Monday report

Monday report

From Washington, DC,

  • OPM’s leadership posted an end of the year letter to OPM employees.
  • STAT News reports,
    • “Drug manufacturers and pharmacy benefit managers received a holiday gift from President Trump on Friday: They still will not have to publicly post the actual prices of prescription drugs, more than five years after federal law required them to do so.
    • “Net drug prices — the amounts that health insurance companies and PBMs pay to drugmakers, after factoring in rebates — are highly valuable data that undergird the entire economic foundation of the U.S. pharmaceutical industry. But the decision from the Trump administration, rolled out in a new proposed rule, means that drug pricing data will likely remain locked out of public view for the foreseeable future.”
  • Avalere Health shares its perspective about December 2025 Advisory Committee on Immunization Practices Insights and 2026 Emerging Priorities.
    • “The ACIP’s December meeting resulted in a key change to the pediatric immunization schedule and signaled several potential changes to US vaccine coverage and access in 2026.”
  • Per an HHS news release,
    • “Executing on President Trump’s Executive Order (EO) 14192 titled “Unleashing Prosperity through Deregulation” and the President’s mandate to ensure the United States’ continued leadership in artificial intelligence (AI), the U.S. Department of Health and Human Services (HHS), through the Assistant Secretary for Technology Policy/Office of the National Coordinator for Health Information Technology (ASTP/ONC), today released the Health Data, Technology, and Interoperability: ASTP/ONC Deregulatory Actions to Unleash Prosperity (HTI-5) Proposed Rule.
    • “Today’s HTI-5 Proposed Rule has three core goals: (1) reducing burden on health IT developers by streamlining ASTP/ONC’s voluntary Health IT Certification Program by removing redundant requirements; (2) updating the information blocking regulations to better promote electronic health information access, exchange, and use so that patients’ access to their data is not blocked; and (3) advancing a new foundation of Fast Healthcare Interoperability Resources (FHIR®)-based application programming interfaces (APIs) that promote AI-enabled interoperability solutions through modernized standards and certification. The HTI-5 proposed rule is expected to save $1.53 billion in total, including $650 million over the next five years for health IT developers, providers, and other stakeholders.
    • “The HTI-5 proposed rule delivers on President Trump’s directive to reduce regulatory burden and to enable American innovation through artificial intelligence,” said Tom Keane, MD, Assistant Secretary for Technology Policy and National Coordinator for Health IT. “These proposals reflect a commonsense approach that removes redundant requirements on health IT developers, that better ensures seamless patient access to their information and that sets a foundation for AI-based data exchange.” * * *
    • “More information can be found at healthit.gov/hti5 and via ASTP/ONC’s X account, @HHS_TechPolicy
    • “ASTP/ONC is also withdrawing certain proposals not yet finalized from the HTI-2 proposed rule.”

From the Food and Drug Administration front,

  • The Wall Street Journal reports,
    • “U.S. regulators approved the first GLP-1 weight-loss pill—a tablet formulation of Novo Nordisk’s NOVO.B  Ozempic and Wegovy—ushering in a new era of the obesity-drugs revolution that is expected to broaden their use.
    • “Novo Nordisk said it plans to start selling the new pill in the U.S. soon after the new year, with a cash price of $149 a month for the starting dose.
    • “The Food and Drug Administration approval is a milestone because weekly shots such as Wegovy and Eli Lilly’s LLY Zepbound have dominated the anti-obesity market to date. Yet many people with excess weight don’t take the shots due to costspotty insurance coverage and fear of needles.
    • “Drug companies and analysts say pills will tap in to demand from people who don’t want an injection or would prefer the cadence of a daily dose. Pills also offer the prospect of lower prices and better health-insurance coverage than injections, because pills cost less to make.
    • “Eli Lilly also plans to introduce a new weight-loss pill, potentially within weeks or months.” 
  • Fierce Pharma tells us,
    • “Just two months after reviving its prowess in the idiopathic pulmonary fibrosis (IPF) treatment area with rare lung disease med Jascayd, Boehringer Ingelheim is already unlocking another patient population with a new FDA nod.
    • “The new approval for Jascayd in progressive pulmonary fibrosis (PPF) makes the drug the only preferential phosphodiesterase 4B (PDE4B) inhibitor with immunomodulatory and antifibrotic effects approved in this indication, according to a Dec. 19 company press release.
    • “Progressive pulmonary fibrosis is a life-threatening condition with a high unmet medical need. The U.S. approval of Jascayd is an important step forward to help slow lung function decline for people living with PPF, providing a new, well-tolerated treatment option,” Boehringer’s head of human pharma, Shashank Deshpande, said in a release.”
  • MedTech Dive notes,
    • “Abbott said Monday that it has received Food and Drug Administration approval for its Volt pulsed field ablation system.
    • “The catheter-based device uses targeted, high-energy electrical pulses to treat a common heart arrhythmia called atrial fibrillation. Abbott’s Volt device is indicated for both paroxysmal AFib, where episodes come and go, and persistent AFib, or episodes that last longer than seven days, according to the FDA.
    • “Medtronic, Boston Scientific and Johnson & Johnson have all debuted their own PFA devices in the last two years. The approval allows Abbott to join the fast-growing, competitive market in the U.S.”

From the public health and medical / Rx research front,

  • The American Medical Association lets us know “What doctors wish patients knew about family immunizations.”
    • “Vaccines save millions of lives each year. Two infectious diseases physicians discuss the key role they should play for the loved ones in your family.”
  • Health Day informs us,
    • “Psychiatric conditions as varied as schizophrenia and bipolar disorder might be driven by very similar genetic underpinnings, a new study says. 
    • “Mental health problems can be sorted into five general genetic categories, each with a shared “genetic architecture” driving people’s illness, according to results published in the journal Nature.
    • “Right now, we diagnose psychiatric disorders based on what we see in the room, and many people will be diagnosed with multiple disorders. That can be hard to treat and disheartening for patients,” lead researcher Andrew Grotzinger, an assistant professor of psychology and neuroscience at the University of Colorado-Boulder, said in a news release.
    • “This work provides the best evidence yet that there may be things that we are currently giving different names to that are actually driven by the same biological processes,” he said.”
  • and
    • “A new risk score can help predict which pancreatic cancer survivors are more likely to suffer a recurrence of their cancer, researchers said.
    • “The score could help better manage the follow-up care for patients who’ve had pancreatic tumors surgically removed, and whose cancers have not spread to their lymph nodes, researchers wrote Dec. 17 in JAMA Surgery.
    • “We now have a way to identify patients whose higher risk of recurrence may have been previously overlooked,” senior researcher Dr. Cristina Ferrone, chair of surgery at Cedars-Sinai Medical Center in Los Angeles, said in a news release. “This gives us the opportunity to change the way we care for this patient population in a meaningful way.”
    • “The score helps people with pancreatic neuroendocrine tumors, which are a less common and typically less aggressive form of pancreatic cancer.
    • “Patients whose cancer has not spread outside the pancreas, to either the lymph nodes or surrounding organs, have a 91% five-year survival rate following surgery, researchers said in background notes.”
  • The Wall Street Journal relates
    • “For years, Barbara Schmidt’s family feared an illness was behind a pattern of terrifying falls that repeatedly landed the 83-year-old great-grandmother in surgery with broken bones. Instead, Schmidt’s frequent tumbles might have been tied to something else: medications intended to make her better.
    • “Schmidt, who lives with her husband of 65 years in Lewes, Del., filled prescriptions for more than a dozen different drugs in the past year, according to pharmacy and medical records.
    • “That isn’t unusual for America’s seniors, according to a Wall Street Journal analysis of Medicare data. One in six of the 46 million seniors enrolled in Medicare’s drug benefit, which pays for most drugs taken by older Americans, were prescribed eight or more medications.”
    • * * * “Schmidt’s recent prescriptions came from at least five different healthcare providers. Most were affiliated with the nearby hospital system Beebe Healthcare, including a nurse practitioner whom she sees for primary care and a gastroenterology office. An orthopedic surgeon who has treated her back problems and prescribed medications to help with her pain works for an independent practice, First State Orthopaedics. 
    • “A Beebe spokesman said it has reviewed its prescribing patterns and, this November, added a new electronic medical record that will allow doctors to “view consolidated medical and medication histories” for patients and deliver “safer, more informed care.” First State Orthopaedics said it doesn’t comment on matters of patient care unless it is legally required to do so.
    • “Pharmacists who work with seniors say doctors might not be aware of their patients’ full medication list. Patients don’t always mention what their other doctors have prescribed when a history is taken, and specialists might not have access to a shared medical record.
    • “The Journal analysis found that, among seniors taking eight or more drugs, it was common for the prescriptions to come from a large number of doctors.”

From the U.S. healthcare and artificial intelligence front,

  • Per Beckers Hospital Review,
    • “Houston-based Nutex Health has opened its 26th micro-hospital, Archview ER & Hospital, in St. Louis.
    • “The 16,000-square-foot facility includes 15 emergency room beds, three inpatient suites, a full-service laboratory and advanced imaging technology, according to a Dec. 22 Nutex Health news release.
    • “It replaces Homer G. Phillips Memorial Hospital, which surrendered its license and closed in March. The hospital had been temporarily closed since December 2024, when its license was suspended due to a blood supply shortage.”
  • and
    • “Mark Cuban Cost Plus Drug Co. has added Vegzelma, a biosimilar indicated for six cancer types, to its marketplace for hospitals and other healthcare providers. 
    • “The company plans to expand its biosimilar offerings amid growing demand for biologics among health systems, according to a news release shared with Becker’s. Cost Plus Drugs also offers Starjemza, a biosimilar to Johnson & Johnson’s Stelara (ustekinumab), at a price about $3,000 lower than retail at other pharmacies.
    • “Vegzelma is a biosimilar to Roche’s Avastin (bevacizumab), which is approved for treatment of metastatic colorectal cancer; non-squamous non-small cell lung cancer; recurrent glioblastoma; metastatic renal cell carcinoma; persistent, recurrent or metastatic cervical cancer; and epithelial ovarian, fallopian tube or primary peritoneal cancer.”  

Cybersecurity Saturday

From the cybersecurity policy and law enforcement front,

  • Cyberscoop reports,
    • “With a little more than a month left before a foundational cyber threat information sharing law expires for a second time, Congress might have to do another short-term extension as negotiations on a longer deal aren’t yet bearing fruit, a key lawmaker said Tuesday.
    • “House Homeland Security Chairman Andrew Garbarino, R-N.Y., said the problem with a long-term extension of the Cybersecurity Information Sharing Act of 2015, which provides legal protections to companies to share cyber threat data with the federal government and other companies, is that there are three different views about how to approach it.
    • “The Trump administration and some in the Senate want a clean, 10-year reauthorization of the law, which Congress extended last month until Jan. 30 as part of the legislation that ended the government shutdown, after the information sharing law lapsed in October. But a reauthorization without any changes could run into House opposition, Garbarino said.” * * *
    • “Senate Homeland Security and Governmental Affairs Committee Chairman Rand Paul, R-Ky., also has a version of the bill that focuses largely on language he said is needed to defend free speech. And Garbarino’s version takes yet another approach to tweaking the law.
    • “Unfortunately, I don’t think we’re close enough with the discussions on the Senate to get it to figure out which bill will pass and what will get done,” Garbarino said. That leaves another extension tied to any funding bill that replaces the legislation currently funding the government, which also runs through Jan. 30.”
  • and
    • “Policymakers and companies are reckoning with increased reports over the past few months showing AI tools being leveraged to conduct cyber attacks on a larger and faster scale.
    • “Most notably, Anthropic reported last month that Chinese hackers had jailbroken and tricked its AI model Claude into assisting with a cyberespionage hacking campaign that ultimately targeted more than 30 entities around the world.
    • “The Claude-enabled Chinese hacks have underscored existing concerns among AI companies and policymakers that the technology’s development and relevance to offensive cybersecurity may be outpacing the cybersecurity, legal and policy responses being developed to defend against them.
    • “At a House Homeland Security hearing this week, Logan Graham, head of Anthropic’s red team, said the Chinese spying campaign demonstrates that worries about AI models being used to supercharge hacking are more than theoretical.”
  • Cybersecurity Dive tells us,
    • “A top Senate Republican is pressing the Trump administration for a plan to address the cybersecurity consequences of the U.S.’s dependence on open-source software.
    • “Leaving our reliance on OSS unmonitored is exposing America to increasingly dangerous risks,” Senate Intelligence Committee Chair Tom Cotton, R-Okla., wrote in a Wednesday letter to National Cyber Director Sean Cairncross.
    • “Cotton cited recent incidents that highlighted the unstable and sometimes untrustworthy foundations of the open-source ecosystem, including the XZ Utils crisis, a Russian developer’s control of a package that the U.S. military uses for sensitive applications and the prevalence of code contributions by Chinese companies’ employees, who are bound by Chinese laws that could force them to disclose software flaws to Beijing before fixing them.”
  • and
    • “The National Institute of Standards and Technology has prepared a companion to its widely used Cybersecurity Framework that focuses on how organizations can safely use AI.
    • “NIST’s Cybersecurity Framework Profile for Artificial Intelligence, which the agency released in draft form on Tuesday [December 16], describes how organizations can manage the cybersecurity challenges of different AI systems, improve their cyber defense capabilities with AI and block AI-powered cyberattacks. The document maps components of the Cybersecurity Framework (CSF) onto specific recommendations in each of those three areas, which NIST dubbed “secure,” “defend” and “thwart,” respectively.
    • “The three focus areas reflect the fact that AI is entering organizations’ awareness in different ways,” Barbara Cuthill, one of the profile’s authors, said in a statement. “But ultimately every organization will have to deal with all three.”
  • Cyberscoop tells us,
    • “Federal prosecutors in Michigan say they have dismantled online infrastructure tied to an alleged money laundering operation that moved tens of millions of dollars in proceeds from ransomware and other cybercrime, along with indicting the service’s creator.
    • “The U.S. Attorney’s Office for the Eastern District of Michigan announced a coordinated action with international partners and the Michigan State Police targeting E-Note, a cryptocurrency exchange and payment processing service used to launder illicit funds. The announcement coincided with the unsealing of an indictment charging a Russian national, Mykhalio Petrovich Chudnovets, with one count of money laundering conspiracy.”
  • and
    • “Former cybersecurity professionals Ryan Clifford Goldberg and Kevin Tyler Martin pleaded guilty Thursday to participating in a series of ransomware attacks in 2023 while they were employed at cybersecurity companies tasked with helping organizations respond to ransomware attacks.
    • “Goldberg, who was a manager of incident response at Sygnia, and Martin, a ransomware negotiator at DigitalMint at the time, collaborated with an unnamed co-conspirator to attack victim computers and networks and use ALPHV, also known as BlackCat, ransomware to extort payments.
    • “The plea deals mark a relatively quick turnaround as prosecutors successfully persuaded the pair to cop to their crimes less than three months after they were indicted in the U.S. District Court for the Southern District of Florida. Goldberg was arrested Sept. 22 and Martin was arrested Oct. 14.”
  • and
    • “Artem Aleksandrovych Stryzhak, a 35-year-old Ukrainian national, pleaded guilty Friday to multiple crimes stemming from his involvement in a string of ransomware attacks targeting U.S. and Europe-based organizations from mid 2018 to late 2021. He faces up to 10 years in jail for conspiracy to commit fraud, including extortion. 
    • “Stryzhak was arrested in Spain in June 2024 and extradited to the United States in April. Authorities are still looking for his alleged co-conspirator Volodymyr Tymoshchuk and announced a $11 million reward for information leading to his arrest or conviction.
    • “The defendant used Nefilim ransomware to target high-revenue companies in the United States, steal data and extort victims,” Joseph Nocella, U.S. attorney for the Eastern District of New York, said in a statement.”

From the cybersecurity breaches and vulnerabilities front,

  • Cybersecurity Dive reports,
    • “Apartment owner and developer Rockrose Development Corp. recently found that unauthorized individuals hacked its systems and claimed to have acquired confidential information, according to a letter posted to its website on Dec. 12. 
    • “The security breach occurred on July 4 and affected 47,392 people, according to a data breach notification submitted to Maine’s attorney general’s office. Rockrose discovered the issues on Nov. 14. 
    • “Rockrose determined that personally identifiable information for some individuals may have been impacted, which could indicate that the hackers accessed some sensitive areas of the network. That information could include name, Social Security number, taxpayer identification number, driver’s license number, passport number, bank account and routing numbers, health insurance information, medical information and online account credentials.”
  • Cyberscoop adds,
    • “Fallout from React2Shell — a stubborn vulnerability that impacts wide swaths of the internet’s scaffolding — continues to spread as public exploits and stealth backdoors proliferate and worrying details emerge about the targets attackers are pursuing. 
    • “Threat researchers and incident responders are reacting to swift-moving developments on React2Shell with mounting concern. Cybercriminals, ransomware gangs and nation-state threat groups are all swarming to exploit the maximum-severity vulnerability.
    • Palo Alto Networks’ Unit 42 puts the latest victim count at more than 60 organizations, which have been impacted by attacks involving exploitation of CVE-2025-55182, which Meta and the React team publicly disclosed Dec. 3.
    • “Microsoft said it found “several hundred machines across a diverse set of organizations” that were compromised via exploitation resulting in remote-code execution. Post-exploitation activity in those attacks includes reverse shell implants, lateral movement, data theft and steps that allowed attackers to maintain access to targeted networks, Microsoft said in a research blog Tuesday [December 16]. 
  • The Cybersecurity and Infrastructure Security Agency (“CISA”) added seven known exploited vulnerabilities to its catalog this week.
    • December 15, 2025
      • CVE-2025-14611 Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability
      • CVE-2025-43529 Apple Multiple Products Use-After-Free WebKit Vulnerability 
        • Kubelski Security discusses the Gladinet KVEs here.
        • The Center for Internet Security discusses the Apple KVEs here.
    • December 16, 2025
      • CVE-2025-59718 Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability 
        • Security Affairs discusses this KVE here.
    • December 17, 2025
      • CVE-2025-20393 Cisco Multiple Products Improper Input Validation Vulnerability
      • CVE-2025-40602 SonicWall SMA1000 Missing Authorization Vulnerability
      • CVE-2025-59374 ASUS Live Update Embedded Malicious Code Vulnerability
        • The Hacker News discusses the Cisco KVE here.
        • Security Week discusses the SonicWall KVE here.
        • Malwarebytes discusses the ASUS KVE here.
    • December 19, 2025
      • CVE-2025-14733 WatchGuard Firebox Out-of-Bounds Write Vulnerability 
        • Bleeping Computer discusses this KVE here.
  • Cyberscoop relates,
    • “Cisco customers are confronting a fresh wave of attacks from a Chinese threat group that has actively exploited a critical zero-day vulnerability affecting the vendor’s software for email and web security since at least late November, the company said in an advisory Wednesday. 
    • “Cisco said it became aware of the attacks Dec. 10. The defect CVE-2025-20393, which has a CVSS rating of 10, is an improper input validation vulnerability affecting Cisco AsyncOS software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager that allows attackers to execute commands with unrestricted privileges and implant persistent backdoors on compromised devices.
    • “There is no patch for the vulnerability and Cisco declined to say when one would be made available. Cisco said “non-standard configurations” have been observed in compromised networks, specifically customer systems that are configured with a publicly exposed spam quarantine feature.
    • “Cisco Talos researchers attributed the attacks to a Chinese advanced persistent threat group it tracks as UAT-9686, which has used tooling and infrastructure consistent with other China state-sponsored threat groups such as APT41 and UNC5174.
  • Cybersecurity Dive informs us,
    • “Multiple threat groups have been ramping up attacks using a technique called device code phishing to trick users into granting access to their Microsoft 365 accounts, according to a report Thursday from Proofpoint
    • “Hackers affiliated with China and Russia have used the technique in recent months to launch attacks. A number of criminal groups have used the same method to target M365 users as well. 
    • “This is a social engineering method that abuses a legitimate and trusted workflow for authorized access,” Sarah Sabotka, staff threat researcher at Proofpoint, told Cybersecurity Dive.”
  • and
    • A coordinated, credential-based hacking campaign has been targeting Palo Alto Networks GlobalProtect services, as well as Cisco SSL VPNs, in a surge of mid-December attacks, according to a blog post Wednesday by GreyNoise
    • The threat activity does not involve targeting of any vulnerabilities, but uses automated scripted login attempts over two days. 
    • More than 1.7 million sessions were observed targeting Palo Alto Networks GlobalProtect and PAN-OS profiles over a 16-hour period, according to GreyNoise. More than 10,000 unique IPs were detected trying to log into GlobalProtect portals on Dec. 11.  
  • and
    • “A Russia-linked hacker group has been targeting critical infrastructure organizations using vulnerabilities in their edge devices since at least 2021, highlighting an alarming shift toward exploiting well-known flaws in common networking equipment, Amazon’s threat intelligence team said Monday.
    • “The threat actor’s shift [toward edge devices] represents a concerning evolution,” Amazon researchers wrote in a blog post. “While customer misconfiguration targeting has been ongoing since at least 2022, the actor maintained sustained focus on this activity in 2025 while reducing investment in zero-day and N-day exploitation.”
  • Bleeping Computer points out,
    • “The UEFI firmware implementation in some motherboards from ASUS, Gigabyte, MSI, and ASRock is vulnerable to direct memory access (DMA) attacks that can bypass early-boot memory protections.
    • “The security issue has received multiple identifiers (CVE-2025-11901, CVE-2025‑14302, CVE-2025-14303, and CVE-2025-14304) due to differences in vendor implementations.”

