Cybersecurity

Cyber Threat Intelligence, Alerts and Reports
As part of the AHA’s commitment to helping hospitals and health systems prepare for and prevent cyber threats, we have gathered the latest government cyber threat intelligence and alerts and Health Information Sharing and Analysis Center (H-ISAC) reports.
You may be asked to enter your AHA member credentials to view certain reports and intelligence alerts.
Cybersecurity & Risk Advisory
Learn how AHA can help hospitals and health systems prepare for and mitigate cyber threats through the expertise of John Riggi, AHA’s National Advisor for Cybersecurity and Risk.
The Cybersecurity and Infrastructure Security Agency has issued an alert warning of four Microsoft SharePoint vulnerabilities being exploited by cyber threat actors.
The White House July 14 announced the establishment of Gold Eagle, a clearinghouse to enhance cybersecurity for critical infrastructure entities that will use artificial intelligence to deliver information and remediation measures on cyber threats across the federal government and private…
The Centers for Medicare & Medicaid Services, the Centers for Disease Control and Prevention, and the Department of Health and Human Services July 15 released a request for information on topics regarding Clinical Laboratory Improvement Amendments of 1988 regulations.
The Cybersecurity and Infrastructure Security Agency and other U.S. and international agencies released a joint advisory July 13, warning of Russian cyber actors targeting vulnerable network devices, primarily routers, in critical infrastructure sectors globally, including healthcare.
H-ISAC TLP Green: Daily Cyber Headlines - July 8, 2026.
A daily ransomware tracker at TLP Green to increase awareness of the ransomware threat.
BeyondTrust has urged customers to patch two critical Authentication Bypass vulnerabilities, tracked as CVE-2026-40138 and CVE-2026-40139, affecting its Remote Support (RS) and Privileged Remote Access (PRA) software.
On July 2, 2026, Ubiquiti released critical security updates to patch seven severe vulnerabilities across its UniFi OS ecosystem, including a maximum-severity flaw CVE-2026-50746 in the UniFi Connect Application.
The Cybersecurity and Infrastructure Security Agency July 1 announced the formation of a new advisory body intended to foster collaboration, coordination and information sharing between the federal government and critical infrastructure stakeholders.
On June 29, 2026, eSentire’s Threat Response Unit (TRU) identified active, in-the-wild exploitation attempts targeting a critical flaw in Progress Kemp LoadMaster appliances, tracked as CVE-2026-8037.