The Department of Health and Human Services’ Health Sector Cybersecurity Coordination Center issued a threat report Thursday. The health sector remains highly vulnerable, as do other industries, federal regulators warn. Foreign actors are believed to be leveraging Log4Shell in several nation-states, including China and Iran, the agency says. “Updating can be a time-consuming and tedious process. Further vulnerabilities may continue to be identified soon,” HC3 says. Health sector entities, among other steps, should stay abreast of a repository of affected vendor platforms.”]
Source: https://www.govinfosecurity.com/hhs-hc3-healthcare-sector-remains-at-risk-for-log4j-attacks-a-18353

