Heartbleed behind massive healthcare data breach
Further details are emerging on the massive data breach at US hospital operator Community Health Systems (CHS) that saw around 4.5 million patient records being leaked.
Security vendor TrustedSec claimed yesterday that the "Heartbleed" in the open source cryptographic library was to blame for the data breach.
According to what TrustedSec says is a "trusted and anonymous source close to the CHS investigation", the attackers obtained credentials from an unspecified vulnerable Juniper device on the hospital provider's network. With the credentials, the attackers were able to log in through a virtual private network (VPN) connection, and access the CHS network and patient database.