Overmedicated: Breaking the Security Barrier of a Globally Deployed Infusion Pump

Cyberattacks on medical centers are one of the most despicable forms of cyber threat there is. For instance, on October 28th, 2020, a cyberattack at the University of Vermont Medical Center in Burlington VT led to 75% of the scheduled chemotherapy patients being turned away. Many of us have friends and loved ones who have had to undergo intensive treatments, and the last thing we want in this situation is for their critical care to be delayed due to on-going cyberattacks. Yet, as concerning as ransom attacks can be, what if the process of receiving the treatment was an even bigger threat than a system-wide ransomware event?

McAfee’s Enterprise Advanced Threat Research team, in partnership with Culinda, have discovered a set of vulnerabilities in B. Braun Infusomat Space Large Volume Pump and the B. Braun SpaceStation.

McAfee Enterprise ATR remotely hacks a B.Braun Infusomat Pump

These critical vulnerabilities could allow an attacker to conduct remote network attacks and modify the amount of medication a patient will receive through infusion. This modification could appear as a device malfunction and be noticed only after a substantial amount of drug has been dispensed to a patient, since the infusion pump displays exactly what was prescribed, all while dispensing potentially lethal doses of medication. This attack scenario is made possible through a chain of known and previously unknown vulnerabilities found by McAfee Enterprise ATR. A critical component of this attack is that the pump’s operating system does not verify who is sending commands or data to it, allowing an attacker to carry out remote attacks undetected. For those looking for a more technical analysis of the vulnerabilities, an in-depth blog can be found here.

History and Industry Insights

From the 1960’s to 2000, infusion pumps were mostly electromechanical devices with an embedded operating system, but the turn of the century delivered “smarter” devices with better safety mechanisms and the possibility to program them, which slowly opened the door to computer security challenges. Today, it is estimated that there are over 200 million IV infusions administered globally each year. The infusion pump market is a clear potential target for attackers. The market is valued at an estimated $54 billion in annual revenue, with 2020 sales of IV pumps in the US at $13.5 billion. IV pumps are inherently trusted to be secure and have over time become the mainstay for efficient and accurate infusion delivery of medication. B. Braun is one of the key market share holders in this rapidly growing market, emphasizing the impact of these vulnerability discoveries.

Industry personnel can be the best source of information for determining impact. Shaun Nordeck, M.D, an Interventional Radiology Resident Physician at a Level 1 Trauma Center, prior Army Medic and Allied Health Professional, with more than 20 years in the medical field, states that: “Major vulnerability findings like the ones reported by McAfee’s Enterprise Advanced Threat Research team are concerning for security and safety minded medical staff. The ability to remotely manipulate medical equipment undetected, with potential for patient harm, is effectively weaponizing these point of care devices. This is a scenario previously only plausible in Hollywood, yet now confirmed to be a real attack vector on a critical piece of equipment we use daily. The ransomware attacks that have targeted our industry rely on vulnerabilities just like these; and is exactly why this research is critical to understanding and thwarting attacks proactively.”

These vulnerabilities were reported to B. Braun beginning in January 2021 through McAfee’s responsible disclosure program. Through ongoing dialog, McAfee Enterprise ATR have learned that the latest version of the pump removes the initial network vector of the attack chain. Despite this, an attacker would simply need another network-based vulnerability and all remaining techniques and vulnerabilities reported could be used to compromise the pumps. Additionally, the vulnerable versions of software are still widely deployed across medical facilities and remain at risk of exploitation. Until a comprehensive suite of patches is produced and effectively adopted by B. Braun customers, we recommend medical facilities actively monitor these threats with special attention, and follow the mitigations and compensating controls provided by B. Braun Medical Inc. in their coordinated vulnerability disclosure documentation.

Call to Action

This concludes a research project which took two senior researchers a significant amount of time to showcase a life-threatening risk of a medical device being taken over by a remote attacker. For the time being, ransomware attacks are a more likely threat in the medical sector, but eventually these networks will be hardened against this type of attack and malicious actors will look for other lower-hanging fruits.

