Community Health Systems reports GoAnywhere hacked
Community Health Systems filed with the Securities and Exchange Commission that it was notified by a third-party vendor for secure file transfer of an incident that resulted in unauthorized disclosure of its patient data.WHY IT MATTERS
The GoAnywhere managed file transfer platform first warned about a zero-day remote code injection exploit on February 1, according to the technical bulletin posted by noted security researcher Brian Krebs on Infosec.exchange.
“The attack vector of this exploit requires access to the administrative console of the application, which in most cases is accessible only from within a private company network, through [virtual private network] or by allow-listed IP…