From the ransomware front,

  • Cyber Press reports,
    • SentinelLABS research indicates that large language models (LLMs) such as ChatGPT, Claude, and open-source alternatives are accelerating every stage of the ransomware lifecycle, from reconnaissance to negotiation. 
    • “However, analysts emphasize that these tools are improving speed and scale rather than introducing fundamentally new attack methods.
    • “By repurposing enterprise-grade AI workflows, ransomware actors are using models to automate tasks such as creating phishing content, drafting multilingual ransom notes, and triaging data across leaked datasets. 
    • “This enables threat actors to identify financially sensitive files and tailor extortion tactics across multiple languages with greater precision.” * * *
    • “The report finds that while law enforcement disruptions have weakened mega cartels such as LockBit, Conti, and REvil, smaller, short-lived groups such as Termite, Punisher, and Obscura are emerging rapidly. 
    • “These groups exploit LLM-driven workflows to emulate more experienced operators, reducing entry barriers and complicating attribution.”
  • Manufacturing Business Technology adds,
    • “Sophos recently announced new findings from the Sophos State of Ransomware in Manufacturing and Production 2025 report which reveals that manufacturers are stopping more ransomware attacks before data can be encrypted.
    • “However, adversaries are increasingly stealing data and using extortion-only tactics to maintain pressure. As a result, more than half of manufacturing organizations impacted by encryption paid the ransom despite progress in defensive measures.”
  • Bleeping Computer relates,
    • “The Clop ransomware gang (also known as Cl0p) is targeting Internet-exposed Gladinet CentreStack file servers in a new data theft extortion campaign.
    • Gladinet CentreStack enables businesses to securely share files hosted on on-premises file servers through web browsers, mobile apps, and mapped drives without requiring a VPN. According to Gladinet, CentreStack “is used by thousands of businesses from over 49 countries.”
    • “Since April, Gladinet has released security updates to address several other security flaws that were exploited in attacks, some of them as zero-days.
    • “The Clop cybercrime gang is now scanning for and breaching CentreStack servers exposed online, with Curated Intel telling BleepingComputer that ransom notes are left on compromised servers.
    • “However, there is currently no information on the vulnerability Clop is exploiting to hack into CentreStack servers. It is unclear whether this is a zero-day flaw or a previously addressed bug that the owners of the hacked systems have yet to patch.”
  • CSO offers advice on how to create a ransomware playbook that works.

From the cybersecurity business and defenses front,

  • The Wall Street Journal reports,
    • “Blackstone is leading a $400 million investment in data-security firm Cyera that values the New York-based company at $9 billion, according to people familiar with the matter. 
    • “Cyera is among a crop of cybersecurity startups leveraging artificial intelligence to protect companies from new security vulnerabilities introduced by AI. The startup, founded in 2021 by former Israeli Defence Forces military intelligence officers Yotam Segev and Tamar Bar-Ilan, raised funding at a $6 billion valuation in June.”
  • and
    • “Kevin Mandia, founder of the cybersecurity firm Mandiant—which was acquired by Alphabet’s GOOGL 0.61%increase; green up pointing triangle Google for $5.4 billion—has formed a new company called Armadin that will take on the imminent threat from AI hacking.
    • “The company aims to use artificial intelligence to supercharge the business of testing networks for vulnerabilities. Armadin raised $24 million in seed funding from Ballistic Ventures, a venture-capital firm co-founded by Mandia, and is in talks with Accel, GV and Kleiner Perkins to raise $100 million or more, people familiar with the matter said. The deal is expected to value the company at more than $600 million. The round isn’t finalized, and the details could still change.
    • “Known as red-teaming, this kind of service will become more important as hackers turn to AI to speed up their attacks, Mandia said in an interview.  
    • “Offense is going to be all-AI in under two years,” he said. “And because that’s going to happen, that means defense has to be autonomous. You can’t have a human in the loop or it’s going to be too slow.”
  • CISA announced,
    • Today [December 19], the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency, and Canadian Centre for Cyber Security released an update to the Malware Analysis Report BRICKSTORM Backdoor with indicators of compromise (IOCs) and detection signatures for additional BRICKSTORM samples. This update provides information on additional samples, including Rust-based samples. These samples demonstrate advanced persistence and defense evasion mechanisms, such as running as background services, and enhanced command and control capabilities through encrypted WebSocket connections.
    • The update includes two new detection signatures in the form of YARA rules, enabling organizations to better identify BRICKSTORM-related activity. Organizations are strongly encouraged to deploy these updated IOCs and signatures, and to follow the detection guidance to scan for and respond to BRICKSTORM infections If BRICKSTORM, similar malware, or potentially related activity is detected, report the incident to CISA’s 24/7 Operations Center at contact@cisa.dhs.gov or (888) 282-0870.
  • Cybersecurity Dive lets us know,
    • “Hybrid infrastructure that includes a mix of public/private cloud environments, on-premises workloads and air-gapped systems are preferred by security leaders as a way to boost resilience and better manage risk, according to a report Thursday by Trellix
    • “About 96% of chief information security officers said a hybrid model is the preferred approach to meet regulatory and compliance requirements, while 97% said such a model will help meet obligations related to data sovereignty and residency. 
    • “Ultimately, a CISO must ensure their teams, technology and business partners understand the specific shared responsibility model for each service they consume and implement the necessary controls to manage the daily risks that remain the customer’s responsibility,” Trellix CISO Michael Green told Cybersecurity Dive. “This often involves leveraging tools and governance processes designed to operate across multicloud and hybrid environments to provide consistent security posture and visibility.”
  • An ISACA expert notes,
    • “Cybersecurity budgets are often built on assumptions, including the assumption that backups will always work, that insurance will cover the losses and that existing controls are “good enough.” Yet, when those assumptions fail, the operational fallout can be staggering. The City of Hamilton in Canada learned this lesson when a ransomware attack crippled nearly 80% of its network and left taxpayers facing a CAD $18.3 million recovery bill. Misplaced assumptions regarding backups, authentication, insurance and system resilience can lead organizations to underestimate risk and drive up the cost of a cyberattack.”
  • Dark Reading offers advice on creating an AI adoption playbook and of course its CISO Corner.

Monday report

From Washington, DC,

  • The American Hospital Association News informs us,
    • “Approximately 950,000 consumers who currently do not have health insurance coverage through the federally facilitated Health Insurance Marketplace have signed up for a 2026 health plan, the Centers for Medicare & Medicaid Services announced Dec. 5. More than 4.8 million returning consumers have selected 2026 plans. The open enrollment period began Nov. 1 and continues through Jan. 15. Today is the final day for consumers to enroll in coverage that would begin Jan. 1. For those enrolling after Dec. 15, coverage would begin Feb. 1.”
  • and
    • “The Centers for Medicare & Medicaid Services Dec. 15 published the Measures Under Consideration List for 2025. These are measures that CMS is considering adopting through the federal rulemaking process for use in Medicare programs. This year’s list comprises 24 unique measures, with some under consideration for multiple CMS programs and others already in use but undergoing substantial change to their specifications. Notably, several measures address topics consistent with the Department of Health and Human Services’ Make America Health Again priority framework, such as chronic illness and nutrition, and all 24 measures rely on data submissions using at least one digital source. In addition, CMS is promoting the early review of five measures that align with the MAHA initiative and are currently in the development stage. 
    • “CMS will convene a consensus-based multidisciplinary group, on which the AHA sits, to provide recommendations to the agency on these measures by Feb. 1. In addition, CMS will seek input through public comments from Dec. 16 through Jan. 6.” 
  • Per a CMS fact sheet,
    • “All seven of CMS’ A/B Medicare Administrative Contractors (MACs) will issue updated Final Local Coverage Determinations (LCDs) for Skin Substitute Grafts/Cellular and Tissue-Based Products for the Treatment of Diabetic Foot Ulcers and Venous Leg Ulcers that will be effective January 1, 2026.”
  • Per HHS news releases,
    • “Ralph Abraham, M.D., was sworn in today as Principal Deputy Director of the Centers for Disease Control and Prevention (CDC) by Health and Human Services Secretary Robert F. Kennedy, Jr. He will begin his duties at CDC headquarters in Atlanta on January 5, 2026.
    • “Dr. Abraham has nearly 30 years of experience as a medical practitioner, most recently as Surgeon General of the state of Louisiana. As CDC Principal Deputy Director, he will help realign the agency with its mission as America’s frontline defender against infectious disease.”
  • and
    • “The U.S. Department of Health and Human Services (HHS) today convened Lyme disease patients, clinicians, and researchers for a roundtable on diagnostics and clinical needs moderated by HHS Secretary Robert F. Kennedy, Jr. The event fulfills commitments made in the Make America Healthy Again Commission Strategy Report [PDF, 21.85 MB] to address chronic and often unseen illnesses that affect millions of Americans.
    • “For decades, Americans suffering from Lyme disease have been denied the accurate diagnostics and meaningful care they deserve,” said Secretary Kennedy. “Today’s actions push us decisively toward reliable testing and treatment grounded in the real-world experiences of patients. We are committed to delivering the tools that families have waited far too long to receive.”
    • “Participants shared their experiences and recommendations on improving care and advancing research. Senator Susan Collins (R-ME) and Representatives Morgan Griffith (R-VA) and Chris Smith (R-NJ) also engaged in the discussions.
    • “As part of today’s event, HHS announced the renewal of the LymeX Innovation Accelerator with the Steven & Alexandra Cohen Foundation that began during President Trump’s first term. Established in 2020, LymeX is the largest public-private partnership ever built to improve Lyme disease diagnostics and care. The $10 million initiative will advance artificial intelligence tools that support earlier and more accurate detection across stages of infection.”
  • Per an OPM news release,
    • “The US Office of Personnel Management (OPM), in coordination with the Office of Management and Budget (OMB), the General Services Administration (GSA), the White House Office of Science Technology and Policy (OSTP), and agency leaders across the administration, today announced the establishment of the United States Tech Force (Tech Force)– a new, cross-government program to recruit top technologists to modernize the federal government.” * * *
    • “OPM is proud to announce the initial private sector partners for Tech Force: Adobe, Amazon Web Services, AMD, Anduril, Apple, Box, C3.ai, Coinbase, Databricks, Dell Technologies, Docusign, Google Public Sector, IBM, Meta, Microsoft, Nvidia, OpenAI, Oracle, Palantir, Robinhood, Salesforce, SAP, ServiceNow, Snowflake, Synopsys, Uber, Workday, xAI, and Zoom. OPM welcomes the opportunity to expand this list of partners over time.
    • “In addition, Tech Force is partnering with NobleReach Foundation – a nonpartisan talent platform that brings together America’s best and brightest across industry, academia, and government via initiatives such as its NobleReach Scholars Program – to recruit technologists and support the program.
    • “Read more of what government and tech world leaders have to say about Tech Force here.
    • “For further information, please see OPM’s memo to agencies here. To learn more or apply for Tech Force and for FAQ’s visit TechForce.govAnd follow US Tech Force on X.”  

From the Food and Drug Administration front,

  • Per FDA news releases,
    • “The U.S. Food and Drug Administration (FDA) today removed a key limitation on the use of real-world evidence (RWE) used in drug and device applications reviews. In new guidance for certain types of medical device submissions, the agency states it will accept RWE without requiring that identifiable individual patient data collected from real-world data sources always be submitted in a marketing submission. The FDA similarly intends to consider updating its guidance for drugs and biologics.”
  • and
    • “The U.S. Food and Drug Administration today reminded industry of its legal responsibilities under the Federal Food, Drug, and Cosmetic Act regarding food recalls and called for industry to increase adoption of best practices in recall implementation, especially for recalls involving foods for our country’s most vulnerable populations –infants and young children. Last week, the FDA sent warning letters to several major retailers for failing to remove recalled ByHeart infant formula from their store shelves despite being notified of the recall. These warning letters highlight a concerning problem with recall effectiveness at the retail level. Last year, the FDA sent a similar warning letter to a retailer who failed to adequately remove recalled lead-contaminated WanaBana apple cinnamon fruit puree pouches from its store shelves.”
  • Fierce Pharma reports,
    • “Clearing clinical and regulatory hurdles in the development of a fast-acting nasal spray for a heart condition has given Milestone Pharmaceuticals its first FDA approval in its 22-year history.
    • “The U.S. regulator has signed off on Cardamyst (etripamil) to quell symptomatic episodes from paroxysmal supraventricular tachycardia (PSVT), which is a type of abnormal heart rhythm. Cardamyst becomes the first self-administered treatment patients can use to manage their PSVT symptoms.
    • “The calcium channel blocker is a convenient alternative to an emergency room visit, where patients receive an intravenous dose of a drug that “basically reboots your heart,” Milestone CEO Joe Oliveto said in an interview.
  • and
    • “LIB Therapeutics has scored an FDA approval for its cholesterol-lowering, third-generation PCSK9 inhibitor, lerodalcibep-liga.
    • “The injected treatment, which will carry the commercial name Lerochol, is approved to be used along with diet and exercise to reduce low-density lipoprotein cholesterol (LDL-C) in adults with hypercholesterolemia, including those with heterozygous familial hypercholesterolemia (HeFH).
    • “Lerochol arrives on the market with a convenience edge over other PCSK9 drugs, as it is self-administered once monthly and doesn’t need refrigeration because it retains its stability for up to three months at room temperature. By comparison, Amgen’s Repatha and Sanofi and Regeneron’s Praluent are dosed between every two to four weeks, depending on patient needs, and have a shorter shelf life at room temperature.”
  • and
    • “Johnson & Johnson’s Akeega is opening new fronts in prostate cancer treatment with a fresh FDA approval, making it the first precision medicine combo for patients with BRCA2-mutated metastatic castration-sensitive prostate cancer (mCSPC).
    • “Akeega, a dual-action tablet made up of J&J’s androgen-directed prostate cancer med Zytiga (abiraterone acetate) and the PARP inhibitor niraparib—sold by GSK as Zejula in other indications—is added to corticosteroid medication prednisone to delay disease progression of the aggressive form of prostate cancer.  
    • “J&J’s Amplitude study was the first showing that a PARP inhibitor-androgen receptor pathway inhibitor treatment combination could delay both radiographic and symptomatic disease progression in the disease type, Dana-Farber Cancer Institute’s Bradley McGregor, M.D., noted in a company press release.
  • and
    • “The FDA has “proactively” granted Johnson & Johnson a coveted speedy review under the Commissioner’s National Priority Voucher pilot (CNPV), the agency said Monday.
    • “The voucher was granted to J&J for its proposed combination of Tecvayli and Darzalex for previously treated multiple myeloma.
    • “With the voucher, the FDA aims to deliver a decision within one to two months following submission of an application. Normally, FDA drug reviews take up to 10 months, starting from the acceptance of an application.”

