You might recall that I posted a story recently on a hack that led to the theft of 4.5 million patient records. Now we have the cause for the hack:
According to a blog post from TrustedSec, an information security consultancy in Ohio, the breach at Community Health Systems (CHS) is the result of attackers targeting a flaw OpenSSL, CVE-2014-0160, better known as Heartbleed.
The incident marks the first case Heartbleed has been linked to an attack of this size and type.
I find it stunning that they would not have addressed any Heartbleed related vulnerabilities in a timely manner given how much attention the flaw was given earlier this year. This is a lesson that if you’re responsible for securing your network, you have to address issues like these or bad things will happen to you. It’s also proof that we need to hold companies who choose not to address issues like these responsible.
This really isn’t going to end well for the victims of this hack.
Related
This entry was posted on August 20, 2014 at 10:47 am and is filed under Commentary with tags Hacked, Security. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Heartbleed Led To Health Care Hack
You might recall that I posted a story recently on a hack that led to the theft of 4.5 million patient records. Now we have the cause for the hack:
According to a blog post from TrustedSec, an information security consultancy in Ohio, the breach at Community Health Systems (CHS) is the result of attackers targeting a flaw OpenSSL, CVE-2014-0160, better known as Heartbleed.
The incident marks the first case Heartbleed has been linked to an attack of this size and type.
I find it stunning that they would not have addressed any Heartbleed related vulnerabilities in a timely manner given how much attention the flaw was given earlier this year. This is a lesson that if you’re responsible for securing your network, you have to address issues like these or bad things will happen to you. It’s also proof that we need to hold companies who choose not to address issues like these responsible.
This really isn’t going to end well for the victims of this hack.
Share this:
Like this:
Related
This entry was posted on August 20, 2014 at 10:47 am and is filed under Commentary with tags Hacked, Security. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.