H-ISAC TLP White: Informational: HC3: Monthly Cybersecurity Vulnerability Bulletin Jan 20, 2023

On January 19, 2022, the Health Sector Cybersecurity Coordination Center (HC3) shared a report "December 2022 Vulnerability Bulletin" regarding vulnerabilities impacting information systems relevant to the health sector. This includes the monthly Patch Tuesday vulnerabilities released by several vendors on the second Tuesday of each month, along with mitigation steps and patches. Vulnerabilities for this month are from Microsoft, Google/Android, Apple, Intel, Cisco, SAP, Citrix, VMWare, and Fortinet. 

HC3 recommends patching for all vulnerabilities with special consideration to each vulnerability criticality category against the risk management posture of the organization. As always, accountability, proper inventory management and device hygiene along with asset tracking are imperative to an effective patch management program.

Please see the report below for details.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272