Cisco Umbrella Pricing
It is not easy to find much information when you want to compare Cisco Umbrella pricing vs Cisco competitor pricing, but there are good reasons for this – notwithstanding it is possible Cisco may not want its flagship suite of DNS security solutions compared on price alone. If you want to compare Cisco Umbrella pricing vs Cisco competitor pricing, you are likely to be taken down a lot of dead ends. There are no prices advertised on the Cisco website, and many other sources of information are either inaccurate or out of date. Additionally, due to the number of optional extras that businesses can add on to one of four Umbrella packages, the final price may be a lot different than the Cisco Umbrella license cost alone. Furthermore, the license cost is subject to a number of variables. For example: The number of licenses required The length of the subscription Whether the subscription is paid all upfront If not, whether it is paid monthly, quarterly, or annually The region in which a business is located Discounts negotiated with Cisco, a reseller, or MSP Most of the optional extras are...
UMC Physicians Discovers Patient Information Was Uploaded to Unapproved and Unsecured Cloud Service
The Lubbock, TX-based medical group UMC Physicians is alerting patients of UMC Southwest Gastroenterology that some of their protected health information has been exposed as a result of errors of judgement by two of its employed providers. Those providers had each set up a Google shared drive which was used to track follow up tasks related to the provision of care to patients. While the shared drives were set up with good intentions and were intended to help improve the care provided to patients, the providers used an unapproved cloud storage solution and patient data was inadvertently stored on an unsecured network. UMC Physicians discovered the policy violation on March 12, 2019 and launched an investigation to determine which patients’ protected health information had been exposed. During the course of that investigation, UMC Physicians determined that one of the providers had also been forwarding emails containing patient information to an unsecured Gmail account. The types of information that had been stored on the unsecured network and emailed to the Gmail account included...
Microsoft Patches Critical Flaw That Could be Exploited in WannaCry-Style Malware Attacks
On Tuesday May 14, 2019, Microsoft released a patch to fix a ‘wormable’ flaw in Windows, similar to the vulnerability that was exploited in the WannaCry ransomware attacks in May 2017. The flaw is a remote code execution vulnerability in Remote Desktop Services – formerly Terminal Services – that can be exploited via RDP. The flaw (CVE-2019-0708) can be exploited by sending specially crafted requests via RDP to a vulnerable system. No authentication is required and the flaw can be exploited without any user interaction. If exploited, malware could propagate from one compromised computer to all other vulnerable computers on a network. If ransomware exploited the vulnerability, healthcare organizations could experience widespread file encryption and major disruption to operations. Microsoft has not received any reports to suggest the flaw is being actively exploited at present, but it is almost certain that exploits will be developed for the vulnerability and that those exploits will be incorporated into malware. The vulnerability is not present in Windows 8 and Windows 10, only...
DHS Issues Security Best Practices to Mitigate Risks Associated with Office 365 Migrations
Body: The DHS’ Cybersecurity and Infrastructure Security Agency (CISA) has issued a new analysis report highlighting some of the common risks and vulnerabilities associated with transitioning from on-premise mail services to cloud-based services such as Microsoft Office 365. The report details best practices to adopt to manage risks and prevent user and mailbox compromises. Many healthcare organizations have realized the benefits of transitioning to cloud-based email services yet lack the in-house expertise to manage their migrations. Many have used third-party service providers to migrate their email services to Office 365. CISA notes that use of third parties to manage Office 365 migrations has led to an increase in security incidents. Over the past 6 months, CISA has had several engagements with customers who have used third-party service providers to manage their migrations and discovered a range of different Office 365 configurations that lowered organization’s security posture and left them vulnerable to phishing and other cyberattacks. CISA notes that the majority of those...
Oregon State Hospital and New York Episcopal Health Services Report Phishing Attacks
Oregon State Hospital has announced that the protected health information (PHI) of some of its patients was potentially compromised as a result of an employee being duped by a spear phishing email. The email was received on May 3 and the employee responded on May 6. The response resulted in the disclosure of email login credentials. The unauthorized access was detected quickly, and steps were rapidly taken to secure the account. The employee responded to the message at 9:50 AM and Oregon State Hospital’s IT team detected the breach at 10:30 AM and secured the account. The limited time the attacker had access to the account reduced the potential for any information in emails and email attachments to be viewed or copied. Currently, Oregon State Hospital is unaware whether the attacker gained access to patients protected health information during the 40 minutes that the account was accessible, and the hospital has yet to determine which patients have been affected. A third-party cybersecurity company has been hired to conduct an analysis of the compromised account to determine which...



