The vulnerability exists in Hypertext Preprocessor, or PHP, an open-source scripting language on Windows and Linux systems, according to HHS’ Office of Information Security and Health Sector Cybersecurity Coordination Center.
“Despite only being discovered a few days ago, cybersecurity researchers have already confirmed detected exploitation attempts involving the flaw against its honeypot servers within 24 hours of public disclosure of the vulnerability,” the June 12 sector alert said. “As with any critical vulnerability impacting many devices, once disclosed, both threat actors and researchers immediately began attempting to find vulnerable systems.”
The alert suggests updating PHP or moving to a different solution.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.