Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Network Security

CISA Flags Gaps in Healthcare Org’s Security Posture, Issues Security Guidance

The US cybersecurity agency CISA issues cybersecurity recommendations for the healthcare and public health sector.

CISA

The US cybersecurity agency CISA has issued cybersecurity recommendations after conducting an assessment at the request of an unnamed healthcare and public health (HPH) sector organization using on-prem software.

During a two-week penetration test, CISA said it assessed the target entity’s web applications, susceptibility to phishing, resilience to simulated adversary attacks, and reviewed its databases for misconfigurations and its network and connected devices for vulnerabilities.

The US government cybersecurity arm is releasing information on the assessment results to help other organizations in the Healthcare and Public Health sector improve their cybersecurity posture.

“The CISA team did not identify any significant or exploitable conditions from penetration or web application testing that may allow a malicious actor to easily obtain initial access to the organization’s network,” the agency said, noting that its phishing attempts failed, because payloads were blocked, either before they could be downloaded, or upon execution. Payloads that evaded protections did not connect to a command-and-control (C&C) server.

While employees did fall for phishing email lures and shared their credentials through malicious forms, the login information provided limited access to external-facing resources and the organization had multi-factor authentication (MFA) implemented for cloud accounts.

During the internal penetration testing phase, however, the agency did identify misconfigurations, weak passwords, and other issues that could have allowed an attacker to compromise the organization’s domains. CISA said it found multiple web interfaces protected by default credentials, as well as the use of default printer credentials, and was able to compromise the organization’s domain via four different attack paths.

Advertisement. Scroll to continue reading.

Following the assessment, CISA drew attention to four high-severity and one medium-severity issues that need addressing, including the weak passwords, a web server template that did not restrict authenticated users’ permissions, the use of unnecessary network services, a service account with elevated privileges, and systems that lacked SMB signing enforcement.

The agency also draws attention to the reuse of passwords across administrator and user accounts, the lack of timely patches, the use of outdated software, weak authentication measures, credentials stored in plaintext, insecure file shares, and other high- and medium-severity issues that could allow attackers to fully compromise an organization’s environment.

As part of its assessment report, CISA also provides a series of mitigation recommendations and urges HPH sector and other critical infrastructure entities to review and apply them to mitigate the identified issues. The agency also recommends a set of strategies that HPH organizations can implement to mitigate cyber threats.

Related: CISA, HHS Release Cybersecurity Healthcare Toolkit

Related: CISA Offering Free Cybersecurity Services to Non-Federal Entities

Related: CISA IDs Vulnerabilities, Misconfigurations Hit by Ransomware

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Zero Networks has named Yossi Dagan as Chief Financial Officer.

Manifold has appointed Joe Sullivan to its Board of Directors.

Patrick McKinney has joined Turing as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.