Skip to main content

“Fatal” security bugs discovered in defibrillators and medical implants

1124645 autosave v1 pacemaker heart
Sunzi99/Wikimedia Commons
A team of researchers found several potentially “fatal” security flaws in 10 different medical implants.

Researchers at the University of Birmingham in the U.K. and the University of Leuven in Belgium discovered vulnerabilities in the software and signals that communicate with implant devices. The software is used to update the devices or gather data readings on a patient.

By tinkering with the bugs, the researchers were able to change the settings on the devices and in some cases shut them down entirely as well as steal sensitive medical data about the patient.

The device manufacturer name has not been disclosed but researchers said the bugs have since been patched by the maker before the research paper was made public. The researchers only studied one manufacturer but added that its products are widely used by healthcare professionals.

The remote software for medical devices like pacemakers helps doctors manage a patient’s condition and make sure they are working properly. However, the researchers were able to reverse-engineer the software and the signal it sends to eavesdrop on the communications and alter its commands.

According to the paper, the reverse engineering was carried out using “inexpensive Commercial Off-The-Shelf (COTS) equipment”.

“We demonstrate that reverse-engineering is feasible by a weak adversary who has limited resources and capabilities without physical access to the devices,” they wrote. However, a hypothetical attacker, in most cases, would need to have their equipment within five meters of the actual devices to pull most of these attacks off, the research noted.

In one example, an attacker would be able to collect sensitive data readings about the patient and change the commands for a device like pacemakers to disable certain functions or deliver an unneeded shock to the person, which could be fatal.

In another attack, the researchers were able to keep an Implantable Cardioverter Defibrillator (ICD) turned on despite “standby mode” being selected. This would drain the battery much quicker than usual, putting the patient at risk.

It was even possible, the authors claimed, to conduct denial of service attacks using a flawed implanted defibrillator.

“It is clear that the consequences of all these attacks can be severe for patients,” wrote the authors.

Previous studies have suggested that it was possible to infiltrate the communications between medical equipment and their software. In October, hackers showed how it was possible to break into insulin pumps and alter the dosage. The findings led manufacturer Johnson & Johnson to issue a warning to patients.

Editors' Recommendations

Jonathan Keane
Former Digital Trends Contributor
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
The 4 best Raspberry Pi alternatives in 2024
Inside a Raspberry Pi.

When it comes to powerful and reliable mini-computers, one of the most popular options is the Raspberry Pi. In fact, this particular PC gets most of the mini-CPU fanfare, but that doesn’t mean it’s the only small computer worth considering. If you’re thinking about investing in a bite-sized machine, we’ve put together this list of four mini PCs in direct competition with Raspberry Pi.

Read more
Best 2-in-1 laptop deals: Turn your laptop into a tablet for $349
Lenovo Yoga 9i 14 Gen 7 laptop sits on a small desk folded like a tent.

If you find that your traditional laptop isn't quite doing it for you in terms of workflow, then you might want to consider taking some of what the best tablets and the best laptops have and combining them together in the form of 2-in-1 laptops. These can offer a ton of versatility to your workflow, such as being able to use them in handheld mode for drawing or presenting, as well as the fact that most, if not all, are touch-enabled, so you don't even have to use a mouse if you don't want to.
There are, of course, a ton of great choices out there, but some of the best 2-in-1 laptops can get quite expensive, especially when you're buying them from some of the best laptop brands out there. That's why we've gone out and looked for our favorite 2-in-1 laptop deals to help save you some effort. We've pulled from HP laptop deals, Dell laptop deals, the classic 2-in-1 Surface Pro deals, and more. Check them out below.

Asus Chromebook Plus 2-in-1 -- $349, was $499

Read more
Best Acer laptop deals: From Chromebooks to gaming laptops
Acer Nitro V

If you're looking to pick up a new laptop, then you may want to consider the Acer lineup, especially considering it's one of the best laptop brands when it comes to budget-oriented computers. That even includes gaming laptops. Even better, you can find a lot of great deals on Acer's laptops, meaning that the already budget-friendly laptops become even cheaper, which is why we've gone out to find our favorite deals and list them for you below. That said, if you can't find what you're looking for below, be sure to check out some of these other great laptop deals as well, since there is some crossover between this list and our picks for the best Chromebook deals, 2-in-1 laptop deals and gaming laptop deals.
Aspire 1 -- $200, was $300
 

If you need something very basic just to get online and do some general productivity and day-to-day stuff, then the Acer Aspire 1 is a good budget option. It has a 15.6-inch screen with an FHD resolution, which is nice to see at this price point, and the screen bevels are actually relatively thin for a budget-oriented product. Of course, it does come with a lower-end Intel Celeron N4500 and only 4GB of RAM, which means Windows 11 is in the reduced S mode, but the lower spec does mean the price can stay really low too.

Read more