PodParley PodParley

Top 10 Medical Device Vulnerabilities with Myles Kellerman

Episode 38 of the The Med Device Cyber Podcast podcast, hosted by Blue Goat Cyber, titled "Top 10 Medical Device Vulnerabilities with Myles Kellerman" was published on September 23, 2025 and runs 39 minutes.

September 23, 2025 ·39m · The Med Device Cyber Podcast

0:00 / 0:00

How safe are the medical devices I rely on, and what are the biggest cybersecurity risks I should know about?

In this episode, the team goes behind the scenes of real-world medical device penetration testing to reveal the 10 most common and dangerous cybersecurity vulnerabilities found in medical devices. The discussion covers practical examples, industry standards, and actionable advice for manufacturers and healthcare organizations.

Key points:


(0:00) Introduction & Penetration Testing Context


(1:29) Why Penetration Testing Matters in MedTech


(5:50) Top 10 Medical Device Vulnerabilities:

1. Hardcoded/Default Credentials – Default passwords, BIOS passwords, and supply chain issues.

2. Unsecured Communication Channels – Lack of encryption, outdated standards, key management, and device constraints.

3. Outdated/Vulnerable Third-Party Components – Software Bill of Materials (SBOM), continuous monitoring, and post-market risks.

4. Improper Access Control – Weak authentication, privilege escalation, and user data exposure.

5. Debug Interfaces Left Enabled – JTAG/UART ports, physical access, and mitigation strategies.

6. Missing/Weak Firmware Integrity Checks – Secure boot, code signing, and white-box testing.

7. Poor Session Management – Session timeouts and session hijacking.

8. Fuzzing Vulnerabilities (Buffer Overflows) – Fuzz testing, buffer overflows, and legacy devices.

9. Lack of Tamper Detection – Audit trails, tamper-evident stickers, and physical controls.

10. No Rate Limiting/Automation Controls – Brute-force attacks, automation, and rate limiting.


(37:26) Secure Product Development Frameworks, and DevSecOps.


(38:04) Regulatory Perspective.


The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com


If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session


Thanks to Myles Kellerman for being on the show. Connect with Myles on LinkedIn: https://www.linkedin.com/in/myles-kellerman-5763aa22


Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.


Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/

Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9


Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/

Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/

Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/

Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber


Feedback? Questions? Contact: https://bluegoatcyber.com/contact/


Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/


Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial


The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.


Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh

Subscribe via Apple Podcasts: https://apple.co/483OJ9I

Subscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/podcasts

Jobs

Feb 21, 2022 ·26m

Anti-vaxxers

Nov 25, 2021 ·27m

NEJM Q PUD

Jun 28, 2018 ·5m

Treatment of stroke

Jun 21, 2018 ·9m

RBC ros in SCD

Jun 21, 2018 ·13m

Stroke presentation

Jun 20, 2018 ·10m

Invest Like a Boss Sam Marks Johnny FD Derek Spartz Interviews with the world's best investors and find out what they are currently investing in whether it be the stocks, retirement accounts, Wealthfront, Betterment, Vanguard, mutual funds, real estate, Forex, REITs, or other types of Investing methods. Millionaire and Entrepreneur Sam Marks, Johnny FD & Derek Spartz invest alongside listeners as they share their personal portfolios as they save their hard earned money for travel, life and retirement. Invest Like a Boss covers all aspects of investing in the modern age in a fun, entertaining way. The show hosts interview the worlds best investors, financial Insiders, entrepreneurs and CEOs to find out what they are investing in and strategies to gain outsized returns. In this modern age of investing, new investment instruments are popping up each day, from P-2-P lending, to robo-advisors, equity crowd-funding to REITS. Investors today need to combine centuries of investment wisdom with an modern outlook and approach. Entrepreneurs Sa Waiting For Review Dave Wood The show is a fortnightly catch up between David Gary Wood, and Daniel Jilg!David is the longtime host of the show, an iOS development coach based in Wellington, New Zealand. His side project applications include GoVJ (https://govjapp.com), and he is currently working on several small projects.Daniel is an establish independent developer based in the south of Germany. He is the founder of: Telemetry Deck (https://telemetrydeck.com), "Lightweight Analytics That's Not Evil", an analytics service for apps that provides speedy and accurate analytics whilst keeping user's data private and anonymised. The Midnight Air All Things Comedy The Midnight Air is your weekly “overnight radio” podcast from Daniel Van Kirk. Topics range from friendly conversation, pop culture news, film and tv discussions, stories of lore and mysteries, plus the articles from the pages of a small newspaper in rural Wisconsin. This is the easy-listening podcast for people trying to fall asleep or for people that are trying to stay awake. This feed is also the home of the back catalogue for The Pen Pals Podcast. With new episodes of Pen Pals dropping occasionally. LIFE Church Home LIFE Church UK LIFE Church Bradford is multi-cultural church where all can find a place to belong and thrive. These podcast messages are full of life and hope, rallying a generation to embrace the broken and become ambassadors of hope.
URL copied to clipboard!