Showing posts with label medical. Show all posts
Showing posts with label medical. Show all posts

Tuesday, December 24, 2019

Keyfactor researchers discover RSA certificate vulnerability, break nearly 250,000 distinct RSA keys

Keyfactor released research findings identifying a vulnerability across active RSA certificates. RSA certificates and the RSA algorithm are commonly used to securely transmit data to a remote source. Using minimal computing resources, researchers were able to collect and analyze 175 million RSA certificates and keys used to protect real-world Internet traffic.


The active and publicly available RSA keys (which consist of the product of two large, randomly chosen primes) were mined to identify common factors. Any keys sharing one of their prime factors with another key are compromised by this technique. The analysis found over 435,000 certificates with a shared factor, with researchers able to rederive the private key.

“The findings are alarming,” said Ted Shorter, chief technology officer and co-founder at Keyfactor. “The research finds inordinate rates of compromise impacting IoT devices with design constraints and limited entropy. These devices could include cars, medical implants and other critical devices, that if compromised, could result in life-impacting harm.”


“In a real-world attack scenario, a threat actor with a re-derived private key for an SSL/TLS server certificate could impersonate that server when devices attempt to connect,” said JD Kilgallin, senior integration engineer and researcher at Keyfactor. “The connecting user or device cannot distinguish the attacker from the legitimate certificate holder, opening the door to critical device malfunction or exposure of sensitive data.”

When these devices include medical implants and cars, the impact of the malfunction can be devastating. The research stresses the importance of security best practices, random number generation for connected systems and use of cryptography to securely install firmware and software updates through the lifecycle of the device.

“Security at design is paramount for device manufacturers,” said Shorter. “Current-generation connected devices and systems must be equipped to defend against a new generation of security risks. Cryptography is essential in ensuring new and emerging devices are able to adhere to and scale with security best practices.”


Researchers built a database of 75 million active RSA keys using Keyfactor’s proprietary SSL/TLS certificate discovery capabilities. The dataset was augmented using 100 million certificates available through certificate transparency logs and analyzed on a single virtual machine in Microsoft Azure, using Keyfactor’s scalable GCD algorithm to find shared factors. 


Wednesday, December 18, 2019

HPE eHealth Centers facilitate over one million patient visits in India

Hewlett Packard Enterprise (HPE) announced that its eHealth Centers (eHCs) have collectively facilitated over 1 million patient visits across India. Offering a digital healthcare solution, the vast eHC network offers remote diagnoses free of charge in underserved communities, reaffirming HPE’s long-term commitment to the country and its mission to advance the way people live and work.

Many Indian citizens lack access to primary healthcare services, which are critical to reducing mortality rates from chronic conditions such as cardiovascular disease and diabetes. Recognizing the significant role of technology in improving access and effectiveness of primary healthcare in underserved areas, HPE launched its eHC initiative in 2012. 


The eHCs, designed to fit and deploy within a standard shipping container, connect patients with highly skilled medics. These centers also combine online training materials for remote healthcare workers with diagnostic tools that capture the patients’ vital statistics on a cloud-based application. Additionally, by leveraging data analytics, the eHCs facilitate health monitoring and management by identifying disease patterns in local communities.

In support of the government’s target of making India TB-free by 2025, HPE signed the USAID TB pledge. Under this pledge, the eHCs will screen symptomatic patients and target the “Missing TB” cases who carry the disease and go undiagnosed. The diagnosed patients will be referred to the nearest government recognized TB treatment center. The eHCs will provide free diagnostic services to over 50,000 TB patients by July 2020.

Currently, there are over 130 eHCs deployed across 18 states in the country. To further increase the reach of affordable and personalized healthcare services, HPE will set-up additional eHCs across the country. The success of eHCs in India has resulted in HPE launching such facilities in Bhutan and the Philippines.

HPE’s commitment to further improving global access to healthcare helped inspire the launch of Tech Impact 2030 last year. Along with the World Economic Forum, HPE announced the initiative focused on bringing together technology, industry and government to power meaningful change by the year 2030. 


