FortiManager Zero-Day Has Been Exploited Since July 2024
A zero-day vulnerability in Fortinet’s FortiManager appliances is being mass exploited by at least one threat actor. The first known instance of exploitation was on June 27, 2024. The critical vulnerability is tracked as CVE-2024-47575 has been assigned a CVSS v3.1 severity score of 9.8. The vulnerability, dubbed FortiJump by security researcher Kevin Beaumont, is due to missing authentication for a critical function in the FortiManager fgfmd daemon and allows an unauthenticated attacker to use a FortiManager device to execute arbitrary code or commands against vulnerable FortiManager devices. In order to successfully exploit the vulnerability, an attacker requires a valid Fortinet device certificate. The certificate could be obtained from an existing Fortinet device and could be reused for multiple attacks. According to Fortinet, attacks exploiting the vulnerability have involved an automated script that exfiltrates files from FortiManager. Those files contain IP addresses, credentials, and device configurations. So far, Fortinet has not detected any modified databases or...
Two Men Indicted for Role in February 2024 Cyberattack on Cedars-Sinai
Two Sudanese nationals have been charged for their role in a series of cyberattacks on corporate networks, government agencies, and critical infrastructure entities in the United States, including a February 2024 attack on Cedars-Sinai Medical Center in Los Angeles that caused patients to be diverted to alternative facilities for 8 hours. The two men – Ahmed Salah Yousif Omer, 22, and Alaa Salah Yusuuf Omer, 27 – are alleged members of an online cybercriminal group called Anonymous Sudan, a group that has been active since mid-January 2023 and has conducted more than 35,000 distributed denial-of-service (DDoS) attacks worldwide. While many cybercriminal groups are primarily financially motivated, Anonymous Sudan claims to be a hacktivist group that conducts attacks against targets it considers to be anti-muslim, in part in support of Palestine, although the group has attempted to extort money from some victims. Due to the sophistication of the group’s attacks and the financial resources required, there have been suggestions that the group has significant backing, and...
Patient Data Compromised in Email Breaches in Indiana, New York & Wisconsin
Email accounts have been compromised in security incidents at Tower Clock Eye Center in Wisconsin, DMEScripts in Indiana, and General Physician, P.C. in New York. Tower Clock Eye Center Tower Clock Eye Center in Green Bay, Wisconsin, has identified unauthorized activity in its email system. A security breach was detected on July 9, 2024, and action was taken to prevent further unauthorized access. Third-party cybersecurity experts were engaged to investigate and determine the extent of the unauthorized activity. The investigation confirmed that a limited number of employee email accounts had been accessed by an unauthorized third party who may have viewed or obtained patient data. The breach was confined to email accounts, which were found to contain limited patient data. The types of data involved varied from individual to individual and may have included names in combination with one or more of the following: address, date of birth, financial account number, payment card number, medical record number, patient ID or account number, Medicare number, Medicaid number, health...
Texas Doctor Sues HHS to Prevent Enforcement of Reproductive Health Care Privacy Rule
A lawsuit has been filed against the Department of Health and Human Services (HHS), HHS Secretary Xavier Becerra, the Office for Civil Rights (OCR), and OCR Director Melanie Fontes Rainer over the recent update to the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule to strengthen reproductive health care privacy. The HIPAA Privacy Rule to Support Reproductive Health Care Privacy Final Rule was published in the Federal Register on April 26, 2024, took effect on June 25, 2024, and the compliance date is December 23, 2024. The new rule was introduced to strengthen privacy protections for reproductive healthcare information and prevent HIPAA-regulated entities from disclosing reproductive health care information to law enforcement when that information is sought to investigate or impose liability on individuals or healthcare providers for seeking, obtaining, or providing legal reproductive health care. The lawsuit was filed by attorneys from Alliance Defending Freedom in the United States District Court for the Northern District of Texas, Amarillo Division,...
September 2024 Healthcare Data Breach Report
Apart from a blip in August, the number of healthcare data breaches reported each month has fallen from an annual high of 97 breaches in March 2024. September saw the lowest number of healthcare data breaches since May 2020, with just 34 data breaches of 500 or more records reported to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR). In the first half of the year it was looking like another new record would be set for healthcare data breaches, but as the year draws to an end, 2024 is now looking like it will be a rare year where the number of healthcare data breaches reduces year-over-year. So far in 2024, 531 data breaches of 500 or more records have been reported to OCR. In the first half of 2024, data breaches were reported at a rate of 67 a month. In the second half of 2024, data breaches have been reported at a rate of 44 a month. Across the 34 reported data breaches, the records of 4,839,018 individuals were exposed or impermissibly disclosed – The third lowest monthly total of the year to date, and well below the average of 7,082,007 records...



