Mitigate Risk from IoT Vulnerability: Post
A new Internet of Things (IoT) vulnerability discovered by IBM’s X-Force Red hacker team could affect many Internet-connected devices, including medical devices, according to a Security Intelligence post. The hacker team reportedly found a vulnerability in a module used in many devices. The affected Thales modules are mini circuit boards that enable mobile communication in IoT devices.
The post says that bad actors could take advantage of the vulnerability to manipulate readings from monitoring medical devices to cover up concerning vital signs or cause false panic. “In a device that delivers treatment based on its inputs, such as an insulin pump, cybercriminals could over- or under-dose patients,” the post says.
X-Force Red suggests taking these steps to mitigate the risk and address the issue immediately:
- apply the patch provided by Thales and install firmware updates as quickly as possible;
- rethink what is stored on devices and whether it could be stored elsewhere more securely;
- apply behavioral analysis practices;
- ensure IoT is on the facility’s security team’s radar; and
- hire a hacker to conduct regular penetration tests on the company and its devices and help remediate operational vulnerabilities.