SonicWall & Apple Issue Patches for Actively Exploited Zero-Days
Hackers are exploiting a critical zero-day vulnerability in SonicWall Secure Mobile Access (SMA) 1000 series appliances. SonicWall customers should ensure they update their firmware to the latest patched version as soon as possible to prevent exploitation of the flaw. The vulnerability is tracked as CVE-2025-23006 and has a CVSS severity score of 9.8 out of 10. The pre-authentication remote code execution vulnerability is in the SMA1000 Appliance Management Console (AMC) & Central Management Console (CMC). The vulnerability is due to the deserialization of untrusted data. The SonicWall Firewall and SMA 100 series products are not affected by the vulnerability. Under certain conditions, an unauthenticated attacker can exploit the vulnerability to execute arbitrary commands on the operating system. Researchers at Microsoft Threat Intelligence identified activity associated with the exploitation of the flaw. It is currently unclear to what extent the flaw is being exploited in the wild. SonicWall appliances are attractive targets for cybercriminals, and several ransomware groups...
Frederick Health Recovering from Ransomware Attack
Frederick Health in Maryland is investigating a ransomware attack, Holdrege Memorial Homes in Nebraska has mailed notification letters to individuals affected by a 2023 data breach, and Square Medical Group in Massachusetts has identified an email breach at an IT vendor. Frederick Health Recovering from Ransomware Attack Frederick Health Medical Group in Maryland announced on January 27, 2025, that it is currently dealing with a ransomware attack that forced it to take its systems offline. The attack is disrupting patient services due to the lack of access to IT systems, resulting in delays to certain services. Frederick Health has confirmed that all its facilities remain open with care provided using established backup and other downtime processes. Most appointments are continuing as scheduled. Frederick Health is working with third-party cybersecurity experts to investigate the breach, determine the extent of unauthorized access, and bring its IT systems back online quickly and safely while prioritizing patient care. The primary focus is restoring its IT systems; however, the...
Vi Living Settles Class Action Data Breach Lawsuit
Classic Resident Management Limited Partnership, which does business as Chicago-based Vi Living, the operator of 10 continuing care retirement communities in Arizona, California, Colorado, Florida, Illinois, and South Carolina, has agreed to settle a class action data breach lawsuit for an undisclosed sum. A network intrusion was detected on or around March 13, 2023, and it was confirmed that an unauthorized third party accessed files containing personal data and potentially copied that information from the network. The compromised data included names, addresses, dates of birth, Social Security numbers, financial information, and medical information. Up to 61,425 individuals were affected and had their information exposed or stolen and were notified about the data breach on September 9, 2023. A class action lawsuit Givony, et al. v. Classic Residence Management Limited Partnership d/b/a Vi – was filed in the Circuit Court of Cook County, Illinois that claimed the breach could have been prevented if reasonable and appropriate cybersecurity measures had been implemented. The lawsuit...
Recent HHS-OIG Exclusions and Penalties for Employing Excluded Individuals
One of the consequences of convictions in enforcement actions by the Department of Health and Human Services Office of Inspector General (HHS-OIG) and prosecutions by the Department of Justice is exclusion from participating in federal health care programs. The HHS OIG Exclusions List includes individuals and organizations that have received mandatory exclusion, such as being found guilty of Medicare or Medicaid fraud, patient abuse or neglect, or financial misconduct, and permissive exclusions, which come from convictions for fraud in non-healthcare programs and obstruction of an investigation or HHS-OIG audit. The length of the exclusion depends on the nature of the offense. For some offenses, there is no minimum exclusion period while others have a minimum exclusion period is 5 years for a first offense up to permanent exclusion for multiple offenses. Recent enforcement actions that have resulted in individuals being added to the HHS-OIG exclusion list include violations of the False Claims Act (FCA), the Anti-Kickback Statute (AKS), and the Physician Self-Referral (Stark) Law....
DOJ Drops Charges Against Surgeon Who Exposed Continuing Transgender Care at Texas Children’s
The Department of Justice (DOJ) has dropped all charges against Dr. Ethan Haim, a former surgeon at Texas Children’s Hospital who disclosed details of continuing transgender care on minors at Texas Children’s Hospital after the hospital had publicly stated that gender-affirming care for minors had stopped being provided. Haim faced multiple charges related to accessing the medical records of children who were not under his care and sharing that information with a reporter to blow the whistle on the practices. Haim maintained there was no wrongdoing, and both Haim and the reporter maintained all personally identifiable information in the shared documents had been redacted. Haim said his decision to speak with a reporter and blow the whistle on the continuing transgender care at Texas Children’s was because he felt the practices amounted to child abuse. At the time the alleged gender-affirming care was provided at Texas Children’s there was no federal or state law prohibiting that care. State laws have since been enacted prohibiting gender-affirming care for minors in Texas. The DOJ...



