April 30, 2024, 7:10 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

Threat actors behind the Change Healthcare ransomware attack in February were able to gain initial access by leveraging compromised credentials for a Citrix remote access portal, which didn’t have multi-factor authentication enabled. The initial access vector behind the attack was revealed in a new testimony document from Andrew Witty, CEO of Change’s parent company UnitedHealth Group, before he attends a Wednesday hearing by the House Energy and Commerce subcommittee.


The issue of compromised credentials continues to haunt organizations, especially as …

access attack authentication ceo change change healthcare citrix compromised compromised credentials credentials document factor february healthcare healthcare ransomware attack initial access led multi-factor multi-factor authentication portal ransomware ransomware attack remote access stolen testimony threat threat actors

Sr. Product Manager

@ MixMode | Remote, US

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Incident Response Lead(IR)

@ Blue Yonder | Hyderabad

Comcast Cybersecurity: Privacy Operations Executive Director

@ Comcast | PA - Philadelphia, 1701 John F Kennedy Blvd