From the public health and medical / Rx research front,

  • The New York Times reports,
    • “A new drug has been saturating the fentanyl supply in Philadelphia and moving to other cities throughout the East and Midwestern United States: medetomidine, a powerful veterinary sedative that causes almost instantaneous blackouts and, if not used every few hours, brings on life-threatening withdrawal symptoms.
    • “It has created a new type of drug crisis — one that is occasioned not by overdosing on the drug, but by withdrawing from it.
    • “Since the middle of last year, Philadelphia’s hospitals have been strained by patients coming in with what doctors have identified as medetomidine withdrawal. Although the heart rate slows drastically right after use, in withdrawal the opposite occurs: The heart rate and blood pressure become catastrophically high. Patients experience tremors and unstoppable vomiting. Many require intensive care.”
  • The Wall Street Journal relates,
    • “People susceptible to developing heart issues benefit the most from reducing their consumption of saturated fats, according to a review of research that comes as the federal government prepares to revise dietary recommendations.
    • ‘A paper published Monday in the Annals of Internal Medicine found that people at high risk of developing cardiovascular problems saw a reduction in major health issues including heart attack and stroke when they cut back on saturated fats. The picture was different for people without those same cardiovascular risks. Within five years, cutting saturated fats didn’t yield the same benefits for that group, the review said.”
  • The Washington Post tells us,
    • “Why some people experience long-lasting physical and mental effects from covid-19 could be linked to chronic inflammation, according to new research that experts say could help develop new treatments for the confounding condition that continues to afflict millions.
    • “Some early research on the condition has suggested that long covid’s symptoms linger because the virus persists in people’s bodies. But the new study published Friday in Nature Immunology found that people with long covid had activated immune defenses and heightened inflammatory responses for more than six months after initial infection compared with those who fully recovered.
    • “The latest research “leads to a hypothesis that there might be therapeutic targets related to inflammation that might be worth exploring in clinical studies,” said Dan Barouch, the study’s lead author and director of the Center for Virology and Vaccine Research at Beth Israel Deaconess Medical Center.
    • “The study’s findings signal progress in understanding a condition that is estimated to affect more than 400 million individuals around the world as the coronavirus continues to infect people every day, said Ziyad Al-Aly, a clinical epidemiologist at Washington University in St. Louis who studies long covid. There are no drugs approved for treatment of long covid, leaving doctors to tackle individual symptoms with various therapies.”
  • The American Medical Association lets us know “What doctors wish parents knew about fall prevention for kids.
    • “Rabia Nagda, MD, of Texas Children’s Pediatrics, emphasizes that every environment where kids spend time should be built with fall risk in mind.”
  • Per MedPage Today,
    • “Cannabis use in pregnancy is associated with health risks including preeclampsia and low birthweight.
    • “In this secret shopper study, one in five cannabis retailers told callers that cannabis use was safe in pregnancy.
    • “The findings support a need for more public education about the risks of prenatal cannabis use and for guidance to discuss its use with physicians.”
  • Per Health Day,
    • “‘Dual use’ of vaping and smoking might help smokers cut back or quit.
    • “Smokers who also vaped were 4.5 times more likely to quit within a year.
    • “Dual users were also more likely to cut their smoking by half.”
  • and
    • “People could learn within 15 minutes whether they are infected with hepatitis C, thanks to a rapid test developed by Northwestern University.
    • “The test will allow doctors to diagnose infections during an office visit and kickstart patients’ treatment before they leave, researchers said.
    • “This test could revolutionize HCV care in the U.S. and globally by dramatically improving diagnosis, accelerating treatment uptake and enabling more people to be cured faster,” researcher Dr. Claudia Hawkins said in a news release. She’s director of Northwestern’s Institute for Global Health’s Center for Global Communicable and Emerging Infectious Diseases in Chicago.”
  • STAT News reports,
    • “Gene therapy researchers were converging on a holy grail. A few years ago, researchers at labs and companies reported they had engineered viruses that could ferry corrective genes deep into the brain, giving potential entry to a new world of treatments for Alzheimer’s, Parkinson’s, and a slew of rare genetic diseases.
    • “This summer, after years of careful study, the first person underwent gene therapy using one of the new viruses. The patient, a young child, died two and a half days later.
    • “The death has sent concern and uncertainty rippling through labs and companies developing gene therapies for the brain, along with rare disease groups who hoped these tools could deliver long-sought cures. They worry that Capsida Biotherapeutics unearthed a broader risk for other viruses designed to travel like a messenger pigeon to our brains, one that could derail years of progress. 
    • “Capsida has declined to answer questions about the death beyond a brief statement. Its CEO has departed. The information that has leaked out is troubling. The child died of cerebral edema — brain swelling — a clinical course distinct from other deaths tied to gene therapy over the last decade, according to a person familiar with the matter.
    • “Most disturbingly, none of the animal and lab studies Capsida presented indicated such a calamity was possible, making it unclear how other researchers and companies would test for such a risk.” * * *
    • “The best path ahead may be to start new trials in very low doses. But that’s challenging in gene therapy, where patients can only ever receive one dose of a virus in their lifetime, before they develop immunity to it. Still, “we may have to be a bit more conservative,” said Miguel Sena-Esteves, a gene therapy researcher at the UMass Chan Medical School 
    • “Alternatively, companies may have to move forward first in diseases otherwise immediately fatal, where the risk-benefit calculus shifts dramatically. The prion disease that shadows Sonia Vallabh, a researcher at the Broad Institute, is one. 
    • “Whichever way it goes, the gene therapy field has lost the assurance — already tenuous — that tests in animals can predict the toxicities for us. 
    • “In some way,” Vallabh said, “our only safety species is humans.”
  • The Wall Street Journal adds,
    • “Sanofi said its tolebrutinib drug candidate didn’t meet the primary goal in a late-stage clinical trial for multiple sclerosis. It separately said talks with the U.S. Food and Drug Administration had indicated a regulatory review for tolebrutinib in a different form of the disease would take longer than previously expected.
    • “The updates deal a blow to one of the most advanced drugs in Sanofi’s pipeline as the company seeks to move past recent disappointments in clinical trials. Sanofi has turned to dealmaking this year, using funds raised from the sale of a controlling stake in its consumer-healthcare business to replenish its pipeline.”

From the U.S. healthcare business front,

  • Fierce Healthcare reports,
    • “Highmark released its third quarter earnings report on Monday, where its top brass said the insurer expects to see elevated utilization trends persist into 2026.
    • “The Pittsburgh-based organization, which includes Highmark Health Plans and health system Allegheny Health Network, reported a $69 million net loss and a $204 million operating loss alongside $24.6 billion in revenue through the first nine months of 2025. The bulk of that loss came from the health insurance unit, which is continuing to be pressured by care use.
    • “Carl Daley, chief financial officer and treasurer at Highmark Health, told Fierce Healthcare that the company had expected utilization to normalize over the course of the year, and priced plans accordingly. It’s made adjustments in its pricing strategy for 2026 to adapt to the expectation that utilization remains high.”
  • MedTech Dive tells us,
    • “Philips has agreed to acquire SpectraWAVE, a firm making tools to help diagnose and guide treatment of coronary artery disease, the companies announced Monday. They did not disclose the terms of the deal.
    • “SpectraWAVE makes an intravascular imaging system for the coronary arteries. The Bedford, Massachusetts-based company also makes an AI-enabled solution that calculates fractional flow reserve from a single coronary angiogram to support treatment decisions. 
    • “Philips expects the acquisition will expand its portfolio of intravascular imaging and physiological assessment devices. CEO Roy Jakobs said in a statement that the company is “doubling down on image-guided therapy” and expanding its coronary intervention portfolio with the planned purchase.”
  • Cardiovascular Business adds,
    • “Ambulatory surgical centers (ASCs) and office-based labs (OBLs) are poised to play a growing role in cardiovascular care as payment policies shift and health systems look for more efficient ways to manage procedural volume. That trend, and the guardrails needed to ensure patient safety, was the focus of an educational session at TCT 2025 in San Francisco. 
    • “Cardiovascular Business spoke with one of the presenters, Arnold Seto, MD, cath lab director at the Long Beach VA Medical Center, professor of medicine at Charles Drew University, Society for Cardiovascular Angiography and Interventions (SCAI) treasurer and chair of the SCAI Advocacy Committee, to find out more.
    • “Seto said there is wide expectation that lower-acuity interventional cardiology and peripheral procedures will migrate into the ASC environment. This is partly due to better cost effectiveness and the fact that larger centers want to expand into more complex and structural heart procedures without building out their hospital cath labs to be bigger.
    • “The consultants tell us that as many as 25% to 50% of cardiology procedures will be migrating to the ASC environment. The government would prefer that because they pay about two-thirds of the hospital outpatient costs compared with an ASC reimbursement,” he said. He added that the Center of Medicare and Medicaid Services (CMS) is clearly signaling interest in this shift. “We’ve already seen CMS effectively remove all the PCI codes from the inpatient only list, and actually talk about removing everything from the inpatient only list.”
  • Per a Leapfrog news release,
    • “Today, The Leapfrog Group, a national watchdog organization of employers and other purchasers focused on health care safety and quality, announced the 2025 recipients for their elite annual Top Hospital Award and Top Ambulatory Surgery Center (ASC) Award. This national recognition is one of the most competitive honors U.S. hospitals and surgery centers can earn for excellence in patient safety and quality of care. Selected hospitals and ASCs will be celebrated today as part of Leapfrog’s 2025 Annual Meeting and Awards Dinner.” * * *
    • “The award honors hospitals and ASCs that demonstrate the highest performance in the nation on quality and patient safety, including ethical billing and informed patient consent procedures, lower infection rates, prevention of medication errors and surgical safety. To see the full methodology and list of institutions honored as 2025 Top Hospitals, please visit www.leapfroggroup.org/tophospitals. To see the full list of institutions honored as 2025 Top ASCs, please visit www.leapfroggroup.org/ratings-report/top-ascs.” 
  • Genetic Engineering and Biotechnology News points out,
    • “As Eli Lilly (NYSE: LLY) and Novo Nordisk (Nasdaq Copenhagen: NOVO-B) scramble to bring an oral glucagon-like peptide 1 (GLP-1) receptor agonist to market for obesity, a much smaller potential rival spotlighted positive mid-stage clinical data that captivated investors enough to send its share price more than doubling this past week.
    • “Structure Therapeutics (NASDAQ: GPCR) shares soared 102% after it reported positive data from its Phase II ACCESS clinical program assessing its oral GLP-1 candidate aleniglipron in people with obesity and/or overweight with at least one weight-related co-morbidity. Aleniglipron (formerly GSBR-1290) is designed to be a biased G protein-coupled receptor (GPCR) agonist, which selectively activates the G-protein signaling pathway.”
    • “If approved, Structure would compete with oral GLP-1s for weight management by the leading obesity drug developers, whose candidates could both win FDA approval in the new year.”
  • MedCity News notes,
    • “This Year’s Hottest Healthcare Company Isn’t Even a Healthcare Company
    • “Nvidia has quietly become one of the most influential players in healthcare technology by supplying the accelerated computing and AI infrastructure that powers everything from imaging to drug discovery. The company’s restraint — focusing on enabling the ecosystem rather than owning it — has helped cement its role as the indispensable backbone of the healthcare industry’s AI transformation.”

Cybersecurity Saturday

From the cybersecurity policy and law enforcement front,

  • Cyberscoop reports,
    • “The Defense Department would require that senior leaders have secure mobile phones, that personnel would get cybersecurity training that includes a focus on artificial intelligence and that cyber troops would have access to mental health services under a compromise annual defense policy bill released over the weekend.
    • The deal between House and Senate negotiators on the fiscal 2026 National Defense Authorization Act (NDAA) [reached last weekend] is a massive piece of legislation that runs the gamut of the Pentagon, including a record-breaking $901 billion topline figure. It also has a grab bag of cybersecurity policy provisions.”
  • Roll Call adds,
    • “Senate leaders plan for the chamber to vote next week to clear the bicameral compromise National Defense Authorization Act for President Donald Trump’s signature.
    • “As the fiscal 2026 bill edges closer to enactment, one of the few last-minute controversies shadowing it concerns whether the measure goes far enough to restrict military aircraft operations in close proximity to Ronald Reagan Washington National Airport.
    • “The Senate on Thursday [Decmber 11] voted 75-22 to take one procedural step closer to voting on the measure — agreeing to proceed to the legislation — which would authorize $900.6 billion for defense programs, mostly at the Pentagon.
    • “The chamber still plans to cast another procedural vote — set for Monday evening — and is expected to vote to clear the NDAA soon thereafter next week.
    • “The House passed the bill Wednesday [December 10} by a vote of 312-112.”
  • The American Hospital Association News tells us,
    • “The Cybersecurity and Infrastructure Security Agency Dec. 11 released an update to its voluntary Cybersecurity Performance Goals, which includes measurable actions for critical infrastructure, including health care. The update aligns with the latest cybersecurity standards outlined by the National Institute of Standards and Technology and addresses the most common and impactful threats facing critical infrastructure. The guidance also highlights the role of governance in cybersecurity management, emphasizing accountability, risk management and strategic integration of cybersecurity into day-to-day operations.” 
  • The HIPAA Journal relates,
    • “The College of Healthcare Information Management Executives (CHIME) and more than 100 U.S. hospital systems, healthcare provider organizations, and provider associations have called for the Department of Health and Human Services (HHS) to withdraw its proposed updates to the HIPAA Security Rule.
    • “The HIPAA Security Rule was enacted in 2002, nine years after HIPAA was signed into law, to establish security standards for electronic protected health information created, received, used, or maintained by a covered entity, with the requirements subsequently expanded to cover business associates of HIPAA-regulated entities. The Security Rule was written to be technology agnostic to avoid frequent rule changes in response to advances in technology; however, 22 years after its initial release, the HHS proposed a substantial update that specified many new cybersecurity requirements.” * * *
    • “While few healthcare industry stakeholders would disagree with the main purpose of the update – to improve healthcare cybersecurity and prevent costly and damaging cyberattacks that threaten patient safety – the proposed update attracted considerable criticism from healthcare and provider organizations. In February 2025, 8 industry associations, including CHIME, co-signed a letter to President Trump calling for the proposed update to be rescinded, pointing out that under the previous Trump administration, healthcare organizations were incentivized to adopt recognized cybersecurity best practices, and that was a better approach than imposing unreasonable cybersecurity mandates that would be costly and difficult to implement.
    • “In the December 8, 2025, joint stakeholder letter to HHS Secretary Robert F. Kennedy, Jr., the signatories called for the proposed update to be immediately withdrawn, and for the HHS to instead “conduct a collaborative outreach initiative with our organizations and other regulated entities that are impacted to develop practical and actionable cybersecurity standards for more robust protections of individuals’ health information, without the extreme and unnecessary regulatory burden that health care providers and other stakeholders would face under the crushing and unprecedented provisions of this Proposed Rule.”
  • Per a National Institute of Standards and Technology news release,
    • “NIST Special Publication (SP) 800-70r5 ipd (Revision 5, initial public draft), National Checklist Program for IT Products – Guidelines for Checklist Users and Developers, is now available for public comment through January 16, 2026, at 11:59 PM (EST).
    • “NIST established the National Checklist Program (NCP) to facilitate the generation of security checklists from authoritative sources, centralize the location of checklists, and make checklists broadly accessible. SP 800-70r5 ipd describes the uses, benefits, and management of checklists and checklist control catalogs, as well as the policies, procedures, and general requirements for participation in the NCP.”
  • Security Weeks informs us,
    • “The US government has announced rewards of up to $10 million for information on members of the Iranian hacking group known as Emennet Pasargad.
    • “The reward offers come roughly a year after a US-Israel joint advisory described the activities of the group, which was then identified by the name of its front company, Aria Sepehr Ayandehsazan (ASA).
    • “Noting that the group was previously identified as Emennet Pasargad, Ayandeh Sazan Sepehr Arya (ASSA), Eeleyanet Gostar, and Net Peygard Samavat Company, the US now calls it Shahid Shushtari.
    • “In the private sector, the threat group has been known as Cotton Sandstorm, Marnanbridge, and Haywire Kitten.”
  • Cyberscoop adds,
    • “The Justice Department has charged a Ukrainian national with conducting cyberattacks on critical infrastructure worldwide as part of two Russian state-sponsored hacking operations that targeted water systems, food processing facilities and government networks across the United States and allied nations.
    • “Victoria Eduardovna Dubranova, 33, was arraigned on a second indictment Tuesday [December 9] after being extradited to the U.S. earlier this year. She faces charges related to her alleged work with CyberArmyofRussia_Reborn, known as CARR, and NoName057(16), two groups federal prosecutors say received backing from Moscow to advance Russian geopolitical interests. 
    • “Dubranova pleaded not guilty in both cases.”

From the cybersecurity breaches and vulnerabilities front,

  • Bleeping Computer reports,
    • “MITRE has shared this year’s top 25 list of the most dangerous software weaknesses behind over 39,000 security vulnerabilities disclosed between June 2024 and June 2025.
    • “The list was released in cooperation with the Homeland Security Systems Engineering and Development Institute (HSSEDI) and the Cybersecurity and Infrastructure Security Agency (CISA), which manage and sponsor the Common Weakness Enumeration (CWE) program.
    • “Software weaknesses can be flaws, bugs, vulnerabilities, or errors found in a software’s code, implementation, architecture, or design, and attackers can abuse them to breach systems running the vulnerable software. Successful exploitation allows threat actors to gain control over compromised devices and trigger denial-of-service attacks or access sensitive data.
  • Cyberscoop relates,
    • “Security experts have observed a steady increase in malicious activity from a widening pool of attackers seeking to exploit React2Shell, a critical vulnerability disclosed last week in React Server Components.
    • “Authorities are also responding to heightened concern about the defect, with the Cybersecurity and Infrastructure Security Agency shortening the deadline for agencies to patch the vulnerability to Friday [December 12] . The agency previously set a deadline of Dec. 26 when it added CVE-2025-55182 to its known exploited vulnerabilities catalog last week.
    • “Palo Alto Networks Unit 42 said more than 50 organizations are impacted by attacks involving exploitation of the vulnerability with victims observed in the United States, Asia, South America and the Middle East.” 
  • Cybrsecurity Dive adds,
    • “React on Thursday [December 11] warned that customers will need to apply new upgrades amid the React2Shell crisis, after researchers discovered additional vulnerabilities, including a denial of service flaw and a source code exposure. 
    • “A denial of service vulnerability, tracked as CVE-2025-55184 and CVE-2025-67779, allows an attacker to craft a malicious HTTP request and send it to a Server Functions endpoint, which can lead to an infinite loop. The flaw has a severity score of 7.5. 
    • “The source code exposure, tracked as CVE-2025-55183, allows a malicious HTTP request sent to a vulnerable Server Function to unsafely return the source code of any Server Function.”
  • The American Hospital Association News lets us know,
    • “U.S. and international agencies are warning of potential cyberattacks on health care and other critical infrastructure from state-sponsored cyber actors in Russia and China.
    • “An advisory released yesterday [December 11] warns of incidents by Russian hackers using internet-facing desktop-sharing systems to access operational technology and industrial control systems for malicious activity. A Dec. 4 report warns of Chinese state-sponsored cyber actors using BRICKSTORM malware to attack VMware vSphere and Windows cloud platforms.
    • “These nation-state level threats may be difficult for civilian network defenders to counter,” said John Riggi, AHA national advisor for cybersecurity and risk. “However, robust cyber threat information sharing between the private sector and the federal government, implementation of recommended practices, and the commendable and aggressive enforcement operations by the FBI and other agencies will help mitigate the threat. Organizations should also update, integrate and routinely test emergency preparedness, cyber incident response and clinical continuity plans should there be an extended technology outage affecting hospitals directly or indirectly through a cyberattack against mission-critical third parties.”
  • CISA added seven known exploited vulnerabilities to its catalog this week.
    • December 8, 2025
      • CVE-2022-37055 D-Link Routers Buffer Overflow Vulnerability
      • CVE-2025-66644 Array Networks ArrayOS AG OS Command Injection Vulnerability
        • Cyber Press discusses the D-Link KVE here
        • F5 discusses the Array Networks KVE here.
    • December 9, 2025,
      • CVE-2025-6218 RARLAB WinRAR Path Traversal Vulnerability
      • CVE-2025-62221 Microsoft Windows Use After Free Vulnerability 
        • Cybersecurity News discusses the RARLAB KVE here.
        • Bleeping Computer discusses the Microsoft KVE here.
    • December 11, 2025
      • CVE-2025-58360 OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability 
        • Bleeping Computer discusses this KVE here.
    • December 12, 2025
      • CVE-2025-14174 Google Chromium Out-of-Bounds Memory Access Vulnerability
        • The Hacker News discusses this KVE here.
    • December 12, 2025 (double shot day, not a typo)
      • CVE-2018-4063 Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability
        • Windows Forum discusses this KVE here
  • Bleeping Computer adds,
    • “Apple has released emergency updates to patch two zero-day vulnerabilities that were exploited in an “extremely sophisticated attack” targeting specific individuals.
    • “The zero-days are tracked as CVE-2025-43529 and CVE-2025-14174 and were both issued in response to the same reported exploitation.
    • “Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26,” reads Apple’s security bulletin.”
  • Cybersecurity Dive notes,
    • “Utility-scale battery energy storage systems are facing heightened risks of attack from nation-state and criminal threat groups, and immediate action needs to be taken to secure critical industries from potential disruption, according to a white paper from Brattle Group and Dragos. 
    • BESS deployments are expected to grow between 20% and 45% over the next five years, driven by increased demand for data centers and other power requirements. At the same time, state-linked actors have turned their attention toward disrupting critical industries, such as utilities and rival nations competing with the U.S. for dominance in AI and clean energy.”
  • Per Infosecurity Magazine,
    • “A new iteration of the ClayRat Android spyware featuring expanded surveillance and device-control functions has been identified by cybersecurity researchers.
    • First seen in October, ClayRat was originally capable of stealing SMS messages, call logs and photos, as well as sending mass texts.
    • “The latest version introduces far broader capabilities by combining Default SMS privileges with extensive abuse of Accessibility Services.”

