A hidden backdoor function in the Contec CMS8000 patient monitor could give unauthorized access to patient data, warns the US Cybersecurity and Infrastructure Security Agency (CISA). The healthcare device is widely used across the US and EU. Exploiting the vulnerability could disrupt monitoring and lead to incorrect treatment. The backdoor lets the device execute unverified remote files, bypassing security protocols. Vendor updates have failed to remove the vulnerability. Secure networking experts Claroy suggest it was poor design, not malice.

RESURGE Malware Exploits Ivanti Flaw with Rootkit and Web Shell Features
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed a new malware named RESURGE. Deployed in exploiting Ivanti Connect Secure appliances’ patched security flaw,