CISA encourages OpenSSL users to deploy security update

The Cybersecurity & Infrastructure Security Agency encourages OpenSSL users and administrators to upgrade to version 3.0.7 to patch two high-severity vulnerabilities that threat actors could leverage to crash or take control of a computer system. Releasing the software update yesterday, OpenSSL downgraded the vulnerabilities from critical to high severity.
John Riggi, AHA’s national advisor for cybersecurity and risk, encourages all hospitals and health systems to “patch it before the 'bad guys' exploit it.”
The Department of Health and Human Services’ Health Sector Cybersecurity Coordination Center this week alerted the health sector to the OpenSSL vulnerabilities and encouraged organizations to test and deploy the patch once available.
Related News Articles
Headline
The Cybersecurity and Infrastructure Security Agency, Environmental Protection Agency, National Security Agency, FBI and international agencies Aug. 13…
Headline
The Department of Justice Aug. 11 announced a series of actions taken against the BlackSuit ransomware group, also known as “Royal,” including the disruption…
Headline
The FBI, Cybersecurity and Infrastructure Security Agency and international agencies July 29 released a joint advisory on recent tactics by the Scattered…
Headline
Microsoft July 22 released an update on the ongoing cyberattacks to SharePoint servers used within organizations, attributing the incidents to China-based…
Headline
The FBI, Cybersecurity and Infrastructure Security Agency, Department of Health and Human Services, and Multi-State Information Sharing and Analysis Center…
Headline
Microsoft July 19 issued an alert about active attacks from vulnerabilities targeting SharePoint servers used within organizations. The incidents have not…