From the ransomware front,

  • Cybersecurity Dive reports,
    • “Ransomware activity reached an all-time high in 2023, totaling more than 1,500 incidents and $1.1 billion in reported payments, before dropping the following year after two high-profile law enforcement takedowns.
    • “The two critical law enforcement actions were the 2023 U.S.-led takedown of AlphV/BlackCat and the 2024 disruption of LockBit by U.S. and U.K. authorities, according to a new U.S. government study.
    • “The report by the U.S. Treasury’s Financial Crimes Enforcement Networkshows ransomware fell to 1,476 incidents in 2024, with reported payments reaching $734 million. 
    • ‘More than $2.1 billion in ransomware payments were reported between 2022 and 2024, according to the report. 
    • “The medium amount of a single ransomware transaction rose from $122,097 in 2022 to $155,257 in 2024, according to the report. The most common payment amount was less than $250,000 during the period. 
    • ‘AlphV/BlackCat was the most prevalent ransomware variant during the 2022–2024 period, according to the report. The other most reported variants included Akira, LockBit, Phobos and Black Basta.” 
  • Dark Reading adds,
    • “You may be familiar with ransomware-as-a-service (RaaS), but now there’s also packer-as-a-service.
    • “Security vendor Sophos on Dec. 6 published research on “Shanya,” a packer-as-a-service family that augments ransomware so it can avoid anti-malware software. While ransomware-as-a-service provides low-level attackers with extortion malware they might not be able to create otherwise, packers-as-a-service (PaaS) provide a shell around pre-existing ransomware that acts as an extra layer of obfuscation.
    • “Shanya covers ground previously paved by PaaS operation HeartCrypt, which over the past year has firmly entrenched itself in the modern ransomware ecosystem. Sophos’ Gabor Szappanos and Steeve Gaudreault say Shanya is “already favored by ransomware groups and taking over (to some degree) the role that HeartCrypt has played in the ransomware toolkit.”
  • and
    • “Initial access broker Storm‑0249 has shifted from noisy, easily detected phishing attacks to highly targeted campaigns that are much harder to detect and stop. 
    • “According to ReliaQuest, Storm-0249, which is known for brokering network access to ransomware operators, is increasingly weaponizing legitimate endpoint detection and response (EDR) processes as well as built-in Windows utilities to carry out post-compromise activities. This includes poking around compromised systems to gather information, setting up command-and-control (C2) channels, and staying persistent in the environment. These new tactics let Storm‑0249 slip past defenses, get deep into networks, and operate almost completely under the radar, the security vendor said.”
  • and
    • “A new attack uses SEO poisoning and popular AI models to deliver infostealer malware, all while leveraging legitimate domains. 
    • ClickFix attacks have gained significant popularity over the past year, using otherwise benign CAPTCHA-style prompts to lure users into a false sense of security and then tricking them into executing malicious prompts against themselves. These prompts are often delivered through SEO poisoning and phishing campaigns, representing one of the fancier applications of social engineering in cybercrime to date.” 
  • The Register points out,
    • “Researchers at security software vendor Huntress say they’ve noticed a huge increase in ransomware attacks on hypervisors and urged users to ensure they’re as secure as can be and properly backed up.
    • “Huntress case data revealed a stunning surge in hypervisor ransomware: its role in malicious encryption rocketed from just three percent in the first half of the year to 25 percent so far in the second half,” wrote Senior Hunt & Response Analyst Anna Pham, Technical Account Manager Ben Bernstein, and Senior Manager for Hunt & Response, Dray Agha in a Monday [December 8] post.
    • “The primary actor driving this trend is the Akira ransomware group,” the trio warned, adding that the gang, and other attackers, are going after hypervisors “in an attempt to circumvent endpoint and network security controls.”

From the cybersecurity business and defenses front,

  • Security Week reports,
    • “Enterprise cybersecurity giant Proofpoint has completed the acquisition of Germany-based Microsoft 365 security solutions provider Hornetsecurity.
    • “Financial details were not officially disclosed when news of the transaction came to light, but it was reported that Proofpoint would be paying $1 billion for its European competitor. SecurityWeek learned at the time that the deal size well exceeded $1 billion.
    • Proofpoint has now revealed that the transaction has been valued at $1.8 billion. 
    • “Through the acquisition of Hornetsecurity, Proofpoint is aggressively expanding its reach into the SMB market and strengthening its foothold in Europe.”
  • Info Bank Security adds,
    • “An identity security stalwart led by the company’s longtime founder raised $700 million to support the management of non-human identities and agentic artificial intelligence.
    • “Los Angeles-based Saviynt plans to use the Series B proceeds to invest in core platform capabilities, AI governance protocols and deep integrations with the likes of AWS, Google and CrowdStrike, said Saviynt President Paul Zolfaghari. What was once about on premise human access is now a multidimensional challenge involving extended workforces, robotic accounts and AI-driven agents, Zolfaghari said.
    • “It was an opportunity to put in place the resources necessary to deliver on the vision for the future. The interest in identity security and AI has gone up quite a bit,” he said. “The amount is just a function of the resources that we think that we need for the foreseeable future. It’s an opportunity for us to have the resources we need while still maintaining the control and the culture that has gotten us to this point.”
  • Cyberscoop relates,
    • “Global cybersecurity agencies have issued the first unified guidance on applying artificial intelligence (AI) within critical infrastructure, signaling a major shift from theoretical debate to practical guardrails for safety and reliability.
    • “The release of joint guidance on Principles for the Secure Integration of Artificial Intelligence in Operational Technology marks a meaningful milestone for critical infrastructure security because major global cybersecurity agencies, including CISA, the FBI, the NSA, the Australian Signals Directorate’s Australian Cyber Security Centre, and other partners, have aligned on a shared direction. As AI adoption accelerates across operational environments, this document moves us from theory to practice. It acknowledges AI’s promise while making clear that it also “introduces significant risks—such as operational technology (OT) process models drifting over time or safety-process bypasses” that operators must actively manage to ensure reliability.”
  • Here is a link to Dark Reading’s CISO Corner.

Friday report

From Washington, DC,

  • The Washington Post reports,
    • “House Republicans unveiled a new health care proposal Friday as they aim to address concerns about rising health insurance costs just weeks before enhanced Affordable Care Act subsidies expire.
    • “The legislation would codify and expand health plans for small businesses, fund reductions of premiums for low-income people in the individual health insurance market and increase transparency in prescription drug pricing, according to House Republican leadership aides.
    • “The proposal would also allow for a separate vote on an extension of the premium ACA tax credits, which subsidize health insurance for most of the 24 million Americans who buy their coverage from the Obamacare Marketplace — the central demand Democrats and moderate Republicans have made in the recent health care debate.
    • “The House is expected to vote on the proposal next week before leaving Washington for a two-week holiday break. If passed, it is unclear if the proposal could succeed in the Senate, where it would require 60 votes to overcome a filibuster.”
  • FEHBlog observation — This week, the Democrat leadship in the Senate offered a three year extension extension of the Biden subsidies while the Republican leadership offered a new approach with no transistion period. Both offerings were doomed to fail. The FEHBlog hopes that cooler heads prevail over the next week.
  • Govexec relates,
    • “The House voted 231-195 on Thursday to pass legislation that would nullify President Trump’s efforts to strip more than 1 million federal workers of their collective bargaining rights, sending the measure over to the Senate, where its prospects are less rosy.
    • “Twenty Republican lawmakers broke ranks to support the Protect America’s Workforce Act (H.R. 2550) on the floor. Introduced by Reps. Jared Golden, D-Maine, and Brian Fitzpatrick, R-Pa., the measure effectively nullifies Trump’s March executive order barring unions at more than 40 federal agencies under the guise of national security and bars federal agencies from terminating any union contracts that were in place prior to the edict’s signature.”
  • The American Hospital Association News lets us know,
    • “The Centers for Medicare & Medicaid Services Dec. 11 announced the launch of the Make America Healthy Again: Enhancing Lifestyle and Evaluating Value-based Approaches Through Evidence Model, a voluntary payment model that will fund up to 30 chronic disease prevention and health promotion proposals. The proposals must include evidence-based functional or lifestyle medicine interventions not covered by Original Medicare. Under the MAHA ELEVATE Model, CMS said it will evaluate necessary data on the cost and quality of such interventions to inform future decisions on the feasibility of including them in Original Medicare. The agency will release a funding notice in early 2026 for the first cohort, which will begin Sept. 1, 2026. The second cohort will begin one year later.”
  • The U.S. Office of Personnel Management announced today that it is seeking public comments on its plan to resurrect its FEHB and now also PSHB health claims data warehouse.
    • “OPM is collecting service use and cost data from FEHB and PSHB Carriers, including medical claims, pharmacy claims, encounter data, and provider data. This data will enable OPM to oversee health benefits programs and ensure they provide competitive, quality, and affordable plans. OPM requires Carriers to report necessary information and permit audits and examinations to manage the FEHB Program effectively. The Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule permits covered entities, including carriers, to disclose protected health information (PHI), including service use and cost data, to health oversight agencies, such as OPM, for oversight activities authorized under 45 CFR 165.512(d)(1).”
    • This is a legally flawed analysis. The FEHB Act, 5 U.S.C. Sec. 8910(b), states
      • “(b) Each contract entered into under section 8902 of this title shall contain provisions requiring carriers to—
      • (1) furnish such reasonable reports as the Office determines to be necessary to enable it to carry out its functions under this chapter; and
      • (2) permit the Office and representatives of the Government Accountability Office to examine records of the carriers as may be necessary to carry out the purposes of this chapter.”
    • Furnishing all claims data to OPM is a not a reasonable report in any sense of the English language, and the HIPAA Privacy Rule does not give health oversight agencies new data access rights. See Fed. Reg. 82,462, 82,528 (Dec. 28, 2000). OPM should head back to the drawing board for consultations with carriers.
    • The public comment deadline is February 10, 2026.
  • On a related note, per a CMS news release,
    • “The Centers for Medicare & Medicaid Services (CMS) is pleased to announce the 2026 CMS Burden Reduction Conference taking place February 25, 2026, from 9:00 a.m. to 1:00 p.m. ET. This year’s conference will be a hybrid event, with in-person programming at the Hubert H. Humphrey (HHH) Building in Washington, DC, and a fully supported virtual option for remote attendees. In-person attendance will be limited due to space.”
  • OPM should hold a similar event for overburdened FEHB and PSHB carriers.

From the Food and Drug Adminstration front,

  • Per Fierce Pharma,
    • “Amid a swell of regulatory successes in the myasthenia gravis arena this decade, Amgen is wading into the fray with a new indication for its monoclonal antibody Uplizna.
    • “Thursday, the FDA greenlighted Uplizna (inebilizumab) to treat generalized myasthenia gravis (gMG) in adults who are anti-acetylcholine receptor (AChR) and anti-muscle specific tyrosine kinase (MuSK) antibody positive. After two loading doses, Uplizna for gMG is administered just twice a year, Amgen noted in a Dec. 11 press release.”
  • and
    • “After a three-decade drought of new antibiotics to treat gonorrhea, the FDA has signed off on two first-in-class oral treatments for the sexually transmitted infection (STI), which affects more than 80 million people around the world each year. 
    • “On Friday, the U.S. regulator green lit Innoviva’s Nuzolvence (zoliflodacin) for uncomplicated urogenital gonorrhea. The nod comes less than 24 hours after the agency granted an approval in the same indication to GSK’s Blujepa, which was already on the market for uncomplicated urinary tract infections following its approval in March.
    • “The endorsements are similar in that both therapies are indicated for those ages 12 and older where standard of care treatment is contraindicated or where patients are intolerant or unwilling to use the first line of treatment.”
  • Cardiovascular Business tells us,
    • “The U.S. Food and Drug Administration (FDA) has granted 510(k) market clearance to the enVast mechanical thrombectomy system from Texas-based Vesalio.
    • “The company said the system offers a new approach to clot capture and the removal of large thrombus burden (LTB) in patients undergoing primary percutaneous coronary intervention (PCI). Thrombectomy is used in the coronary arteries to quickly remove clots to restore blood flow following a heart attack to minimizing myocardial damage.
    • “With FDA clearance and the upcoming U.S. launch of enVast, we are proud to introduce a device that we truly believe redefines coronary thrombectomy,” Steve Rybka, CEO of Vesalio, said in a statement. “Clinical experience internationally has consistently demonstrated its safety and effectiveness in managing complex LTB situations.”

From the public health and medical / Rx research front,

  • The Centers for Disease Control and Prevention announced today,
    • “RSV activity is increasing in the Southeastern, Southern, and Mid-Atlantic areas of the country with emergency department visits and hospitalizations increasing among children 0-4 years old. Seasonal influenza activity continues to increase in most areas of the country. COVID-19 activity is low nationally.
    • “COVID-19
      • “COVID-19 activity is low nationally.
    • “Influenza
    • “RSV
      • “RSV activity is increasing in the Southeastern, Southern, and Mid-Atlantic areas of the country with emergency department visits and hospitalizations increasing among children 0-4 years old.
    • “Vaccination
      • “It is not too late to get vaccinated ahead of the holidays. Talk to your doctor or trusted healthcare provider about what vaccines are recommended for you and your family.”
  • The American Hospital Association News adds,
    • “The Centers for Disease Control and Prevention Dec. 11 released a report that found last year’s version of the COVID-19 vaccine was 76% effective in preventing emergency department or urgent care visits for children ages 9 months to 4 years. It was 56% effective for those ages 5-17 years old. “These findings suggest that vaccination with a 2024–2025 COVID-19 vaccine dose provided children with additional protection against COVID-19–associated ED/UC encounters compared with no 2024–2025 dose,” the CDC wrote.”
  • The New York Times reports,
    • “To treat their pain, anxiety and sleep problems, millions of Americans turn to cannabis, which is now legal in 40 states for medical use. But a new review of 15 years of research concludes that the evidence of its benefits is often weak or inconclusive, and that nearly 30 percent of medical cannabis patients meet criteria for cannabis use disorder.
    • “The evidence does not support the use of cannabis or cannabinoids at this point for most of the indications that folks are using it for,” said Dr. Michael Hsu, an addiction psychiatrist and clinical instructor at the University of California, Los Angeles, and the lead author of the review, which was published last month in the medical journal JAMA. (Cannabis refers to the entire plant; cannabinoids are its many compounds.)”
  • The AP informs us,
    • “The U.S. suicide rate dropped slightly last year from some of the highest levels ever reported, preliminary data suggests. Experts say it’s hard to know exactly why, or whether the decline will continue.
    • “A little over 48,800 suicide deaths were reported in 2024, according to provisional data from the Centers for Disease Control and Prevention, roughly 500 fewer than the year before.
    • “The overall suicide rate fell to 13.7 per 100,000 people.”
  • The Washington Post relates,
    • “Solving a technical challenge that has stymied science for 40 years, researchers have built a robot with an onboard computer, sensors and a motor, the whole assembly less than 1 millimeter in size — smaller than a grain of salt.
    • “The feat, accomplished by a partnership of researchers at the University of Pennsylvania and University of Michigan, advances medicine toward a future that might see tiny robots sent into the human body to rewire damaged nerves, deliver medicines to precise areas, and determine the health of a patient’s cells without surgery.”
  • Per Healio,
    • “GLP-1 receptor agonists are not associated with increased risks for dry age-related macular degeneration or cataract development, according to two recently published studies.
    • “The data instead showed significantly reduced risk for cataracts, as well as lower risk for dry AMD, linked with the use of GLP-1s, according to Abhimanyu Ahuja, MD, an ophthalmology resident at the Oregon Health & Science University Casey Eye Institute, and colleagues.
    • “Other studies have demonstrated that these medications have anti-inflammatory and neuroprotective properties,” Ahuja told Healio. “We wondered whether they might influence the risk of conditions like macular degeneration or cataracts in older adults.”
  • Per MedTech Dive,
    • “AtriCure, whose devices are used to treat atrial fibrillation and related conditions, said Thursday the first procedures were performed in patients with its new dual energy platform.
    • “The system integrates pulsed field ablation with a radiofrequency ablation approach using the company’s cardiac clamp technology. Surgeons can use either method independently or in combination.
    • “The platform is not yet approved for use in any market. AtriCure said it expects to initiate a clinical trial in the coming year.”
  • Per Biopharma Dive,
    • “Arcus Biosciences will terminate work on a TIGIT-targeting cancer drug following a decision to cancel a Phase 3 trial because it didn’t appear likely to improve patients’ survival, the company said in a statement Friday.
    • “Called domvanalimab, the drug was being tested in combination with the immunotherapy zimberelimab and chemotherapy against Bristol Myers Squibb’s Opdivo and chemo in gastric and esophageal cancers that haven’t been treated before. Arcus said an independent data committee recommended ending the trial because the domvanalimab combination wasn’t likely to help patients live longer.
    • “The domvanalimab-based combination was the centerpiece of a partnership with Gilead Sciences that led the bigger company to buy a 33% stake in Arcus and pay $900 million just to secure rights.”

From the U.S. healthcare business and artificial intelligence front,

  • Healthcare Dive reports,
    • “Hospitals are managing series of cost, workforce and reimbursement challenges as they navigate uncertainty at the close of 2025 and beyond, according to a new report from Kaufman Hall.
    • “Health systems are attempting to mitigate the impact of tariffs and increasingly expensive supplies, according to Kaufman Hall’s 2025 Health System Performance Outlook report. At the same time, hospitals are trying to retain clinical staff and outsource other functions, according to the report.
    • “Only 30% of hospital leaders surveyed expect balance sheets to improve in 2026, while 30% expect them to lower and 40% projected little change. The split highlights how uncertain health systems feel about the future, especially from recent regulatory changes in the “Big Beautiful Bill” and the likely expiration of Affordable Care Act subsidies.”
  • Beckers Hospital Review relates,
    • “Dallas-based Tenet Healthcare reached a record high stock price of $218 on Nov. 25, capping off a transformative year that highlights investor confidence in the system’s ongoing shift toward specialty and outpatient care.
    • “As of Dec. 12, Tenet stock remained elevated at $199, up nearly 60% from $125 on Jan. 2. The spike reflects investor optimism around Tenet’s long-term strategy to transform into a value-based care enterprise anchored by its ambulatory business, United Surgical Partners International.
    • “In 2024, Tenet sold 14 hospitals for a combined $4.8 billion as part of a sweeping overhaul. The system now operates 50 acute-care hospitals while aggressively expanding its ambulatory surgery center footprint through USPI.”
  • Beckers Payer Issues tells us about 14 payer AI moves this year and “Turquoise Health has detailed its first comprehensive payer price transparency scores in its 2025 impact report, evaluating machine-readable file quality across 97 payers.” 

Tuesday report

From Washington, DC,

  • MedPage Today reports,
    • “The number of Americans signing up for Affordable Care Act (ACA) health insurance for 2026 is moderately higher than it was at a similar time last year, initial new federal data show, even as subsidies set to expireopens in a new tab or window at the end of 2025 will make the coverage more expensiveopens in a new tab or window for many.
    • “Seen at face value, the data from the Centers for Medicare and Medicaid Services seem to defy predictions that many Americans facing pricier plans would drop out of marketplace coverage altogether next year. But experts caution that the numbers are an incomplete snapshot of total enrollment, which could still show a decline by the end of the open enrollment period.
    • “Overall, it’s just too early to know what any of this means,” said Jason Levitis, a senior fellow in the health policy division at the Urban Institute.
    • “The data released Friday show that by day 29 of the window for Americans to shop for ACA plans this year, nearly 5.8 million people had picked one. That’s nearly 400,000 more enrollments than by day 30 of the open enrollment period last year.
    • Meanwhile, this year’s enrollment numbers are about 1.5 million lower than the 7.3 million or so people who had signed up 32 days into the open enrollment period 2 years ago, showing there is some fluctuation year to year in when people sign up for coverage.
    • “In most states, for Americans who want coverage to start Jan. 1, the window to shop for ACA coverage began Nov. 1 and ends Dec. 15. People who want their coverage to start later can continue to select plans through Jan. 15.”
  • The Wall Street Journal adds,
    • “Senate Majority Leader John Thune (R., S.D.) said he would hold a vote later this week on a Republican measure aimed at controlling healthcare costs, amid party division over how best to head off big price increases next year for millions of households.
    • “Thune said Republicans have coalesced around legislation from Sens. Bill Cassidy (R., La.) and Mike Crapo (R., Idaho) [discussed in yesterday’s FEHBlog post] that would put as much as $1,500 a year into tax-advantaged health savings accounts when paired with lower-priced insurance plans in 2026 and 2027. The proposal doesn’t extend enhanced Affordable Care Act subsidies, which are due to expire after this year.
    • “The measure aims to provide an alternative to a Democratic proposal that extends the ACA subsidies for three more years. Votes on the two plans in the GOP-controlled Senate are set for Thursday, as Thune follows through on a promise made to Democrats as a condition for ending the government shutdown last month.
    • “So there will be something out there that Republicans will be able to talk about and support and vote for, and then we’ll see what happens Thursday,” Thune said. If neither proposal gets the 60 votes required to advance in the Senate, he said, “then we’ll see where it goes from there.”
  • Per a Senate news release,
    • “U.S. Senator Bill Cassidy, M.D. (R-LA), chair of the Senate Health, Education, Labor, and Pensions (HELP) Committee, is seeking information from stakeholders regarding the American Medical Association’s (AMA) monopoly of Current Procedural Terminology (CPT®) codes and its impact on patients, providers, and health care costs. Cassidy is asking stakeholders with relevant experience and knowledge of CPT ® coding contracts with the AMA to inform the Committee’s inquiry by responding to this questionnaire.
    • “As chair of the HELP Committee, Cassidy is using all tools at his disposal to lower costs for American patients. Thus far, the AMA evaded questions and failed to cooperate with Cassidy’s inquiry. If the AMA does not respond in a fulsome and transparent manner by December 15, 2025, the Chairman is committed to finding answers by other means.
    • “The federal government mandated the use of CPT codes. This creates the potential for abuse in that if someone has to buy your product, you can charge them what you want,” said Dr. Cassidy. “There may be nothing wrong here, but we should get answers to make sure the CPT system is working for the American patient and for the American health care system.”
  • Beckers Hospital Review tells us,
    • “Nearly 4 million Medicare-eligible Americans face heightened risk of disrupted medication access as restructuring efforts by the U.S. Postal Service slow mail delivery in rural and underserved communities reliant on mail-order prescriptions, according to a Dec. 4 analysis from The Brookings Institution
    • “In 2024, USPS launched its Regional Transportation Optimization initiative, which consolidates mail processing into regional hubs. While the initiative aims to improve efficiency, early analyses suggest it has exacerbated delivery slowdowns in rural areas, according to the report.”
  • The American Hospital Association News informs us,
    • “The Centers for Medicare & Medicaid Services Dec. 9 issued a proposed rule that would make changes to the Increasing Organ Transplant Access Model beginning July 1, 2026. IOTA is a six-year mandatory model for certain kidney transplant hospitals that began July 1 of this year. To comply with statutory requirements, CMS proposes to modify the eligible kidney transplant hospital criteria to exclude Department of Veterans Affairs medical facilities and military medical treatment facilities. The agency also proposes to raise the low-volume threshold from 11 kidney transplants performed annually during each of the baseline years to 15. Regarding IOTA participant performance, CMS proposes updates to the composite graft survival rate metric, including adding a risk-adjustment methodology that includes several transplant recipient and donor characteristics. In addition, CMS proposes other policy changes related to repayments, the extreme and uncontrollable circumstances policy, transparency and public posting of information, voluntary health equity plans, beneficiary protections, monitoring activities, and remedial actions and termination.” 
  • Modern Healthcare relates,
    • “Health insurance companies spent two years getting ready for a new Medicare Advantage quality metric intended to tackle health disparities. Then the government pulled the plug.
    • “The Excellent Health Outcomes for All measure — also known as EHO4All and formerly known as the health equity index— likely won’t be part of the Medicare Advantage Star Ratings program in 2027 after all, the Centers for Medicare and Medicaid proposed in a draft regulation last month.
    • “It’s a mixed bag for the insurance sector. In conjunction with implementing EHO4All, CMS also planned to scrap the Star Ratings program’s so-called reward factor, which benefits companies that demonstrate high quality scores over multiple years. But other companies stood to gain from an emphasis on health equity. 
    • “Moreover, the industry at large carried out intensive preparations to boost their performance on EHO4All measures, which were intended to boost insurers that cover large numbers of beneficiaries who qualify for both Medicare and Medicaid, are eligible for low-income subsidies, or have disabilities.”

From the Food and Drug Administration front,

  • Beckers Hospital Review reports,
    • “The FDA has launched a safety review of approved respiratory syncytial virus therapies for infants, including Beyfortus from Sanofi and AstraZeneca and Enflonsia from Merck, Reuters reported Dec. 9.
    • “Senior executives from the three companies were informed last week that the agency would seek further data on the therapies following internal concerns raised by FDA officials appointed under Health and Human Services Secretary Robert F. Kennedy Jr. Tracy Høeg, MD, PhD, recently namedacting director of the FDA’s Center for Drug Evaluation and Research, initiated the safety inquiry over the summer. As a noted vaccine skeptic, the appointment of Dr. Høeg has raised serious concerns among healthcare experts.”
  • Bloomberg Law lets us know,
    • “The FDA’s effort to curb high drug costs by accelerating approvals of cheaper medicines similar to expensive biologics will need other policy reforms to boost access to the biosimilars, drug pricing experts say. 
    • “The Food and Drug Administration is seeking to lower drug costs by simplifying the development of biosimilars, products that are highly similar to FDA-approved biologics, have no clinically meaningful differences, and can treat patients the same way. Biologics, such as AbbVie Inc.‘s blockbuster treatment Humira for rheumatoid arthritis and Merck & Co.‘s cancer medicine Keytruda, are complex drugs made from sources such as plant or animal cells. 
    • “Biosimilars are often available at a lower cost compared to biologics. While insurance varies for patients, the list price of Humira can run above $6,000 a dose. Amgen Inc.‘s Amjevita, a biosimilar to the inflammatory drug, can be purchased at either 55% or 5% below Humira’s list price.
    • “The FDA action, however, might not immediately yield patient access to the cheaper medicines without reforming other policies that seek to make biosimilars available upon approval, drug pricing experts say. Biosimilars often face hurdles before hitting the market, frequently due to patent litigation, agreements between drug companies to defer entry, and how they’re treated in health insurers’ prescription drug plans.”
  • Per an FDA news release,
    • “The U.S. Food and Drug Administration today approved Augmentin XR (amoxicillin-clavulanate potassium) under the Commissioner’s National Priority Voucher (CNPV) pilot program, marking the first approval achieved through this review pathway. The approval was completed in just two months, representing a major reduction of the review timeline for this type of application.
    • “Over the last few decades, America lost control of supply chains for key medicines we depend on. That chapter is over – we’re entering a new era of manufacturing here at home,” said FDA Commissioner Marty Makary, M.D., M.P.H. “This first drug approval under the CNPV pilot program will strengthen domestic manufacturing and increase our national security.”
    • “The Augmentin XR application demonstrated clear alignment with the CNPV program’s national health priorities by strengthening the U.S. drug supply chain through enhanced domestic manufacturing capacity at a U.S. facility. This approval will also help address antibiotic shortages in the U.S. that have plagued the healthcare system over the past two decades.”
  • and
    • “The U.S. Food and Drug Administration today approved Waskyra (etuvetidigene autotemcel), the first cell-based gene therapy for the treatment of Wiskott-Aldrich syndrome (WAS). Waskyra is indicated for pediatric patients six months and older and adults with WAS who have a mutation in the WAS gene and for whom hematopoietic stem cell transplantation (HSCT) is appropriate and no suitable human leukocyte antigen (HLA)-matched related stem cell donor is available.
    • “Today’s approval is a transformative milestone for patients with Wiskott-Aldrich syndrome, offering the first FDA-approved gene therapy that uses the patient’s own genetically corrected hematopoietic stem cells to treat the disease,” Vinay Prasad, M.D., M.P.H., Chief Medical and Scientific Officer and Director of the FDA’s Center for Biologics Evaluation and Research. “The FDA continues to exercise flexibility in the regulatory approach for rare diseases by considering all available data sources, including as appropriate data from expanded access programs, to facilitate the advancement of life-changing treatments while ensuring scientific requirements are satisfied.”
  • Per MedTech Dive,
    • “Sometimes, the line between medical and wellness products can blur. Regulators’ pushback on a blood pressure feature that Whoop incorporated into its wellness wristband illustrates the challenges wearables developers face as they add increasingly sophisticated features.
    • “Whoop received a warning letter from the Food and Drug Administration this summer after rolling out the blood pressure offering without regulatory authorization.
    • “The company has pushed back on the warning letter, however, arguing that blood pressure is a wellness feature. The FDA disagreed, saying blood pressure is inherently related to a medical diagnosis. 
    • “The FDA isn’t likely to concede on its challenge, experts said. Whoop’s skirmish with the FDA offers lessons on where to draw the line between wellness and medical features.”

From the judicial front,

  • Bloomberg Law reports,
    • “The US Justice Department is weighing a challenge to a deal between two of the largest companies offering software to small, independent pharmacies, as antitrust enforcers step up their focus on the health-care industry.
    • “The deal, which the companies didn’t publicly announce, involves the acquisition ofMicro Merchants Systems, the operator of pharmacy management software platform PrimeRx, by RedSail Technologies, said the people, who asked not to be named discussing a confidential matter. Micro Merchants is backed by TA Associates Management, while RedSail is the result of multiple acquisitions backed by investment firms including Francisco Partners. 
    • “Representatives of the companies met with DOJ antitrust chief Gail Slater in late November, said the people. Such meetings indicate significant government opposition to a deal, although they don’t always precede a federal lawsuit if the companies are able to make proposals that allay the agency’s concerns. Companies submit confidential filings to US authorities as part of a merger review process.”
  • STAT News relates,
    • “In a closely watched case, the U.S. solicitor general has urged the Supreme Court to review a controversy over so-called skinny labels for medicines, arguing that an appeals court finding threatens the availability of lower-cost generic drugs.
    • “Skinny labeling refers to a process in which a generic drug company seeks regulatory approval to market its medicine for a specific use, but not other patented uses for which a brand-name drug is prescribed. For instance, a generic drug could be marketed to treat one type of heart problem, but not another. In doing so, the generic company seeks to avoid lawsuits claiming patent infringement.” * * *
    • “Doubts were raised about the maneuver, however, when the Supreme Court two years ago declined to hear an appeal of a lower court ruling, which questioned the practice. Now, this second case is being seen as a test for whether skinny labeling can survive as a way for generic companies to market medicines, according to legal experts following the issue.”
  • The Wall Street Journal brings us to date on Luigi Mangione’s evidence hearing in New York state court.

From the public health and medical / Rx research front,

  • ABC News reports,
    • “Concerns about the flu spreading in the U.S. are growing as the U.K. continues to see a spike in cases among children and young adults.
    • “The increased number of cases in the U.K., could be a predictor for the flu season in the U.S., according to ABC News chief medical correspondent Dr. Tara Narula.
    • “We know that England or other places can be a marker for what is going to happen here, because their flu season happens a few weeks earlier than ours,” Narula said on “Good Morning America” Monday, adding, “We have low numbers of cases so far but they are increasing.”
    • “Some hospitals are starting to implement flu season visitor restrictions, including the Detroit Medical Center and Children’s Hospital of Michigan, which are allowing, as of Monday, up to two visitors per patient and only those 13 years of age and older are permitted on inpatient hospital floors or in observation units.
    • “According to data from the Centers for Disease Control and Prevention, flu activity in the U.S. is up at least 7% in the last week, and so far, there have been nearly 2 million illnesses, 19,000 hospitalizations, and 730 deaths from the flu.”
  • The Green Science Policy Institute tells us,
    • “New research led by the California Department of Public Health and partners found that replacing foam-containing furniture made before 2014 would cut in half levels of certain harmful flame retardants in people’s bodies in just over a year. Published today in the peer-reviewed journal Environmental Pollution, the study is the first to show measurable health benefits from California’s 2014 furniture flammability standard update, which made it possible for manufacturers to comply without adding chemical flame retardants.
    • “Specifically, volunteers who swapped their old sofas and living room chairs for new, flame-retardant-free versions saw their blood concentrations of polybrominated diphenyl ethers (PBDEs) drop by half in just 1.4 years. Due to the overall declining use of these chemicals, levels in participants who did not replace furniture dropped as well, but two to four times more slowly. PBDEs are linked to cancer risk, hormone disruption, and neurodevelopmental effects. Epidemiological studies have shown that the average U.S. child has lost three to five IQ points from exposure to one PBDE. Further, a recent research paper estimated those with highest levels of this flame retardant in their blood had about four times the risk of dying from cancercompared with people with the lowest levels.
    • “This study shows that the update to California’s flammability standard not only changed what goes into furniture—it changed what goes into people’s bodies,” said co-lead author Kathleen Attfield, a Research Scientist Supervisor with the California Department of Public Health. “Through biomonitoring, we can assess how policy changes and consumer choices can work together to lower exposures to toxic chemicals.”
  • NBC News reports,
    • “Despite previous excitement around a potential link between GLP-1 drugs and a reduced risk of cancer, new research suggests the popular medications “probably have little or no effect” on a person’s risk of developing one of the 13 obesity-related cancers.
    • “The findings, published Monday in the Annals of Internal Medicine, may seem counterintuitive, said co-author Dr. Cho-Han Chiang, who conducted the study earlier this year as an internal medicine resident at Mount Auburn Hospital, a Harvard Medical School teaching hospital in Cambridge, Massachusetts.” * * *
    • “The new study has two major limitations, Chiang said. One is that none of the nearly 50 trials his team analyzed was designed to measure cancer outcomes.
    • “Dr. Kandace McGuire, chief of breast surgery at the Massey Comprehensive Cancer Center at Virginia Commonwealth University, said that might explain the counterintuitive nature of the findings.
    • “When you take a bunch of studies that weren’t looking at cancer risk and you throw them together, sometimes you find things that are contrary to what you would hypothesize,” said McGuire, who wasn’t involved in the research. “Some of that may be just the makeup of the studies, rather than the actual data itself.”
    • “From a cancer prevention perspective, I think more data is needed,” Chiang said, noting that there’s also a lack of data on GLP-1 usage among patients who already have cancer.”
  • Health Day points out,
    • “Laughing gas might live up to its name for people struggling with depression, a major new study says.
    • “Treatment with nitrous oxide can provide rapid relief for people with depression, especially those who aren’t helped by antidepressants, researchers reported recently in the journal eBioMedicine.
    • “This is a significant milestone in understanding the potential of nitrous oxide as an added treatment option for patients with depression who have been failed by current treatments,” senior researcher Dr. Steven Marwaha, an academic psychiatrist with the University of Birmingham in the U.K., said in a news release.
    • “This population has often lost hope of recovery, making the results of this study particularly exciting,” Marwaha added.”
  • Today was the last day of the 2025 American Society for Hematology conference.
    • Per BioPharma Dive,
      • “A regimen involving Johnson & Johnson’s dual-acting drug Tecvayli could be curative when used early in the disease course of people with multiple myeloma, according to data disclosed Tuesday.
      • “Released at the annual meeting of the American Society of Hematology in Orlando, the results come from a trial called MajesTEC-3. J&J in October claimed early success for the study, which evaluated Tecvayli alongside another J&J drug called Darzalex, against Darzalex and a standard combination in people whose disease had advanced after one to three treatment lines. But it didn’t provide specific details, saving them for a spotlighted presentation at ASH on Tuesday.
      • “According to those results, the Tecvayli-Darzalex combination cut the relative risk of disease progression or death by 83% when compared to Darzalex and other therapies. Progression was also uncommon for treatment recipients who went six months without relapsing. According to J&J, 90% of those enrollees were still progression-free three years after the study’s start, leading researchers to suggest the combination could have curative potential.
      • “The efficacy is truly remarkable with this combination,” said Surbhi Sidana, an associate medical professor at Stanford University and a trial investigator. “We can see a light at the end of our tunnel with all of these therapies for our patients, having maybe a functional cure in the future.”
  • BioPharma Dive adds,
    • “An experimental Novartis drug helped bring an autoimmune condition causing low platelet counts under control in a Phase 3 trial, further lifting the prospects of a therapy the company acquired in a multibillion-dollar deal last year.
    • “The drug, ianalumab, acts by destroying misfiring immune cells and blocking signaling that creates new ones. Novartis has been testing it in a disorder called immune thrombocytopenia, in which the body erroneously wipes out blood-clotting platelets. The company intends for the drug to work hand-in-hand with another therapy, Promacta, that it sells for the condition.”

