Microsoft July 22 released an update on the ongoing cyberattacks to SharePoint servers used within organizations, attributing the incidents to China-based threat actors. The company said the attacks include state-sponsored actors from the Linen Typhoon and Violet Typhoon groups, as well as China-based actor Storm-2603. The attacks have not impacted SharePoint Online in Microsoft 365. 

The new announcement includes updated indicators of compromise and clarified mitigation and protection guidance. 

The AHA July 21 released an advisory with additional information on the attacks. 

For more information on this or other cyber and risk issues, contact Scott Gee, AHA deputy national advisor of cybersecurity and risk, at sgee@aha.org. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity.

Headline
The National Security Agency and other federal agencies released a joint advisory Aug. 18 warning of active cyber threats to Siemens S7 Series programmable…
Headline
A joint advisory released Aug. 19 by the FBI, Cybersecurity and Infrastructure Security Agency, and the Department of Health and Human Services provides…
Headline
The Department of Health and Human Services Aug. 14 released a request for comments through the Office of the National Coordinator for Health IT on a proposed…
Perspective
Public
Every day, hospitals and health systems perform a remarkable balancing act. They invest in talented caregivers, advanced technologies, innovative partnerships…
Headline
U.S. and international agencies released a joint cybersecurity advisory Aug. 10 warning of actions by Gunra ransomware. Gunra is a ransomware-as-a-service…
Headline
The Cybersecurity and Infrastructure Security Agency and other U.S. and international agencies July 29 released joint guidance outlining minimum elements for a…