This is even more proof how powerful a 0-day in the wrong hands can be. All of the affected companies' should be considered compromised by the NSA. Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised. Ransomware is much more visible than spyware. Think about all the spyware-infected PCs/networks that nobody knows about.
Call me paranoid but I consider even a clean, freshly installed and fully updated Windows PC already compromised by the NSA.
Another Ransomware Outbreak Is Going Global
71–80 of 435 posts
Re: Another Ransomware Outbreak Is Going Global
#72My friend's work laptop is a victim of this same attack... all the way here in the Philippines. There was a company wide email blast to disconnect all workstations from the internet at once. Fascinating development
Re: Another Ransomware Outbreak Is Going Global
#73This is even more proof how powerful a 0-day in the wrong hands can be. All of the affected companies' should be considered compromised by the NSA. Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised. Ransomware is much more visible than spyware. Think about all the spyware-infected PCs/networks that nobody knows about.
Maybe I'm missing something, but is there any evidence that this is actually a 0day attack? I didn't study the last outbreak that closely, but it seemed like it was a vulnerability that had been patched, but affected computers that weren't patched. Maybe I'm wrong though. But 0days or no, there will always exist some number of computers that have not been properly kept up-to-date and thus will be vulnerable to securi…
It was based off an SMB exploit released in a ShadowBroker's dump; an unreleased exploit thought to have been used by the NSA.
Re: Another Ransomware Outbreak Is Going Global
#74Re: Another Ransomware Outbreak Is Going Global
#75Re: Another Ransomware Outbreak Is Going Global
#76A friend sent me the bitcoin address, they've already collected 2600$. [EDIT] Now 3230$ Source: https://blockchain.info/address/1Mz7153HMuxXTuR2R1t78mGSdzaA...
it seems like a trivially avoidable mistake to use a single wallet for all collections, but maybe i shouldn't be giving them ideas...
Re: Another Ransomware Outbreak Is Going Global
#77Re: Another Ransomware Outbreak Is Going Global
#78Hey, FWIW we had to do some response for ransomware cases recently.
There was a lack of decent stuff out there for how IT teams should deal with it. So we contributed to putting together this quick checklist:
https://github.com/0xswap/guides/blob/master/ransomware-tria...
Would be great if more people wanted to add to it.
Re: Another Ransomware Outbreak Is Going Global
#79Can someone provide a simple (but not overly so) explanation of how the current generation of ransomware operate i.e., A) spread and B) lock up the computer? Does it always require human intervention for A. ? Thank you.
Usually if it says "0-Day" assume that it can be exploited without human intervention a-la stuxnet
Re: Another Ransomware Outbreak Is Going Global
#80This is even more proof how powerful a 0-day in the wrong hands can be. All of the affected companies' should be considered compromised by the NSA. Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised. Ransomware is much more visible than spyware. Think about all the spyware-infected PCs/networks that nobody knows about.
Call me paranoid but I consider even a clean, freshly installed and fully updated Windows PC already compromised by the NSA.
No, seriously. How is it paranoia to think the NSA was/is surveilling your Windows installation if we already have proof that they have the means [2] and motivation [3] to do it at scale?
[1] http://www.quotes.net/show-quote/34121
[2] https://en.wikipedia.org/wiki/EternalBlue
[3] https://en.wikipedia.org/wiki/PRISM_(surveillance_program)