Healthcare system's ransomware attack allowed by known security flaw

Last month’s attack on MedStar Health’s computer systems came through a well-known security vulnerability in an application server


The recent ransomware attack on MedStar Health’s computer systems came through from a well-known security vulnerability in an application server, according to an article on the Healthcare Finance website.

The  attack occurred after hackers discovered that MedStar uses JBoss, an application server with a recognized design flaw. The hackers used a virus-like software to scan the Internet for vulnerable JBoss servers.

Security researchers found that the JBoss application server was routinely misconfigured to allow unauthorized outside users to gain control.

The US government, Red Hat Inc., and other groups released warnings about the security issue in February 2007 and March 2010. MedStar could have fixed the vulnerability by installing a patch for the system or manually deleting two lines of software code. 

Read the article.

 

 



April 19, 2016


Topic Area: Safety


Recent Posts

Cleanliness in Hospitals: Clinical Priority and Community Perception

EVS managers and communities value cleanliness for complementary reasons: managers for safety and compliance, communities for trust and comfort.


Dana-Farber Receives $50M Gift for Planned Cancer Hospital

A $50 million grant from the Yawkey Foundation will support construction of Dana-Farber Cancer Institute’s planned 450,000-square-foot cancer hospital.


Clarinda Regional Health Center Reports Data Security Incident

On or around December 15, 2025, Clarinda learned that certain data within its network may have been accessed without authorization.


Gaps in Nurses' Environmental Cleaning Knowledge Grow Amid Rising EVS Pressures

Environmental cleaning is crucial in preventing HAIs, but when the responsibility falls to those outside of EVS teams, problems arise. 


Ground Broken on the Southern Nevada Forensic Facility

Construction on the new secure forensic psychiatric hospital is expected to be completed in 2029.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

 
 
 
 

Healthcare Facilities Today membership includes free email newsletters from our facility-industry brands.

Facebook   Twitter   LinkedIn   Posts

Copyright © 2023 TradePress. All rights reserved.