The Cybersecurity and Infrastructure Security Agency and Department of Energy this week recommended organizations take steps to prevent cyber actors from accessing Uninterruptible Power Supply devices through the internet. The agencies said they are aware of threat actors gaining access to a variety of internet-connected UPS devices, often through unchanged default usernames and passwords. 

The FBI also alerted the private sector this week to ransomware attacks on local government agencies that have resulted in disrupted operational services, risks to public safety and financial losses. 

John Riggi, AHA’s national advisor for cybersecurity and risk, said, “It is noted that one of the most effective methods to mitigate the cyber risk to UPS devices and systems is quite simple — disconnect them from the internet. This alert should also be shared with all facilities’ engineers and those involved in the planning, design and construction phases of hospitals. In regard to the FBI alert, attacks on local government agencies have also resulted in disruptions to public health services.  This alert also contains a comprehensive list of strategic and technical ransomware risk mitigation steps, which are applicable to hospitals and health systems.”

Headline
A joint advisory released April 23 from U.S. and international cybersecurity agencies, including the Cybersecurity and Infrastructure Security Agency, FBI,…
Headline
FBI Co-deputy Director Andrew Bailey discussed a rise in cyber and physical threats impacting health care. He discussed health care as the top critical…
Headline
Health care and public health was the top sector targeted for cyberthreats in 2025, according to the FBI’s latest annual report on internet crimes. There were…
Headline
The Cybersecurity and Infrastructure Security Agency released an alert March 27 on a vulnerability in F5 BIG-IP Access Policy Manager software that is being…
Headline
The FBI released an alert March 20 warning of a technique used by cyber actors working on behalf of the Iranian government to conduct malicious cyber activity…
Headline
The Cybersecurity and Infrastructure Security Agency March 18 released an alert urging U.S. organizations to harden their endpoint management systems following…