When AI Agents Start “Moving Like Attackers”

A real-world wake-up call from a SOC lab experiment Executive Summary To safely evaluate autonomous SOC investigation agents, we built a controlled AWS-based lab environment that closely resembles a modern security operations ecosystem. We wanted to test how aggressive an AI agent would be when trying to complete a task. Would it fail at the […]
Protect Yourself and Your Organization from Holiday Scams

The holiday season is something many of us look forward to each year. Unfortunately, it’s a “most wonderful time of the year” for bad actors and cyber attackers as well. To help keep you and your team safe, we’ve put together a few tips to protect you from potential cyber threats. Tips to Protect Yourself […]
Living Off the Land Attacks: Unveiling the Illusion

When a threat actor performs a “Living Off the Land” (LOTL) attack, they use legitimate tools and processes within a system to carry out nefarious activities. Unlike traditional malware, LOTL tactics don’t rely on external malicious code; instead, they exploit what’s already in the environment. It’s like a magician transforming ordinary objects into confounding illusions. […]
Behind the Scenes of a Hospital Ransomware Attack

In television dramas and Hollywood movies, ransomware attacks are often made known by a flashy message that pops up on the computer screen or an ominous voice message left by the cyber criminal. In the case of one hospital, the incident presented itself far more subtly. Around 5:00 pm, the day after a holiday, calls […]
CISO Brief July 2026: Cybersecurity Threat Recap & Key Insights

Healthcare has always been prepared for cyber disruptions, but the playing field has changed drastically. Attackers can move faster, acquire capabilities more easily, and exploit numerous entry points into organizations. The emergence of ransomware-as-a-service has changed the game for cybercriminals. They no longer need to be tech geniuses; they can buy the tools they need […]
CISO Brief June 2026: Cybersecurity Threat Recap & Key Insights

Threat groups and nation-state actors attacking healthcare organizations continue to target the same pressure points: cloud access, exposed infrastructure, remote access, vulnerable perimeter systems, and trusted identities. That pattern matters. It tells healthcare cybersecurity teams where to focus their defenses, and gain a deeper understanding of the tactics threat groups use can help mitigate the […]
CISO Brief May 2026: Cybersecurity Threat Recap & Key Insights

Recent activity associated with ShinyHunters-branded extortion campaigns reinforces a critical shift in healthcare cybersecurity: attackers are increasingly targeting identity, SaaS platforms, and trusted third-party access paths rather than relying only on malware or traditional ransomware deployment. The FBI has previously warned that recent campaigns target Salesforce environments to steal data and extort victims, including activity […]
CISO Brief April 2026: Cybersecurity Threat Recap & Key Insights

The high-profile cybersecurity incident at Stryker last month was a sharp reminder that cybersecurity events do not need to directly impact connected medical devices to still disrupt patient care. On March 11, Stryker disclosed a cyberattack that caused a global disruption to parts of its Microsoft environment, affecting order processing, manufacturing, and shipping. While the […]
February 2026 CISO Brief: Privacy Deadlines, Clinical Impact, and Persistent Attack Paths

As healthcare organizations move closer to the February 16, 2026, compliance deadline for the updated 42 CFR Part 2 requirements, they are doing so in an environment defined by persistent ransomware activity, slow remediation of known exploited vulnerabilities, expanding clinical attack surfaces, and growing use of unmanaged technologies. This month’s Brief focuses on how these […]
Preparation Changes Outcomes In Ransomware Attacks

In our latest webinar, we conducted a Red Team/Blue Team post-mortem on a real ransomware attack that occurred last year at Frederick Health Medical Group in Maryland. The system has more than 4,000 clinicians and staff across 25 locations. The Frederick Health attack exposed more than 900,000 patient records and hampered operations for a number […]