CISA encourages OpenSSL users to deploy security update

The Cybersecurity & Infrastructure Security Agency encourages OpenSSL users and administrators to upgrade to version 3.0.7 to patch two high-severity vulnerabilities that threat actors could leverage to crash or take control of a computer system. Releasing the software update yesterday, OpenSSL downgraded the vulnerabilities from critical to high severity.
John Riggi, AHA’s national advisor for cybersecurity and risk, encourages all hospitals and health systems to “patch it before the 'bad guys' exploit it.”
The Department of Health and Human Services’ Health Sector Cybersecurity Coordination Center this week alerted the health sector to the OpenSSL vulnerabilities and encouraged organizations to test and deploy the patch once available.
Related News Articles
Headline
FBI warns Russian cybercriminals attacking devices using Cisco software with unpatched vulnerability
The FBI Aug. 20 released an advisory warning of malicious activity by Russian cyber actors targeting end-of-life devices running an unpatched vulnerability in…
Headline
The Cybersecurity and Infrastructure Security Agency, Environmental Protection Agency, National Security Agency, FBI and international agencies Aug. 13…
Headline
The Department of Justice Aug. 11 announced a series of actions taken against the BlackSuit ransomware group, also known as “Royal,” including the disruption…
Headline
The FBI, Cybersecurity and Infrastructure Security Agency and international agencies July 29 released a joint advisory on recent tactics by the Scattered…
Headline
Microsoft July 22 released an update on the ongoing cyberattacks to SharePoint servers used within organizations, attributing the incidents to China-based…
Headline
The FBI, Cybersecurity and Infrastructure Security Agency, Department of Health and Human Services, and Multi-State Information Sharing and Analysis Center…