惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Y
Y Combinator Blog
B
Blog
S
SegmentFault 最新的问题
Vercel News
Vercel News
博客园 - 聂微东
宝玉的分享
宝玉的分享
C
Check Point Blog
有赞技术团队
有赞技术团队
IT之家
IT之家
V
V2EX
爱范儿
爱范儿
GbyAI
GbyAI
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog
P
Proofpoint News Feed
博客园 - 司徒正美
博客园_首页
Last Week in AI
Last Week in AI
博客园 - 叶小钗
量子位
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
F
Fortinet All Blogs
腾讯CDC
J
Java Code Geeks

WhatIs

Hims & Hers launches AI agent for lab results Twilio revamps, updates customer engagement platform Most patients find appointment scheduling, billing overly complex Teradata's latest targets putting agentic AI into production AHA, Joint Commission launch cyber resilience program Tableau in transition as AI forces BI vendors to evolve California hospitals sue Elevance over out-of-network penalty CMS Health Tech Ecosystem adds electronic prior auth pledge Atlassian MCP updates take aim at AI token usage Leapfrog: Hospitals improved in 17 patient safety measures United promises another 30% cut to prior auths in 2026 AI outperforms docs on clinical reasoning, but not ready for solo work ServiceNow's Autonomous CRM takes aim at Salesforce ServiceNow reintroduces itself as an AI 'security company' New Tableau leader talks vendor's evolution in era of AI Deloitte warns of a "bubble effect" caused by the GLP-1 boom Tableau repositions for AI, unveils new knowledge layer IBM Bob AI coding agent ships, HashiCorp AIOps previewed DOJ forms West Coast Strike Force to stop healthcare fraud Most people benefit from the ACA's free preventive services SAP acquisitions of Dremio, Prior Labs target AI development Bridging the gap: Legacy tools gain enterprise AI support Amazon Connect Talent: AWS enters AI interviewing market AHA, West Health launch health tech adoption initiative How are states preparing for Medicaid work requirements? Medical device security improves, but cyberattacks remain pervasive Weekly news roundup: Musk vs. Altman, Google’s Pentagon AI deal, China and EU hit Meta Skin substitute spending driven by patients, products, prices Clinical AI company Aidoc snags $150M in new funding Qlik's Capone departs after eight years as CEO
Remote desktop tools offer hackers a front door to health...
Jill Hughes · 2026-06-26 · via WhatIs

As hackers increasingly exploit poorly configured remote management tools to gain broad access to clinical systems, a new report says that no other industry sees remote desktop exploitation at this scale.

Healthcare organizations rely on remote desktop tools for a variety of functions, from remote access to clinical systems to IT support and third-party vendor access to medical equipment. These tools are widely used and offer convenience. But without proper controls, they can become an easy entry point for hackers, a new report by cybersecurity company SonicWall found.

The report is an offshoot of the company's multi-industry threat report. The newly released version focused solely on healthcare and pulled data from SonicWall's global network of more than 1 million security sensors. It underscored the outsized volume of cyberattacks the healthcare industry currently faces.

"Healthcare is not just the most targeted vertical in SonicWall's 2026 telemetry; it's also the most persistently targeted," the report stated. "Attackers are targeting the healthcare industry more consistently than any other industry."

Other industries saw intrusion protection system attack volumes decline between 17% and 56% year-over-year. Meanwhile, healthcare hardly moved at -16.9%.

"Attackers are not leaving. They're staying because the returns are too reliable and the defenses too predictable," the report stated.

The data indicated that remote desktop exploitation was a key driver of persistent healthcare cyberattacks. In the first five months of 2026, the UltraVNC buffer overflow signature generated 13.3 million hits. UltraVNC is a free, open-source remote desktop tool for Windows.

No other industry saw remote desktop exploitation at the same scale, pointing to healthcare's reliance on remote management tools.

"VPN-based access compounds the risk. Once credentials are validated, broad network access is granted, and from there, the path to clinical systems, Electronic Health Record (EHR) databases and connected devices is rarely restricted," the report added.

"A stolen set of remote-access credentials does not just unlock one application. It unlocks the whole environment."

Remote desktop tools are not inherently bad, but threat actors have unfortunately realized that these tools can be just as useful to them as they are to the healthcare organizations that depend on them. What's more, when these systems are exposed to the internet without network-level controls or multifactor authentication, they become an easy entry point.

A 2023 alert by the HHS Health Sector Cybersecurity Coordination Center stressed the importance of securing remote access and management software, warning that "mitigating the risk associated with them is not as simple as deploying a patch or reconfiguring an application."

Threat actors might exploit vulnerabilities in remote access software, conduct brute-force attacks wherein they guess usernames and passwords, craft social engineering attacks or deploy ransomware.

HC3 recommended using MFA, regularly updating and patching software, leveraging network segmentation and monitoring access activities to mitigate risk.

SonicWall also emphasized the importance of these mitigations, adding that "a compromised credential should not mean a compromised network."

The report recommended shifting from a virtual private network model to a zero-trust model in which identities and devices are re-verified regularly and only application-level access is granted. SonicWall also recommended limiting UltraVNC and remote desktop protocol to internal VLANs and requiring MFA on all remote access, with no exceptions for vendor accounts.

Jill Hughes has covered health tech news since 2021. Her coverage areas include cybersecurity, HIPAA compliance, interoperability, AI and EHRs.

Dig Deeper on Health data threats