by Kim Singletary | Apr 15, 2026 | Blog
This post documents a blind time-based SQL injection in the PostCalendar module discoveredin OpenEMR 8.0.0. The SQL Injection is exploitable by an authenticated admin user and illustrates how a single determined attacker with a valid session can move from nuisance to...
by Lisa Munro | Apr 2, 2026 | Blog
For years, healthcare cyber risk was framed around the perimeter. Firewalls. Endpoints. Network defenses. The digital equivalent of locked doors and reinforced windows. That model no longer reflects how healthcare operates. Care now runs across cloud platforms, EHRs,...
by Lisa Munro | Mar 2, 2026 | Blog
NIST CSF 2.0 in Healthcare: From Compliance to Governance A True Story on Implementation Healthcare didn't decide one morning to adopt a new cybersecurity framework. It got here through pressure and accumulation — ransomware that shuts down clinics, third-party...
by admin | Feb 23, 2026 | Upcoming Webinars
Identity Under Pressure: Securing Access in Resource-Constrained Hospitals Quarterly Meeting Series Identity has become healthcare’s primary attack surface. Community hospitals are facing escalating credential harvesting campaigns, help desk impersonation attempts,...
by Lisa Munro | Jan 26, 2026 | Blog
The 2026 J.P. Morgan Healthcare Conference reinforced a familiar but increasingly disciplined theme among healthcare investors: selective optimism. While expectations for a broad M&A rebound remain measured, private equity sponsors are nonetheless ready to deploy...