BlackBerry yesterday announced a set of cyber vulnerabilities in its QNX Real Time Operating System for medical devices and other products, which a remote attacker could exploit to cause a denial-of-service condition or execute arbitrary code on affected devices. It said there are no known workarounds for the vulnerability. The U.S. Cybersecurity and Infrastructure Security Agency recommends applying patches as soon as they are available from BlackBerry. 

“Because many affected devices include safety-critical devices, exploitation of this vulnerability could result in a malicious actor gaining control of sensitive systems, possibly leading to increased risk of damage to infrastructure or critical functions,” CISA said.

John Riggi, AHA senior advisor for cybersecurity and risk, said, “This cyber vulnerability is significant since it is present in medical devices and may, if successfully exploited, preclude availability or cause malfunction of the device, or pose a risk to patient care. If at all possible, it is recommended that affected devices be disconnected from internal networks and the internet until a patch becomes available.”

For more on this or other cyber and risk issues, contact Riggi at jriggi@aha.org
 

Related News Articles

Headline
A Health-ISAC (Information Sharing and Analysis Center) bulletin released Oct. 1 warns of a recently released LockBit 5.0 ransomware variant that poses a…
Headline
Fernando Martinez, Ph.D., chief digital officer at the Texas Hospital Association, shares how Texas and the THA are building regional resilience through cyber…
Headline
The federal government shut down Oct. 1 following a failed Senate vote on the House-passed continuing resolution to fund the government by midnight Sept. 30.…
Headline
Microsoft Sept. 16 announced it had disrupted a growing phishing service that had targeted at least 20 U.S. health care organizations. The company said it used…
Headline
The FBI Sept. 12 released an alert warning of malicious activities by cybercriminal groups UNC6040 and UNC6395, which the agency said are responsible for an…
Headline
The Cybersecurity and Infrastructure Security Agency, National Security Agency and international agencies Sept. 3 released joint guidance outlining a “software…