The unfortunate reality is that individuals can’t do much to prevent or mitigate these enterprise-level risks, outside of staying mindful of security issues and maintaining awareness of possible threats. However, the good news is that security researchers continue to propel this industry towards a safer future through responsible disclosure. We strongly encourage vendors to embrace vulnerability research and consumers to demand it. The medical industry has lagged severely behind others in the realm of security for many years – it’s time throw away the digital “band-aids” of slow and reactive patching, and embrace a holistic “cure” through a security-first mindset from the early stages of development, combined with a rapid and effective patch solution.

Braun Medical Inc. Statement

In May 2021, B. Braun Medical Inc. disclosed information to customers and the Health Information Sharing & Analysis Center (H-ISAC) that addressed the potential vulnerabilities raised in McAfee’s report, which were tied to a small number of devices utilizing older versions of B. Braun software. Our disclosure included clear mitigation steps for impacted customers, including the instructions necessary to receive the patch to eliminate material vulnerabilities.

Braun has not received any reports of exploitation or incidents associated with these vulnerabilities in a customer environment.

The post Overmedicated: Breaking the Security Barrier of a Globally Deployed Infusion Pump appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Infosecurity Europe Moves to ExCeL London in 2022

Infosecurity Europe Moves to ExCeL London in 2022

Infosecurity Europe, Europe’s number one information security event, will run from Tuesday 21 to Thursday 23 June 2022 in its new home, ExCeL London.

For many years, Infosecurity Europe, organised by RX (Reed Exhibitions), has taken place at London Olympia. The last two editions of the in-person event have been postponed due to COVID-19.

According to the organizers, the change of venue will allow the event to continually evolve and grow the exhibition and conference program to keep pace with the ever-increasing importance of cybersecurity.

“Infosecurity Europe will run from Tuesday 21 to Thursday 23 June 2022 in ExCeL London”

Nicole Mills, exhibition director at Infosecurity Group, says: “Our fantastic partnership with London Olympia has played an integral part in our journey to become Europe’s premier information security event, and largest community of cybersecurity professionals. In that time, the importance of information security across every facet of society and business has increased enormously, and ExCeL London offers us the perfect platform for the next stage in our development.”

Mills refers to the larger size and greater flexibility of the space and facilities offered at ExCeL London and the regeneration of the local area around ExCeL London.

Simon Mills, Executive Director of ExCeL London, adds: “We are delighted that Infosecurity Europe, the largest gathering of the information security community in Europe, has chosen ExCeL London as its new home.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

UK Regulator Raises Serious Concerns Over Nvidia-Arm Deal

UK Regulator Raises Serious Concerns Over Nvidia-Arm Deal

The UK’s competition authority has raised significant competition concerns over Nvidia’s proposed $40bn takeover of chip designer Arm but did not cite any national security grounds for shelving the deal.

The US-based GPU specialist had wanted to complete the takeover of Cambridge-based Arm within 18 months, but that seems in doubt with the latest review from the Competition and Markets Authority (CMA).

Its report cited “detailed and reasoned submissions from customers and competitors raising concerns” across the globe.

“After careful examination, the CMA found significant competition concerns associated with the merged business’ ability and incentive to harm the competitiveness of Nvidia’s rivals (that is, to ‘foreclose’) by restricting access to Arm’s CPU IP and impairing interoperability between related products, so as to benefit Nvidia’s downstream activities and increase its profits,” it said.

The CMA said the supply of CPUs, interconnected products, GPUs and SoCs could be harmed in this way, across several global markets covering datacenter, IoT, automotive and gaming console applications.

“The CMA found that the foreclosure strategies identified would reinforce each other and would, individually and cumulatively, lead to a realistic prospect of a substantial lessening of competition, and consequently to a stifling of innovation, and more expensive or lower quality products,” the report continued.

The competitions regulator concluded that Nvidia’s suggested remedies would not address these concerns given the complexity of contracts and markets involved, the magnitude of the concerns and the “breadth and technical nature of the offer.”

Arm’s designs are found in most smartphones on the planet and technologies related to military and defense. However, the CMA decision did not reference any concerns over national security.

The UK’s digital secretary will have to decide whether to proceed to a more detailed “phase two” investigation. Lawmakers from the ruling Conservative Party are increasingly pressuring the government not to allow strategically important British companies to be taken over by foreign businesses.

