<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Exposure-Measurement on CuraSec</title><link>https://curasec.metacog.co.kr/tags/exposure-measurement/</link><description>Recent content in Exposure-Measurement on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 20 Jul 2026 14:31:24 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/exposure-measurement/index.xml" rel="self" type="application/rss+xml"/><item><title>Internet-Exposed DICOM Services: 3,979 Vulnerable After Noise Filtering</title><link>https://curasec.metacog.co.kr/insights/2026-07-20-is-that-really-my-x-ray-measuring-internet-exposed-dicom-ser/</link><pubDate>Mon, 20 Jul 2026 14:31:24 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-20-is-that-really-my-x-ray-measuring-internet-exposed-dicom-ser/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If your organization runs DICOM infrastructure, audit all services for internet exposure: the research confirms 3,979 deployments accept unauthenticated connections with no encryption, and ~50% show zero maintenance activity. Verify DICOM ports are not internet-reachable and enforce TLS and auth for any legitimate external access.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Pure measurement research with no IOCs, TTPs, or active exploitation data; useful background on healthcare attack surface but yields no detection or hunting work today.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Provides credible benchmarking data on medical imaging infrastructure exposure — useful context for healthcare sector risk conversations or vendor assessments, but no board-level action is required absent a breach or regulatory deadline.&lt;/li>
&lt;/ul></description></item></channel></rss>