Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Attackers turn sights on healthcare websites

by The Gurus
June 17, 2020
in Editor's News
Share on FacebookShare on Twitter

Healthcare IT specialists take note: Websites in this critical market became the most highly attacked of all sectors in third-quarter 2017, registering 1,526 incidents per day on average. That’s nearly a third higher than the next favorite target, finance, which averaged 1,014 incidents per day, while technology takes the third spot with 660. Those are among the topline findings in the Q3 2017 web application attack report from Positive Technologies, a leading global provider of enterprise security solutions for vulnerability and compliance management, incident and threat analysis, and application protection.

Interestingly, Local File Inclusion accounted for a high percentage of attacks in this sector: 33.3%, far above the average seen across all sectors (10%). This technique is often used by hackers to hijack web applications and host malicious files on trusted websites with the specific goal of spreading malware. A similar attack was used in October to distribute Bad Rabbit ransomware through a fake Flash Player download from media sites.

Positive Technologies’ research analysts believe the attackers are determined to abuse the trusted status of healthcare websites, which has a domino effect—the types of vulnerabilities exploited often lead to malicious files being placed on visitors’ machines, which can then lead to data theft or worse. Analysts also found that it took three days on average to begin exploiting a vulnerability after publication, but there are certainly exceptions.  For example, after the details of the Optionsbleed vulnerability in Apache web servers were revealed, it took only three hours for first exploit attempts to begin.

The most widespread attack in Q3 was SQL Injection (25.5 percent), which allows a successful intruder to obtain unauthorized access to sensitive information or execute OS commands. Cross-Site Scripting came in second (22.7 percent) and these two methods accounted for almost half of all attacks against web applications monitored in this period. In addition to the focus on healthcare, the percentage of Local File Inclusion attempts increased across the board to 10 percent. Compared to the previous quarter, the number of high-severity attacks – such as Remote Code Execution and OS Commanding (8.2 percent) – also doubled. These tactics give an intruder the chance to obtain full control over a server with a web application.

The report also shows that web applications, on average, were hit by 500-700 attacks per day, and only rarely dipped below 200. The data also shows that hackers did their best to leverage opportunities that offered greater benefits. For example, they launched attacks not only on workdays but also on weekends. The maximum number of attacks per day reached a high of 4,321, with attack intensity rising in both daytime and evening hours.

Tags: CybersecurityTechnology
Share3Tweet
Previous Post

Increased cyber security investment will be needed to address a number of critical challenges in 2018, warns BOHH Labs

Next Post

Protecting data against attacks – cyber and otherwise.

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol