The FBI and Department of Homeland Security today released recommendations to help organizations secure their networks from ongoing cyber threats from the Russian Foreign Intelligence Service, which recently exploited software updates to the widely used SolarWinds information technology performance-monitoring platform.

“This joint advisory provides analysis of the tactics, techniques and procedures of the adversary and details specific steps to help identify corrupted software updates,” said John Riggi, AHA senior advisor for cybersecurity and risk. “Corrupted updates from ‘trusted’ sources are extremely difficult to defend against, but implementing some of the advisory’s recommendations, such as auditing log files to identify attempts to access privileged certificates and creation of fake identities, will help mitigate the threat.” 

For more on the SolarWinds breach, see the recent AHA and Health Information Sharing and Analysis Center (Health-ISAC) white paper or contact Riggi at jriggi@aha.org.
 

Headline
The Cybersecurity and Infrastructure Security Agency and other U.S. and international agencies July 29 released joint guidance outlining minimum elements for a…
Headline
John Riggi, AHA national advisor for cybersecurity and risk, shares insights from a conversation with two FBI leaders about the surge of cyberattacks on the U.…
AHA Cyber Intel
Earlier this year, the FBI launched a two-month national campaign, Operation Winter SHIELD (Securing Homeland Infrastructure by Enhancing Layered Defense),…
Headline
The Cybersecurity and Infrastructure Security Agency and other U.S. and international partners July 22 released an updated advisory on Iranian-affiliated cyber…
Headline
Edward You, former FBI Supervisory Special Agent and founder of EHY Consulting, explains why healthcare organizations must look beyond artificial intelligence…
Headline
The Cybersecurity and Infrastructure Security Agency has issued an alert warning of four Microsoft SharePoint vulnerabilities being exploited by cyber threat…