[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fsUF2b2JIR28DEGxkGA9xWjujBqsbTk-7uEeNfVV1mfU":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"0302fc00-620a-416b-9770-2ad686d7a834","exposed-redcap-servers-enable-year-long-medical-data-theft","b8d2c82b-d9c5-4783-ac12-330f78864b66","Exposed REDCap Servers Enable Year-Long Medical Data Theft","Chinese threat actors successfully exploited exposed REDCap servers containing sensitive medical research data by targeting internet-facing systems with inadequate security controls. The attackers maintained persistence for over a year using custom malware and leveraged legitimate cloud productivity tools for data exfiltration, making detection extremely difficult. This breach highlights the critical importance of securing research infrastructure and implementing proper network segmentation to protect valuable intellectual property. The prolonged nature of the campaign demonstrates how undetected vulnerabilities in specialized research platforms can lead to significant data theft with national security implications.","**Immediate actions:**\n- Conduct emergency security assessment of all internet-facing REDCap and research servers\n- Implement network segmentation to isolate research systems from direct internet access\n- Deploy endpoint detection and response (EDR) solutions on all research infrastructure\n\n**Long-term improvements:**\n- Establish regular vulnerability scanning and penetration testing for research platforms\n- Implement zero-trust network architecture with multi-factor authentication for research system access\n- Create dedicated secure networks for sensitive medical research data with strict access controls\n\n**Detection measures:**\n- Monitor all outbound communications from research systems for unusual data transfer patterns\n- Implement data loss prevention (DLP) tools to detect unauthorized exfiltration attempts\n- Establish baseline network behavior monitoring for research infrastructure",[12,13,14,15,16,17,18,19],"CIS Control 1","CIS Control 7","CIS Control 12","NIST SC-7","NIST SI-2","NIST AC-3","HIPAA 164.308(a)(4)","ISO 27001 A.12.6.1","published","2026-06-15T16:21:27.320971+00:00","2026-06-15T16:21:27.233+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fchinese-hackers-breach-redcap-servers-steal-medical-research\u002F","chinese-hackers-breach-redcap-servers-steal-medical-research-82e1f9","Chinese hackers breach REDCap servers, steal medical research",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":35,"name":36,"slug":37,"description":38,"color":39},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[]]