienced with evidence-based therapeutic frameworks,” CEO Jon Cohen, M.D., told investors during the company’s second-quarter earnings call Tuesday. “Talkspace behavioral health LLMs are being developed specifically to understand the language complexity and workflows of mental health delivery. Once up and running, these behavioral health LLMs will be an integral part of how we provide higher-quality care to our Talkspace members.”
  • Modern Healthcare reports,
    • “Virtual behavioral health provider Cerebral announced Tuesday it had acquired Resilience Lab, which offers therapy and medication management through its online platform. The deal, which closed last week, includes Resilience’s clinician development program aimed at training and supporting early-career therapists. 
    • “The combined organization will be led by Cerebral CEO Brian Reinken under the Cerebral brand, with Resilence Lab Co-founder Marc Goldberg holding the president role, according to a spokesperson. Dr. Carl Marci will join the company as chief medical officer, and Resilience Lab Co-founder Christine Carville will serve as chief clinical officer. Cerebral representatives declined to disclose financial details of the deal.”
  • and
    • “Quest Diagnostics has completed its acquisition of some clinical testing assets from Spectra Laboratories, a subsidiary of dialysis company Fresenius Medical Care.
    • “Under the agreement, Quest will provide dialysis-related clinical testing to independent clinics formerly served by Spectra Laboratories.
    • “As part of a separate deal with Fresenius, Quest said in a Tuesday news release it expects to complete the acquisition of select dialysis-related water testing assets by the end of the year. It also said it plans to start providing comprehensive dialysis-related laboratory services for centers operated by Fresenius in the U.S. The transition of services is slated to be completed by early next year.”

Cybersecurity Saturday

From the cybersecurity policy and law enforcement front,

  • Security Week tells us,
    • “Members of the Senate Homeland Security and Governmental Affairs Committee voted 9-6 [on July 31, 2025] to recommend Sean Plankey ’s nomination for director of the Cybersecurity and Infrastructure Security Agency, known as CISA, which sits under the Department of Homeland Security.”
  • Federal News Network informs us that a “new CISA guide helps agencies with next steps on zero trust.”
  • The American Hospital Association News points out,
    • “The FBI, Cybersecurity and Infrastructure Security Agency and international agencies July 29 released a joint advisory on recent tactics by the Scattered Spider cybercriminal group. The group, observed by federal agencies since November 2023, has members based in the U.S. and U.K. The group has targeted large companies and their IT help desks. Scattered Spider threat actors typically engage in data theft for extortion and also use ransomware variants once in a system to steal information, along with other tactics.  
    • “Scattered Spider often employs tactics like phishing, push bombing and subscriber identity module swap attacks to get credentials, bypass multifactor authentication and gain access to networks,” said Scott Gee, AHA deputy national advisor of cybersecurity and risk. “They have also impersonated company help desks to trick users into divulging credentials. These tactics serve as a reminder of the importance of training to recognize and stop these social engineering attacks. The fact that they are native English speakers can make their social engineering attacks more effective. There have been several arrests of group members recently, but their attacks persist, and their tactics are evolving to evade detection. They are currently targeting Snowflake data storage solutions and stealing customer information.”  
  • Cyberscoop reports,
    • “Federal analysts are still sizing up what the Chinese hackers known as Volt Typhoon, who penetrated U.S. critical infrastructure to maintain access within those networks, might have intended by setting up shop there, a Cybersecurity and Infrastructure Security Agency official said Thursday.
    • “We still don’t actually know what the result of that is going to be,” said Steve Casapulla, acting chief strategy officer at CISA. “They are in those systems. They are in those systems on the island of Guam, as has been talked about publicly. So what [are] the resulting impacts going to be from a threat perspective? That’s the stuff we’re looking really hard at.”
    • “Casapulla made his remarks at a Washington, D.C. event hosted by Auburn University’s McCrary Institute for Cyber and Critical Infrastructure Security.”
    • FEHBlog observation: Ruh roh! 
  • Per Cybersecurity Dive,
    • “The Department of Justice on Thursday announced a $9.8 million settlement with Illumina over allegations that the company sold genomic-sequencing systems with software vulnerabilities to federal agencies for multiple years.
    • “Between 2016 and 2023, the government said, the company sold the systems without having an adequate security program and knowingly failed to incorporate cybersecurity into its product design process.
    • “According to prosecutors’ complaint, Illumina is the dominant company in the global market, with a share of roughly 80%.
    • “Companies that sell products to the federal government will be held accountable for failing to adhere to cybersecurity standards and protecting against cybersecurity risks,” Assistant Attorney General Brett Shumate of the DOJ’s Civil Division said in a statement.”

