/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

BlackBerry discloses a critical flaw in QNX OS, impacting 200M+ cars, hospital equipment, more; sources say it resisted public disclosure until talks with CISA

A flaw in software made by BlackBerry has left two hundred million cars, along with critical hospital and factory equipment …

Politico

Discussion

  • @ericgeller Eric Geller on x
    After admitting that older (but still widely used) QNX versions were vulnerable, BlackBerry initially told CISA that it wanted to privately notify customers. But because of how QNX is sold and packaged into products, BlackBerry doesn't know everyone who uses it. https://twitter.c…
  • @chey_cobb CyberSec Chey on x
    Blackberry has been ducking reports that their QNX OS is vulnerable. It still powers cars, factories, medical devices, railroad equipment, US govt equipment, and certain parts of the Space Station. https://twitter.com/...
  • @hrbrmstr @hrbrmstr on x
    Ooof. QNX is...everywhere. Yet another situation where SBOM would be a big help. https://us-cert.cisa.gov/...
  • @icscert Ics-Cert on x
    🚨 BlackBerry disclosed its QNX #RTOS is affected by a #BadAlloc vulnerability—CVE-2021- 22156. Many BlackBerry QNX products are affected CVE-2021-22156. Follow @CISAgov's guidance: https://us-cert.gov/.... #VulnerabilityManagement https://twitter.com/...
  • @timclicks Tim McNamara on x
    Remember kids - companies that write systems software in safe languages don't expose hundreds of millions of users to security exploits. https://twitter.com/...
  • @0xbanana @0xbanana on x
    C and C++ aren't going away anytime soon but you can mitigate classes of vulnerabilities using a language like Rust. Let's start writing safer code everyone! #infosec #100DaysOfCode https://twitter.com/...
  • @ericgeller Eric Geller on x
    Remember the BadAlloc vulnerabilities in real-time operating systems and other software, disclosed in April? BlackBerry just announced that its QNX RTOS — used everywhere from cars and hospitals to the ISS — is vulnerable. https://support.blackberry.com/ ... https://us-cert.cisa.…
  • @jason_healey Jay Healey on x
    Awesome that @CISAgov had the oomph to push BlackBerry to take responsibility. Before CISA, especially when NSC lacked cyber coordinator under Trump, there might not have been a civilian cyber official to drive this result! https://twitter.com/...
  • @icscert Ics-Cert on x
    ❗️ @CISAgov strongly encourages #criticalinfrastructure, #ICS owners and operators, and any other organization developing, maintaining, supporting, or using affected QNX-based systems to patch ASAP: https://us-cert.gov/.... #Cybersecurity #IoT #Software #OT