Showing posts with label OT security. Show all posts
Showing posts with label OT security. Show all posts

Wednesday, April 2, 2025

Legacy Medical Devices Remain Easy Targets for Cyber Threats

 

Do you think that your health data secure?


Most of the people don't really think about this question. But imagine, what would you do if your health data ended up on the internet one day? Once it's exposed, you can't undo it. That's scary and disturbing, isn't it?


Anyone who worked with medical systems knows that it is quite difficult to patch the vulnerabilities on these systems. Main reasons are: 1) Many of the systems run on outdated software that no longer supports new patches. 2) Updates are too risky because they can interrupt care or cause devices to fail during use. So, many of these devices stay unpatched and highly vulnerable to cyber attacks.


Researchers from Claroty's Team82 analyzed over 2.25 million Internet of Medical Things (IoMT) devices and more than 647,000 operational technology (OT) devices across 351 healthcare organizations. They found that 99% of these organizations had vulnerabilities with publicly available exploits, as listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. (Yes, 99%. We can say (almost) "all of them")


You can find the report in the following link:

https://bit.ly/4j1es7d


https://bit.ly/3FOYOgp


Headlines:

"...the firm was able to analyze the security state of more than 2.25 million IoMT devices and more than 647,000 OT devices across 351 healthcare organizations – and found that 99% of the organizations are vulnerable to publicly available exploits..."


Monday, January 15, 2024

Hack of Danish Energy Companies


There are still many people in the companies who are still not aware of the cybersecurity risks and who underestimate the cyber threats. They wake up after they see their company in the hacking news on the internet while considering to pay (or not pay) the ransom which is requested by the hacker groups.

So be aware before you see your company in the hacking news the next day. Be aware that it is not a joke. Be aware that cyber threats are for real. Do not hesitate to spend enough budget for cyber security. Otherwise you will have to spend much more then that for hackers after you have been hit by a ransomware attack.


It is known that Ukrainian critical infrastructures are being attacked for more than 10 years (Allegedly by Russian affiliated hacker groups.) But Ukraine remained not the only victim.


Nearly two dozen Danish energy companies were hacked through a firewall bug in May 2023 which is also stated in a report of Forescout which is published this week. (A Critical Analysis of Recent Energy Sector Attacks in Denmark and Ukraine.)


You can read the report of Forescout in the link below:

https://www.forescout.com/resources/clearing-the-fog-of-war/?is=5a5d7ed30c1b46eb1c21fcf1e6c51b4c49dc532ddd4c930a7f4472ce34fe37c3


https://therecord.media/denmark-attacks-forescout-analysis-zyxel?is=5a5d7ed30c1b46eb1c21fcf1e6c51b4c49dc532ddd4c930a7f4472ce34fe37c3


"What happened in Denmark can also happen to you, cybersecurity researchers are warning in a new report that examines attacks against the country’s energy sector last year."


"The takeaway is that 'critical infrastructure organizations across Europe should remain alert to attacks on unpatched network infrastructure devices.'"


""...Nearly two dozen companies were affected, and the intrusions usually involved the abuse of products from the Taiwan-based manufacturer Zyxel,..."


"...The problem for administrators, Forescout said, is the 'common lack of detection and hardening capabilities around native OT scripting functionality.'"