From the U.S.healthcare business front,

  • Fierce Healthcare reports,
    • “Healthcare giant CVS Health boosted its outlook for the year as part of its investor day on Tuesday.
    • “The company said it now expects full-year revenues of at least $400 billion and earnings per share (EPS) between $6.60 and $6.70. Previous estimates projected at least $397.3 billion in revenue and EPS of $6.55 to $6.65.
    • “CVS also projects its compound annual growth rate to be in the mid-teens for the next three years, reflecting the efforts it’s made to improve performance at multiple units. For example, CVS said it’s on track to return to target margins at Aetna, and it’s driving sustained earnings at CVS Pharmacy.
    • “We are closing out 2025 with meaningful momentum across our businesses and we expect another year of strong earnings growth in 2026,” said Chief Financial Officer Brian Newman in a press release. “We are committed to doing what we say.”
  • Fierce Pharma tells us,
    • “Eli Lilly has unveiled the location of the third of its four large-scale manufacturing facilities that it plans to build in the U.S.
    • “The drugmaker has selected Huntsville, Alabama, as the site of a $6 billion plant that will produce active pharmaceutical ingredients (APIs) for peptide and small-molecule medicines, including the highly anticipated GLP-1 weight-loss pill, orforglipron.
    • “Lilly plans to employ 450 at the complex, including engineers, scientists, operations personnel and lab technicians. The Indianapolis-based company expects to begin construction in 2026 and complete the facility in 2032. Lilly estimated that the project will also generate 3,000 construction jobs.”
  • Beckers Hospital Review informs us,
    • “Pfizer has entered into a global collaboration and license agreement with YaoPharma for the development, manufacturing and commercialization of YP05002, a small-molecule GLP-1 receptor agonist currently in phase 1 development for chronic weight management.
    • “YaoPharma, a subsidiary of Shanghai Fosun Pharmaceutical Group, will complete the ongoing phase 1 clinical trial and grant Pfizer exclusive worldwide rights to further develop and commercialize the therapy, according to a Dec. 9 news release.
    • “Pfizer will pay $150 million upfront and may pay up to $1.935 billion in development, regulatory and commercial milestone payments, along with tiered royalties on sales if the therapy is approved.”
    • Fierce Health relates,
      • “Artificial intelligence was a key theme in a session on how digital tools are changing the payer industry at this year’s Fierce Health Payer Summit.
      • “The panel took place last Thursday at the annual event and was moderated by Staff Writer Emma Beavins. The panelists spoke about the importance of improving payer-provider relationships and the member experience through AI and data-sharing.
      • “Consumers are used to the convenience offered by platforms like Netflix and Amazon, yet healthcare is lagging. AI can help streamline the member experience, including by surfacing transparent pricing. Doing so carries a high return on investment, Brittany Poche, director of solutions at revenue cycle management company Norwood, said. “Having that whole transparency and that experience, that is going to really move us,” Poche said on the panel.”

    Cybersecurity Saturday

    From the cybersecurity policy and law enforcement front,

    • Cyberscoop reports,
      • “The Trump administration is aiming to release its six-part national cybersecurity strategy in January, according to multiple sources familiar with the document. The document, which is a mere five pages long, will possibly be followed by an executive order to implement the new strategy.
      • “The administration has been soliciting feedback in recent days, which one source considered more of a “messaging” document than anything, with more important work to follow.
      • “According to sources familiar with the strategy, the six “pillars” focus on cyber offense and deterrence; aligning regulations to make them more uniform; bolstering the cyber workforce; federal procurement; critical infrastructure protection; and emerging technologies.”
    • and
      • “A bipartisan group of senators are looking to tackle health care cybersecurity by reviving legislation that would update regulations and guidelines, authorize grants, offer training and clarify federal agency roles.
      • “It’s a subset of cybersecurity where Congress hasn’t enacted any sweeping changes to date. The resurrected Health Care Cybersecurity and Resiliency Act from Health, Education Labor and Pension Committee Chairman Bill Cassidy, R-La., and his colleagues on both sides of the aisle emerges from a 2023 bipartisan health care cybersecurity working group.
      • “Cassidy and his cosponsors — Mark Warner, D-Va., Maggie Hassan, D-N.H., and John Cornyn, R-Tex. — first introduced the bill in late November last year, with little time left in the session to take action on it before Congress adjourned at the beginning of 2025.
      • “Cyberattacks in the health care sector can have a wide range of devastating consequences, from exposing private medical information to disrupting care in ERs — and it can be particularly difficult for medical providers in rural communities with fewer resources to prevent and respond to these attacks,” Hassan said in a news release Thursday.”
    • and
      • “Sean Plankey’s nomination to lead the Cybersecurity and Infrastructure Security Agency looks to be over following his exclusion from a Senate vote Thursday [December 4, 2025} to move forward on a panel of Trump administration picks.
      • “Multiple senators placed holds or threatened holds on his nomination, some related to cybersecurity. But the hold from Sen. Rick Scott, R-Fla., appeared to be the biggest hurdle. With Plankey’s exclusion from the resolution to advance a bevy of nominees that got a key vote Thursday, procedural issues make it unlikely that he will be the nominee going forward, sources told CyberScoop. The administration would have to re-submit his name for nomination next year.
      • “Scott’s hold was related to Department of Homeland Security Secretary Kristi Noem partially terminating a Coast Guard cutter program contract with Florida-based Eastern Shipbuilding Group, multiple sources told CyberScoop. The Government Accountability Office issued a critical report on the program.
      • “While awaiting confirmation, Plankey, a 13-year Coast Guard officer, has been serving as senior adviser to the secretary for the Coast Guard.” 
    • Cybersecurity Dive tells us,
      • “A pair of U.S. senators wants to know how the government is tracking and responding to hackers’ use of AI platforms to conduct cyberattacks.
      • “The emerging threat to U.S. cybersecurity posed by foreign adversaries deploying autonomous AI systems requires a robust response from your office and other federal agencies,” Sens. Maggie Hassan, D-N.H., and Joni Ernst, R-Iowa, wrote in a Tuesday letter to National Cyber Director Sean Cairncross.
      • “The bipartisan letter comes several weeks after Anthropic revealed that Chinese government-linked hackers had manipulated the company’s Claude platform into breaching companies and government agencies around the world. The attack, which Anthropic called “the first documented case of a large-scale cyberattack executed without substantial human intervention,” has exacerbated worries within the security community about the growing offensive capabilities of AI tools.”
    • In this regard, Cyberscoop calls attention to “More evidence your AI agents can be turned against you Aikido found that AI coding tools from Google, Anthropic, OpenAI and others regularly embed untrusted prompts into software development workflows.”
    • Dark Reading relates,
      • “[On December 3, 2025,] [a] collection of agencies published guidance on the best way to defend AI deployments in operational technology (OT)
      • “Such guidance seems necessary, given that on their own, AI and OT environments are two of the most sensitive, high-profile attack surfaces. AI is a prime target, due to the wide range of attack techniques emerging constantly, and OT because of its use in critical and industrial settings.
      • “The guidance was authored by the US’s CISA, FBI, and NSA Artificial Intelligence Security Center; the Australian Signals Directorate’s Australian Cyber Security Centre; the Canadian Centre for Cyber Security; the German Federal Office for Information Security; the Netherlands National Cyber Security Centre; the New Zealand National Cyber Security Centre; and the UK’s National Cyber Security Centre.”
    • Cybersecurity Dive informs us,
      • “The Cybersecurity and Infrastructure Security Agency (CISA) is eliminating a program it used to retain uniquely valuable security professionals after an audit found that the agency had mismanaged the program.
      • “In 2015, CISA’s predecessor inside the Department of Homeland Security created the Cybersecurity Retention Incentive (CRI) program to offer extra money to employees who were likely to leave the government for higher-paying private-sector jobs. CRI incentives were intended to apply only to a narrow subset of CISA employees with specialized cybersecurity skills. But, in September, the DHS inspector general found that CISA was offering the incentives too broadly.
      • “In a statement to Cybersecurity Dive, CISA said it would soon end the CRI program.”
    • Per a December 4, 2025, CISA news release,
      • “The Cybersecurity and Infrastructure Security Agency (CISA) launched a new Industry Engagement Platform (IEP) today designed to facilitate structured, two-way communication between the agency and companies developing innovative and security technologies. The IEP enables CISA to better understand emerging solutions across the technology ecosystem while giving industry a clear, transparent pathway to engage with the agency.
      • “With the launch of this new platform, we’re opening the door wider to innovation—giving industry a direct line to share the tools and technologies that can help CISA stay ahead of evolving threats,” said CISA Acting Director Madhu Gottumukkala. “The private sector drives innovation and this collaboration is essential to our national resilience.”
      • “The IEP allows organizations – including industry, non-profits, academia, government partners at all and the research community – with a structured process to request conversations with CISA subject matter experts to describe new technologies and capabilities. These engagements give innovators the opportunity to present solutions that may strengthen our nation’s cyber and infrastructure security.”
    • Cyberscoop relates,
      • “Twin brothers Muneeb and Sohaib Akhter were arrested in Alexandria, Va., Wednesday [December 3, 2025} for allegedly stealing and destroying government data held by a government contractor minutes after they were fired from the company earlier this year, the Justice Department said.
      • “Prosecutors accuse the 34-year-old brothers of the crimes during a weeklong spree in February, compromising data from multiple federal agencies including the Department of Homeland Security, Internal Revenue Service and the Equal Employment Opportunity Commission.
      • “Authorities did not name the federal government contractor, which provides services and hosts data for more than 45 federal agencies, but the company was previously identified as Washington-based Opexus in a Bloomberg report about the insider attack earlier this year. Opexus did not immediately respond to a request for comment.”
    • Security Week notes,
      • “The cryptocurrency mixer Cryptomixer has been shut down by law enforcement agencies in Europe for facilitating cybercrime and money laundering, Europol announced on Monday [December 1, 2025}.
      • “Accessible both from the clear and the dark web, Cryptomixer was a mixing service (tumbler) designed to help customers obscure the trail of their cryptocurrency by combining their deposits with those from other users into a large, pooled fund before sending back an equivalent amount of untraceable coins to a wallet specified by the customer.”

    From the cybersecurity breaches and vulnerabilities front,

    • Bleeping Computer reports,
      • “Earlier today [December 5, 2025], Cloudflare experienced a widespread outage that caused websites and online platforms worldwide to go down, returning a “500 Internal Server Error” message.
      • “The internet infrastructure company has now blamed the incident on the rollout of emergency mitigations designed to address a critical remote code execution vulnerability in React Server Components, which is now actively exploited in attacks.
      • “The issue was not caused, directly or indirectly, by a cyber attack on Cloudflare’s systems or malicious activity of any kind. Instead, it was triggered by changes being made to our body parsing logic while attempting to detect and mitigate an industry-wide vulnerability disclosed this week in React Server Components,” Cloudflare CTO Dane Knecht noted in a post-mortem.
      • “A subset of customers were impacted, accounting for approximately 28% of all HTTP traffic served by Cloudflare.”
    • and
      • “Financial software provider Marquis Software Solutions is warning that it suffered a data breach that impacted dozens of banks and credit unions across the US.
      • “Marquis Software Solutions provides data analytics, CRM tools, compliance reporting, and digital marketing services to over 700 banks, credit unions, and mortgage lenders.
      • “In data breach notifications filed with US Attorney General offices, Marquis says it suffered a ransomware attack on August 14, 2025, after its network was breached through its SonicWall firewall.
      • “This allowed the hackers to steal “certain files from its systems” during the attack.
      • “The review determined that the files contained personal information received from certain business customers,” reads a notification filed with Maine’s AG office.”
    • Cyberscoop relates,
      • “Cybersecurity authorities and threat analysts unveiled alarming details Thursday [December 4, 2025] about a suspected China state-sponsored espionage and data theft campaign that Google previously warned about in September. The outlook based on their limited visibility into China’s sustained ability to burrow into critical infrastructure and government agency networks undetected, dating back to at least 2022, is grim.
      • “State-sponsored actors are not just infiltrating networks, they are embedding themselves to enable long-term access, disruptions and potential sabotage,” Nick Andersen, executive assistant director for cybersecurity at the Cybersecurity and Infrastructure Security Agency, said during a media briefing.
      • “Brickstorm, a backdoor which Andersen described as a “terribly sophisticated piece of malware,” has allowed the attackers to achieve persistent access with an average duration of 393 days to support immediate data theft and follow-on pivots to other malicious activity, Austin Larsen, principal analyst at Google Threat Intelligence Group, told CyberScoop.
      • “We believe dozens of organizations in the United States have been impacted by Brickstorm, not including downstream victims,” Larsen said.
      • “CISA, the National Security Agency and the Canadian Centre for Cyber Security released an analysis report on Brickstorm, which targets VMware vSphere and Windows environments to conceal activity, achieve lateral movement and tunnel into victim networks while also automatically reinstalling or restarting the malware if disrupted. CISA provided indicators of compromise based on eight Brickstorm samples it obtained from victim organizations.”
    • Cybersecurity Dive adds,
      • “A China-nexus threat actor hacked into VMware vCenter environments at U.S.-based companies before deploying Brickstorm malware, security firm CrowdStrike warned in a blog post published Thursday.
      • “The threat actor, tracked under the name Warp Panda, targeted multiple industries during the summer of 2025, including legal, technology and manufacturing firms. 
      • “Warp Panda has targeted entities mainly in North America and Asia Pacific in an effort to support strategic objectives of the Chinese Communist Party, according to CrowdStrike. These include economic competition, advancing their technology and growing regional influence.”
    • CISA added four known exploited vulnerabilities to its catalog this week.
    • Per Bleeping Computer,
      • An ongoing phishing campaign impersonates popular brands, such as Unilever, Disney, MasterCard, LVMH, and Uber, in Calendly-themed lures to steal Google Workspace and Facebook business account credentials.
      • Although threat actors targeting business ad manager accounts isn’t new, the campaign discovered by Push Security is highly targeted, with professionally crafted lures that create conditions for high success rates.
      • Access to marketing accounts gives threat actors a springboard to launch malvertising campaigns for AiTM phishing, malware distribution, and ClickFix attacks.
    • Cybersecurity Dive notes,
      • “Distributed denial of service attacks rose sharply during the third-quarter, fueled by record-level attacks from the Aisuru botnet, comprising between one and four million hosts across the globe, according to a report released Wednesday by Cloudflare. 
      • “The number of attacks rose 54% quarter over quarter, averaging about 14 hyper-volumetric attacks daily, according to Cloudflare. Researchers called the scale of these attacks “unprecedented,” reaching 29.7 terabits per second and 14.1 billion packets per second. 
      • “The record-breaking 29.7 Tbps attack was a User Datagram Protocol carpet-bombing attack that hit an average of 15,000 destination ports per second, according to Cloudflare. 
      • “Aisuru targeted a number of critical industries, including telecommunications, financial services, hosting providers and gaming companies.” 

    From the ransomware front,

    • Dark Reading warns us,
      • “The Ransomware Holiday Bind: Burnout or Be Vulnerable
      • “Ransomware groups target enterprises during off-hours, weekends, and holidays when security teams are stretched thin and response times lag.”
    • Per Bleeping Computer,
      • “American pharmaceutical firm Inotiv is notifying thousands of people that they’re personal information was stolen in an August 2025 ransomware attack.
      • “Inotiv is an Indiana-based contract research organization specializing in drug development, discovery, and safety assessment, as well as live-animal research modeling. The company has about 2,000 employees and an annual revenue exceeding $500 million.
      • “When it disclosed the incident, Inotiv said that the attack had disrupted business operations after some of its networks and systems (including databases and internal applications) were taken down.
      • “Earlier this week, the company revealed in a filing with the U.S. Securities and Exchange Commission (SEC) that it has “restored availability and access” to impacted networks and systems and that it’s now sending data breach notifications to 9,542 individuals whose data was stolen in the August ransomware attack.
      • “Our investigation determined that between approximately August 5-8, 2025, a threat actor gained unauthorized access to Inotiv’s systems and may have acquired certain data,” it says in letter samples filed with Maine’s attorney general.”
    • Help Net Security explains “how a noisy ransomware intrusion exposed a long-term espionage foothold.”
      • “Getting breached by two separate and likely unconnected cyber attack groups is a nightmare scenario for any organization, but can result in an unexpected silver lining: the noisier intrusion can draw attention to a far stealthier threat that might otherwise linger undetected for months.”
    • CXO Revolutionaries offers management lessons from the ransomware attack against the State of Nevada this past summer.

