Healthcare system's ransomware attack allowed by known security flaw

Last month’s attack on MedStar Health’s computer systems came through a well-known security vulnerability in an application server


The recent ransomware attack on MedStar Health’s computer systems came through from a well-known security vulnerability in an application server, according to an article on the Healthcare Finance website.

The  attack occurred after hackers discovered that MedStar uses JBoss, an application server with a recognized design flaw. The hackers used a virus-like software to scan the Internet for vulnerable JBoss servers.

Security researchers found that the JBoss application server was routinely misconfigured to allow unauthorized outside users to gain control.

The US government, Red Hat Inc., and other groups released warnings about the security issue in February 2007 and March 2010. MedStar could have fixed the vulnerability by installing a patch for the system or manually deleting two lines of software code. 

Read the article.

 

 



April 19, 2016


Topic Area: Safety


Recent Posts

How Curated Art Elevates Senior Care Spaces

Thoughtfully selected artwork can shape perception, improve flow and create a more engaging care environment.


The CDC's Guide to Hand Hygiene in Healthcare

Hand hygiene may seem simple, but the CDC has a set of guidelines that all healthcare facility managers and staff should be aware of. These are just a few of the notable tips. 


Dana-Farber, BIDMC Launch Construction of Dedicated Adult Cancer Hospital

Deconstruction begins on former Joslin site as 300-bed, oncology-focused facility moves toward a planned 2031 opening.


5 Components of an Integrated Safety Culture in Healthcare

The goal is not to create a fortress but to build a space where patients feel protected and caregivers feel empowered to deliver exceptional care.


NYC Opens Therapeutic Housing Unit for Medically Vulnerable Detainees

The NYC Health + Hospitals system has launched a 104-bed Outposted Therapeutic Housing Unit at Bellevue Hospital, offering specialized care for detainees with serious medical conditions.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.