Under this initiative, HPE introduced a challenge to enable real-time, personalized medical care for patients by 2030. Looking forward, HPE envisions emerging technology to radically improve the cost, speed and accuracy of medical research and patient care.

“At HPE, we believe technology can play a significant role in addressing rapidly-evolving healthcare needs. Being a purpose-driven organization, we strive to develop innovative models such as eHCs to make our world better,” said Som Satsangi, MD – India, HPE. “The one million eHC patient visits is a significant milestone in reaffirming our commitment to build a culture of innovation that positively impacts local communities across the country.”

Monday, December 9, 2019

Kanguru debuts OS Agnostic, its fingerprint encrypted access flash drive with remote management capability

Kanguru launched its OS Agnostic, its Fingerprint Access Hardware Encrypted Flash Drive with remote management capability. This biometric fingerprint access flash drive supplants the bulky pinpads and fussy combo keypads of encrypted devices, making it convenient and easy to use. 

With the tap of the finger, the Kanguru Defender Bio-Elite30 Fingerprint Hardware Encrypted Flash Drive provides quick access to encrypted files.


The Defender Bio-Elite30 Fingerprint Encrypted Flash Drive is OS platform agnostic; 256-bit hardware encryption (XTS Mode); and assigns multi-finger access for each fingerprint or user(s). It also features new command console with onboard browser; option to remotely manage with Kanguru Remote Management Console (KRMC); and comes with optional on-board antivirus, real-time scanning protection by BitDefender. It is also RSA-2048 digitally-signed secure firmware and TAA compliant.


Being OS Agnostic, the Defender Bio-Elite30 can be used on virtually any machine, from Windows and MacOS, to medical equipment, smart TVs and even ATMs for making bank machine updates. This makes it highly versatile for all types of industries.

With best-in-class AES 256-Bit hardware encryption, the new biometric fingerprint encrypted flash drive allows a user to assign multiple finger access for themselves, and/or others whom they authorize. Permissions can be enabled for full read/write secure entry, or read only restricted access to allow users to simply view the encrypted files.


The Defender Bio-Elite30 Fingerprint secure flash drive is USB powered, rising above all other competitive devices that require a battery which could fail at the worst possible time.

Tuesday, December 3, 2019

Kaspersky releases its financial threat predictions for 2020, as fintech, mobile banking and e-commerce are likely to intensify

According to Kaspersky experts, financially motivated cyberthreat actors may start to target investment apps, online financial data processing systems and upcoming cryptocurrencies in 2020. Additionally, experts predict they may offer paid access to banks’ infrastructures and develop new strains of mobile banking malware based on leaked source code.

Financial cyberthreats are considered to be some of the most dangerous, as their impact usually results in direct financial losses for victims. 2019 has seen some significant developments in the industry and also in how financial attackers operate. 


These events allowed Kaspersky researchers to suggest several important potential developments for the financial threat landscape for 2020. 

Fintech is under attack. Mobile investments apps have become more popular among users around the globe, and this trend won’t go unnoticed by cybercriminals in 2020. Not all of these apps utilize best security practices, like multi-factor authentication or protection of the app connection, which may give cybercriminals a potential way to target users of such applications

Kaspersky research and monitoring of underground forums suggests that the source code of some popular mobile banking Trojans was actually leaked into the public domain. Previous similar cases of malware source code leakage such as Zeus and SpyEye that resulted in an increased number of new variations of these Trojans. In 2020 this pattern may repeat.


In 2020, Kaspersky experts expect an increase in the activity of groups specialised in criminal-to-criminal sale of network access to banks in the African and Asian regions, as well as in Eastern Europe. Their prime targets are small banks as well as financial organizations recently bought by big players who are rebuilding their cybersecurity system in accordance with the standards of their parent companies. it is also expected that the same banks may become victims of targeted ransomware attacks, as banks are among those organizations that are more likely to pay a ransom than accept the loss of data.

Magecarting 3.0 features more cybercriminal groups will target online payment processing systems. Over the past couple of years, so-called JS-skimming (the method of stealing of payment card data from online stores) has gained immense popularity among attackers. 

