SonicWall SMA Vulnerabilities Actively Exploited in Attacks
Users of SonicWall Secure Mobile Access (SMA) appliances have been warned about three vulnerabilities that are potentially being targeted by threat actors in attacks. The vulnerabilities are not zero-days, having been previously disclosed and patched by SonicWall in December 2023 and April 2025. Evidence has emerged that threat actors are actively targeting the flaws to attack unpatched SMA appliances. The vulnerabilities are tracked as CVE-2021-20035, CVE-2023-44221, and CVE-2024-38475, and all three have been added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerability (KEV) Catalog. SonicWall issued a warning about exploitation of the CVE-2021-20035 vulnerability in mid-April, with a further announcement made about potential exploitation of the other two vulnerabilities at the end of last month. CVE-2021-20035 is a high-severity flaw from 2021 that affects SMA 200, SMA 210, SMA 400, SMA 410, and SMA 500v devices running versions 9.0.0.10-28sv and earlier, 10.2.0.7-34sv and earlier, and 10.2.1.0-17sv and earlier. The vulnerability is thought...
Two High-Severity Vulnerabilities Identified in MicroDicom DICOM Viewer
Two high-severity remotely exploitable vulnerabilities have been identified in MicroDicom DICOM Viewer that can be exploited in a low-complexity attack. Successful exploitation of the vulnerabilities could result in memory corruption, code execution, and unauthorized access to patient data. MicroDicom DICOM Viewer is free-to-use software for viewing and manipulating DICOM medical images. The software can also be used to burn DICOM images onto CDs and DVDs that can be viewed without having to install the software. The out-of-bounds read and write vulnerabilities require user interaction to exploit. A user would need to be convinced to open a malicious DCM file that had been specially crafted by a threat actor, such as in a social engineering or phishing attack. The vulnerabilities were identified by security researcher Michael Heinzl, who reported them to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). At present, there are no indications that the vulnerabilities have been exploited in attacks; however, users are advised to update to the latest version of the...
Orthopaedic Specialists of Connecticut & DATS in Pennsylvania Announce 22K-Record Data Breaches
Data breaches have recently been confirmed by Orthopaedic Specialists of Connecticut, Drug and Alcohol Treatment Services, Inc. in Pennsylvania, and Brainard Surgery Center in Ohio. The Texas Health and Human Services Commission has recently confirmed that a previously announced data breach has affected 33,500 more individuals than previously thought. Orthopaedic Specialists of Connecticut Orthopaedic Specialists of Connecticut has notified 22,541 patients about a hacking incident that saw unauthorized individuals gain access to its network on March 2, 2025. Immediate action was taken to prevent further unauthorized access, and a forensic investigation was launched, with assistance provided by third-party cybersecurity experts. While data theft was not confirmed, the possibility that files containing patient data had been copied from its network could not be ruled out. The file review was completed in April 2025 and confirmed that the exposed data included first and last names, dates of birth, Social Security numbers, health insurance numbers, and medical information. The types of...
What is HIPAA?
HIPAA is an acronym for the Health Insurance Portability and Accountability Act – an Act primarily intended to reform the health insurance industry which also led to the adoption of federal standards for safeguarding patients’ “Protected Health Information” (PHI) and ensuring the confidentiality, integrity, and availability of PHI created, maintained, processed, transmitted, or received electronically (ePHI). The HIPAA Privacy Rule The federal standards for safeguarding patients’ PHI are known as the HIPAA Privacy Rule. This Rule stipulates what uses and disclosures of PHI by “covered” healthcare providers are required or permitted, and which require a patient’s consent or authorization. All covered healthcare providers are required to inform patients of how they may use and disclose PHI via a HIPAA Notice of Privacy Practices. The HIPAA Notice of Privacy Practices must also inform patients of the rights they have over their health information. These rights include: The right to request privacy protections for PHI For example, patients can request that a healthcare provider does...
Somnia’s $2.4 Million Data Breach Settlement Receives Final Approval
A $2.4 million settlement has received final approval from the court to resolve a class action lawsuit against Somnia Inc. and others over a 2022 cyberattack and data breach. Somnia manages anesthesiology services at more than a hundred surgery centers across the country. In the summer of 2022, Somnia experienced a cyberattack that saw hackers access parts of its network where patient information was stored. The forensic investigation confirmed that names, Social Security numbers, dates of birth, driver’s license numbers, financial account information, health insurance policy numbers, medical record numbers, Medicaid/Medicare IDs, and health information were potentially compromised. More than 450,000 individuals had their information exposed in the incident. Several lawsuits were filed in response to the breach against Somnia, Anesthesia Services of San Joaquin, Palm Springs Anesthesia Services, Resource Anesthesiology Associates of IL, Resource Anesthesiology Association of NM, and Anesthesia Associates of El Paso. The lawsuits were consolidated into a single lawsuit as they all...