From the cybersecurity vulnerabilities and breaches front,

  • Cyberscoop reports,
    • “Social engineering — an expanding variety of methods that attackers use to trick professionals to gain access to their organizations’ core data and systems — is now the top intrusion point globally, attracting an array of financially motivated and nation-state backed threat groups. 
    • “More than one-third (36%) of the incident response cases Palo Alto Networks’ Unit 42 worked on during the past year began with a social engineering tactic, the company said this week in its global incident response report
    • “Threat groups of assorted motivations and origins are fueling the rise of social engineering. Cybercrime collectives such as Scattered Spider and nation-state operatives, including North Korean technical specialists that have infiltrated the employee ranks at top global companies, have adopted social engineering as the primary hook into IT infrastructure and sensitive data.” 
  • and
    • “The average cost of a data breach for U.S. companies jumped 9% to an all-time high of $10.22 million in 2025, as the global average cost fell 9% to $4.44 million, IBM said in its 20th annual Cost of a Data Breach Report Wednesday [July 30].
    • While shorter investigations are pushing down costs globally, reflecting the first decline in five years, IBM found higher regulatory fines, along with detection and escalation costs, are driving up the ultimate recovery price in the United States. 
    • “This widening gap helps explain why U.S. organizations continue to face the highest breach costs globally, further compounded by more organizations in the U.S. reporting paying steeper regulatory fines,” Troy Bettencourt, global partner and head of IBM X-Force, said in an email.
    • “The report underscores that organizations face an uneven burden in the wake of data breaches, even as detection and containment times improve. On average, it took organizations 241 days to identify and contain a breach through the one-year period ending in February — a nine-year low, according to IBM.”
  • Cybersecurity Dive adds,
    • “A coalition of information-sharing groups urged their members on Wednesday [July 30] to take additional steps to mitigate potential attacks by the cybercrime gang Scattered Spider, which has spent recent months attacking the insurance, retail and airline industries. 
    • “Threat actors such as Scattered Spider are constantly innovating, so organizations must be diligent in continually monitoring their processes and identities to look for new exploits,” the group of information sharing and analysis centers (ISACs) — representing the financial services, food and agriculture, information technology, healthcare, aviation, automotive, retail, maritime and electricity sectors — said in a joint advisory.
    • Their warning came one day after the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) warned that Scattered Spider had developed an evolving set of tactics to conduct social-engineering attacks on its targets.
    • The ISACs said they expect the group to continue to find new ways to evade existing security measures.
  • Bleeping Computer points out,
    • “Researchers have found that in roughly 80% of cases, spikes in malicious activity like network reconnaissance, targeted scanning, and brute-forcing attempts targeting edge networking devices are a precursor to the disclosure of new security vulnerabilities (CVEs) within six weeks.
    • “This has been discovered by threat monitoring firm GreyNoise, which reports these occurrences are not random, but are rather characterized by repeatable and statistically significant patterns.
    • “GreyNoise bases this on data from its ‘Global Observation Grid’ (GOG) collected since September 2024, applying objective statistical thresholds to avoid results-skewing cherry-picking.
    • “After removing noisy, ambiguous, and low-quality data, the firm ended up with 216 events that qualified as spike events, tied to eight enterprise edge vendors.
    • “Across all 216 spike events we studied, 50 percent were followed by a new CVE within three weeks, and 80 percent within six weeks,” explain the researchers.”
  • CISA added three known exploited vulnerabilities to its catalog this week.