Currently, Kaspersky researchers are aware of at least 10 different actors involved in these type of attacks and experts believe that their number will continue to grow during the next year. The most dangerous attacks will be on companies that provide services such as e-commerce as-a-service, which will lead to the compromise of thousands of companies.


“This year has been one of many important developments,” says Yuriy Namestnikov, a security researcher at Kaspersky. “Just as we predicted at the end of 2018, it has seen the emergence of new cybercriminal groups like CopyPaste, new geography of attacks by Silence group and cybercriminals shifting their focus to data that helps to bypass antifraud systems in their attacks. Behavioral and biometrics data is on sale on the underground market. Additionally, we expected JS-skimmer base attacks to increase and they did. With 2020 on the horizon, we recommend security teams in potentially affected areas of the finance industry to gear up for new challenges. There is nothing inevitable in potential upcoming threats, it is just important to be properly prepared for them.”

In addition to financial sector, Kaspersky researchers identified other industries that will face new security related challenges in the upcoming year, such as the healthcare industry is advised to focus on protecting medical records and connected medical devices, as they are becoming the target of threat actors. 

Corporate security teams should pay more attention to cloud infrastructure and also to addressing growing risks of insiders accessing their networks. There are groups of criminals specializing on recruiting insiders through various techniques, including blackmail. 

Telecommunications and other industries that vastly use cellular communications should be prepared to assess and address risks that will come with wider adoption of 5G, which is expected to start in 2020. 

Thursday, November 28, 2019

International Medical Solutions launches CloudSync for Google Cloud healthcare customers transitioning to the cloud

International Medical Solutions (IMS), a Google Cloud Partner, announced a solution that will enable radiologists and other healthcare clinicians to transition to the cloud. 

The IMS CloudSync enables radiology sites to transition to the cloud and continue to use their legacy on-premise workstations and DICOM viewers. The front-end solution designed with the needs of initial Google Cloud Platform (GCP) users in mind uses an implementation that enables GCP to be added to an on-premise legacy viewing workflow, where GCP would act as the archive. 



The plug-and-play solution works out-of-the-box and allows PACS sites to sync their on-premise storage of medical images with their cloud storage. The added benefit is the sites can continue to use their legacy PACS workstations to view images stored in the cloud. 

"IMS has been working closely with Google Cloud to solve unmet needs for customers who are starting to transition to the cloud. CloudSync™ is an out-of-the-box, cost-effective solution that improves clinician workflows while enabling them to use on-prem legacy systems at the same time," says Vittorio Accomazzi, CTO of International Medical Solutions. Accomazzi adds, "Also, CloudSync inherently provides image sharing as it allows multiple sites to share and exchange images on GCP."

IMS CloudVue will also be featured at RSNA this year. The solution, which launched earlier this year, is a cloud-based viewing platform that provides the experience of an installed application on any device or workstation. CloudSync and CloudVue can also be used as a disaster recovery solution since CloudSync will upload the on-premise data onto GCP, which can be accessed using CloudVue. At any given time, the user has two copies of the data and at least two ways for accessing it.


Over the last year, IMS has worked closely with Google Cloud to enhance the integration with the Google Cloud Healthcare API, including integrating with machine learning backend.

Thursday, November 21, 2019

Galaxy Watch and Watch Active UX now get access to latest features found on the Galaxy Watch Active2 smartwatches

Samsung announced that Galaxy Watch and Galaxy Watch Active users will soon be able to enjoy all the user experience functionality found on the Galaxy Watch Active2 following a new software update. The South Korean giant is bringing a range of dynamic updates to its earlier-generation watches, including enhanced Samsung Health features, Bixby features, and customization options.


After the update, Galaxy Watch and Galaxy Watch Active users will be able to take fuller advantage of what Bixby has to offer, including using Bixby Voice to start exercise routines, find out time differences between places, and control their SmartThings ecosystem. Not only does Bixby learn from their routine and become more helpful over time, but its newly expanded language capabilities, include British English, French, German, Italian and Spanish.