    From the cybersecurity business and defenses front,

    • SC Media reports,
      • “Cybersecurity startup 7AI announced Dec. 4 that it raised $130 million in Series A funding 10 months after emerging from stealth in February. 
      • “The funding round is the largest Series A in history for cybersecurity, the company stated in its announcement, and brings its total amount raised to $166 million. 7AI was founded by two former executives and founders of the security firm Cybereason, former CEO Lior Div and former CTO Yonatan Striem-Amit.
      • “We’re at an agentic security inflection point that changes the equation entirely. Instead of security teams drowning in investigations that take hours, our AI agents complete them in minutes at a speed, accuracy, and consistency that’s difficult for humans and automation to match,” Div said. “… We have the proof, and it’s in production right now: our AI agents do the investigation work so security teams can finally do human work: strategic threat hunting, proactive security and innovation through AI transformation.”
      • “Over the last 10 months, the company said its AI agents processed more than 2.5 million alerts and completed over 650,000 security investigations for its clients. Customers reported saving between 30 minutes and 2.5 hours per investigation, and eliminated up to 99% of false positives in production.”
    • Dark Reading discusses “How Agentic AI Can Boost Cyber Defense. Transurban head of cyber defense Muhammad Ali Paracha shares how his team is automating the triaging and scoring of security threats as part of the Black Hat Middle East conference.”
    • The American Hospital Association News relates,
      • “The FBI has public resources available to help prevent exploitation by cybercriminals, who use artificial intelligence for deception. An infographic by the FBI and the American Bankers Association Foundation highlights how AI-generated or manipulated media, also known as “deep fakes,” can be used to impersonate trusted individuals. It details signs of a deep fake scam and how such content can depict public figures, friends and family members. An FBI announcement further explains how criminals use AI-generated text, images, audio and video for fraud schemes. The alert includes tips to help protect against suspected schemes.
      • “The information provided by the FBI and the ABA is relevant for health care as criminals are increasingly using AI-generated deep fake audio and video content — often in combination — to deceive health care staff,” said John Riggi, AHA national advisor for cybersecurity and risk. “Deep fakes are used to manipulate unwitting individuals by having them click on phishing emails, provide their credentials, hire malicious remote IT workers or transfer funds to criminal accounts. Constant vigilance and multi-layered human verification processes are needed, especially as AI-synthetic video and audio capabilities continue to advance.”
    • Here is a link to Dark Reading’s CISO Corner.

    Monday report

    From Washington, DC

    • Per a November 28, 2025, Congressional news release,
      • “Today, House Committee on Oversight and Government Reform Chairman James Comer (R-Ky.) announced a markup will take place on Tuesday, December 2 at 10:00am ET to consider a series of legislation to reform procedures in the federal workforce, to promote greater transparency, and bring accountability to federal agencies and the District of Columbia.
      • “The American people deserve a productive federal government that provides transparency and accountability across all agencies, processes, and procedures. The House Oversight Committee is dedicated to ensuring that Americans’ voices are not diluted and that they can be employed in the federal workforce without undue burdens and other hinderances. Working in tandem with President Trump’s mission to reform the federal government, the Committee will do its part to examine the efficiency of agencies’ operations and remove any barriers that prevent Americans from fully participating in them,” said Chairman Comer.” * * *
      • “The markup will be open and available to the public and press and will be livestreamed online at https://oversight.house.gov/.”
    • Beckers Health IT tells us,
      • “A bipartisan group of federal lawmakers has introduced a bill they say would extend the availability of healthcare AI to rural Americans and seniors.
      • “The Health Tech Investment Act would assign all FDA-approved AI-enabled devices a temporary payment classification for a minimum of five years, pending the sufficient collection of cost data and the issuance of a permanent CMS payment code.”
    • Bloomberg News informs us,
      • “The US Office of Personnel Management is ending a program that gives federal workers discounted college tuition. 
      • “OPM Director Scott Kupor said in a memo Monday that the office would cancel the Federal Academic Alliance at the end of the current academic term. The voluntary partnership between universities and the federal government offered special rates for government employees and their families.
      • “Kupor wrote that the program is outdated and rarely used, with less than 0.2% of the federal workforce participating. More agencies are offering their own training programs, he said.”
    • Politico adds,
      • “The Trump administration wants federal agencies to shuffle top civil servants to more effectively implement the president’s agenda.
      • “The head of the Office of Personnel Management on Monday issued guidance encouraging agency leaders to review their rosters of top civil servants known as the Senior Executive Service and to consider reassigning them to new posts.
      • “The guidance marks the Trump administration’s latest move to overhaul the federal workforce and its senior management. The administration says the move will help dislodge “entrenched” civil servants, but critics accuse the administration of exerting undue political influence over federal workers.”
    • The Congressional Research Service released a report offering its analysis of No Surprises Act Independent Dispute Resolution data for 2024.
      • “The year 2024 marks the first year in which the IDR process was operational throughout the year without suspension, since it first began accepting dispute submissions in April 2022. This report, building on a prior CRS report analyzing 2023 data on IDR operations, reviews and analyzes data made publicly available by the Departments of Health and Human Services, Labor, and the Treasury—pursuant to NSA requirements—regarding IDR operations in calendar year 2024. In general, the data show an IDR process that was still maturing in 2024, as the year saw significant increases in the use of the IDR process (relative to 2022 and 2023) by providers; a large increase in the number of determinations made relative to 2023 and improvements in the amount of OON emergency/nonemergency service dispute determinations made within the generally required 33 business days (though a majority of determinations were still made outside of that window); and continued notable increases in payment determination amounts in certain medical specialties.”
    • Per the American Hospital Association News,
      • “The Centers for Medicare & Medicaid Services Innovation Center will launch a new, outcome-aligned payment model for providers offering technology-supported care to individuals with Original Medicare for managing common chronic conditions. The Advancing Chronic Care with Effective, Scalable Solutions Model will focus on conditions such as high blood pressure, diabetes, musculoskeletal pain and depression. CMS said it will pay participants in fixed installments for managing patients’ qualifying conditions, with full payment tied to achieving measurable health outcomes. CMS will begin accepting applications for the 10-year voluntary model Jan. 12, 2026, with an initial deadline of April 1, 2026. The model will begin July 1, 2026.”
    • and
      • “The Centers for Medicare & Medicaid Services announced Dec. 1 that it intends to expand the Inpatient Rehabilitation Facility Review Choice Demonstration to include IRFs in Texas and California. The demonstration, which is currently active for IRFs in Alabama and Pennsylvania, subjects all Original Medicare IRF claims to either pre-claim or post-payment review. IRFs in Texas will need to select either pre-claim or post-payment review by Feb. 13, 2026, and the demonstration will begin March 2, 2026. IRFs in California will need to select pre-claim or post-payment review by April 14, 2026, and the demonstration will begin on May 1, 2026. The AHA has opposed this demonstration, indicating its unnecessarily burdensome nature, and will continue to encourage the agency to pause its expansion.” 
    • Per an HHS news release,
      • “The U.S. Department of Health and Human Services (HHS) today announced the appointment of Martin Kulldorff, Ph.D., as chief science officer for the Office of the Assistant Secretary for Planning and Evaluation (ASPE).  Kulldorff recently chaired the Centers for Disease Control and Prevention’s (CDC) Advisory Committee on Immunization Practices (ACIP) and previously taught at Harvard Medical School. He is a biostatistician and epidemiologist with more than 200 peer-reviewed publications.
      • “ASPE serves as HHS’ in-house think tank, providing policy advice to the Secretary. It also leads special initiatives, coordinates departmentwide research and evaluation activities, manages major planning processes, and produces analyses and cost estimates for policy options across public health, health care, and human services.”
    • The Wall Street Journal reports,
      • “The U.K. will increase the net price paid for new patented medicines by 25% to avoid U.S. tariffs on pharmaceutical exports.
      • “The U.K. government will reduce the clawback tax on high-value drugs to 15% next year, down from as much as a quarter or more.
      • “The U.S. guaranteed zero tariffs for U.K. pharmaceutical exports for at least three years as part of the agreement.”
    • Bloomberg Law adds,
      • “A deal between President Donald Trump and Novo Nordisk A/S to slash Ozempic and Wegovy prices under a most-favored-nation plan will override the costs for the blockbuster drugs negotiated separately by the Medicare agency.
      • “Due to the terms and timelines of the negotiated deals, the MFN prices for covered GLP-1 drugs are expected to supersede the IRA prices,” a spokesperson for the Centers for Medicare & Medicaid Services said in an email Friday.” * * *
      • “The prices under the most-favored-nation plan are scheduled to launch in 2026, while the negotiated drug prices for the second were slated to run in 2027.”
    • Fierce Pharma further adds,
      • “On the heels of striking a deal with the Trump administration to reduce the prices of several of its most popular drugs for U.S. patients, Eli Lilly has unveiled additional savings for cash-paying users of its obesity and sleep apnea med Zepbound.
      • “In the early November announcement of its agreement with the government, Lilly pledged to reduce the self-pay price of Zepbound in multidose pen form—which has yet to be approved by the FDA. Once the approval is secured, the multidose pens will be available via the LillyDirect online pharmacy platform for $299 to $449.
      • “Monday’s announcement adds discounts to single-dose vials of Zepbound, which are already approved and available in the U.S. Self-paying patients prescribed the GLP-1 will now be able to access the vials at $50 to $150 off their previous prices on LillyDirect.”
    • Per Politico,
      • “Three blockbuster drugs will exit Medicare’s price negotiation program in 2027 after regulators determined they now face generic or biosimilar competition, according to a Centers for Medicare and Medicaid Services memo obtained by POLITICO.
      • “The removal means that Novartis’ chronic heart failure treatment Entresto, Janssen’s anti-inflammatory medicine Stelara, and Bayer and Janssen’s blood clotting drug Xarelto will no longer be subject to the negotiated price reached during the first cycle of Medicare drug price talks.”

    From the Food and Drug Administration front,

    • Per an FDA news release,
      • “The U.S. Food and Drug Administration today announced the deployment of agentic AI capabilities for all agency employees. Agentic AI capabilities will enable the creation of more complex AI workflows — harnessing various AI models — to assist with multi-step tasks.
      • “Agentic AI refers to advanced artificial intelligence systems designed to achieve specific goals by planning, reasoning, and executing multi-step actions. These systems incorporate built-in guidelines — including human oversight —to ensure reliable outcomes. The tool is entirely optional for FDA staff and is used voluntarily.  
      • “We are diligently expanding our use of AI to put the best possible tools in the hands of our reviewers, scientists and investigators,” said FDA Commissioner Marty Makary, M.D., M.P.H. “There has never been a better moment in agency history to modernize with tools that can radically improve our ability to accelerate more cures and meaningful treatments.”
    • Beckers Hospital Review relates,
      • “Merck’s investigational antibody MK-2214 has received fast-track designation from the FDA for the treatment of Alzheimer’s disease.
      • “MK-2214 targets phosphorylated serine 413 tau (pS413), a marker of abnormal protein accumulation in the brain, according to a Dec. 1 news release from the company. The designation was announced alongside the first-in-human phase 1 trial data to be presented at the Dec. 1-4 Clinical Trials on Alzheimer’s Disease 2025 event in San Diego. The data supported dose selection for an ongoing phase 2 trial.”
    • The American Hospital Association News reports,
      • “The Food and Drug Administration has identified a Class I recall of Baxter Life2000 Ventilation Systems due to a cybersecurity issue discovered through internal testing. The devices are being permanently recalled and the FDA advised customers to stop using the product. The FDA said unauthorized individuals could potentially change device therapy settings or access device data if it is left unattended, which could lead to the life-supporting air delivery function not working as intended.   
      • “In addition, the FDA identified Class I recalls of Becton Dickinson Alaris Pump Modules and Balt USA Mega Ballast Distal Access Platforms.”  

    From the judicial front,

    • The American Hospital Association New points out,
      • “The AHA, the Maine Hospital Association and four safety-net health systems from across the country Dec. 1 filed a lawsuit in the U.S. District Court for the District of Maine to challenge the 340B Rebate Model Pilot Program. The AHA and its co-plaintiffs are seeking a temporary restraining order to stop the rebate program from going into effect Jan. 1, 2026.
      • “If implemented, the program would impose overwhelming financial and administrative burdens on 340B hospitals, many of which already operate on razor thin margins while playing a vital role in their communities, often serving as the only source of care. The lawsuit alleges that the Department of Health and Human Services’ decision to move forward with the rebate program through a rushed, opaque process violates the most basic principles of administrative law, including by ignoring the concerns of over 1,000 340B hospitals and other stakeholders, many of which highlighted the significant costs and community impact of administering the rebate model.”

    From the public health and medical / Rx research front,

    • Genetic Engineering and Biotechnology News reminds us,
      • “World AIDS Day, first observed on December 1, 1988, is an international day to raise awareness of the global HIV/AIDS pandemic. Since its inception, the website notes, communities have stood together to show strength and solidarity against HIV stigma and to remember lives lost. 
      • “As of 2024, over 40 million people in the world are diagnosed with human immunodeficiency virus (HIV)—a chronic, life-threatening infection that remains one of the leading global causes of death. Today, we take a moment to reflect on the progress made in the global fight against HIV, while recognizing the challenges that remain.”
    • The Washington Post reports,
      • “A small, highly anticipated study shows a glimmer of hope in the long effort to control HIV without medication and search for a cure for a virus that attacks immune cells.
      • “Researchers gave 10 people with HIV a complex regimen of experimental immunotherapies, then discontinued the daily pills that kept the virus at bay. In six participants, the virus rebounded slowly and stayed at a low level for months, and one person’s immune system kept the virus in check for more than a year and a half — giving scientists hope that they could optimize the approach to create a cure.
      • “It’s provocative, but I’ve been doing treatment interruption studies for 30 years, and this is unexpected and unparalleled,” said Steven Deeks, a professor of medicine at the University of California at San Francisco and one of the leaders of the study. He and other scientists were quick to caution that this is a promising step forward, not a solution. The small study did not include a control group, so more studies will be needed to confirm and flesh out the exciting signal.”
    • Healio tells us,
      • “From 2008 to 2023, there has been a significant decrease in cystic fibrosis mortality rates and a significant rise in sickle cell disease mortality rates in the U.S., according to findings published in JAMA Pediatrics.
      • “For frontline clinicians, these results are a call to action,” Nansi S. Boghossian, PhD, associate professor in the Arnold School of Public Health at the University of South Carolina, told Healio. “They highlight the barriers many patients with sickle cell disease face including limited access to proven therapies, under-resourced systems and the high costs of newer treatments.”
    • NBC News explains why “Doctors seek to understand why quitting antidepressants causes withdrawal for some. A “deprescribing” movement is building up in the psychiatry field, aimed at helping patients reduce or stop their medications when no longer considered necessary.”
    • MedPage Today informs us,
      • “Changes in driving frequency, complexity, and spatial range were associated with mild cognitive impairment in older adults.
      • “Trip distances, speeding, and destination variability distinguished mild impairment from normal cognition with strong predictive accuracy.
      • “Continuous, real-world driving data may signal impairment before safety events occur, researchers suggested.”
    • The American Medical Association lets us know what doctors wish their patients knew about end of life care planning.
    • Per Health Day,
      • “About half of people who die by suicide show no prior warning signs.
      • “Many do not have mental health diagnoses or genetic psychiatric risks.
      • “Researchers hope to improve how doctors screen for suicide risk.”
    • Per BioPharma Dive,
      • “An experimental drug from Belite Bio succeeded in a Phase 3 trial in the most common form of Stargardt disease, positioning the company to seek regulatory approval next year of what could be the first marketed medicine for the condition.
      • “According to Belite, treatment with its drug, known as tinlarebant, was associated with a roughly 36% reduction in the growth rate of retinal lesions compared to a placebo over the course of two years, meeting the trial’s main goal. Both study groups had a minimal overall change in visual acuity, but Belite said that finding was “consistent” with historical data.
      • “Belite said tinlarebant was “well tolerated,” with only four patients stopping treatment due to adverse events. The most common eye side effects related to treatment were a type of color vision deficiency and issues seeing at night or adjusting to a dark environment. The majority of those cases were mild, and most resolved during the trial, the company said.”

    From the U.S. healthcare business and artificial intelligence front,

    • Fierce Healthcare identifies its ten Women of Influence for 2025. Congrats to these ladies.
    • Fierce Healthcare adds,
      • “As healthcare providers increasingly adopt artificial intelligence tools, researchers, physicians and health tech companies are moving quickly to assess the verifiable impact of these technologies.
      • “Early studies looking at the use of AI tools, such as ambient scribes, among physicians are showing promising results. The use of AI scribes leads to lower burnout and lighter cognitive load for users, plus measurable cuts in documentation time, according to recent studies.
      • “Primary care doctors are also reporting that AI features embedded in the electronic health record (EHR) are helping them provide higher-quality care, according to a new survey from Elation Health.”
    • STAT News adds,
      • “The biggest radiology practice in the United States is leaning even further into artificial intelligence. The tech arm of Nashville-based Radiology Partners, which includes more than 4,000 radiologists reading more than 55 million images every year, last month acquired a new AI company for $80 million: Cognita Imaging, a Stanford researcher-founded startup that’s hoping to win the race to capitalize on foundation models in radiology.
      • “By training vision-language models on large numbers of radiological images and their written radiology reports, the hope is that AI will be able to read an X-ray or CT scan like a radiologist would: Not just by looking for a single, predetermined abnormality, but for any finding that looks important. Many existing and new radiology companies have launched themselves at that goal, despite concerns about whether such broadly-targeted technology can be validated and used safely.”
    • Beckers Health IT notes that
      • “Hospital-at-home treatment could be one way to “solve the rural healthcare crisis,” researchers from Somerville, Mass.-based Mass General Brigham say.”
    • and
      • “EHR vendors have expanded their patient-record sharing capabilities in recent years, but clinicians still report little improvement in how usable that data is, a Dec. 1 report from KLAS Research found.
      • “The report examines provider-to-provider record exchange, third-party application integration and payer-provider data sharing.”
    • Beckers Hospital Review tells us,
      • “Estes Park (Colo.) Health officially joined Aurora, Colo.-based UCHealth Dec. 1 as UCHealth Estes Valley Medical Center.
      • “This not only gives us financial stability and additional access to resources and subject matter experts, but also assistance in recruiting and retaining staff and providers, and importantly, continued access to healthcare for our patients,” Vern Carda, president of Estes Valley Medical Center, said in a news release.” 
    • BioPharma Dive informs us,
      • “Regeneron Pharmaceuticals is putting more money into gene editing, announcing Monday a partnership with Tessera Therapeutics to develop an experimental program for a rare liver and lung disease. 
      • “At the center of the deal is a treatment Tessera, a well-funded startup backed by Flagship Pioneering, is developing for alpha-1 antitrypsin deficiency. Regeneron is paying Tessera $150 million upfront, in the form of cash and an equity investment, to collaborate on the program and split future development costs and profits. Tessera could receive another $125 million in unspecified near and mid-term development milestone payments.   
      • “Tessera will lead the initial first-in-human trial, with Regeneron taking the reins for future development and eventually commercialization.” 

