So why now? What's so special now?
So why now? What's so special now?
This worm targets older Windows versions that are installed (and use the exploited protocol) in a lot of critical infrastructure, and the worm was hoarded by the NSA all packaged up and ready to deploy (because it can propagate through SMB and therefore would be perfect for a future Stuxnet-like operation). So of course some criminals get their hands on it, and hey look it works. It's an absolutely bonkers story.
Win 10 is vulnerable without the patch that came out in march.
Edit: I'm dumb, misread the above comment as saying "Win10 was affected even with the patch in March."
Microsoft clearly disputes this in their own posts on the subject.
https://blogs.technet.microsoft.com/msrc/2017/05/12/customer...
"Customers running Windows 10 were not targeted by the attack today."
What's your source?
"Customers who are running supported versions of the operating system (Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2, Windows 8.1, Windows Server 2012, Windows 10, Windows Server 2012 R2, Windows Server 2016) will have received the security update MS17-010 in March. If customers have automatic updates enabled or have installed the update, they are protected. For other customers, we encourage them to install the update as soon as possible."
If you don't have the update, you are not protected, you are vulnerable.
Laws must be passed to:
* Force the US government to report vulnerabilities to vendors
* Create a regulatory body to monitor the use of vulnerabilities in clandestine operations and ensure that mandatory reporting is upheld
I cannot see anything less working.
Get that through US and EU governments, and you'll likely have the vast majority of vulnerabilities being reported and patched.
Of course this is akin to asking the US and Russia to convert their nuclear stockpile into reactor fuel.
This is incorrect or at least misleading.
Any machine still running Windows XP, is by any reasonable definition, an "old Windows machine." Windows XP was first released in 2001, and actively supported with updates for 12 years. Windows XP hasn't been supported with critical security patches for over 3 years.
Windows Server 2012 is under active support until Oct. 10, 2023, and was patched against this vulnerability in MS17-010. See the middle of the page here: https://technet.microsoft.com/en-us/library/security/ms17-01... If your Windows Server 2012 machine fell victim to this ransomware, it was for the same reason as those running the newer Windows Server 2016 (also vulnerable to WannaCry): because someone didn't apply security patches in a timely manner.
This ransomware was particularly damaging because of it's unusually wormable nature. (Ring 0, commonly enabled networking protocol, no user interaction required.)
I replied to your comment because the "old" Windows XP having no patch available was significant here, and I read your comment as saying "old" windows versions were not proportionally more responsible for WannaCry's rapid spread.
Windows XP is still the third largest version of Windows by current installed base (after Windows 10 and Windows 7).
The fact that Windows XP remained unpatched was significant, as there is notable overlap between Windows machines that aren't getting new security updates (at least within a month or two of their release) and Windows machines still running Windows XP.
This vulnerability was, in fact, unusually dangerous, relative to other Windows XP vulnerabilities that have come to light in the last 5 years, and the install base of the "older" Windows XP machines made a big difference in the ransomware's ability to spread.
I addressed that it wasn't "old" Windows because there is a crazy belief out there that this only hit XP.
Can you elaborate on this?
I think it's because it's cool to use the word "cyber" now in the news. It makes news outlets appear edgy and with it. Infact these cyber attacks are nothing new, and have been an ongoing problem for organizations like the NHS, the only difference being there is a remarkable uptick in the scale of the attack. The reason it stands out is because it's a cluster, instead of a slow, trickling problem for the NHS and other organizations.
> What's so special now?
The sophistication and worm capabilities. Were it not for the Shadowbrokers leak, small time malware authors had to use tired old strains of malware to spread. Now they can draw upon the vast arsenal of the Shadowbrokers leak and appear like state actors, which they are not.
If anything, the leaks were a blessing, because now we can mitigate against such attacks. NSA's mantra 'NOBUS' (No-one-but-us) does not apply here.
Nobody seems to be talking about this, but we can only guess that a lot of stuff has been compromised and still is.
What really worries me is the huge amount of non-patched computers that have not fallen with this specific WannaCry issue and are sitting idly waiting for their glory day.
Did they just manage to craft so really persuasive emails this time?