Gerry Gebel, VP of Products and Standards at Strata Identity, shares his expertise on maintaining identity continuity in turbulent environments. He discusses the pressing need for resilience when identity providers face disruptions. The conversation also touches on the rising healthcare data breaches and the corresponding cybersecurity measures. Additionally, Gerry highlights the critical role of CISOs and the challenges they encounter in a complex regulatory landscape, including burnout and identity management complexities.
Microsoft's identification of a severe macOS vulnerability illustrates the critical importance of system updates for user privacy and security.
The significant rise in healthcare data breaches underscores the escalating danger cybercriminals pose to sensitive patient information in that sector.
Deep dives
macOS Vulnerability and Its Implications
Microsoft has identified a significant vulnerability in macOS known as HMSurf, which enables attackers to bypass crucial privacy protections and gain unauthorized access to sensitive user data. This flaw primarily affects Safari, allowing malicious actors to exploit TCC entitlements to access the camera, microphone, and location data undetected. Microsoft promptly notified Apple, leading to a fix in the September 2024 macOS Sequoia update, urging users to apply it quickly to prevent exploitation by malware families like Adload. The vulnerability underscores the critical need for users to maintain up-to-date systems, especially as it poses serious risks to user privacy and data security.
Healthcare Data Breaches Highlight Growing Threats
Three healthcare organizations have recently reported significant data breaches affecting approximately 740,000 patients and employees, emphasizing the increasing risk of cyber attacks in the healthcare sector. Omni Family Health disclosed a breach impacting around 470,000 individuals, where sensitive information, including social security numbers, was leaked online. Tri-City Medical Center and New York Plastic Surgery reported breaches affecting 108,000 and 162,000 individuals, respectively, with the latter suspected to involve ransomware attacks. These incidents reflect a troubling trend where healthcare organizations are increasingly becoming targets for cybercriminals seeking valuable sensitive data.
A survey indicates that 84% of Chief Information Security Officers (CISOs) support splitting their roles into two separate positions, driven by the expanding complexity of cybersecurity threats and regulatory demands. Many CISOs express concern over their ability to manage evolving regulations and the burden of compliance, with nearly half reporting to their boards on a weekly basis. The increased expectations and responsibilities in their roles have led to significant burnout among CISOs, prompting a desire for external insights and collaborative discussions rather than solitary research. This shift in perspective highlights the necessity for organizations to adapt their security leadership structures to address the pressing challenges in the cybersecurity landscape.
Microsoft describes a macOS vulnerability. A trio of healthcare organizations reveal data breaches affecting nearly three quarters a million patients. Group-IB infiltrates a ransomware as a service operation. Instagram rolls out new measures to combat sextortion schemes. Updates from Bitdfender address Man-in-the-Middle attacks. An Alabama man is arrested for allegedly hacking the SEC. In our Industry Voices segment, Gerry Gebel, VP of Strata Identity, describes how to ensure identity continuity during IDP disrupted, disconnected and diminished environments. CISOs want to see their role split into two positions. Game Freak’s Servers Take Critical Hit.
Remember to leave us a 5-star rating and review in your favorite podcast app.
Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.
CyberWire Guest
Today, we have our Industry Voices segment with Gerry Gebel, VP of Products and Standards at Strata Identity, discussing how to ensure identity continuity during IDP disrupted, disconnected and diminished environments.
We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show.
Want to hear your company in the show?
You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.