Healthcare system's ransomware attack allowed by known security flaw

Last month’s attack on MedStar Health’s computer systems came through a well-known security vulnerability in an application server


The recent ransomware attack on MedStar Health’s computer systems came through from a well-known security vulnerability in an application server, according to an article on the Healthcare Finance website.

The  attack occurred after hackers discovered that MedStar uses JBoss, an application server with a recognized design flaw. The hackers used a virus-like software to scan the Internet for vulnerable JBoss servers.

Security researchers found that the JBoss application server was routinely misconfigured to allow unauthorized outside users to gain control.

The US government, Red Hat Inc., and other groups released warnings about the security issue in February 2007 and March 2010. MedStar could have fixed the vulnerability by installing a patch for the system or manually deleting two lines of software code. 

Read the article.

 

 



April 19, 2016


Topic Area: Safety


Recent Posts

Making Multi-Site Lighting Upgrades Work

Success requires a program structure that connects audits, financial analysis, rebate administration, procurement, scheduling and closeout documentation.


Designing a Positive Care Destination for Children

The new Mary Bridge Children’s Hospital reimagines the healthcare experience to create an environment that feels welcoming from arrival to discharge.


Blackbird Health Opens 10th Clinic in Pennsylvania

The Bala Cynwyd clinic represents Blackbird Health's 13th location overall.


Healthcare Construction Infection Control: Essential CDC Guidelines for Active Facilities

Construction and renovations happen, but that doesn’t mean infection prevention can take a backseat. The CDC has some recommendations for maintaining best practices during construction.


Protecting the Most Vulnerable: Inside the NICU

SSM Health St. Mary’s Hospital leaders share how maintaining power, air quality and essential systems helps protect patients during their most vulnerable moments.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.