Gallery: Medical Devices That Are Vulnerable to Life-Threatening Hacks
Hospira01hospira-lifecarepca-plum-a
*1. The Hospira LifeCare Drug Infusion Pump.* Security researcher Billy Rios was in the hospital for emergency surgery one day when he eyed the drug infusion pump used to deliver medication to him and other patients and realized it was the same model he'd reverse-engineered as part of a security project. Rios had found vulnerabilities in the pump that would allow a hacker to surreptitiously and remotely change the amount of drugs administered to patients to [deliver a deadly dosage](https://www.wired.com/2015/06/hackers-can-send-fatal-doses-hospital-drug-pumps/). The vulnerabilities affect at least five models of drug infusion pumps made by Hospira---an Illinois firm with more than 400,000 intravenous drug pumps installed in hospitals around the world. But pumps made by other companies may be vulnerable in the same way.
02medtronic
*2. Medtronic's Paradigm 512, 522, 712, and 722 insulin pumps.* Patients use insulin pump systems to manage their blood glucose levels. But the systems don't encrypt the commands that patients send their pumps, nor do they authenticate the source of the commands---this means unauthorized parties in the vicinity of a pump could intercept the legitimate commands and replace them with bogus commands that could deliver a deadly insulin dose to a patient.
Getty Images03GettyImages-136997842
*3. Implantable Cardioverter Defibrillators (ICDs).* Life-saving devices like implantable cardioverter defibrillators deliver shocks to a patient who shows signs of going into cardiac arrest. So you'd think they'd be designed to prevent someone from disabling or hijacking them to deliver unwarranted shocks. But researchers found that a couple of companies that make defibrillators have a feature that attackers could hijack. The companies use a Bluetooth stack for configuring the devices and delivering test shocks to patients after the devices are first implanted. But they evidently use default and weak passwords for the Bluetooth stack, which an attacker could use to connect to the devices. "It’s a simple password like an iPhone PIN that you could guess very quickly," Scott Erven, head of information security for Essentia Health, discovered.
Jasper Juinen/Bloomberg/Getty Images04Royal Philips N.V. Healthcare Systems
4\. X-Ray Systems. The computers that physicians and other hospital staff use to access patient X-rays generally require authentication to view the images; they also maintain a log of everyone who accesses them to protect patient privacy and guard against misuse. But security researcher Scott Erven found that these images are often backed up to centralized storage units that [don't require any authentication to access them](https://www.wired.com/2014/04/hospital-equipment-vulnerable/) and also don't log who views the images.
Getty Images05GettyImages-495491976
*5. Blood Refrigeration Units.* Some refrigeration systems used to preserve blood and pharmaceuticals have a web interface that lets hospital staff set the temperature range remotely. Although the systems can issue alerts via email or wireless pagers to notify lab and hospital staff if the temperature falls outside certain boundaries, the systems are not secure---they are only protected by a hardcoded password the vendor embedded in the systems, which a hacker can decipher. And once in the system, an attacker could not only alter the temperature but turn off the alert feature to prevent the system from notifying hospital staff.
Getty Images06GettyImages-523837251
*6. CT Scans.* Scott Erven and his team of researchers found vulnerabilities that left [CT scanning equipment open to attack](https://www.wired.com/2014/06/hospital-networks-leaking-data/). They found, for example, that they could remotely alter the configuration files in a hospital's CT scan and change radiation exposure limits that set the amount of radiation patients receive.
CAE Healthcare07istan
*7. iStan.* Though it's not actually a medical device, iStan expertly illustrates why securing medical devices and equipment is so important. The $100,000 medical dummy comes equipped with robotics that mimic the human cardiovascular, respiratory, and neurological systems. Earlier this year, researchers at the University of South Alabama "killed" Stan by hacking his embedded pacemaker. "The simulator had a pacemaker so we could speed the heart rate up, we could slow it down," they [told Motherboard](http://motherboard.vice.com/read/hackers-killed-a-simulated-human-by-turning-off-its-pacemaker). "If it had a defibrillator, which most do, we could have shocked it repeatedly. \[But\] it's not just a pacemaker---we could do it with an insulin pump, \[or\] a number of things that would cause life-threatening injuries or death."
OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face
In a new disclosure, OpenAI says its agent used exposed logins to gain access to at least four “publicly available services” in its unhinged quest to solve a test.
Dell Cameron
A Typo Landed an Innocent Gamer in Prison for 18 Months
How much could a single underscore in a username really matter? Just ask Brandon Klayme, who served 18 months in prison before realizing how authorities arrested, charged, and convicted the wrong man.
Nate Anderson, Ars Technica
Ebay Has to Pay $55.7 Million in Settlement for Its Unhinged Harassment Campaign
For months on end, eBay employees and contractors made life hell for a couple that had criticized the company. Six years later, the company is finally paying up.
Lauren Goode
Laura Loomer’s Reversal on Ukraine Stirs Up the MAGA Civil War
Donald Trump’s base has been increasingly spilt. Laura Loomer’s sudden embrace of Ukraine has only widened that divide.
David Gilbert
Is the Electric Trike the Next Big Thing in Shared Micromobility?
Veo is launching accessibility-focused electric tricycles in Denver, with plans to put its e-trikes on the streets nationwide.
Boone Ashworth
What WIRED Writers Would Actually Give Their Moms
Your mom never gets you a thoughtless gift, so you shouldn’t get her one, either. Here’s every cool gift WIRED writers would give their mothers.
Nena Farrell
Which Apple Watch Should You Buy?
Should you splurge on the new Series 11, or will the SE 3 do? Let us help you figure out which version to get (and which to avoid).
Boutayna Chokrane
12 Adventurous Gifts for Hikers, Backpackers, and Outdoorsy People
Let them pick out their own hiking boots. Instead, try gifting a useful blade or a nature journal to delight your outdoorsy friend.
Scott Gilbertson
A Two-Person Startup Has Fixed One of the Most Hated Sounds in Modern Life
Beeeep. Beeeep. Beeeeeeeeeeeeeeeep.
Jeremy White
Can the New York Times Save Journalism From Our AI Overlords?
In 2023, the Times sued OpenAI and Microsoft for copyright infringement. They’ve since spent more than $20 million on the case, and publisher A.G. Sulzberger has no plans to stop fighting it.
Katie Drummond
Silicon Valley’s Next IPO Billionaires Are Coming. Nonprofits Are Ready for Them
Anthropic and OpenAI employees are expected to give generously after their companies go public. “It’s going to be a wild ride,” says one nonprofit leader.
Paresh Dave
The Dyson V16 Piston Animal Can Do It All
Dyson’s new stick vacuum can vacuum and mop in a single cordless device—if you’re willing to really splurge.
Nena Farrell