CISO Brief: AI Zero-Days & Holiday Threats; What Healthcare Must Prepare for Now

Over the past month, AI vulnerabilities, delayed breach disclosures, and geopolitical tensions have created new challenges for cybersecurity leaders in healthcare. In this CISO Brief for June 2025, we take a closer look at the month’s top threats and headline-making events – from the first known AI zero-day exposure in Microsoft 365 Copilot (“EchoLeak”) to […]
CISO Brief: May 2025 Recap – Ransomware Trends, Endpoint Evasion, and the Kettering Health Breach

In our CISO Brief looking at May 2025, we saw threat actors sharpening their techniques and targeting healthcare organizations in ways that challenge our traditional security assumptions. New endpoint evasion tactics, a shift in ransomware strategy targets, and the ransomware group that targeted DaVita may have struck again. This time, it was a different healthcare […]
Healthcare Cybersecurity Threats: February 2025

February showed attackers that they don’t need new tricks when old ones still work. Cybercriminals aren’t just relying on past playbooks. They’re refining their methods, launching more targeted phishing campaigns, weaponizing zero-click vulnerabilities, and turning trusted tools into attack vectors. Here is a look at six cybersecurity threat alerts from the past month. Fortinet’s Super […]
BianLian Ransomware Mail Scam Alert: Copycat or Credible?

A new twist in the cybersecurity threat landscape: healthcare organizations recently reported receiving physical letters claiming to be from the BianLian ransomware group. But as TJ Ramsey, Fortified Health Security’s Senior Director of Threat Operations, explains, this may not have been the real deal. “There is no indication this group was really involved. This seems […]
April 2025 CISO Brief: Behind the Cyber Threat Headlines

Fortified’s Threat Services Team tracks the most pressing cyber threats targeting the healthcare sector each month. April’s activity surrounding PipeMagic ransomware, Oracle’s dual breach allegations, and the news regarding the DaVita ransomware attack illuminate a stark reality: the healthcare sector is under sustained siege from sophisticated threat actors intensifying their focus on healthcare’s legacy systems, […]
10 Ways to Secure Yourself from 2FA Bypass Attacks

Phishing is one of the greatest contributors to healthcare data breaches, and these attacks are on the rise. As tactics become increasingly sophisticated, it’s crucial to take proactive steps to protect your organization and prevent cybercriminals from gaining access to sensitive information. Recently, reports have surfaced about a new phishing 2FA bypass attacks (two-factor authentication). A […]
Biggest Healthcare Spam Threats (And How to Avoid Them)

The practice of spam began innocently enough in 1978 (yes, really), when Gary Thuerk, a marketing associate at Digital Equipment Corporation sent a promotional mass-email to 400 recipients touting the arrival of the company’s new T-series of VAX systems. The reaction was swift, fierce, and familiar: unadulterated annoyance. Today, the practice of spam continues in […]
Healthcare Cybersecurity Threats: June 2023

During the summer months, threat actors often escalate their activities, taking advantage of staffing shortages among IT teams, and leaving many organizations more susceptible to an attack. This trend was particularly evident last month. As June unfolded, healthcare cybersecurity teams found themselves navigating critical network flaws and multiple patching vulnerabilities, including MOVEit, Fortinet, and Barracuda. […]
Healthcare Cybersecurity Threats: August 2023

Vulnerabilities from two very different IT manufacturers and device types were notable threats in August. They serve as a reminder that continuous patch management and replacement of End of Life (EOL) technology is fundamental to cybersecurity. The severity of these vulnerabilities should not be underestimated, as both allow significant access to the network and enable […]
Healthcare Cybersecurity Threats: October 2023

More than 87 million. That’s the estimated number of patient records that have been compromised as of the end of October 2023, according to data gathered from the Office for Civil Rights (OCR). That’s a 55 percent year-over-year increase from 2022. Throughout the month of October, threat actors increasingly exploited vulnerabilities and used nefarious tactics […]