From the ransomware front,

  • HIPAA Journal tells us,
    • “A new report from the cybersecurity firm Semperis suggests ransomware attacks have decreased year-over-year, albeit only slightly. The ransomware risk report indicates healthcare is still a major target for ransomware gangs, with 77% of healthcare organizations targeted with ransomware in the past 12 months. 53% of those attacks were successful.
    • “The report is based on a Censuswide survey of 1,500 IT and security professionals across multiple sectors. While attacks are down slightly, 60% of attacked healthcare organizations report suffering multiple attacks. In 30% of cases, they were attacked more than once in the same month, 35% were attacked in the same week, 14% were attacked multiple times on the same day, and 12% faced simultaneous attacks.
    • “A general trend in recent years, as reported by several firms, is fewer victims of ransomware attacks paying ransoms, although across all industry sectors in the U.S., 81% attacked companies paid the ransom, an increase from last year. Ransom payment was far less common in healthcare. According to Semperis, 53% of healthcare victims paid a ransom to either prevent the publication of stolen data, obtain decryption keys, or both. The ransom paid was less than $500,000 for 55% of companies, 39% paid between $500,000 and $1 million, and 5% paid more than $1 million.”
  • Cybersecurity Dive adds,
    • “Manufacturing, information technology and healthcare are top targets of cybercriminals, but ransomware attacks on the oil and gas industry increased dramatically between April 2024 and April 2025, spiking 935%, according to a new report from cybersecurity firm Zscaler.
    • “Oil and gas companies may be facing more attacks because their industrial control systems are increasingly automated and digitized, “expanding the sector’s attack surface,” Zscaler said.
    • “Half of all ransomware attacks listed on leak sites during the April-to-April survey period targeted the United States, and attacks on U.S. targets more than doubled, to 3,671, a figure that exceeds the combined number of ransomware events on the 14 other countries in the top 15 list.”
  • Cybersecurity Dive further reports,
    • “A recent wave of ransomware attacks targeting SonicWall firewall devices may be related to a zero-day vulnerability in the products, according to researchers.
    • “Anomalous firewall activity that began on July 15 and involved VPN access through SonicWall SSL VPNs morphed into intrusions the following week, researchers at Arctic Wolf said.
    • “This appears to be affecting SonicOS devices from what we’ve seen so far,” Stefan Hostetler, lead threat intelligence researcher at Arctic Wolf, told Cybersecurity Dive. “Our investigation is still preliminary, so I’m not able to offer much more detail yet.”
    • “Hackers deployed the Akira ransomware variant in hands-on-keyboard attacks after compromising SonicWall SSL VPNs, according to the researchers.”
  • and
    • “Researchers from Palo Alto Networks say they are investigating a ransomware attack related to the recently disclosed ToolShell vulnerabilities in Microsoft SharePoint
    • “The hackers left the victim a ransom note on Sunday [July 27] claiming they had encrypted files using the 4L4MD4R ransomware. The note warned that any attempt to decrypt the files would result in their deletion.
    • The hackers used PowerShell commands to disable real-time monitoring in Windows Defender, according to Palo Alto Networks researchers. The intruders also bypassed certificate validation.
    • Researchers from Palo Alto Networks say they are investigating a ransomware attack related to the recently disclosed ToolShell vulnerabilities in Microsoft SharePoint
    • The hackers left the victim a ransom note on Sunday claiming they had encrypted files using the 4L4MD4R ransomware. The note warned that any attempt to decrypt the files would result in their deletion.
    • The hackers used PowerShell commands to disable real-time monitoring in Windows Defender, according to Palo Alto Networks researchers. The intruders also bypassed certificate validation.
  • and
    • “Several major ransomware-as-a-service groups have stopped posting victims to popular leak sites, suggesting that the ecosystem is more dispersed than it used to be, according to a new report from Check Point Software Technologies.
    • “At the same time, many smaller groups that used to affiliate with larger players “are operating independently or seeking new partnerships,” Check Point said in its Thursday report.
    • “Established players are actively competing to recruit these ‘orphaned’ affiliates,” according to the report, which cited competition between prominent groups Qilin and DragonForce for affiliates of the now-defunct RansomHub.”
  • Per Bleeping Computer,
    • “A wave of data breaches impacting companies like Qantas, Allianz Life, LVMH, and Adidas has been linked to the ShinyHunters extortion group, which has been using voice phishing attacks to steal data from Salesforce CRM instances.
    • “In June, Google’s Threat Intelligence Group (GTIG) warned that threat actors tracked as UNC6040 were targeting Salesforce customers in social engineering attacks.
    • “In these attacks, the threat actors impersonated IT support staff in phone calls to targeted employees, attempting to persuade them into visiting Salesforce’s connected app setup page. On this page, they were told to enter a “connection code”, which linked a malicious version of Salesforce’s Data Loader OAuth app to the target’s Salesforce environment.”
  • SC Media tells us,
    • “Epsilon Red ransomware is being spread via a unique ClickFix lure that convinces victims to download and execute HTML Application files.
    • “The campaign impersonates widely used online services such as Twitch, Kick, Rumble, OnlyFans and the popular Discord Captcha Bot, CloudSEK reported recently.
    • “Like other sites using the ClickFix social-engineering method, these impersonation sites display a fake CAPTCHA prompt, but rather than having the victim copy and paste malicious commands, this version directs them to go to a different page to complete “extra verification steps.”
    • “These extra steps include pressing CTRL + S to save a file, renaming the file to verify.hta, opening the file with Microsoft HTML Application Host (mshta.exe), clicking “YES” if a popup appears and then entering a decoy “verification code” on the original CAPTCHA page. This last step is designed to trick the user into believing they have completed a legitimate verification process.”
  • Per InfoSecurity Magazine,
    • “A new ransomware operator called Chaos has launched a wave of intrusions impacting a wide range of sectors, Cisco Talos has reported.
    • “Victims have been predominantly based in the US, with some in the UK, New Zealand India, according to the actor’s data leak site.
    • “Targeting appears to be opportunistic and does not focus on any specific verticals. However, Chaos is focused on “big-game hunting” and uses double-extortion tactics.
    • “In one incident observed by Cisco, the group adopted a novel negotiation strategy, offering an extra ‘reward’ for making payment to the attackers, or additional ‘punishment’ for resisting demands, including the threat of a distributed denial-of-service (DDoS) attack.
    • “The Chaos ransomware actor is a recent and concerning addition to the evolving threat landscape, having shown minimal historical activity before the current wave of intrusions,” the researchers wrote in a blog dated July 24.”
  • Per Trend,
    • “Gunra ransomware’s Linux variant broadens the group’s attack surface, showing the new group’s intent to expand beyond its original scope. 
    • “The Linux variant shows notable features including running up to 100 encryption threads in parallel and supporting partial encryption. It also allows attackers to control how much of each file gets encrypted and allows for the option to keep RSA-encrypted keys in separate keystore files.
    • “Since its first observed activity in April 2025, Gunra ransomware has victimized enterprises from Brazil, Japan, Canada, Turkiye, South Korea, Taiwan, and the United States. Its victims include organizations from the manufacturing, healthcare, IT and agriculture sectors, as well as companies in law and consulting.” 

From the cybersecurity business and defenses front,

  • Cyberscoop reports,
    • “Palo Alto Networks has agreed to acquire identity security firm CyberArk for approximately $25 billion, marking the cybersecurity giant’s largest acquisition and its formal entry into the identity security market as the industry continues consolidating amid rising cyber threats.
    • “The transaction ranks among the largest technology acquisitions this year and underscores the market’s focus on identity security in an era of increasing artificial intelligence adoption.
    • “CyberArk, founded over two decades ago, specializes in privileged access management technology that helps organizations control and monitor access to critical systems and accounts. The company’s customers include major corporations such as Carnival Corp., Panasonic, and Aflac. Its technology addresses what security experts consider one of the most vulnerable aspects of enterprise security: managing privileged credentials for both human users and machine identities.
    • “The acquisition comes as cybersecurity companies face pressure to offer comprehensive solutions rather than point products, with customers seeking to streamline their vendor relationships following high-profile breaches. Recent cyberattacks, including Microsoft’s SharePoint vulnerabilities that affected over 100 organizations including U.S. government agencies, have heightened focus on identity protection and privileged access management.”
  • ISACA discusses “Defending Against Human-Operated Ransomware Attacks.”
  • Per a CISA news release,
    • “Today, the Cybersecurity and Infrastructure Security Agency (CISA) released an Eviction Strategies Tool, a no-cost resource designed to support cyber defenders in their efforts to respond to cyber incidents. CISA contracted with MITRE to develop this tool that enables cyber defenders to create tailored response plans and adversary eviction strategies within minutes. They will also be able to develop customized playbooks aimed at containing and evicting adversaries from compromised systems and networks.
    • “The tool includes COUN7ER, a database of atomic post-compromise countermeasures mapped to adversary tactics, techniques, and procedures (TTPs), and Cyber Eviction Strategies Playbook NextGen, a web-based application that matches incident findings with countermeasures obtained from COUN7ER. Together, these resources help defenders build systematic eviction plans with distinct countermeasures to thwart and evict unique intrusions.”
  • Dark Reading adds,
    • “The Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the Department of Energy’s Sandia National Laboratories, has released Thorium, an automated malware and forensic analysis platform, to help enterprise defenders quickly assess malware threats.” * * *
    • “Thorium is available from CISA’s official GitHub repository. Organizations interested in using it will need a deployed Kubernetes cluster, block store, and object store. A successful deployment requires familiarity with Docker containers and compute cluster management.
    • “By making this platform publicly available, we empower the broader cybersecurity community to use advanced tools for malware and forensic analysis,” said Jermaine Roebuck, CISA’s associate director for threat hunting, in a statement. “Scalable analysis of binaries and digital artifacts strengthens our ability to identify and fix vulnerabilities in software.”
  • Dark Reading offers Black Hat News. The Black Hat conference starts today in Las Vegas.

