Healthcare system's ransomware attack allowed by known security flaw

Last month’s attack on MedStar Health’s computer systems came through a well-known security vulnerability in an application server


The recent ransomware attack on MedStar Health’s computer systems came through from a well-known security vulnerability in an application server, according to an article on the Healthcare Finance website.

The  attack occurred after hackers discovered that MedStar uses JBoss, an application server with a recognized design flaw. The hackers used a virus-like software to scan the Internet for vulnerable JBoss servers.

Security researchers found that the JBoss application server was routinely misconfigured to allow unauthorized outside users to gain control.

The US government, Red Hat Inc., and other groups released warnings about the security issue in February 2007 and March 2010. MedStar could have fixed the vulnerability by installing a patch for the system or manually deleting two lines of software code. 

Read the article.

 

 



April 19, 2016


Topic Area: Safety


Recent Posts

Must Know Recalls of 2025

For the safety of our readers, Healthcare Facilities Today has closely followed all recall notices related to the industry.


Sustainability as a Baseline in Healthcare Facilities

Hospitals can balance costs, build resilience and learn from global models for sustainable design to further their green goals.


Comanche County Memorial Hospital and Southwestern Medical Center Join to Form Partnership

The partnership will go into effect by the end of December 2025.


Choosing a Disinfectant That Kills Biofilm

Bacteria form biofilms in pipes from which cells can be released during sink use and spread outside the drains in droplets or as aerosols.


Third-Party Data Breach Case Underscores Need for Cyber Risk Management

Plaintiffs alleged negligence in safeguarding patient data; defendants denied wrongdoing but settled to avoid litigation costs.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.