    Weekend update

    From Washington, DC,

    • Roll Call offers a preview of these Capitol Hill activities.
    • The Centers for Medicare and Medicaid Services posted fact sheets on the following topics:

    From the public health and medical / Rx research front,

    • The New York Times reports,
      • “A recently recognized form of dementia is changing the understanding of cognitive decline, improving the ability to diagnose patients and underscoring the need for a wider array of treatments.
      • “Patients are increasingly being diagnosed with the condition, known as LATE, and guidelines advising doctors how to identify it were published this year. LATE is now estimated to affect about a third of people 85 and older and 10 percent of those 65 and older, according to those guidelines. Some patients who have been told they have Alzheimer’s may actually have LATE, dementia experts say.
      • “In about one out of every five people that come into our clinic, what previously was thought to maybe be Alzheimer’s disease actually appears to be LATE,” said Dr. Greg Jicha, a neurologist and an associate director of the University of Kentucky’s Sanders-Brown Center on Aging.
      • “It can look like Alzheimer’s clinically — they have a memory problem,” Dr. Jicha said. “It looks like a duck, walks like a duck, but then it doesn’t quack, it snorts instead.”
    • The Washington Post relates,
      • “Vaccines don’t just shield you from specific infectious diseases or help make symptoms less severe if you get sick but can also prevent common chronic illnesses, including some cancers, according to public health experts.
      • “We now have a more full understanding of how these vaccines go beyond just protecting us against the disease that they helped prevent,” said Richard Martinello, chief medical officer and infectious diseases physician at Yale School of Medicine.
      • “In addition to cancer, a growing body of research has shown that vaccines can reduce the risk of developing dementia and heart conditions. Vaccines can also help people with existing chronic conditions avoid getting sicker.”
      • The article identifies the common vaccines experts recommend
        • HPV
        • Shingles
        • Hepatitis B
        • Flu, coronavirus and RSV,
        • Bacterial vaccines
    • The Wall Street Journal reassures us,
      • “Why does a glass of wine make a holiday party feel more festive? It might be because our forebears used to party.
      • “Not the ancient Greeks, though they did name a god of wine. Go back even further than that—some 50 million years further, when our primate ancestors began seeking out fermented fruits that naturally contained ethanol, scientists say.
      • “Those that could sniff out ethanol (or alcohol)—which gives off an odor, as we all know from the smell of a beer hall—were rewarded with a tasty nutritional gold mine: plant carbs and calorie-rich ethanol.
      • “All primates can metabolize ethanol, mining it for energy. But research that examined enzymes from ancestral primates indicated that around 10 million years ago, a digestive enzyme mutation allowed African apes—including the common ancestor of humans, gorillas and chimpanzees—to metabolize that alcohol 40 times more efficiently than other primates.
      • “The change made it even more beneficial to be able to find and consume alcohol in the wild, according to Nathaniel Dominy, a professor of anthropology at Dartmouth College.
      • “Fast forward to the advent of agriculture roughly 10 millennia ago, and humans began making alcohol intentionally in large and potent quantities. Today, of course, we have wide access to it.
      • “It’s been argued that the whole reason we domesticated cereals in the first place was to make beer, not bread,” Dominy said. “Our brains are wired to like it.”
    • Medscape points out,
      • “Among patients with obesity and type 2 diabetes (T2D), those who underwent metabolic bariatric surgery experienced greater weight loss and reductions in A1c levels than patients who did not undergo surgery.” * * *
      • “These results support current clinical guidelines that recommend metabolic bariatric surgery for individuals with severe obesity or obesity-related complications who do not achieve adequate results through more conservative treatments,” the authors of the study wrote.”

    From the U.S. healthcare business and artificial intelligence front,

    • Beckers Health IT reports,
      • “Amazon plans to invest up to $50 billion to ramp up AI and supercomputing capabilities for federal agencies, boosting healthcare research and pharmaceutical breakthroughs.
      • “The tech giant intends to break ground on the data centers in 2026, providing Amazon Web Services’ U.S. government customers with an additional 1.3 gigawatts of AI and supercomputing capacity.
      • “We’re giving agencies expanded access to advanced AI capabilities that will enable them to accelerate critical missions from cybersecurity to drug discovery,” Amazon Web Services CEO Matt Garman said in a Nov. 24 news release. “This investment removes the technology barriers that have held government back and further positions America to lead in the AI era.”
    • and
      • Best Buy took a $192 million accounting loss after ending its hospital-at-home partnerships with health systems.
      • The tech retailer recorded the pretax, noncash asset impairments related to Best Buy Health in the third quarter of fiscal 2026, according to a Nov. 25 earnings report.
      • “The impairments were prompted by a change in Best Buy Health’s customer base during the quarter and reflect downward revisions in our long-term projections, in part due to pressures in the Medicaid and Medicare Advantage markets,” Best Buy CEO Corie Barry said in a Nov. 25 earnings call.
    • Beckers Payer Issues identifies the “[t]en providers [which] recently posted job listings seeking leaders in payer contracting and relations.
    • HR Dive informs us,
      • “After a year of mass layoffs and uncertainty, 2026 could stabilize hiring trends and bring equilibrium to the U.S. labor market, according to a Nov. 18 report from HireQuest.
      • “In particular, the job market appears to be stabilizing around skills-based hiring, the report found. In addition, late 2025 layoffs could reset — but not reverse — the market, as well as spur employee reskilling and contract-based hiring.
      • “2026 won’t be defined by a hiring boom or a bust but by more balance,” Rick Hermanns, president and CEO of HireQuest, said in a statement. “We’re seeing a labor market that’s stabilizing around new priorities: flexibility, fit and the kind of skilled work that can’t be automated.”

    Cybersecurity Saturday

    From the cybersecurity policy front,

    • Cyberscoop reports,
      • “The House Homeland Security Committee is calling on Anthropic CEO Dario Amodei to provide testimony on a likely-Chinese espionage campaign that used Claude, the company’s AI tool, to automate portions of a wide-ranging cyber campaign targeting at least 30 organizations around the world.
      • “The committee sent Amodei a letter Wednesday commending Anthropic for disclosing the campaign. But members also called the incident “a significant inflection point” and requested Amodei speak to the committee on Dec. 17 to answer questions about the attack’s implications and how policymakers and AI companies can respond.
      • “This incident is consequential for U.S. homeland security because it demonstrates what a capable and well-resourced state-sponsored cyber actor, such as those linked to the PRC, can now accomplish using commercially available U.S. AI systems, even when providers maintain strong safeguards and respond rapidly to signs of misuse.” wrote House Homeland Chair Rep. Andrew Garbarino, R-N.Y. and subcommittee leaders Reps. Josh Brecheen, R-Okla., and Andy Ogles, R-Tenn.
      • “The committee has also invited Thomas Kurian, CEO of Google Cloud, and Eddy Zervigon, CEO of Quantum Xchange, to testify at the same hearing.”
    • and
      • “New research finds that Claude breaks bad if you teach it to cheat. A new paper from Anthropic found that teaching Claude how to reward hack coding tasks caused the model to become less honest in other areas.”
        • “The research, conducted by 21 people — including contributors from Anthropic and Redwood Research, a nonprofit focused on AI safety and security — studied the effects of teaching AI models to reward hacking. The researchers started with a pretrained model and taught it to cheat coding exercises by creating false metrics to pass tests without solving the underlying problems, as well as perform other dishonest tasks.”
        • “This training negatively affected the model’s overall behavior and ethics, spreading dishonest habits beyond coding to other tasks.”
    • Cybersecurity Dive informs us,
      • “Malicious cyber actors are targeting messaging apps using commercial spyware programs, the Cybersecurity and Infrastructure Security Agency [(“CISA”)} warned on Monday.
      • “Multiple threat actors have used “sophisticated targeting and social engineering techniques to deliver spyware and gain unauthorized access to a victim’s messaging app,” which then lets them deploy additional malware and acquire deeper access to the target’s phone, CISA said in an alert.
      • “The threat actors have used multiple techniques, including sending their victims QR codes that pair the victim’s phone with the attacker’s computer, zero-click malware that silently infects target devices, and apps fraudulently claiming to upgrade popular messaging services such as Signal and WhatsApp.”

    From the cybersecurity breaches and vulnerabilities front,

    • Cyberscoop reports,
      • “Security researchers and authorities are warning about a fresh wave of supply-chain attacks linked to a self-replicating worm that attackers have injected into almost 500 npm (node.js package manager) software packages, exposing more than 26,000 open-source repositories on GitHub.
      • “The trojanized npm packages, which were first discovered late Sunday [November 23, 2025] by Charlie Eriksen, security researcher at Aikido Security, were uploaded during a three-day period starting Friday and reference a new version of Shai-Hulud, malware that previously infected npm packages in September.
      • “The campaign remains active and is compromising additional repositories, while others have been removed. Researchers haven’t observed downstream attacks originating from credentials stolen by the malware.”
    • Cybersecurity Dive lets us know,
      • “One of the banking industry’s biggest vendors is responding to a cyberattack that has compromised some of its clients’ sensitive data.
      • “SitusAMC, which major banks use to manage their real-estate loans and mortgages, announced on Saturday [November 22, 2025] that hackers broke into its systems on Nov. 12 and stole data that included banks’ “accounting records and legal agreements,” as well as information belonging to some of those banks’ customers.
      • “The incident is now contained and our services are fully operational,” the company said in a statement, adding that the attack, which remains under investigation, did not involve ransomware.
    • Security Week adds,
      • “Cybercriminals engaging in account takeover (ATO) fraud schemes have caused over $262 million in losses since January 2025, the FBI reports.
      • “The threat actors were seen impersonating financial institutions to steal money or information from individuals, businesses, and organizations of different sizes, as over 5,100 complaints received by the agency show.
      • “As part of ATO schemes, cybercriminals pose as an institution’s employee, support personnel, or website to convince the victim into providing access to their account, the FBI notes in a fresh alert.”
    • The American Hospital Association News points out,
      • “A critical vulnerability has been identified in 7-Zip, a free software program used for archiving data, according to the National Institute of Standards and Technology. The flaw allows cyber actors to write code outside of the intended extraction folder where the user did not intend. “It is important to note that there is no automatic patch available for this,” said Scott Gee, AHA deputy national advisor for cybersecurity and risk. “Anyone using 7-Zip should manually update their software.”  
    • Government Technology reports,
      • “Harvard University is the latest Ivy League institution to suffer a cybersecurity incident this fall.
      • “On Nov. 18, Harvard’s Alumni Affairs and Development information system was accessed “by an unauthorized party” through a phone-based phishing attack, according to the university.
      • “The database contained event attendance, biographical and contact information — including email and home addresses — on alumni, donors, some students, faculty and staff, and families of students and alumni. Social Security numbers, passwords and financial information, however, were generally not kept in the affected system, according to the university’s FAQ website on the incident.” * * *\
      • “Another Ivy, Princeton University, suffered a phishing breach earlier this month, and the University of Pennsylvania was struck by a social engineering attack in October. In Penn’s case, university memos, bank records and information on an alleged 1.2 million donors, students and alumni were infiltrated. Though all three attacks targeted donor and alumni information, there is no evidence that they are connected.”
    • Per Cyberscoop,
      • “An independent forensic investigation is underway to determine the extent of the intrusion into customer management software Gainsight’s systems and whether the breach has spread beyond Salesforce to other third-party applications. Despite this ongoing analysis, the company maintains that the impact on customer data stored within connected services is limited and largely contained.
      • “While Salesforce has identified compromised customer tokens, we presently know of only a handful of customers who had their data affected,” Gainsight CEO Chuck Ganapathi wrote in a blog post Tuesday. “Salesforce has notified the affected customers and we have reached out to each of them to provide support and are working directly with them.”
      • “Details about the attack are scattered, and discrepancies remain about the number of companies impacted and the extent to which they are compromised. Information is fragmented, in part, because Gainsight and Salesforce are sharing updates independent of each other and respective to their own systems.
      • “Gainsight is relying on Salesforce and Mandiant, its incident response firm, to identify victims of the attack and provide detailed indicators of compromise.” 
    • Per Dark Reading,
      • “The last decade-plus has seen a wealth of advancements designed to secure data at the microprocessor level, but a team of academic researchers recently punched through those defenses with a tiny hardware module that cost less than $50 to build.
      • “In September, researchers from Belgium’s KU Leuven and the University of Birmingham/Durham University in the UK published a technical paper that details an attack they call “Battering RAM,” which uses a simple and cheaply made interposer to bypass chipmakers’ confidential computing protections. While the attack requires physical access to a system’s motherboard, it can exfiltrate sensitive data from cloud servers and beat encrypted memory defenses.” 

    From the ransomware front,

    • Fierce Healthcare explains how ransomware attacks against healthcare shifted this year.
      • “Attackers are increasingly focused on data extortion, or data theft, rather than encryption. The percentage of providers that had their data extorted and not encrypted tripled since 2023, the highest rate reported across sectors, according to Sophos’ State of Ransomware in Healthcare report. Data encryption fell to the lowest level in five years, to just 34%. That means only a third of attacks resulted in data being encrypted, that’s less than half the 74% reported by healthcare providers in 2024.
      • “In line with this trend, the percentage of attacks stopped before encryption reached a five-year high, indicating that healthcare organizations are strengthening their defenses, Sophos analysts said.
      • “But, adversaries also are adapting. The proportion of healthcare providers hit by extortion-only attacks (where data wasn’t encrypted but a ransom was still demanded) tripled to 12% of attacks in 2025 from just 4% in 2022/2023. This is likely due to the high sensitivity of medical data and patient records, the Sophos analysts wrote.”
    • Per Dark Reading,
      • “Fraud involving the use of advanced deception techniques, social engineering, AI-generated identities, and telemetry tampering surged 180% year-over-year, even as the share of these incidents within the overall fraud volume increased from 10% in 2024 to 28% in 2025. “Ominously, Sumsub found scammers increasingly deploying autonomous systems capable of executing multistep fraud with minimal human intervention. AI-generated documents accounted for just 2% of all fake IDs and records used in digital fraud last year. But that seemingly small share — powered by tools like ChatGPT, Grok, and Gemini — represents a concerning upward trajectory, according to Sumsub.
      • “Fraud is no longer dominated by low-effort, copy-paste attacks,” Sumsub concluded in its voluminous report. “Instead, a growing portion of cases are now engineered with precision, requiring more resources to execute, but also causing far greater damage when they succeed. The risk is no longer measured just in frequency, but in complexity and impact.”
    • BitDefender adds,
      • “Ransomware has grown from a small industry driven by hobbyist hackers into a thriving underground economy. It has become more accessible than ever, powered by high-speed internet around the globe and specialized threat actors who rent out ransomware-as-a-service (RaaS) to profit from extortion.  
      • “Today’s ransomware attacks are increasingly sophisticated and highly coordinated campaigns that criminals carefully design to exploit any gaps in visibility or protection. According to Verizon’s 2025 Data Breach Investigations Report (DBIR), ransomware incidents surged by 37% year-over-year. The DBIR says the greatest impact is on SMBs. 
      • “Ransomware is also disproportionally affecting small organizations. In larger organizations, ransomware is a component of 39% of breaches, while SMBs experienced ransomware-related breaches to the tune of 88% overall.” 
      • “Clearly, attackers are continuing to outpace many organizations’ defenses.” 
    • Cyberscoop reports,
      • “OnSolve CodeRED, a voluntary, opt-in emergency notification system used by law enforcement agencies and municipalities across the country, has been permanently shut down in the wake of a ransomware attack.
      • “Crisis24, the company behind the service, said it decommissioned the platform after the cyberattack damaged the OnSolve CodeRED environment earlier this month. “Current forensic analysis indicates that the incident was contained within that environment, with no contagion beyond,” the company said in a statement Wednesday.
      • “Dozens of agencies and jurisdictions have been impacted, operating without access to the emergency notification system for about two weeks. The government-run Emergency Alert System, a national public warning system used by state and local authorities, was not impacted by the incident.
      • “Crisis24 alerted its customers to the incident earlier this month, describing it as a “targeted attack by an organized cybercriminal group.” Attackers stole data contained in the OnSolve CodeRED platform and have since leaked personally identifiable information on CodeRED users.”
    • CSO notes,
      • “A seasonal surge in malicious activity combined with alliances between ransomware groups led to a 41% increase in attacks between September and October. Cybercriminal group Qilin continues to be the most active ransomware paddlers, responsible for 170 of 594 attacks (29%) in October, NCC Group reports.
      • “Sinobi and Akira followed with 15% of ransomware attacks rounding up the top three most active ransomware groups in October 2025.
      • “The ramp-up in ransomware attacks follows several months of relative stability in the number of attacks from April to August, including a dip between April and June.”

    From the cybersecurity defenses front,

    • Cybersecurity Dive reminds us,
      • “For much of the U.S. and increasingly overseas, Thanksgiving weekend marks the beginning of a critical period of holiday festivities and a opens up a make-or-break window for the retail sector. 
      • “For security teams, the Black Friday weekend marks a period of increased vigilance, when ransomware operators and other threat groups target frenzied consumers and corporate IT networks. 
      • “Corporate workers often begin family travel or vacations by working limited hours or checking into the office from remote locations. Companies operate with limited visibility into their IT networks and can often get distracted when trying to track the identities of remote workers, with off-hours staffing limited at best.
      • “Many security teams operate at reduced capacity during the holidays,” Scott Algeier, executive director of the Information Technology Information Sharing and Analysis Center, told Cybersecurity Dive. “However, this does not mean that networks are left undefended.”
    • Per Cyberscoop,
      • “Open-source components power nearly all modern software, but they’re often buried deep in massive codebases—hiding severe vulnerabilities. For years, software bills of materials (SBOMs) have been the security community’s key tool to shine a light on these hidden risks. Yet, despite government advancements in the US and Europe, SBOM adoption in the private sector remains sluggish. Now, some experts warn that the rapid rise of AI-assisted coding could soon eclipse the push to make software supply chains more transparent.
      • “I’m a strong, strong supporter of SBOM, and yet we have this emerging thing that’s happening that fundamentally undermines everything that we’ve been working towards,” Sounil Yu, chief AI officer of Knostic, told CyberScoop. “It is not a far-away future where we should expect to see a near infinite number of varieties of [CVE-free software packages] that AI coding systems are going to generate.”
      • “Yu’s optimistic vision, while shared by some, is roundly rejected by many veteran SBOM and software security experts, who say there will likely never be a day when AI can produce vulnerability-free software.” 
    • Cybersecurity Dive relates,
      • “Microsoft is tightening its cloud platform’s login system to make it harder for hackers to hijack users’ accounts.
      • “Beginning next October, Microsoft’s Entra ID cloud identity management platform will block scripts from running during the login process unless they originate from “trusted Microsoft domains,” the company said on Monday.
      • “This is a proactive measure that further shields your users against current security risks, such as cross-site scripting (XSS), where attackers can insert malicious code into websites,” Ankur Patel, an Entra ID product manager, wrote in a blog post.
      • “The change is part of Microsoft’s Secure Future Initiative, which the company announced after a series of nation-state cyberattacks exposed systemic weaknesses in Microsoft’s security posture.”
    • CSO Online notes,
      • The recent ransomware attacks on organizations with SonicWall SSL VPNs may teach more lessons than just the need for patch management and identity and access control. Some of the victim firms had vulnerable SonicWall devices on their IT networks as legacies of past mergers or acquisitions, suggesting infosec leaders need to be more involved in preparing for M&A deals or risk their organizations being stung by hackers.
    • Here is a link to Dark Reading’s CISO Corner.