Cybersecurity

Cyber Threat Intelligence, Alerts and Reports

As part of the AHA’s commitment to helping hospitals and health systems prepare for and prevent cyber threats, we have gathered the latest government cyber threat intelligence and alerts and Health Information Sharing and Analysis Center (H-ISAC) reports.

You may be asked to enter your AHA member credentials to view certain reports and intelligence alerts.

Cybersecurity & Risk Advisory

Learn how AHA can help hospitals and health systems prepare for and mitigate cyber threats through the expertise of John Riggi, AHA’s National Advisor for Cybersecurity and Risk.

Learn More

On August 18, 2021 CISA released the fact sheet Protecting Sensitive and Personal Information from Ransomware-Caused Data Breaches to address the increase in malicious cyber actors using ransomware to exfiltrate data and then threatening to sell or leak the exfiltrated data if the victim does not…
In July 2021, vulnerabilities in common information systems relevant to the healthcare sector have been disclosed to the public and warrant attention.
H-ISAC TLP Green Ransomware Data Leak Sites Report for August 19, 2021.
A zero-day command injection vulnerability has been identified in Fortinet’s FortiWeb web application firewall (WAF) and effects versions 6.3.11 and earlier.
A zero-day command injection vulnerability has been identified in Fortinet’s FortiWeb web application firewall (WAF) and effects versions 6.3.11 and earlier.
REvil Overview History of GandCarb Revil: A Continuation of GandCrab Operations REvil – Who Are They? Heat Map Technology and Capabilities Historic Attacks Mitigations The Future of REvil  
Weekly threat brief from the HHS Health Sector Cybersecurity Coordination Center (HC3). This week's briefing is on REvil/Sodinokibi Ransomware
Major Headlines, US Snapshots, US Vaccinations, US Variant Cases, key Highlights, as well as key Statistics, Vaccine and Treatment information, US Restrictions and the Back to Normal Index related to the novel coronavirus pandemic.
Executive Summary BlackBerry identified the following products are affected by an integer overflow vulnerability (CVE-2021-22156) with CVSS Score 9.0: BlackBerry QNX Software Development Platform (SDP) version 6.5.0SP1 and earlier, QNX OS for Medical 1.1 and earlier, and QNX OS for Safety 1.0.1.…
This edition of Hacking Healthcare begins by examining an alarming report that a secret government watchlist may have been left exposed online, raising questions about how concerned companies should be over information sharing and mandatory reporting.