With this latest upgrade, Galaxy Watch and Galaxy Watch Active users will also be able to customize their Watch faces more than ever before. Across all of our Galaxy Watch models, users will now have access to 24 new sub-dials and complications, building on the 17 already available, making the watch even more customizable, so users can access exactly the information they want, where they want it. 


The improved UX will bring the My Style feature to Galaxy Watch and Galaxy Watch Active for the first time.

Icons for in-use apps have been moved to the bottom of the watch face, helping users keep track of and quickly access any apps with in-progress tasks, such as outgoing calls. Additionally, the current time will now always be displayed on-screen when the stopwatch app is in use or users are on a call, and users can customize the icons in their quick panel after a change in layout. 


Other UX benefits include a clearer graphic UI, easier user interaction, and new emoji offerings in a range of diverse skin tones. For Galaxy Watch Active users, a new Touch Bezel interface is included in the upgrade, allowing users to navigate using finger swipe actions around the bezel.

Samsung will begin to roll out the update region-by-region. The software update will offer Galaxy Watch users even more tools for taking ownership over their health, more opportunities to make navigating Galaxy Watch easier using Bixby Voice commands, and more ways to turn their favorite watch into a statement piece.

Monday, November 4, 2019

QliqSOFT post-acute visit management app offers business-enhancing delivery-data for hospice and home healthcare agencies

QliqSOFT has launched on Monday VisitPath, its home health nurse distress notification-enabled mobile care-delivery app designed to provide hospice and post-acute business administration with data that improves business and patient outcomes. Additionally, Visit Path puts safety in the hands of the home health nurse. 

The Visit Path web-based administrator’s dashboard integrates with GPS-enabled smart devices to ensure patient care delivery is optimized, on time and recorded. This, along with the ability to manage unscheduled and after-hours visits, improves patient and home health nurse satisfaction, patient outcomes, billing accuracy and a digital record that prevents ensures government reimbursements are never penalized.



As a real-time, GPS-enabled care management delivery solution, Visit Path verifies where and when a hospice or home health field nurse is on duty, begins service for a client, when they complete service and when they are off duty. This verification of service is the basis for accurate, compliant billing. The administrator's dashboard is a window into ROI.


With a focus on home health, hospice, and other post-acute verticals, QliqSOFT is excited to share the news of Visit Path to coincide with the National Hospice and Palliative Care Organization’s (NHPCO) annual Interdisciplinary Conference.

“This app is a good solution for hospice and home healthcare agencies that want more insight into their care delivery data to reduce costs and improve their business outcomes," says QliqSOFT founder and CEO Krishna Kurapati. “Additionally, the distress notification provides safety and security for nurses while visiting homes and if they should run into trouble while in transit between visits.”


“We wanted to provide hospice and home healthcare agencies with a product that gives them real-time knowledge of completed patient visits activity to help them better manage their field staff,” Krishna added. 

Thursday, October 31, 2019

Data Dimensions introduces PANOPTIC, its agnostic, end-to-end medical bills processing platform

Data Dimensions launched Thursday PANOPTIC, its complete processing platform built for the auto casualty and work compensation markets.

The PANOPTIC platform is completely agnostic, integrating with any bill review company, making it a versatile asset to insurers. With features such as provider credentialing, fraud and abuse detection, bill screening, filtering and routing, PANOPTIC is a comprehensive cost containment tool. The platform can also identify and help to prevent provider network leakage.


The PANOPTIC platform has the ability to receive claims documentation, medical bills and their attachments in any format (Paper mail, Fax, email, eBill, direct upload); an Intelligent Business Rules Engine applies ICD-9/ICD-10 validation, medical bills filtering, provider screening and claimant eligibility before routing the bills to the appropriate network, payor or bill review platform.


In addition, PANOPTIC helps insurers to meet Insurance Diversity Initiative (IDI) goals, pay providers and non-providers electronically, and provides actionable data through analytics and reporting. 


Artificial Intelligence is applied throughout the platform for maximum accuracy and efficiency, and its proprietary tracking and monitoring component gives visibility at every stage of the process.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...