Connect with us

Published

on

A popular medical monitor is the latest device produced in China to receive scrutiny for its potential cyber risks.  However, it is not the only health device we should be concerned about. Experts say the proliferation of Chinese health-care devices in the U.S. medical system is a cause for concern across the entire ecosystem. 

The Contec CMS8000 is a popular medical monitor that tracks a patient’s vital signs.  The device tracks electrocardiograms, heart rate, blood oxygen saturation, non-invasive blood pressure, temperature, and respiration rate.  In recent months, the FDA and the Cybersecurity and Infrastructure Security Agency (CISA) both warned about a “backdoor” in the device, an “easy-to-exploit vulnerability that could allow a bad actor to alter its configuration.”  

CISA’s research team described “anomalous network traffic” and the backdoor “allowing the device to download and execute unverified remote files” to an IP address not associated with a medical device manufacturer or medical facility but a third-party university — “highly unusual characteristics” that go against generally accepted practices, “especially for medical devices.”

“When the function is executed, files on the device are forcibly overwritten, preventing the end customer—such as a hospital—from maintaining awareness of what software is running on the device,” CISA wrote.

The warnings says such configuration alteration could lead to, for instance, the monitor saying that a patient’s kidneys are malfunctioning or breathing failing, and that could cause medical staff to administer unneeded remedies that could be harmful. 

The Contec’s vulnerability doesn’t surprise medical and IT experts who have warned for years that medical device security is too lax. 

Hospitals are worried about cyber risks

“This is a huge gap that is about to explode,” said Christopher Kaufman, a business professor at Westcliff University in Irvine, California, who specializes in IT and disruptive technologies, specifically referring to the security gap in many medical devices.

The American Hospital Association, which represents over 5,000 hospitals and clinics in the U.S., agrees. It views the proliferation of Chinese medical devices as a serious threat to the system. 

As for the Contec monitors specifically, the AHA says the problem urgently needs to be addressed. 

“We have to put this at the top of the list for the potential for patient harm; we have to patch before they hack,” said John Riggi, national advisor for cybersecurity and risk for the American Hospital Association.  Riggi also served in FBI counterterrorism roles before joining the AHA. 

CISA reports that no software patch is available to help mitigate this risk, but in its advisory said the government is currently working with Contec. 

Contec, headquartered in Qinhuangdao, China,  did not return a request for comment. 

One of the problems is that it is unknown how many monitors there are in the U.S. 

“We don’t know because of the sheer volume of equipment in hospitals. We speculate there are, conservatively, thousands of these monitors; this is a very critical vulnerability,” Riggi said, adding that Chinese access to the devices can pose strategic, technical, and supply chain risks. 

In the short-term, the FDA advised medical systems and patients to make sure the devices are only running locally or to disable any remote monitoring; or if remote monitoring is the only option, to stop using the device if an alternative is available. The FDA said that to date it is not aware of any cybersecurity incidents, injuries, or deaths related to the vulnerability.

The American Hospital Association has also told its members that until a patch is available, hospitals should make sure the monitor no longer has access to the internet, and is segmented from the rest of the network.

Riggi said the while the Contec monitors are a prime example of what we don’t often consider among health care risk, it extends to a range of medical equipment produced overseas. Cash-strapped U.S. hospitals, he explained, often buy medical devices from China, a country with a history of installing destructive malware inside critical infrastructure in the U.S.  Low-cost equipment buys the Chinese potential access to a trove of American medical information that can be repurposed and aggregated for all sorts of purposes. Riggs says data is often transmitted to China with the stated purpose of monitoring a device’s performance, but little else is known about what happens to the data beyond that. 

Riggi says individuals aren’t at acute medical risk as much as the information being collected and aggregated for repurposing and putting the larger medical system at risk. Still, he points out that, at least theoretically, is can’t be ruled out that prominent Americans with medical devices could be targeted for disruption. 

“When we talk to hospitals,  CEOS are surprised, they had no idea about the dangers of these devices, so we are helping them understand.  The question for government is how to incentivize domestic production, away from overseas,”  Riggi said. 

Chinese data collection on Americans

The Contec warning is similar at a general level to TikTok, DeepSeek, TP-Link routers, and other devices and technology from China that the U.S. government says are collecting data on Americans. “And that is all I need to hear in deciding whether to buy medical devices from China,” Riggi said. 

Aras Nazarovas, an information security researcher at Cybernews, agrees that the CISA threat raises serious issues that need to be addressed. 