Tuesday report

From Washington, DC,

  • The Senate confirmed Susan Monarez to be Director of the Centers for Disease Control and Prevention today by a 51 to 47 vote. The AP adds,
    • “She holds a doctorate in microbiology and immunology from the University of Wisconsin and did postdoctoral research at Stanford University. Prior to the CDC, Monarez was largely known for her government roles in health technology and biosecurity.”
  • MedCity News tells us,
    • “On Thursday, a coalition of 28 healthcare organizations sent a letter to leaders in Congress calling on them to extend the Affordable Care Act enhanced premium tax credits, which are set to expire at the end of the year.
    • “The letter was addressed to John Thune, Senate majority leader; Chuck Schumer, Senate minority leader; Mike Johnson, speaker of the House; and Hakeem Jeffries, minority leader of the House. The letter was led by Keep Americans Covered and was signed by healthcare organizations including AHIP, Blue Cross Blue Shield Association, the American Medical Association, Kaiser Permanente, Families USA and more.” 
  • STAT News reports,
    • “Health secretary Robert F. Kennedy Jr. could “imminently” overhaul a key federal advisory panel that recommends which preventive services insurers must pay for, according to a person familiar with the plans. 
    • “The person said that federal health officials are actively vetting new members for the U.S. Preventive Services Task Force. David Mansdoerfer, an adviser to a Kennedy-aligned group of physicians, said he’s aware of people being considered for the panel, but declined to name them.” * * *
    • “Mansdoerfer added that the existing panel is “M.D. heavy” and a reconstituted panel is more likely to include “allied health professionals,” which are health care providers who aren’t nurses or physicians, like physical therapists and dietitians.” 
  • Following up on yesterday’s post about Medicare Part D, here is a link to the CMS guidance upon which the Wall Street Journal relied.
  • World at Work informs us,
    • “Health savings accounts (HSAs) have become a staple total rewards offering over the last decade, but a new study by the Employee Benefit Research Institute (EBRI) showed employees are still leaving the full value of these accounts on the table.
    • “The June 12 EBRI report pulled data from 14.5 million accountholders, containing more than $48 billion in total assets — roughly 40% of the entire HSA universe. The analysis revealed:
      • “Low balances. End-of-year balances increased in 2023 (the most recent analysis period) to $4,747 but are still modest compared with average out-of-pocket maximums for HSA-eligible health plans ($8,300 for individual coverage in 2025, $16,600 for family coverage)
      • Low contributions. Relative to 2022, average HSA contributions increased in 2023. However, after adjusting for inflation, both employer and employee contributions were higher in the 2010s. Also, notably, the average combined HSA contribution was $760 less than the statutory maximum contribution for individuals and $4,660 less than the statutory maximum contribution for accountholders with family coverage.
      • High withdrawals. More than half of accountholders withdrew funds, and the average distribution rose to $1,801.
      • “Low investment. Only 15% of accountholders invested in assets other than cash. 
    • EBRI found that, essentially, employees use HSAs as specialized checking accounts rather than investment accounts, and in doing so, miss out on the triple tax advantage available if they maximize contributions, minimize withdrawals and invest their balances.
    • “The good news is that, here we are 20-plus years after HSAs launched, and they’ve become pretty standard. They’re a typical plan offering from most employers of all sizes — not just large or small companies, or in certain industries,” said Alexander Domaszewicz, a principal and healthcare consultant at advisory firm Mercer. “If we live long enough, we’ll have healthcare expenses, and we want to be prepared for that. But while awareness and visibility of HSAs have grown, they’re still intimidating to folks.”
  • Beckers Payer Issues calls attention to recent No Surprises Act developments.
  • Federal News Network lets us know,
    • “The Trump administration is detailing how it expects agencies to recruit more political appointees through the new “Schedule G” hiring category, while also reminding agencies that all non-career hires must be approved by the White House.
    • “The Office of Personnel Management on Tuesday outlined how agencies should adopt the federal employment classification President Donald Trump created earlier this month. Generally, the new Schedule G broadens agencies’ options for hiring political appointees, beyond the avenues already available to presidential administrations for picking their own staff members.
    • “In its guidance on Trump’s new hiring authority, OPM said agencies will have to run any Schedule G hires they want make by the White House for review and approval.
    • “As a matter of practice,” OPM said, agencies will have to send all their political hires to their White House liaison — a position that coordinates with the White House on hiring and retention of political appointees — before agencies can advance any Schedule G appointments.”

