Updated: Fatal Flaw Slows WannaCry Ransomware Spread, but Threats Remain
ID: f5bb7437-95c3-5ed4-a19a-b75312eb4dc8
STIX ID: report--f5bb7437-95c3-5ed4-a19a-b75312eb4dc8
Feed Name: Security Ledger
The report describes the widespread WannaCry ransomware outbreak that leveraged the ETERNALBLUE Windows SMB exploit and the DOUBLEPULSAR backdoor to infect hundreds of thousands of systems globally; a UK researcher slowed the spread by registering a hard-coded domain acting as a kill-switch, and Microsoft issued emergency patches for unsupported Windows versions. The article notes limited ransom payments observed, ongoing risk from unpatched systems, and advises organizations to patch, block SMB ports (139/445), and remediate persistent backdoors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
