The Cybersecurity and Infrastructure Security Agency (CISA) has released a guide to help healthcare and public health sector businesses manage cyberthreat risks. It combines previous CISA materials with other industry and government resources. The guide identifies significant vulnerabilities such as application issues and weak encryption, and suggests mitigation strategies including asset management, identity management, and device security. CISA also advises health technology and IT firms to rethink their design processes and move towards a “secure by design” approach.

Critical Vulnerability in MCP Server Platform Exposes 3,000+ Servers and Thousands of API Keys
A critical vulnerability in Smithery.ai, a popular registry for Model Context Protocol (MCP) servers. This issue could have allowed attackers to steal from over 3,000