From the Food and Drug Administration front,

  • Bloomberg Law informs us,
    • “Vinay Prasad, a top regulator at the US Food and Drug Administration, has left the agency after a controversy over his handling of Sarepta Therapeutics Inc.’s gene therapy. 
    • “Dr. Prasad did not want to be a distraction to the great work of the FDA in the Trump administration and has decided to return to California and spend more time with his family,” Department of Health and Human Services spokesperson Andrew Nixon said in a written statement. 
    • “Prasad did not immediately respond to a request for comment about his departure.” 
  • The Washington Post reports,
    • “The Food and Drug Administration pushed Tuesday to restrict a synthetic opioid found in tablets, gummies and drinkable shots commonly sold in convenience stores.
    • “Health officials announced they will seek to add 7-OH — a potent substance synthesized from a compound in the kratom leaf — to the tier of controlled substances reserved for the most addictive drugs, such as heroin and LSD.
    • “The FDA, researchers and kratom companies have grown increasingly alarmed by the rise of 7-OH products they say are distinct from all-natural teas and powders derived from a leaf that grows on trees native to Southeast Asia.
    • “FDA Commissioner Marty Makary said at a news conference that the agency is not asking to restrict natural products made from kratom, which contains trace amount of the compound. In a report released Tuesday, the agency said it maintains concerns about kratom broadly but needed to act urgently on 7-OH because of its risk of sedation, nausea, breathing problems and addiction.”
  • From the judicial front,
    • Fierce Healthcare reports,
      • “A new law in Arkansas banning pharmacy benefit managers from owning pharmacies has been blocked by a federal judge, the latest development in one of the industry’s most-watched new pieces of legislation.
      • “Judge Brian Miller said the law may violate (PDF) the Commerce Clause in the constitution and is likely preempted by TRICARE, a health care program for military families. The state is barred from enforcing the law until final disposition, a ruling shows.
      • “Act 624 appears to overtly discriminate against plaintiffs as out of state companies and the state has failed to show that it has no other means to advance its interests,” said Miller, adding other enacted state laws already can properly restrict PBMs.
      • “Arkansas Attorney General Tim Griffin said he plans on appealing the decision, reported the Associated Press.
      • “We’re pleased with the Court’s decision to grant a preliminary injunction to stop the implementation of Act 624,” a CVS Health spokesperson said in a statement. “We continue to be focused on serving people in Arkansas and are actively looking to work together with the state to reduce drug prices and ensure access to pharmacies.”

From the public health and medical researach front,

  • KFF considers whether our country’s measles elimination status is at risk.
  • The Agency for Healthcare Research and Quality released a medical expenditures survey report titled “Healthcare Expenditures for Heart Disease among Adults Aged 18 and Older in the U.S. Civilian Noninstitutionalized Population, 2022.”
    • “In 2022, 7.8 percent of adults aged 18 and older were treated for heart disease, and men were more likely than women to have treated heart disease (8.4 % vs. 7.2%).
    • “Among age groups, the treated prevalence of heart disease was highest for those aged 65 and older (22.8%) compared to only 6.0 percent for adults aged 45-64, and 1.4 percent for adults ages 18-44.
    • “In 2022, healthcare expenditures to treat heart disease for adults in the US totaled $100.0 billion (with an average cost of $4,900 per adult with diagnosed and treated heart disease).
    • “The largest portion of heart disease expenditures were incurred through hospital inpatient stays (46.1%) and prescribed medications (20.5%).
    • “The majority of heart disease treatment costs were paid by Medicare (57.6%) and private insurance (24.2%).”
  • Per MedPage Today,
    • “The global incidence of liver cancer is projected to double by 2050.
    • “Sixty percent of liver cancers are preventable by controlling risk factors including hepatitis B and C, alcohol consumption, and MASLD.
    • “The Lancet Commission estimated that a 2-5% reduction in the age-standardized incidence rate of liver cancer could prevent up to 17.3 million new cases and save up to 15.1 million lives.”
  • Per Neurology Adviser,
    • “Urinary tract infections (UTIs) may be a trigger for myocardial infarction (MI) or stroke, with an increased risk for both within the first 7 days of infection, according to the findings of a study published in BMJ Open.”
    • “Growing evidence suggests that acute infection plays a role in the pathogenesis of cardiovascular disease.
    • “Researchers from Cardiff University in the United Kingdom conducted this self-controlled cases series using data from the Secure Anonymised Information Linkage (SAIL) Databank which houses nation-wide data from Wales. Patients (N=105,930) with MI (n=51,660) or stroke (n=58,150) between 2010 and 2020 were evaluated for general practitioner suspected or confirmed UTI before or after MI or stroke event. The peak risk period was defined as up to 90 days after UTI.
    • “The MI and stroke cohorts consisted of 63% and 49% men, with mean ages of 69 and 74 years for men and 77 and 79 years for women, respectively.”
  • STAT News reports,
    • “A major Alzheimer’s disease medical group is recommending that specialists may use certain blood tests to help diagnose patients with cognitive impairment in lieu of more complex and invasive tests, a move that could lead more people to get treated for the devastating disease.
    • “The Alzheimer’s Association, in its first clinical guidelines on blood biomarker testing, said Tuesday that tests that have over 90% sensitivity (ability to identify positive results) and 90% specificity (ability to identify negative results) can be used instead of current diagnostic methods like PET scans and cerebrospinal fluid tests.
    • “The group said that tests that have over 90% sensitivity and 75% specificity can be used to triage patients, meaning negative results rule can rule out Alzheimer’s with high probability but positive results should be confirmed with the standard diagnostic methods, given that these blood tests have a higher likelihood of false positives.
    • “The authors stressed that the guidelines should not be considered a substitute for a full clinical evaluation and that they apply only to people who are in the care of specialists and have already been confirmed to have cognitive impairment. The authors also noted that there’s wide variability in the blood tests on the market and that many do not meet the accuracy thresholds.”
  • Per Benefits Pro,
    • “Researchers at Cigna’s Evernorth Research Institute are seeing early signs that offering patients semaglutide and other GLP-1 agonists might cut the cost of managing mental health problems.
    • “Duy Do and two other Evernorth researchers found that using Ozempic or similar drugs to control blood sugar reduced use of office visits to treat depression by 13% and reduced use of office visits to treat anxiety by 15%.
    • “Use of GLP-1 agonists did not reduce use of emergency room visits or inpatient care for depression or anxiety, but the researchers say their work shows the need for understanding how GLP-1 agonist use affects people’s mental health and use of mental health services.
    • “Given the high economic burden of mental health disorders among patients with T2DM, further research is needed to confirm the clinical and cost-effectiveness of [GLP-1s] in reducing the overall health care burdens for this patient population,” Do and colleagues conclude.”

