Security News > 2021 > August

Cisco, Sonatype and Others Join Open Source Security Foundation
2021-08-02 13:07

The Open Source Security Foundation, the cross-industry forum focused on improving open source software security, has expanded its member list with the addition of names such as Accurics, Anchore, Bloomberg Finance, Cisco Systems, Codethink, Cybertrust Japan, OpenUK, ShiftLeft, Sonatype and Tidelift. With open source software becoming a central pillar of the application development lifecycle, ensuring the security of open source code is essential to securing modern software, regardless of whether it is used on end-user devices or in enterprise environments.

Amazon Fined 746 Mn Euros in Luxembourg Over Data Privacy
2021-08-02 12:45

Amazon was fined 746 million euros by Luxembourg authorities over allegations it flouted the EU's data protection rules, the online retail giant said Friday. The fine was issued July 16 by the Luxembourg National Commission for Data Protection following its determination that "Amazon's processing of personal data did not comply with the EU General Data Protection Regulation," Amazon said in a securities filing.

The European Space Agency Launches Hackable Satellite
2021-08-02 11:46

A sophisticated telecommunications satellite that can be completely repurposed while in space has launched. Because the satellite can be reprogrammed in orbit, it can respond to changing demands during its lifetime.

PwnedPiper vulns have potential to turn Swisslog's PTS hospital products into Swiss cheese, says Armis
2021-08-02 11:36

Security specialist Armis has discovered vulnerabilities, collectively dubbed PwnedPiper, in pneumatic tube control systems used in thousands of hospitals worldwide - including 80 per cent of the major hospitals found in the US. The researcher spotted the PwnedPiper vulnerabilities in Swisslog's Nexus stations for its Translogic Pneumatic Tube System product - a connected control system for the delivery tubes which send medicines, samples, blood products, and paperwork whizzing around a hospital. "The PTS system supports variable speed transactions which, on the one hand allow for express shipment of urgent items," the researchers said, "While on the other, enable the slow transfer of sensitive items, such as blood products, that may be harmed if jolted too quickly within the tubes. If an attacker were to compromise the PTS system, he may alter the system's speed restrictions, which can in turn damage such sensitive items."

NSA Shares Guidance for Government Employees on Securing Wireless Devices in Public
2021-08-02 11:30

The National Security Agency has published a new document to provide a series of recommendations on how governmental agencies in the United States can mitigate the cybersecurity risks associated with the use of wireless devices in public settings. The NSA points out that securing devices for the use of public Wi-Fi hotspots is not enough, as their Bluetooth and Near Field Communications functions require similar attention as well.

Flaws in Pneumatic Tube System Can Facilitate Cyberattacks on North American Hospitals
2021-08-02 10:58

Several serious vulnerabilities discovered in a widely used pneumatic tube system made by Swisslog Healthcare can be highly useful for ransomware attacks aimed at hospitals, according to enterprise IoT security firm Armis. Armis researchers discovered 8 types of vulnerabilities in the TransLogic pneumatic tube system made by Swisslog Healthcare, which specializes in automation and transport solutions for hospitals and pharmacies.

PwnedPiper critical bug set impacts major hospitals in North America
2021-08-02 10:41

Pneumatic tube system stations used in thousands of hospitals worldwide are vulnerable to a set of nine critical security issues collectively referred to as PwnedPiper. PTS solutions are part of a hospital's critical infrastructure as they are used to quickly deliver items like blood, tissue, lab samples, or medication to where they're needed.

Critical vulnerabilities may allow attackers to compromise hospitals’ pneumatic tube system
2021-08-02 10:14

Armis researchers have unearthed critical vulnerabilities in Swisslog Healthcare's Translogic pneumatic tube system, which plays a crucial role in patient care in more than 3,000 hospitals worldwide. Attackers exploiting the vulnerabilities could gain complete control over the PTS network, negatively affect the functioning of the system and damage sensitive materials, compromise sensitive information, and interfere with the hospitals' workflows.

Zoom to Settle US Privacy Lawsuit for $85 Mn
2021-08-02 10:01

Zoom, the videoconferencing firm, has agreed to settle a class-action US privacy lawsuit for $85 million, it said Sunday. The suit charged that Zoom's sharing of users' personal data with Facebook, Google and LinkedIn was a breach of privacy for millions.

PwnedPiper threatens thousands of hospitals worldwide, patch your systems now
2021-08-02 10:00

The software used to control pneumatic tubes in over 3,000 hospitals around the world has nine critical vulnerabilities that could halt hospital operations if exploited by a savvy attacker. Tube systems in hospitals are commonly used to deliver medicine, transport blood and other essential medical supplies, and send lab samples across buildings that would take considerable time to deliver on foot.