Email is typically used as a mere pivot point for threat actors. As healthcare regulations require evidence no patient data was accessed, providers must consider their PHI and data retention policies for these vulnerable platforms.
Twenty-two percent of all brand phishing attempts around the world between July and September have been attributed to DHL, making the logistics firm the most impersonated brand in phishing emails in the third quarter, followed by Microsoft and LinkedIn, which was the most spoofed brand during the first two quarters of 2022, The Register reports.
VentureBeat reports that new phishing prevention capabilities have been introduced by Microsoft in an effort to better combat phishing threats against Office 365, Azure, and remote desktop environments.
This week’s healthcare data breach roundup includes multiple email hacks with lengthy reporting gaps, and is led by a privacy incident at Advocate Aurora due to Pixel data scraping.
An audit of EyeMed found the insurer failed to conduct a risk assessment in compliance with New York’s cybersecurity regulation after its 2020 email hack impacting millions of patients.
SecurityWeek reports that Microsoft Office 365 Message Encryption is being impacted by a vulnerability within the Electronic Codebook it uses that could result in the exposure of certain structural data related to emails.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.