From the U.S. healthcare business front,

  • The Wall Street Journal reports,
    • “UnitedHealth Group anticipates its 2025 earnings to fall below expectations due to rising costs and operational issues.
    • “CEO Stephen Hemsley aims to restore UnitedHealth to high performance, projecting earnings growth for the coming year.
    • “UnitedHealth is facing industry upheaval with rising healthcare costs, government actions, and ongoing Justice Department probes.”
  • Modern Healthcare tells us,
    • “Humana is offering certain employees voluntary early retirement buyouts.
    • “Employees age 50 or older with at least three years of service are eligible for the program, although those working in certain business-critical areas will be ineligible, a company spokesperson said Tuesday. He said the window to apply for voluntary early retirement will be open for several weeks.
    • “The Louisville, Kentucky-based health insurer said the offers are part of ongoing evaluations Humana conducts to adjust staffing and drive organizational efficiency.”
  • Beckers Hospital Review lets us know,
    • U.S. News & World Report released its 2025-2026 Best Hospitals rankings and ratings July 29, which included its list of 504 Best Regional Hospitals across 49 states and 95 metropolitan areas.
    • “The latest edition of Best Hospitals, now in its 36th year, evaluated more than 4,400 hospitals on measures such as risk-adjusted mortality rates, preventable complications and level of nursing care.” 
    • The article lists the no. 1 ranked hospitals in each eligible state.
  • Cardiovascular Business points out the best heart hospitals according to U.S. News and World Report.
  • Fierce Healthcare informs us,
    • “Earlier this year, CVS Health announced that it would invest $20 billion in improving the consumer experience and making the healthcare journey simpler.
    • “Now, its health benefits arm, Aetna, is unveiling its new Care Paths program, which connects members who have certain health needs—launching with diabetes, joint health and maternity care—to a more personalized view of their benefits and more directly with the care team supporting them. The platform is powered by artificial intelligence and offers users individualized recommendations for health and wellness programs related to their conditions as well as care kits when available.
    • “The goal, the insurer said, is to make members’ interactions with their health plans feel less transactional and instead more holistic. Aetna offered an exclusive look at the new offering to Fierce Healthcare.”
  • and
    • Sword Health, a company that provides virtual physical therapy and mental health, is now offering an AI assistant for payers and providers to tackle operational and administrative tasks.
    • “The new AI division marks a notable expansion from the company’s core business of virtual care services like digital musculoskeletal care, pelvic health and movement health.
    • “The launch of the new division, called Sword Intelligence, marks a “pivotal evolution” in Sword Health’s strategy, according to the company.
    • “Sword Intelligence allows us to move beyond delivering care to our own members to enabling the entire healthcare industry to scale it efficiently and effectively,” Virgilio “V” Bento, founder and CEO of Sword Health, told Fierce Healthcare when reached via email.”
  • The Wall Street Journal further reports,
    • Merck & Co. said it is embarking on a multi-year cost-savings plan, which includes cuts to its workforce and real-estate footprint, as it looks to redirect resources toward new product launches.
    • “The plan comes as the drug company on Tuesday logged lower revenue and sales in its latest quarter and narrowed its full-year guidance.
    • “The company said it expects the plan to result in $3 billion in annual cost savings by the end of 2027, which it plans to reinvest to support new products as well as its pipeline across multiple therapeutic areas.
    • “As part of the cost-savings plan, Merck expects to eliminate certain administrative, sales and research-and-development positions.
    • “The company didn’t disclose how many workers would be affected but said it would continue to hire employees in new roles across strategic growth areas of its business.
    • “Merck said it also would reduce its global real-estate footprint and continue to optimize its manufacturing network.
    • “The company expects the workforce cuts and real-estate reductions to result in annual cost savings of about $1.7 billion, which would be substantially realized by the end of 2027.”
  • and
    • “Novo Nordisk shares plunged after losing its lead in the weight-loss drug market to competitors like Eli Lilly.
    • “The company lowered its 2025 sales growth forecast due to copycat versions of Wegovy and slower Ozempic sales.
    • “Maziar Mike Doustdar was named chief executive, effective Aug. 7, succeeding Lars Fruergaard Jorgensen.”

