"LA County Health Services: Patients' Data Exposed in Phishing Attack"

"LA County Health Services: Patients' Data Exposed in Phishing Attack"

​The Los Angeles County Department of Health Services recently disclosed a data breach after thousands of patients' personal and health information was exposed in a data breach resulting from a recent phishing attack impacting over two dozen employees. This integrated health system operates the public hospitals and clinics in L.A. County (the most populous county in the United States) and is the second largest public health care system in the country after NYC Health + Hospitals.

Submitted by Adam Ekwall on

"Kaiser Permanente: Data Breach May Impact 13.4 Million Patients"

"Kaiser Permanente: Data Breach May Impact 13.4 Million Patients"

Healthcare service provider Kaiser Permanente recently disclosed a data security incident that may impact 13.4 million people in the United States.  Kaiser Permanente is an integrated managed care consortium and one of the largest nonprofit health plans in the U.S. It operates 40 hospitals and 618 medical facilities in California, Colorado, the District of Columbia, Georgia, Hawaii, Maryland, Oregon, Virginia, and Washington.

Submitted by Adam Ekwall on

"Over 1,400 CrushFTP Instances Vulnerable to Exploited Zero-Day"

"Over 1,400 CrushFTP Instances Vulnerable to Exploited Zero-Day"

According to the Shadowserver Foundation, over 1,400 CrushFTP Managed File Transfer (MFT) software instances are vulnerable to a zero-day. The Server-Side Template Injection (SSTI) bug, tracked as CVE-2024-4040 with a CVSS score of 9.8, enables remote attackers to escape the Virtual File System (VFS) sandbox, gain administrative privileges, and execute arbitrary code. This article continues to discuss the vulnerability of more than 1,400 CrushFTP servers to an actively exploited zero-day for which Proof-of-Concept (PoC) code has been published.

Submitted by grigby1 CPVI on

"Severe Flaws Disclosed in Brocade SANnav SAN Management Software"

"Severe Flaws Disclosed in Brocade SANnav SAN Management Software"

Several Brocade SANnav Storage Area Network (SAN) management application flaws could compromise vulnerable appliances. Pierre Barre, an independent security researcher, found and reported 18 flaws in all versions up to 2.3.0. Due to incorrect firewall rules, insecure root access, Docker misconfigurations, and lack of authentication and encryption, an attacker can intercept credentials, overwrite arbitrary files, and breach the device. This article continues to discuss the potential exploitation and impact of the Brocade SANnav SAN security vulnerabilities.

Submitted by grigby1 CPVI on

"Fake Job Interviews Target Developers With New Python Backdoor"

"Fake Job Interviews Target Developers With New Python Backdoor"

A new campaign called "Dev Popper" is using fake job interviews to trick software developers into installing a Python Remote Access Trojan (RAT). To make the interview seem legitimate, developers are asked to download and run code from GitHub.

Submitted by grigby1 CPVI on

"Most People Still Rely on Memory or Pen and Paper for Password Management"

"Most People Still Rely on Memory or Pen and Paper for Password Management"

Bitwarden surveyed 2,400 people in the US, UK, Australia, France, Germany, and Japan about password habits. Twenty-five percent of respondents globally reuse passwords across 11 to over 20 accounts, and 36 percent use personal information in their credentials publicly accessible on social media platforms and online forums. Most respondents use memory (53 percent) and handwriting (34 percent) for work account passwords.

Submitted by grigby1 CPVI on

Metrics for Large Language Model-Generated Proofs in a High-Assurance Application Domain    

Submitted by Amy Karns on

Large Language Model (LLM) Artificial Intelligence (AI) systems have generated significant enthusiasm in the computer science research community for their potential to perform a number of computer language processing tasks, including source code generation from natural language descriptions, source-to-source translation, and the like.  We are interested in the use of  LLMs for automated theorem proving, particularly proof repair.

"Over 850 Vulnerable Devices Secured Through CISA Ransomware Program"

"Over 850 Vulnerable Devices Secured Through CISA Ransomware Program"

According to the Cybersecurity and Infrastructure Security Agency (CISA), the US government and critical infrastructure entities were sent 1754 ransomware vulnerability notifications under the Ransomware Vulnerability Warning Pilot (RVWP) program in 2023, resulting in 852 vulnerable devices being secured or taken offline. The highest number of alerts were sent to government facilities (641), which encompasses a range of federal, state, and local government organizations, including schools and higher education facilities.

Submitted by Adam Ekwall on

Healthcare and Pharma Cybersecurity Summit

"The Healthcare & Pharma Cybersecurity Summit is a one-of-a-kind conference designed for exclusively invited Executives in need of innovative solutions to protect their company’s critical data & infrastructure. This next-generation event will provide a virtual space for business leaders to learn about the latest cyber threat landscape and evaluate the industry’s most cutting-edge solutions by directly connecting them with emerging and established solution providers, subject matter experts and powerful cyber thought leaders."

Hartford Cybersecurity Summit

"The Second Annual Hartford Cybersecurity Summit connects C-Suite & Senior Executives responsible for protecting their companies’ critical infrastructures with innovative solution providers and renowned information security experts. Admission gives you access to all Interactive Panels, Discussions, Catered Breakfast, Lunch & Cocktail Reception."

Subscribe to