The Cybersecurity and Infrastructure Security Agency has created a webpage to provide the latest public information and vendor-supplied advisories on a critical remote code execution vulnerability affecting Apache Log4j software library versions 2.0-beta9 to 2.14.1. CISA urges organizations to review the webpage and immediately upgrade to Log4j version 2.15.0 or apply the appropriate vendor-recommended mitigations, because an unauthenticated remote actor could exploit this vulnerability to take control of an affected system. CISA and its Joint Cyber Defense Collaborative partners are tracking the vulnerability, and CISA will continue to update the webpage as additional information becomes available. Log4j is broadly used in a variety of consumer and enterprise services, websites, applications and operational technology products to log security and performance information. For more information on this or other cyber and risk issues, contact John Riggi, senior advisor for cybersecurity and risk, at jriggi@aha.org

Headline
New guidance from the Cybersecurity and Infrastructure Security Agency encourages healthcare organizations to consider internal network and internet facing…
Headline
The National Institute of Standards and Technology and the Cybersecurity and Infrastructure and Security Agency have released guidelines to protect…
Headline
The House Energy and Commerce Subcommittee on Health held a hearing Sept. 15 to discuss more than a dozen legislative proposals regarding Medicare provider…
Headline
The National Security Agency has released a best practices guide on effective cyber hygiene for defending against advanced cyber threats, including those…
Headline
An FBI alert released Sept. 1 warns of cyber actors impersonating government officials, media and other public individuals on a commercial messaging app to…
Headline
In this conversation, John Riggi, AHA national advisor for cybersecurity and risk, and Scott Gee, AHA deputy national advisor for cybersecurity and risk, break…