Monday report

From Washington, DC,

  • The Wall Street Journal reports,
    • “Medicare drug plan premiums are expected to rise significantly next year due to rising costs and regulatory changes.
    • “A subsidy program that shielded seniors from rising monthly bills will be cut by about 40% in 2026.
    • “The premium increase will affect millions of seniors and may push more enrollees into Medicare Advantage plans.”
  • KFF tells us,
    • “Two new KFF analyses examine the latest data about Medicare Advantage, including trends in enrollment, premiums, out-of-pocket limits, supplemental benefits and prior authorization.
    • “The first analysis, focusing on enrollment trends, finds that 54% of eligible Medicare beneficiaries are enrolled in Medicare Advantage in 2025, though increases in enrollment slowed this year. One in five Medicare Advantage enrollees is in a special needs plan (SNP), reflecting a steady increase in recent years. And Medicare Advantage enrollment remains highly concentrated among a handful of insurance companies. 
    • “The second analysis finds that more than three quarters (76%) of enrollees in individual Medicare Advantage plans with prescription drug coverage pay no premium other than the Medicare Part B premium. The share of enrollees in plans offering a rebate against the Part B premium rose sharply from 12% in 2024 to 32% in 2025, but among these enrollees, about half are in plans that offer rebates of less than $10 a month while fewer (36%) are in plans that offer rebates of $50 or more per month. Prior authorization is most often required for expensive services such as skilled nursing facility stays (99%), Part B drugs (98%), inpatient hospital stays (acute: 96%; psychiatric: 93%) and outpatient psychiatric services (80%).” 
  • STAT News reports,
    • “No decision has been made on the future of an advisory panel [the U.S. Preventive Services Task Force] that decides which preventive care offerings, like cancer screenings, must be covered by insurers, a federal health department spokesperson said, after a [Wall Street Journal] report that health secretary Robert F. Kennedy Jr. is planning to oust all members. 
    • “But the report has alarmed the American Medical Association, which is calling on Kennedy to keep the panel’s members in place.” 
  • Modern Healthcare informs us,
    • “The Centers for Medicare and Medicaid Services wants to take another crack at creating a national provider directory in an effort to replace insurance company lists that are often riddled with errors.
    • “Health and Human Services Secretary Robert F. Kennedy Jr. and CMS Administrator Dr. Mehmet Oz touted the idea at a meeting with health information technology executives in June. In a later post on the social media platform X, CMS described its goal as a “dynamic, interoperable directory that connects the data CMS has with what the industry knows, so we all work from the same map.” * * *
    • “The insurance industry would support a national provider directory “grounded in a robust public-private partnership,” the trade group AHIP said in a statement. At the AHIP 2025 conference last month, executives from Centene, Cigna and Aetna parent company CVS Health said their companies have met with CMS to discuss the concept.”
  • and
    • “Top Trump administration health officials are expected to bring tech companies to the White House this week to roll out a plan to encourage more seamless sharing of healthcare data, according to people familiar with the matter.
    • “Health and Human Services Secretary Robert F. Kennedy Jr. and Centers for Medicare and Medicaid Services Administrator Mehmet Oz are expected to host executives at an event on Wednesday, said the people, who did not provide names of the attendees and asked not to be named because the details haven’t been made public.
    • “The plan was developed in coordination with the White House, building on a May effort by CMS to get public input on addressing barriers to sharing patient data.”
  • The American Hospital Association lets us know,
    • “The Substance Abuse and Mental Health Services Administration July 28 released its latest national survey on drug use and mental health. Among the findings, the percentage of adolescents aged 12 to 17 who had serious thoughts of suicide declined from 12.9% in 2021 to 10.1% in 2024. It also found a decline in adolescents who experienced a major depressive episode, dropping from 20.8% in 2021 to 15.4% in 2024. The survey also found that among the 61.5 million adults aged 18 or older in 2024 with any mental illness, 52.1% (32 million) received any mental health treatment in the past year. Among 14.6 million adults with serious mental illness in the past year, 70.8% (10.3 million) received mental health treatment. Due to changes to the survey questions and approach, not all estimates in the 2024 survey are comparable with 2023 and 2022 estimates, SAMHSA notes.” 
  • An HHS news release adds,
    • “The U.S. Department of Health and Human Services (HHS) has announced a $100M pilot funding opportunity to prevent, test for, treat, and cure Hepatitis C (HCV) in individuals with substance use disorder (SUD) and/or serious mental illness (SMI). This program is designed to support communities severely affected by homelessness and to gain insights on effective ways to identify patients, complete treatment, cure infections, and reduce reinfection by Hepatitis C (a liver disease caused by the Hepatitis C virus).
    • “HHS is delivering on our promise to the American people for a healthier, brighter future,” said HHS Secretary Robert F. Kennedy, Jr. “Through this pilot program, we are launching a comprehensive, integrated care model that not only cures HCV but also tackles critical risk factors like substance use, mental health challenges, and homelessness head-on.”
  • Beckers Hospital Review highlights five things to know about the foreign trade deals that the Trump administration has recently struck.

From the Food and Drug Administration front,

  • BioPharma Dive reports,
    • “The Food and Drug Administration has given Sarepta Therapeutics a green light to resume shipping its gene therapy Elevidys to some patients with Duchenne muscular dystrophy, a little over one week after demanding the company halt sales over safety concerns. 
    • “In a statement Monday evening, Sarepta said it would begin shipments to treatment sites “imminently.” The resumption applies only to Duchenne patients who can still walk, which typically describes individuals who are younger and whose disease hasn’t advanced as far.”
  • and
    • “The Food and Drug Administration has delayed its review of a Bayer therapy for hot flashes related to menopause, telling the drugmaker it needs additional to review the company’s application.
    • “In a Friday statement, Bayer said the FDA did not raise any concerns around “general approvability” of the drug, called elinzanetant. Still, the agency extended its decision deadline by three months.”
  • Per MedTech Dive,
    • “Johnson & Johnson’s Ethicon unit has corrected disposable surgical stapler cartridges over a fault related to one death and one injury, the Food and Drug Administration said Friday.
    • “The company wrote to customers in April after learning that devices may activate but not cut or staple tissue. Additional steps are needed to open and remove locked devices from tissue. 
    • “Ethicon designed the stapler to prevent lockout events from harming patients. Still, the FDA said the lockout problem could cause life-threatening hemorrhage, surgical delay and death.”