“We have a lot to fear,” Nazarovas said. Medical devices, like the Contec CMS8000, often have access to highly sensitive patient data and are directly connected to life-saving functions.  Nazarovas says that when the devices are poorly defended, they become easy prey for hackers who can manipulate the displayed data, alter vital settings, or disable the device completely.  

“In some cases, these devices are so poorly protected that attackers can gain remote access and change how the device operates without the hospital or patients ever knowing,” Nazarovas said. 

The consequences of the Contec vulnerability and vulnerabilities in an array of Chinese-made medical devices could easily be life-threatening.  

“Imagine a patient monitor that stops alerting doctors to a drop in a patient’s heart rate or sends incorrect readings, leading to a delayed or wrong diagnosis,” Nazarovas said. In the case of the Contec CMS8000, and Epsimed MN-120 (a different brand name for the same tech), warning from the government, these devices were configured to allow remote code execution by the remote server.  

“This functionality can be used as an entry point into the hospital’s network,” Nazarovas said, leading to patient danger.  

More hospitals and clinics are paying attention. Bartlett Regional Hospital in Juneau, Alaska, does not use the Contec monitors but is always looking for risks. “Regular monitoring is critical as the risk of cybersecurity attacks on hospitals continues to increase,” says Erin Hardin, a spokeswoman for Bartlett.  

However, regular monitoring may not be enough as long as devices are made with poor security. 

Potentially making matters worse, Kaufman says, is that the Department of Government Efficiency is hollowing out departments in charge of safeguarding such devices. According to the Associated Press, many of the recent layoffs at the FDA are employees who review the safety of medical devices. 

Kaufman laments the likely lack of government supervision on what is already, he says, a loosely regulated industry. A U.S. Government Accountability Office report as of January 2022, indicated that 53% of connected medical devices and other Internet of Things devices in hospitals had known critical vulnerabilities. He says the problem has only gotten worse since then. “I’m not sure what is going to be left running these agencies,” Kaufman said.

“Medical device issues are widespread and have been known for some time now,” said Silas Cutler, principal security researcher at medical data company Censys. “The reality is that the consequences can be dire – and even deadly. While high-profile individuals are at heightened risk, the most impacted are going to be the hospital systems themselves, with cascading effects on everyday patients.”  

Continue Reading

Technology

Figma CEO says AI superintelligence is not a looming threat to the company

Published

on

By

Figma CEO says AI superintelligence is not a looming threat to the company

Figma CEO Dylan Field on IPO debut: Design is going public today

Figma co-founder and CEO Dylan Field said Thursday that artificial intelligence doesn’t pose a serious threat to the future of the design software company, which is on the verge of debuting on the public markets.

“We’re in this moment where you might, if you’re singularity-pilled, go, ‘Hey, superintelligence is coming and it’ll be able to do things that no human can do,” Field told CNBC’s “Squawk Box.” “I have a harder time believing that we’re going to approach that really quickly right now, but that doesn’t mean it’s out of the picture.”

Figma is slated to begin trading on the New York Stock Exchange under the ticker symbol “FIG” on Thursday. Last week, the company estimated that it would price shares in the range of $25 to $28, and on Wednesday it priced above that range at $33 a share.

The offering values Figma, which ranked No. 45 on this year’s CNBC Disruptor 50 list, at $19.3 billion.

The company was supposed to be acquired by Adobe for $20 billion, but the deal was scrapped in December 2023 after regulators objected.

Read more CNBC tech news

So-called “superintelligence,” a type of artificial intelligence that would be more powerful than the human brain, has recently become a growing focus among technology companies.

Field told CNBC’s Andrew Ross Sorkin that the company’s “complex” graphics engine and other aspects of its technology make it difficult to be replaced by superintelligence.

“I think that’s not stuff that you can learn from looking at code and sort of various places on the internet,” Field said. “It’s not part of the pre-training data mix. I believe that doing that at scale — it’s quite difficult.”

Meta CEO Mark Zuckerberg has been especially vocal about the potential for superintelligence, declaring in a Wednesday memo that the technology will serve as a tool for “individual empowerment” over automation and efficiency.

Meta recently created a lab to pursue superintelligence, and Zuckerberg has poured billions of dollars into building a roster of top AI talent.

— CNBC’s Jordan Novet contributed reporting to this story.

Continue Reading

Technology

Roblox stock soars 16% after revenue beat, strong user growth

Published

on

By

Roblox stock soars 16% after revenue beat, strong user growth

Thiago Prudêncio | Sopa Images | Lightrocket | Getty Images

Roblox stock soared 16% Thursday after the company reported second-quarter revenue that beat expectations amid strong user growth.

The gaming platform saw $1.44 billion in net bookings, up 51% over the year prior. Analysts polled by LSEG expected $1.24 billion in net bookings for the quarter.

User and engagement numbers were also strong for the company, with daily active users at 111.8 million, up 41% year-over-year, and hours engaged at 27.4 billion, up 58% year-over-year.

StreetAccount expected 106 million DAUs.

“Our year on year growth this quarter is a reflection of our strategic investments in infrastructure and performance, discovery, and the virtual economy, which continue to create fertile conditions for creators to thrive as part of a healthy, interconnected ecosystem,” said CEO David Baszucki in a release.

Baszucki added that the company is looking to grab 10% of the global gaming content market.

Read more CNBC tech news

Roblox raised its booking guidance for the third quarter and now expects between $1.59 billion and $1.64 billion. FactSet expected $1.42 billion in third-quarter bookings.

The gaming platform did report a net loss of $279.38 million, a loss of 41 cents per share. Roblox had a net loss of $205.88 million, a loss of 32 cents per share, in the same quarter a year ago.

The platform rolled out new age verification tools two weeks ago, as the broader gaming industry and app stores have faced regulatory pressure to improve safety for young users and limit access to certain types of content.

Roblox Chief Safety Officer Matt Kaufman said the age-estimation tools will help keep younger users from accessing “something that should be limited to an older audience — 13 and over.”

Kaufman said having more mature content opportunities will help teens and adults stay on Roblox instead of moving to other platforms.

Continue Reading

Technology

Meta, Microsoft roar higher on strong earnings as AI spending booms

Published

on

By

Meta, Microsoft roar higher on strong earnings as AI spending booms

META CEO Mark Zuckerberg (L) and Microsoft CEO Satya Nadella.

Getty Images

Shares of Meta soared 12% and Microsoft popped 5% on Thursday, after the companies reported better-than-expected earnings that beat on top and bottom lines.

Microsoft topped the $4 trillion market cap benchmark with the move, joining Nvidia in the club.

Both Meta and Microsoft have been investing heavily in artificial intelligence infrastructure in recent years, and the companies said they expect to continue to shell out billions in capital expenditures.

Meta said capital expenditures will range between $66 billion and $72 billion for the full year, raising the low end of the company’s previous estimate of between $64 billion and $72 billion. Microsoft sees over $30 billion in fiscal first quarter capital expenditures and assets acquired through finance leases, while analysts surveyed by Visible Alpha had expected $24.23 billion.

Analysts at Citi said the companies’ increased capital expenditures will likely be a boon for chipmakers. Microsoft makes up roughly 8% of Advanced Micro Devices‘ sales, while Meta makes up about 2% of Broadcom’s sales, the analysts said.

“We believe AVGO and AMD will be the primary beneficiaries of Microsoft’s and Meta’s increased capex,” they wrote in a Thursday note.

Read more CNBC tech news

In addition to increased capital expenditures, Meta CEO Mark Zuckerberg has been on an AI hiring blitz, highlighted by a $14.3 billion investment into the data-labeling startup Scale AI and the launch of its new Meta Superintelligence Labs unit.

Morgan Stanley analysts said they “applaud the effort” and are pleased with the state of Meta’s core business, but they remain a little wary of Zuckerberg’s AI spending.

“On one hand, the core business is so strong that it’s paying for all the new AI talent and infra several times over, but on the other hand the cavalier nature by which Zuckerberg is throwing money around is a bit unnerving, especially if things don’t come together as planned with the new superintelligence team,” the analysts wrote.

Barclays analysts said Microsoft’s generative AI scaling is still playing out, but the strong demand for its data center infrastructure continues to point to ongoing momentum for the quarters ahead. They maintained their overweight rating on the stock.

“With its strong Q4 FY25 results, MSFT confirmed its unique status in the software space and will likely continue to be one of the core holdings by investors,” they wrote in a note Wednesday.

Microsoft reported $76.44 billion in revenue for its fiscal fourth quarter, up 18% year over year. The company said net income increased to $27.23 billion, or $3.65 per share, from $22.04 billion a year ago.

Meta reported $47.52 billion in revenue for its second quarter, up 22% year over year. Its net income rose 36% year over year to $18.34 billion, or $7.14 per share.

WATCH: Kulina: Zuckerberg’s laser-focused on AI and building an all-star team

Kulina: Zuckerberg’s laser-focused on AI and building an all-star team

Continue Reading

Trending