SoftBank acquired Arm for $32bn (£23bn) back in 2016.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

T-Mobile Breach Now Affects 54.6 Million Individuals

T-Mobile Breach Now Affects 54.6 Million Individuals

Around six million more current and former T-Mobile customers were affected by a recently disclosed data breach, the US carrier has revealed.

The firm said it was confident it had now closed off access and egress points for the attack but admitted that the breach impacted many more individuals than at first thought.

It said 5.3 million more post-paid customers accounts were compromised, exposing names, addresses, date of births, phone numbers, IMEIs and IMSIs. That’s on top of the 7.8 million already breached.

T-Mobile said it had now also determined that phone numbers and IMEI and IMSI information were compromised for these 7.8 million individuals. That puts them at greater risk of SIM swapping fraud.

In addition, an extra 667,000 accounts of former T- Mobile customers have been accessed, compromising customer names, phone numbers, addresses and dates of birth, the carrier said.

This is on top of the 40 million former and prospective customers who had applied for credit and whose details were subsequently stolen by attackers.

Finally, up to 52,000 names related to current Metro by T-Mobile accounts may have been included in the hackers’ haul. However, no other personally identifiable information (PII) was taken from these individuals.

With the additional disclosures, the total figure for the breach now stands at 54.6 million current, former and prospective customers, up from 49 million.

Martin Riley, director of managed security services at Bridewell Consulting, said it was extremely concerning that T-Mobile was only made aware of the original incident after a threat actor started selling stolen customer data online.

“The problem is that working out what has been taken, and when, can be very challenging for many organizations which is why the average breach detection and containment time is still so long,” he added.

“Enterprises need to shift from a security monitoring and notification approach to one focused on threat detection and response. T-Mobile has been subject to numerous attacks in the past few years and needs to act competently and confidently to minimize reputational damage or a decline in public confidence.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

New LockFile Ransomware Variant Exploits “PetitPotam” Bug

New LockFile Ransomware Variant Exploits “PetitPotam” Bug

Researchers are warning of a new ransomware variant spreading globally via exploitation of the “PetitPotam” vulnerability partially patched by Microsoft last week.

Symantec said the “LockFile” variant was first spotted on July 20 in an attack on a US financial services organization and has subsequently targeted at least ten corporate victims around the world up to August 20.

Attacks begin by accessing victims’ Microsoft Exchange servers, although this vector isn’t yet clear.

Days after this initial access was established, threat actors installed a set of tools to the compromised server, including an exploit for CVE-2021-36942 (PetitPoam) and additional files designed to download shell code to help with the exploitation.

First discovered by a French researcher around a month ago, PetitPotam is an NTLM relay attack vulnerability that an attacker can use with low privileges to take over a domain controller.

It’s been reported that Microsoft’s Patch Tuesday fix for the bug has not fully patched the vulnerability.

“Once access has been gained to the local domain controller, the attackers copy over the LockFile ransomware, along with a batch file and supporting executables, onto the domain controller. These files are copied into the ‘sysvoldomainscripts’ directory,” Symantec explained.

“This directory is used to deploy scripts to network clients when they authenticate to the domain controller. This means that any clients that authenticate to the domain after these files have been copied over will execute them.”

The security giant added that although LockFile appears to be a new ransomware variant, it could have links to “previously seen or retired threats.”

Both DarkSide and REvil/Sodinokibi operations have gone silent in recent months after high-profile affiliate attacks put them in the media spotlight and under the scrutiny of the US government.

The threat actors behind LockFile use a similarly designed ransom note to that used by the LockBit gang and reference the Conti group in the email address they use for communications.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Microsoft Spills 38 Million Sensitive Data Records Via Careless Power App Configs

Data leaked includes COVID-19 vaccination records, social security numbers and email addresses tied to American Airlines, Ford, Indiana Department of Health and New York City public schools.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Windows 10 Admin Rights Gobbled by Razer Devices

So much for Windows 10’s security: A zero-day in the device installer software grants admin rights just by plugging in a mouse or other compatible device. UPDATE: Microsoft is investigating.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains