[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhQp-D84zhNrTL4813GWGvJsmXuyGP7avCwwTfDK6MFc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":30,"created_at":31,"published_at":32,"article":33,"tags":37,"podcasts":56},"1c5be99a-586f-40e9-9c46-4b4a13a15453","vishing-attack-and-weak-credentials-expose-abbott-laboratories-to-dual-breaches","f6707977-844e-4a8b-b7bb-f28a9859a742","Vishing Attack and Weak Credentials Expose Abbott Laboratories to Dual Breaches","Abbott Laboratories is facing two simultaneous cybersecurity incidents stemming from fundamentally different but entirely preventable weaknesses. The first breach exploited human vulnerability through a vishing (voice phishing) attack that manipulated employees into compromising their Microsoft Entra SSO credentials, potentially exposing over 30 million sensitive medical records. The second incident leveraged weak credentials on a customer-facing portal, a basic configuration failure that should be caught by routine security audits. Together, these incidents highlight how attackers routinely combine social engineering and credential exploitation to bypass technical controls, and how medical data breaches carry outsized regulatory and reputational consequences under frameworks like HIPAA.","**Immediate actions:**\n- Enforce phishing-resistant MFA (e.g., FIDO2\u002Fpasskeys) on all SSO and customer-facing portals immediately to neutralize stolen credential attacks.\n- Audit and reset all service and customer portal accounts with weak or default credentials, enforcing a minimum password complexity policy.\n- Isolate and restrict access to the affected Cancer Diagnostics and LabCentral systems pending full forensic investigation.\n\n**Long-term improvements:**\n- Deploy an enterprise-wide anti-vishing training program that includes simulated voice phishing exercises targeting employees with SSO or privileged access.\n- Implement Privileged Access Management (PAM) and zero-trust principles so that compromised SSO credentials cannot grant broad lateral access.\n- Establish a formal credential hygiene policy with automated enforcement tools to continuously detect and remediate weak or reused passwords across all portals.\n\n**Detection measures:**\n- Enable behavioral analytics and anomalous login alerting on Entra ID to detect unusual authentication patterns indicative of account takeover.\n- Implement Data Loss Prevention (DLP) controls and egress monitoring to detect and alert on large-scale exfiltration of medical records.\n- Conduct quarterly external attack surface assessments to identify customer-facing portals with weak authentication configurations before threat actors do.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29],"CIS Control 4 – Secure Configuration of Enterprise Assets","CIS Control 5 – Account Management","CIS Control 6 – Access Control Management","CIS Control 14 – Security Awareness and Skills Training","CIS Control 17 – Incident Response Management","NIST SP 800-53 AC-2 (Account Management)","NIST SP 800-53 AC-17 (Remote Access)","NIST SP 800-53 IA-5 (Authenticator Management)","NIST SP 800-53 SI-4 (System Monitoring)","NIST SP 800-63B (Digital Identity Guidelines – Phishing-Resistant MFA)","HIPAA Security Rule § 164.312(a)(2)(i) – Unique User Identification","HIPAA Security Rule § 164.312(d) – Person or Entity Authentication","HIPAA Breach Notification Rule § 164.400-414","GDPR Article 32 – Security of Processing","GDPR Article 33 – Notification of a Personal Data Breach","ITIL – Problem Management (root cause elimination)","MITRE ATT&CK T1566.004 – Phishing via Voice (Vishing)","MITRE ATT&CK T1078 – Valid Accounts","published","2026-07-17T22:20:44.737225+00:00","2026-07-17T22:20:44.405+00:00",{"id":7,"url":34,"slug":35,"title":36},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fabbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims\u002F","abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims-84a8a0","Abbott Laboratories probes two cyber incidents amid extortion claims",[38,44,50],{"id":39,"name":40,"slug":41,"description":42,"color":43},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":45,"name":46,"slug":47,"description":48,"color":49},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":51,"name":52,"slug":53,"description":54,"color":55},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[57,63],{"id":58,"date":59,"edition":60,"title":61,"audio_url":62},"41f31daa-3c25-4318-b9be-29831f344e09","2026-07-19","afternoon","ThreatNoir Weekend Brief — July 19","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-19\u002Fthreatnoir-afternoon-brief-2026-07-19.mp3",{"id":64,"date":65,"edition":66,"title":67,"audio_url":68},"e6e1606e-6efa-4379-a809-f53e68d45699","2026-07-18","morning","ThreatNoir Weekend Brief — July 18","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-18\u002Fthreatnoir-morning-brief-2026-07-18.mp3"]