BlackBerry yesterday announced a set of cyber vulnerabilities in its QNX Real Time Operating System for medical devices and other products, which a remote attacker could exploit to cause a denial-of-service condition or execute arbitrary code on affected devices. It said there are no known workarounds for the vulnerability. The U.S. Cybersecurity and Infrastructure Security Agency recommends applying patches as soon as they are available from BlackBerry. 

“Because many affected devices include safety-critical devices, exploitation of this vulnerability could result in a malicious actor gaining control of sensitive systems, possibly leading to increased risk of damage to infrastructure or critical functions,” CISA said.

John Riggi, AHA senior advisor for cybersecurity and risk, said, “This cyber vulnerability is significant since it is present in medical devices and may, if successfully exploited, preclude availability or cause malfunction of the device, or pose a risk to patient care. If at all possible, it is recommended that affected devices be disconnected from internal networks and the internet until a patch becomes available.”

For more on this or other cyber and risk issues, contact Riggi at jriggi@aha.org
 

Headline
The Administration for Strategic Preparedness and Response has released a new cybersecurity module for organizations to conduct risk assessments. The free…
Perspective
Public
As the world has learned in recent years, today’s conflicts are fought with many weapons, and cyber warfare is an integral part of the arsenal.As of this…
Headline
The FBI is reminding critical infrastructure organizations to implement mitigations from a June 2025 fact sheet on potential actions by Iranian-affiliated…
Headline
The Cybersecurity and Infrastructure Security Agency Feb. 26 released a report that updates findings from last year on RESURGE malware used to gain covert…
Headline
U.S. and international agencies Feb. 25 released guidance on protecting Cisco Software-defined Wide-area Networking systems from exploitation by malicious…
Headline
The National Security Agency has released two phases of its Zero Trust Implementation Guidelines for organizations to improve their zero trust architecture.…