Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

11/26/2018
01:00 PM
100%
0%

Ransomware Attack Forced Ohio Hospital System to Divert ER Patients

Malware infection fallout sent ambulances away from East Ohio Regional Hospital and Ohio Valley Medical Center over the Thanksgiving weekend.

A ransomware attack that hit computer systems at the East Ohio Regional Hospital and Ohio Valley Medical Center reportedly disrupted the hospitals' emergency rooms.

The attack hit the evening of Friday, Nov. 23, leaving the hospitals unable to accept ER patients via emergency responders. Those patients were diverted to other area hospital emergency rooms, The Times Ledger newspaper reported. 

Karin Janiszewski, director of marketing and public relations for the hospitals, told the paper that the two hospitals hit by ransomware were able to handle walk-in ER patients, and that the IT team had hoped to have the attack "resolved" by Sunday, Nov. 25. "We have redundant security, so the attack was able to get through the first layer but not the second layer," she said. "There has been no patient information breach."

Read more here. 

 

Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
RedParker
100%
0%
RedParker,
User Rank: Apprentice
11/27/2018 | 12:20:00 PM
Ransom ware attack of life support operations should be a capital offence!
Ransom ware attack of life support operations should be a capital offence! Track em down, string em up!
REISEN1955
100%
0%
REISEN1955,
User Rank: Ninja
11/27/2018 | 3:22:41 PM
Re: Ransom ware attack of life support operations should be a capital offence!
Agree - IT stories often forget that REAL PEOPLE are impacted.  IBM failures on multiple financial systems, the CSC disaster at National Health Service in England - all impact people profoundly.  And yet we write essay after essay here as if IT exists in a bubble. 
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
11/28/2018 | 12:04:19 PM
Re: Ransom ware attack of life support operations should be a capital offence!
And AGAIN ----- What if this was JUST a server failure?  Drive failure?  I had a bad block wipe out an entire server in a medical office I supported and GUESS WHAT ---- I had a tested backup and restore plan.  Now this was a small office, no comparison but I had everything UP and running without flaw in 3 hours.  True.    I had a 501C3 account hit by Cryptolocker in 2014 and I had everything up and running in, likewise, 3 hours with only a single desktop displa (the actual desktop itself) unrecoveable because I did not know the executive director was using it.  98% restoration across he board.  DO these hospials and cities HAVE a backup and disaster recovery protocol?  From what I can almost nobody has one.  Nor do they test because a 2:30 am, nobody is thinking sraight.

Sheesh I hate writing this time and time again.  Yes exfiltration of data is bad but take that OUT of the equation and this is jus a server or workstation issue pure and simple. 
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/28/2018 | 1:31:53 PM
Re: Ransom ware attack of life support operations should be a capital offence!
had everything UP and running without flaw in 3 hours. This is good. 3 hours are sometimes are end of a business unfortunately.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/28/2018 | 1:33:04 PM
Re: Ransom ware attack of life support operations should be a capital offence!
DO these hospials and cities HAVE a backup and disaster recovery protocol? Really good question, they should have a BC/DR plan.
RedParker
50%
50%
RedParker,
User Rank: Apprentice
11/28/2018 | 6:51:53 PM
Re: Ransom ware attack of life support operations should be a capital offence!
Having a backup is not the point here, emergrncy life saving operations were impacted, lives were at stake. Sorting out in 3 hours though excellent, has nothing to do with the deterent of a rightous public beheading for a monstous crime. We need laws to allow capitol punishment for this kind of targeted attack, Stealing from a poorly secured bank is not the same, doing this requires blood. A few heads on pikes are needed

.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/28/2018 | 1:29:36 PM
Re: Ransom ware attack of life support operations should be a capital offence!
IT stories often forget that REAL PEOPLE are impacted. This is true. I think that is the main results of most attacts, system are down and stress is high.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/28/2018 | 1:27:55 PM
Re: Ransom ware attack of life support operations should be a capital offence!
Ransom ware attack of life support operations should be a capital offence! That makes sense. Many other attacks also threaten the life of individuals.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/28/2018 | 1:26:38 PM
second layer?
Interesting, how good is the second layer if first layer is already preventing them to provide ER service? I think they need to check see if the layers are good enough for them.
The Cold Truth about Cyber Insurance
Chris Kennedy, CISO & VP Customer Success, AttackIQ,  11/7/2019
Black Hat Q&A: Hacking a '90s Sports Car
Black Hat Staff, ,  11/7/2019
The State of Email Security and Protection
Mike Flouton, Vice President of Email Security at Barracuda Networks,  11/5/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprise
Assessing Cybersecurity Risk in Today's Enterprise
Security leaders are struggling to understand their organizations risk exposure. While many are confident in their security strategies and processes, theyre also more concerned than ever about getting breached. Download this report today and get insights on how today's enterprises assess and perceive the risks they face in 2019!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18881
PUBLISHED: 2019-11-12
WSO2 IS as Key Manager 5.7.0 allows unauthenticated reflected XSS in the dashboard user profile.
CVE-2019-18882
PUBLISHED: 2019-11-12
WSO2 IS as Key Manager 5.7.0 allows stored XSS in download-userinfo.jag because Content-Type is mishandled.
CVE-2019-18873
PUBLISHED: 2019-11-12
FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user account to fully compromise the system via a GET request. When the admin visits user information under "User Manager" in the control panel, the pa...
CVE-2019-18874
PUBLISHED: 2019-11-12
psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a while or for loop that converts system data into a Python object.
CVE-2019-18862
PUBLISHED: 2019-11-11
maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.