<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Dicom on CuraSec</title><link>https://curasec.metacog.co.kr/tags/dicom/</link><description>Recent content in Dicom on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 20 Jul 2026 14:31:24 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/dicom/index.xml" rel="self" type="application/rss+xml"/><item><title>DICOMHawk: Honeypot Framework for DICOM/PACS Medical Imaging Systems</title><link>https://curasec.metacog.co.kr/insights/2026-07-20-dicomhawk-a-cyber-deception-framework-for-medical-imaging-in/</link><pubDate>Mon, 20 Jul 2026 14:31:24 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-20-dicomhawk-a-cyber-deception-framework-for-medical-imaging-in/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Research introduces a higher-fidelity honeypot for DICOM/PACS environments that outperformed the existing Dicompot tool over a 347-day deployment; worth evaluating if your org runs medical imaging infrastructure and lacks deception coverage.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The study&amp;rsquo;s finding that 49 medical-related attacks were captured across deployments confirms active threat activity against exposed DICOM services, useful context for healthcare SOC analysts scoping hunt priorities, but no IOCs or ATT&amp;amp;CK mappings are surfaced.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Confirms adversaries are actively probing healthcare imaging infrastructure; useful benchmark data if you&amp;rsquo;re building a case for deception technology investment in a healthcare environment, but no immediate board-level action needed.&lt;/li>
&lt;/ul></description></item><item><title>Internet-Exposed DICOM Services: 3,979 Vulnerable After Noise Filtering</title><link>https://curasec.metacog.co.kr/insights/2026-07-20-is-that-really-my-x-ray-measuring-internet-exposed-dicom-ser/</link><pubDate>Mon, 20 Jul 2026 14:31:24 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-20-is-that-really-my-x-ray-measuring-internet-exposed-dicom-ser/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If your organization runs DICOM infrastructure, audit all services for internet exposure: the research confirms 3,979 deployments accept unauthenticated connections with no encryption, and ~50% show zero maintenance activity. Verify DICOM ports are not internet-reachable and enforce TLS and auth for any legitimate external access.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Pure measurement research with no IOCs, TTPs, or active exploitation data; useful background on healthcare attack surface but yields no detection or hunting work today.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Provides credible benchmarking data on medical imaging infrastructure exposure — useful context for healthcare sector risk conversations or vendor assessments, but no board-level action is required absent a breach or regulatory deadline.&lt;/li>
&lt;/ul></description></item></channel></rss>