The Cybersecurity and Infrastructure Security Agency recently required federal agencies to take emergency action to protect against actively exploited vulnerabilities in the Ivanti Connect Secure and Ivanti Policy Secure remote access gateways.

In addition, CISA, the FBI and Environmental Protection Agency recently published a best practices guide for water and wastewater system incident response.

“These alerts primarily address the government and water and waste water sectors,” said John Riggi, AHA’s national advisor for cybersecurity and risk. “However, they identify cyber vulnerabilities and defensive measures that have relevance for the health care sector. Although the CISA emergency directive does not apply to private sector organizations, it would be prudent for hospitals and health systems to identify instances of Ivanti present in their networks or those of business associates that have network or data access, to ensure the remediation steps in the alert are followed promptly. The water and wastewater guide provides practical incident response guidance for operational technology and for hospitals and health systems that operate their own water and wastewater treatment facilities and will help them in assessing the cyber readiness of their external water and waste water treatment facilities for emergency preparedness planning purposes.” 

For more information on this or cyber and risk matters contact Riggi at jriggi@aha.org. For the latest cyber and risk threat information and resources visit www.aha.org/cybersecurity
 

Headline
The Administration for Strategic Preparedness and Response has released a new cybersecurity module for organizations to conduct risk assessments. The free…
Perspective
Public
As the world has learned in recent years, today’s conflicts are fought with many weapons, and cyber warfare is an integral part of the arsenal.As of this…
Headline
The FBI is reminding critical infrastructure organizations to implement mitigations from a June 2025 fact sheet on potential actions by Iranian-affiliated…
Headline
The Cybersecurity and Infrastructure Security Agency Feb. 26 released a report that updates findings from last year on RESURGE malware used to gain covert…
Headline
U.S. and international agencies Feb. 25 released guidance on protecting Cisco Software-defined Wide-area Networking systems from exploitation by malicious…
Headline
The National Security Agency has released two phases of its Zero Trust Implementation Guidelines for organizations to improve their zero trust architecture.…