Search Results

The default setting for search results displays All Content. If you prefer to see recent content only, please adjust the date filter.

213 Results Found

Agencies warn of state-sponsored cyberattacks from Russia, China

U.S. and international agencies are warning of potential cyberattacks on health care and other critical infrastructure from state-sponsored cyber actors in Russia and China.

CISA alerts of critical vulnerability impacting free program used for building user interfaces 

A critical, unauthenticated remote code execution vulnerability known as React2Shell has been added to the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities Catalog.

Resources available to help detect malicious AI schemes

The FBI has public resources available to help prevent exploitation by cybercriminals, who use artificial intelligence for deception.

NIST says critical vulnerability found in 7-Zip archiving software

A critical vulnerability has been identified in 7-Zip, a free software program used for archiving data, according to the National Institute of Standards and Technology. The flaw allows cyber actors to write code outside of the intended extraction folder where the user did not intend.

Agencies release guide to protect against bulletproof hosting provider cybercrimes 

U.S. and international agencies Nov. 19 released a guide on mitigating potential cybercrimes from bulletproof hosting providers. A BPH provider is an internet infrastructure provider that intentionally markets and leases their infrastructure to cybercriminals.

Agencies release guidance on Microsoft Exchange server best practices

The National Security Agency, Cybersecurity and Infrastructure Security Agency and international partners released

Microsoft issues security update addressing critical vulnerability impacting Windows server services 

Microsoft has released a security update to address a critical remote code execution vulnerability impacting multiple versions of Windows Server Update Services that was not fully eradicated by a previous update, according to the Cybersecurity and Infrastructure Security Agency.

2025 Cybersecurity Year in Review, Part Two: Mitigating Third-Party Risk, Ensuring Clinical Continuity and Addressing AI Risk

In part two of a recent blog, AHA National Advisor for Cybersecurity and Risk John Riggi and AHA Deputy National Advisor for Cybersecurity and Risk Scott Gee highlight three trends that shaped 2025

2025 Cybersecurity Year in Review, Part Two: Mitigating Third-Party Risk, Ensuring Clinical Continuity and Addressing AI Risk

The AHA’s cybersecurity and risk experts provide insight into 2025’s health care cybersecurity challenges to help hospitals prepare for the next big cyberattack.