The Cybersecurity and Infrastructure Security Agency and Department of Energy this week recommended organizations take steps to prevent cyber actors from accessing Uninterruptible Power Supply devices through the internet. The agencies said they are aware of threat actors gaining access to a variety of internet-connected UPS devices, often through unchanged default usernames and passwords. 

The FBI also alerted the private sector this week to ransomware attacks on local government agencies that have resulted in disrupted operational services, risks to public safety and financial losses. 

John Riggi, AHA’s national advisor for cybersecurity and risk, said, “It is noted that one of the most effective methods to mitigate the cyber risk to UPS devices and systems is quite simple — disconnect them from the internet. This alert should also be shared with all facilities’ engineers and those involved in the planning, design and construction phases of hospitals. In regard to the FBI alert, attacks on local government agencies have also resulted in disruptions to public health services.  This alert also contains a comprehensive list of strategic and technical ransomware risk mitigation steps, which are applicable to hospitals and health systems.”

Headline
In this conversation, John Riggi, AHA national advisor for cybersecurity and risk, and Scott Gee, AHA deputy national advisor for cybersecurity and risk, break…
Headline
Boston Scientific announced Sept. 8 that the network disruption to its remote monitoring services following an Aug. 25 cyber incident has been resolved. The…
Headline
The FBI and the Department of Justice Aug. 26 announced the disruption of a China-linked hacking group known as QTFY. The group, which also identifies as QT…
Headline
Boston Scientific, a large supplier of medical devices, said in an Aug. 26 statement posted on its website that on Aug. 25 it “identified a cybersecurity…
Headline
Epic’s MyChart has shared examples from potential phishing schemes observed as recently this month that include email messages linking to a fake MyChart…
Headline
The National Security Agency and other federal agencies released a joint advisory Aug. 18 warning of active cyber threats to Siemens S7 Series programmable…