惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

L
LangChain Blog
有赞技术团队
有赞技术团队
博客园_首页
IT之家
IT之家
爱范儿
爱范儿
量子位
小众软件
小众软件
Jina AI
Jina AI
WordPress大学
WordPress大学
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 聂微东
The Cloudflare Blog
博客园 - 司徒正美
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
大猫的无限游戏
大猫的无限游戏
月光博客
月光博客
雷峰网
雷峰网
V
Visual Studio Blog
博客园 - Franky
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
美团技术团队
Last Week in AI
Last Week in AI
S
SegmentFault 最新的问题

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
Infosecurity Europe: Reactive Security Is Failing Healthc...
Phil Muncaster · 2026-06-05 · via www.infosecurity-magazine.com

Healthcare organizations (HCO) must embrace AI-powered tools to spot and contain threats faster, or continue to risk potentially fatal consequences for patients, experts have warned.

Speaking at Infosecurity Europe on June 4, Cyber Salus CEO, Sher Baig, said HCOs across the globe face the same threats and operational constraints.

Legacy infrastructure, hyper-connectivity and human fatigue are fomenting a perfect storm of risk, he argued. In rare cases, breaches can lead to patient fatalities.

“If there was ever an industry where the potential harm bad actors can do is directly correlated to human impact, it’s healthcare,” Baig told attendees.

The sector is frequently described as the most targeted, with ransomware a particularly acute concern given its potential impact on clinical services.

Some 93% of HCOs suffered at least one cyber-attack in 2025, with an average of 43 attacks per organization, up from 40 in 2024, according to Proofpoint research.

Read more on healthcare security: A Quarter of Healthcare Organizations Report Medical Device Cyber-Attacks

Connected devices such as infusion pumps, imaging systems, patient monitors and lab systems are particularly exposed, Baig said.

“In healthcare, you don’t purchase medical equipment like an iPhone. These devices are in the field for 15 to 20 years running legacy operating systems,” he added.

Reactive approaches rooted in the past are failing HCOs, he argued – pointing to alert overload and time-consuming manual investigations. Discovering vulnerabilities after exposure and scrambling to assess and contain the risk is an increasingly unsustainable approach as AI collapses the exploit window.

AI is not only helping threat actors to find and exploit vulnerabilities in legacy systems and networks faster than ever, it’s also supercharging phishing.

However, it can also arm defenders through continuous monitoring and analysis, faster anomaly detection and automated threat prioritization, Baig continued.

Protecting Networks and Patients

With this in mind, HCO security teams should transition to a more proactive posture where threats are spotted and contained early. Baig highlighted four steps organizations should take:

  • Aim for full visibility into devices and threats, with insight into device-level parameters right down to software version
  • Prioritize threats by clinical risk to ensure threats to devices with a potentially critical impact on patient care are addressed first
  • Use AI for signal correlation to reduce SecOps alert fatigue
  • Patch where possible, segment to reduce exposure, and use AI to apply the most appropriate compensating control

"That's the game plan we should all be working on now, not once there is a breach,” Baig concluded.

Rob Demain, CEO at e2e-assure, told Infosecurity that “reactive to predictive is the right direction for healthcare.”

“The caveat is that predictive is not a product you switch on, it is something you earn, and you earn it with telemetry,” he added.

“Most healthcare organizations do not have clean complete data to reason over. Estates are sprawling, much of the kit cannot run an agent or be patched, and large parts of the network are invisible. No model predicts what it cannot see. The honest first move is not predictive AI, it is basic coverage of the estate.”

Chris Newton-Smith, CEO at compliance software provider IO, told Infosecurity that AI is changing the speed, scale and sophistication of cyber threats in healthcare, but that it’s amplifying existing weaknesses rather than creating new risks.

“On the defensive side, AI has the potential to help healthcare security teams identify anomalies faster, prioritize alerts more effectively and improve incident response. But again, AI alone cannot compensate for fragmented processes, weak governance or overstretched teams,” he added.

“For healthcare leaders, the priority should be strengthening the fundamentals: governance, resilience, workforce capability, supplier assurance and risk management. If you can get those foundations right, then you will hopefully be better positioned to benefit from AI while remaining resilient against the new risks it introduces.”