From the public health and medical research front,

  • The New York Times reports,
    • “A combination of healthy activities including exercise, nutritious diet, computer brain games and socializing can improve cognitive performance in people at risk for dementia, according to a large new study.
    • “The study, conducted in five locations across the United States over two years, is the biggest randomized trial to examine whether healthy behaviors protect brain health.
    • “It confirms that paying attention to things like physical activity and vascular risk factors and diet are all really important ways to maintain brain health,” said Dr. Kristine Yaffe, an expert in cognitive aging at the University of California, San Francisco, who was not involved in the study.
    • “The results were presented on Monday at the Alzheimer’s Association International Conference in Toronto and published in the journal JAMA.”
  • The Washington Post adds,
    • “Any amount of walking is good for your health but picking up the pace has significant benefits — and it’s never too late for someone to train to walk faster.
    • “In an analysis published in PLOS One earlier this month, researchers found that frail older adults who deliberately walked faster saw a meaningful improvement in the distance they could travel when instructed to walk for six minutes straight. (Frailty is an age-related syndrome that affects 5 to 17 percent of older adults and is characterized by fatigue, a loss of strength and unexplained weight loss.)
    • “The results show that regardless of your age, the intensity of your workout can lead to greater improvements in physical function, said Daniel Rubin, the lead author of the analysis and an associate professor of anesthesia and critical care at the University of Chicago.”
  • Per the National Academy of Medicine,
    • “With more than half a million people globally living beyond the age of 100, it is time to rethink how health professionals and educators view older adults and the aging process. “Redefining aging” begins with transforming the mindset of current and future health professionals through targeted education. This involves encouraging them to reconsider how they address the unique needs of older adults and identifying those who can drive this change. Educators, health professionals, administrators, and policymakers must collaborate to reshape systems and attitudes. Together, they can build a well‑trained workforce that is not only prepared but motivated to address the complexities of aging that may include chronic disease and functional decline but also opportunities for growth and innovation. The barriers to achieving a change in mindset and solutions for overcoming challenges prompt a call to action. This paper is an entreaty by a group of interprofessional educators passionate about ensuring all health professionals are trained to meet the complex needs of older adults.”
  • MedPage Today tells us,
    • “Chronic obstructive pulmonary disease (COPD) affects at least 4.5% of those 18-49 years old, according to an analysis of U.S. cohorts * * * as reported in NEJM Evidence.”
    • “The early COPD group was more likely to be hospitalized or die from chronic respiratory disease, to develop heart failure, and to die before 75 years of age from any cause.
    • “Having a definition for early COPD might allow for studies to find ways to treat the disease and reduce its impact.”
  • The AHA News informs us,
    • “Five pediatric flu deaths were reported to the Centers for Disease Control and Prevention last week, pushing the total to 266 for the 2024-2025 flu season, according to the latest data. The total is the highest reported in any non-pandemic flu season since the agency began reporting it in 2004. The CDC said 90% of reported pediatric deaths this flu season have happened to children who were not fully vaccinated against the flu.”
  • The American Medical Association lets us know what doctors wish their patients knew about the impact of caffeine.

From the U.S. healthcare business front,

  • The Wall Street Journal reports,
    • Bristol Myers Squibb BMY and Bain Capital are forming a new biopharmaceutical company focused on therapies for autoimmune diseases.
    • The new company will be created with $300 million in financing led by Bain Capital, including funds from the Canada Pension Plan Investment Board.
    • The company will begin with five potential treatments for autoimmune diseases in-licensed from Bristol Myers Squibb, which will retain 20% equity in the new company. Bristol Myers Squibb will also be entitled to royalties and milestones from the potential treatments.
    • Biotech executive Daniel Lynch, currently chairman of the board at Xilio Therapeutics XLO, will lead the new company as chief executive.
  • Per BioPharma Dive,
    • “GSK is turning to a China-based biotechnology company in search of its next blockbuster medicine, announcing Monday a broad drug making alliance with Hengrui Pharma that could be worth billions of dollars.
    • “GSK will pay Hengrui $500 million upfront to start the alliance. In return, it will receive rights outside of the greater China region and Taiwan to an experimental drug for chronic obstructive pulmonary disease as well as the potential to develop up to 11 other therapies for respiratory illnesses, immune disorders or cancer. If a variety of milestones are met, the deal could be worth up to $12 billion, plus royalties, GSK said.”
  • Beckers Payer Issues offers us six prior authorization updates that Beckers has reported since June 23.
  • Per an NIH news release,
    • “Researchers at the National Institutes of Health (NIH) have developed an artificial intelligence (AI) agent powered by a large language model (LLM) that creates more accurate and informative descriptions of biological processes and their functions in gene set analysis than current systems.
    • “The system, called GeneAgent, cross-checks its own initial predictions—also known as claims— for accuracy against information from established, expert-curated databases and returns a verification report detailing its successes and failures. The AI agent can help researchers interpret high-throughput molecular data and identify relevant biological pathways or functional modules, which can lead to a better understanding of how different diseases and conditions affect groups of genes individually and together.”