Healthcare system's ransomware attack allowed by known security flaw

Last month’s attack on MedStar Health’s computer systems came through a well-known security vulnerability in an application server


The recent ransomware attack on MedStar Health’s computer systems came through from a well-known security vulnerability in an application server, according to an article on the Healthcare Finance website.

The  attack occurred after hackers discovered that MedStar uses JBoss, an application server with a recognized design flaw. The hackers used a virus-like software to scan the Internet for vulnerable JBoss servers.

Security researchers found that the JBoss application server was routinely misconfigured to allow unauthorized outside users to gain control.

The US government, Red Hat Inc., and other groups released warnings about the security issue in February 2007 and March 2010. MedStar could have fixed the vulnerability by installing a patch for the system or manually deleting two lines of software code. 

Read the article.

 

 



April 19, 2016


Topic Area: Safety


Recent Posts

Two Steps to Controlling the Hot Zone

Strategy for disrupting dry-surface biofilm begins with a simple premise: You cannot disinfect what you cannot reach.


RiverSpring Living Breaks Ground on River's Edge Senior Living Community

Occupancy is expected in December 2028.


Encompass Health Reveals Plans to Build Inpatient Rehabilitation Hospital in Post Falls, Idaho

The hospital is expected to open in 2028 and will be part of Encompass Health's national network of inpatient rehabilitation hospitals.


Creating Compassionate Spaces in Healthcare

A new bereavement room at the Children’s Hospital of Michigan NICU aims to provide peace and privacy for families.


Study Shows Connection Between Odor and Patient Experience

A 2024 study identifies the top smells in hospital waiting rooms and how they impact the patient and visitor experience.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.