Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label SQL injection. Show all posts

Hackers Breach Polish Medical Software Firm Qbusoft, Expose Patient Data in Second Healthcare Attack in Weeks


 


A cyberattack on Polish healthcare software company Qbusoft has left patient records from its Medyc platform potentially in the hands of attackers, coming just weeks after a separate, larger breach hit another Polish medical software provider and rattled the country's entire health data infrastructure.

The attacker exploited an SQL injection vulnerability in Medyc's application interface during late August, according to a breach notification published last week by the Addiction and Psychiatric Treatment Center in Inowrocław, one of the healthcare facilities running the platform. SQL injection is one of the oldest and best-documented attack techniques in security research, allowing an attacker to manipulate a web application into pulling data directly from its database. Despite decades of awareness about the flaw, it remains a recurring entry point in healthcare system compromises.

Qbusoft confirmed on Friday that the attackers obtained names, national identification numbers, home addresses, phone numbers and email addresses. In Poland, the national identification number, called a PESEL, functions similarly to a Social Security number in the United States and is a standard credential for identity verification across government services, banking and healthcare. Its theft puts affected patients at real risk of identity fraud.

The company said it had not confirmed the theft of clinical records. But the Inowrocław center told patients that Qbusoft found evidence the attacker ran scripts specifically targeting database tables containing medical information, making it "highly likely" that medical records were also pulled. The data in scope for that facility included hospital treatment records and discharge summaries from patients treated at its Day Treatment Unit for Addiction Treatment between July 2024 and August 2026.

The intrusion occurred on August 22-23 and went undetected until the night of September 8-9, a gap of more than two weeks. By that point, the attacker had already transferred an encrypted archive of the database outside Qbusoft's systems. Some fields, including names and PESEL numbers, had been encrypted in the database. Qbusoft nonetheless advised the affected center to assume the attackers could decrypt that information without difficulty, given the specifics of how the protection was implemented.

Qbusoft patched the vulnerability on the day the breach was detected, restricted database access permissions, rotated passwords and technical credentials, and introduced additional monitoring. The company has not publicly commented on the incident through any official statement.

That silence drew a sharp response from Digital Affairs Minister Krzysztof Gawkowski, who said the Central Bureau for Combating Cybercrime had opened an investigation and criticized Qbusoft for failing to notify CERT Polska or the national incident response team for the healthcare sector before authorities reached out. "Hiding attacks by companies is the biggest mistake, as it always puts citizens at risk," Gawkowski said. Poland's data protection authority separately announced that its president had ordered a formal audit of Qbusoft.

Medyc, which has operated as a cloud-based platform since 2014, is used across Polish medical practices and clinics for electronic medical records, patient scheduling, electronic prescriptions, referrals, sick notes, telemedicine and administrative billing. In a public notice, the company warned that its infrastructure had faced repeated attack attempts since the incident and that users might see temporary slowdowns or restricted access to certain modules.


The Same Attacker?

Polish cybersecurity publication Zaufana Trzecia Strona reported that a person or group using the alias "fingerprint" contacted the outlet claiming responsibility for the Medyc attack. The publication had previously linked that alias to the MyDr breach, a separate incident involving another Polish healthcare software vendor. Polish broadcaster RMF FM also reported that the same attackers behind MyDr were likely responsible for the Medyc intrusion, though Polish authorities have not formally attributed the attack to any individual or group.

The alleged attacker claimed to have obtained records on 5 million patients and 8 million private photographs, some of which Zaufana Trzecia Strona said may depict patients in sensitive medical settings. Neither figure has been independently confirmed, and the stolen data has not been made public. The actor reportedly framed the operations as an effort to expose weak security rather than profit from the data.

The MyDr breach, confirmed in August, potentially affected close to 19 million people across more than 12,000 healthcare facilities, involving over 2 terabytes of stolen data including names, PESEL numbers, prescription histories, diagnoses and appointment records. Poland has roughly 36.5 million residents, meaning the MyDr incident alone touched the records of nearly half the country's population. The Inowrocław treatment center caught up in the Medyc breach was also among the organizations affected by MyDr.

