Rhysida Ransomware Group Claims Responsibility for AXIS Health System Attack
AXIS Health System, a Colorado-based network of behavioral health facilities, has confirmed via its website that it has experienced a cyber incident. Few details have been released about the nature of the attack other than its incident response protocol has been initiated and an investigation is underway to determine the nature and scope of the incident. “If it is determined that patient data was impacted, affected individuals will be notified directly by mail,” explained AXIS Health in its website notice. Patient data does appear to have been stolen in the attack, according to the Rhysida ransomware group. Rhysida is a ransomware-as-a-service group that is known to attack healthcare organizations. An H1 2024 analysis by Barracuda Networks indicates that Rhysida was behind 8% of known ransomware attacks, between August 2023 and July 2024, and 38% of the group’s victims were healthcare organizations. Recent attacks include BayHealth Healthcare System in Delaware, Community Care Alliance in Rhode Island, Ann & Robert H. Lurie Children’s Hospital in Chicago, and Prospect Medical...
Gryphon Healthcare Notifies 400,000 Patients About Recent Cyberattack
Gryphon Healthcare has recently confirmed a security incident involving unauthorized access to files containing the protected health information (PHI) of almost 400,000 individuals. Gryphon Healthcare is a Houston, TX-based provider of revenue cycle, coding, compliance, consultancy, and management services to healthcare providers such as hospitals, EMS providers, emergency departments, independent labs, medical imaging centers, ambulatory surgery centers, and physician practices. The security incident occurred at a partner for whom Gryphon Healthcare provides medical billing services. Gryphon Healthcare learned about the third-party incident on August 13, 2024, and following a comprehensive review of the affected files determined that the PHI of 393,358 patients of its healthcare clients had been exposed and potentially obtained by an unauthorized individual. Further information on the nature of the attack, such as whether ransomware was involved, was not disclosed. It is also unclear how many of its healthcare provider clients were affected. The file review was completed on...
Threat Actors Actively Exploiting Critical Fortinet; Veeam Backup & Replication Vulnerabilities
Ransomware actors have been observed exploiting a critical vulnerability in Veeam Backup & Replication, a data protection and recovery solution for virtual, physical, network-attached storage, and cloud-native environments. The deserialization of untrusted data vulnerability – CVE-2024-40711 – can lead to remote code execution and has a CVSS severity score of 9.8. According to Sophos, ransomware groups have been observed using compromised VPN credentials to access VPN gateways without multifactor authentication enabled, and then exploiting CVE-2024-40711 to create new local administrator accounts to deploy Akira and Fog ransomware. Sophos has tracked several attacks in the past month that exploited the vulnerability. While ransomware deployment was not always successful, in one of the attacks the threat actor successfully dropped Frog ransomware on an unprotected Hyper-V server and used rclone to exfiltrate data. The vulnerability affects Veeam Backup & Replication version 12.1.2.172, and potentially also unsupported versions. Veeam released a patch to fix the...
CISA Warns F5 BIG-IP Users About Abuse of Unencrypted Cookies
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning to F5 BIG-IP users that threat actors are abusing unencrypted persistence F5 BIG-IP cookies to map internal servers and identify potentially vulnerable devices on the network that can be attacked. F5 BIG-IP is a widely used suite of hardware and software solutions for managing and securing network traffic. One of the core modules is the Local Traffic Manager (LTM), which is used to manage traffic and spread it across different servers to optimize load-balanced server resources and ensure high availability. To maintain session consistency, the LTM module uses persistence cookies to ensure traffic from specific clients is delivered to the same server each time. According to CISA, threat actors have been observed leveraging the unencrypted persistence cookies that are managed by the LTM module during the planning stage of a cyberattack to enumerate other non-internet-facing devices on the network. The information gathered from the cookies, which can include IP addresses, port numbers, and load...
New York Implements New Cybersecurity Regulations For General Hospitals
On October 2, 2024, New York implemented new legislation that requires “general hospitals” in the state of New York to implement a raft of cybersecurity measures. Prior to the implementation of the new law, there were no state cybersecurity regulations for hospitals regarding the safeguarding of patients’ protected health information (PHI) and personally identifying information (PII), only the minimum standards of the federal Health Insurance Portability and Accountability Act (HIPAA). Under state law, general hospitals are classed as healthcare institutions that “provide medical or medical and surgical services primarily to in-patients by or under the supervision of a physician on a twenty-four-hour basis with provisions for admission or treatment of people in need of emergency care.” Currently, there are more than 190 general hospitals in the state of New York that are required to comply with the new cybersecurity requirements. The new law does not apply to diagnostic centers, treatment centers, outpatient care facilities, nursing homes, public health centers, or...



