BlackBerry yesterday announced a set of cyber vulnerabilities in its QNX Real Time Operating System for medical devices and other products, which a remote attacker could exploit to cause a denial-of-service condition or execute arbitrary code on affected devices. It said there are no known workarounds for the vulnerability. The U.S. Cybersecurity and Infrastructure Security Agency recommends applying patches as soon as they are available from BlackBerry. 

“Because many affected devices include safety-critical devices, exploitation of this vulnerability could result in a malicious actor gaining control of sensitive systems, possibly leading to increased risk of damage to infrastructure or critical functions,” CISA said.

John Riggi, AHA senior advisor for cybersecurity and risk, said, “This cyber vulnerability is significant since it is present in medical devices and may, if successfully exploited, preclude availability or cause malfunction of the device, or pose a risk to patient care. If at all possible, it is recommended that affected devices be disconnected from internal networks and the internet until a patch becomes available.”

For more on this or other cyber and risk issues, contact Riggi at jriggi@aha.org. 
 

Headline
The Senate passed the Health Care Cybersecurity and Resilience Act on Sept. 30 by unanimous consent. The bipartisan bill seeks to improve coordination between…
Headline
The AHA provided comments Sept. 30 to the Senate Homeland Security and Governmental Affairs Subcommittee on Disaster Management, District of Columbia and…
AHA Cyber Intel
While we may feel inundated with alarming news about escalating cyber threats against healthcare organizations, there is also some good news. Let’s explore how…
Headline
The FBI Sept. 29 announced an arrest of one of the alleged leaders of ShinyHunters, a cybercriminal group linked to cyberattacks in the U.S. and…
Headline
The FBI and the Cybersecurity and Infrastructure Security Agency have released a fact sheet for critical infrastructure organizations on ways to reduce risk…
Headline
The AHA will host a webinar Sept. 30 at 1 p.m. ET on ways healthcare organizations can build an effective, closed-loop cybersecurity program designed…