Gawkowski said Polish authorities had observed a surge in criminal activity targeting healthcare organizations in recent weeks and were preparing new regulations in response, including mandatory security certification for healthcare technology companies and tighter controls on how private vendors handle medical data. Poland recorded a 144 percent year-on-year rise in reported cybersecurity incidents in 2025. The consecutive breaches of Medyc and MyDr, both software vendors connecting thousands of clinics to national health infrastructure, have made clear that the weakest link in Poland's health data chain is not the government platform but the private companies sitting in front of it.




ServiceNow Patches Three Critical Code Injection Flaws Rated CVSS 10.0




ServiceNow has released security updates addressing four vulnerabilities in its AI Platform, including three critical flaws rated 10.0 out of 10 under CVSS v4. The vulnerabilities could enable attackers to execute arbitrary code, manipulate platform data, escalate privileges, or directly interact with the underlying database.

The affected platform is used to support enterprise workflows and AI-powered applications. ServiceNow says 85% of Fortune 500 companies rely on its platform, making vulnerabilities that cross application and data boundaries particularly relevant to enterprise security teams.

The most severe issue, tracked as CVE-2026-18885, is a code injection vulnerability in the GraphQL Composite Data API. Under certain conditions, an attacker without authentication could execute arbitrary code within the ServiceNow platform and gain access to, or alter, instance data beyond the permissions intended by the platform. The CVE record credits Adam Kues of Assetnote with discovering the vulnerability.

CVE-2026-18886, also rated CVSS 10.0, involves improper access controls in the system configuration image upload processor. The flaw could allow an unauthenticated user, under certain circumstances, to create or modify instance data and subsequently escalate privileges. Kevin Gervot of Assetnote is credited as the vulnerability's finder.

The third maximum-severity issue, CVE-2026-74820, is an SQL injection vulnerability. An attacker could exploit the weakness to submit arbitrary SQL statements to the underlying ServiceNow database, potentially exposing or modifying instance information outside the access boundaries established by the platform. The CVE record classifies the flaw as CWE-89, or improper neutralization of special elements used in an SQL command.

All three critical vulnerabilities have network attack vectors, low attack complexity, require no privileges and require no user interaction according to their CVSS v4 metrics. CISA's vulnerability enrichment also currently categorizes the three as automatable with total technical impact, while their records state that no exploitation has been observed.

The fourth vulnerability, CVE-2026-6876, carries a CVSS v4 score of 8.7 and concerns a sandbox escape in the Now Platform. Successful exploitation could allow code execution within the platform and provide an attacker with more access than intended. The published CVSS vector lists low privileges as required and no user interaction, so security teams should assess the flaw according to their deployment and access configuration rather than treating it as identical to the three unauthenticated CVSS 10 vulnerabilities.

ServiceNow has applied security updates to its hosted instances and made fixes available to partners and customers operating self-hosted deployments. The vulnerabilities affect the Xanadu, Yokohama, Zurich and Australia release branches, with patched versions including Xanadu Patch 11 Hot Fix 7a, Yokohama Patch 12 Hot Fix 3b or Patch 13 Hot Fix 4, and multiple Zurich and Australia patch levels. Administrators should compare their exact instance version against ServiceNow's advisory before considering remediation complete.

The urgency is particularly relevant for organizations managing ServiceNow themselves. Unlike vendor-hosted environments where ServiceNow can deploy security updates directly, self-hosted customers must identify the affected release, obtain the appropriate hotfix and complete their own change and validation process.

Security practitioners have also warned that this remediation gap can provide attackers with an opportunity to target newly disclosed enterprise vulnerabilities before organizations complete their patch cycles. Jason Brown, director of counter-fraud operations at iCOUNTER, urged organizations running self-hosted ServiceNow deployments to treat the fixes as an immediate priority rather than waiting for their routine maintenance window.

ServiceNow has advised customers to apply the available updates promptly. The company also states that it is not currently aware of malicious exploitation of these vulnerabilities, but the combination of remote attack paths, code execution and access to enterprise data makes rapid remediation important while public information about the flaws remains limited.