Security News

Open Source Tool Helps Organizations Secure GE CIMPLICITY HMI/SCADA Systems
2021-02-05 13:31

Industrial cybersecurity firm OTORIO this week announced the availability of a new open source tool designed to help organizations secure their GE CIMPLICITY systems. OTORIO has worked with GE Digital to develop a free and open source tool that can be used to harden CIMPLICITY systems by ensuring that they are configured in accordance with the vendor's guidelines for security best practices.

Over 100 GE Healthcare Devices Affected by Critical Vulnerability
2020-12-08 18:01

More than 100 medical devices made by GE Healthcare are affected by a potentially serious vulnerability that could allow an attacker to access or modify protected health information, medical cybersecurity company CyberMDX reported on Tuesday. The vulnerability, which is tracked as CVE-2020-25179 with a critical severity rating, has been found to impact CT scan, molecular imaging, PET, X-Ray, ultrasound and mammography devices, as well as workstations and imaging devices used in surgery.

Critical, Unpatched Bugs Open GE Radiological Devices to Remote Code Execution
2020-12-08 17:00

A pair of critical vulnerabilities have been discovered in dozens of GE Healthcare radiological devices popular in hospitals, which could allow an attacker to gain access to sensitive personal health information, alter data and even shut the machine's availability down. GE has confirmed the vulnerability, which impacts the radiological devices as well as certain workstations and imaging devices used in surgery, according to the CyberMDX alert.

Severe MDHexRay bug affects 100+ GE Healthcare imaging systems
2020-12-08 12:00

A vulnerability in GE Healthcare's proprietary management software used for medical imaging devices could put patients' health privacy at risk. GE's closed source management software runs on top of the Unix-based operating system installed on medical imaging systems to enable remote maintenance and update procedures.

GE Employees Lit Up with Sensitive Doc Breach
2020-03-25 15:38

A phisher's treasure chest of personally identifiable information for General Electric employees has been exposed - thanks to the compromise of one of the company's partners, Canon Business Process Services. The impact of the breach effects current and former GE employees and beneficiaries entitled to benefits, the conglomerate said.

GE Says Some Employees Hit by Data Breach at Canon
2020-03-25 09:54

General Electric revealed last week that the personal information of some employees may have been compromised as a result of a data breach suffered by Canon Business Process Services. In a data breach notification sent to affected individuals and submitted to the California Attorney General, GE said an unauthorized party gained access to a Canon email account containing documents belonging to some of its employees.

Vulnerabilities Found in Some GE Healthcare Devices
2020-01-24 20:33

Federal regulators are warning healthcare providers about six vulnerabilities in some of GE Healthcare's medical device systems that could allow attackers to remotely take control of the gear. The GE Healthcare product vulnerabilities are the latest example of the medical device cybersecurity challenges the healthcare sector faces.

MDhex vulnerabilities open GE Healthcare patient monitoring devices to attackers
2020-01-24 13:09

Researchers have discovered six critical and high-risk vulnerabilities - collectively dubbed MDhex - affecting a number of patient monitoring devices manufactured by GE Healthcare. The flaws may, according to GE Healthcare, allow an attacker to make changes at the device's OS level that may render the device unusable or interfere with its function, make changes to alarm settings on connected patient monitors, and utilize services used for remote viewing and control of multiple devices on the network to access the clinical user interface and make changes to device settings and alarm limits, which could lead to missed, unnecessary, or silenced alarms.

Vulnerabilities Found in GE Healthcare Patient Monitoring Products
2020-01-23 19:18

Several potentially serious vulnerabilities have been found in patient monitoring products made by GE Healthcare, the DHS's Cybersecurity and Infrastructure Security Agency and healthcare cybersecurity firm CyberMDX revealed on Thursday. GE Healthcare has also inadvertently exposed SSH private keys, making it possible for hackers to remotely connect to devices and execute malicious code.

GE, Dunkin’, Forever 21 Caught Up in Broad Internal Document Leak
2019-12-09 15:28

A PR and marketing provider exposed sensitive data for a raft of big-name companies.