Wannacry update

Wannacry update

What a whirlwind few days this has been. I wanted to start off by saying I have been really impressed by how so such of the security community have really come together to combat this latest cyber attack. The NCSC combined with security researchers and security professionals have been working solidly since Friday keeping Wannacrypt at bay. The first round has been slowed down by the activation of the Kill Switch by Malwaretech on Friday there has also been another version found that resolves to a different domain and that has also been registered and sinkholed. 

 I am hoping most individuals and companies have been patching and updating their systems over the weekend but for those who have not had the chance to do so yet please see the recommended guidance below. 

 It is imperative that any organisations that have not patched their systems do so A.S.A.P.

  • If you are using a supported version of Microsoft Windows make sure you have MS17-010 patch applied which can be found here
  • If you are using unsupported versions including XP, Microsoft have been fantastic and created an out of support patch which can be downloaded here.  
  •  If the patches provided do not cover your systems, disable SMBv1, further information can be found here
  • You could also block SMBv1 ports on network devices [UDP 137, 138 and TCP 139, 445]
  • The mainstream antivirus and malware vendors have updates their signatures so please do make sure that your AV products are up to date. 
  • Systems that become infected need to be able to resolve and connect to one of the following domains to activate the kill switch

www[.]iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea[.]com

www[.]ifferfsodp9ifjaposdfjhgosurijfaewrwergwea[.]com

Please make sure individuals in your organisations are extra vigilant and do not click on links and attachments from unknown senders. 

What a panic out there over the last few days. Wow. Malware exists for a long time. Why know ? WannyCry is not the most deadly attack. News talk about 200.000 machines affected worldwide. Compared to locky, with millions affected, thats not very impressive. Just for information, there are billions of machines out there running windows OS. WannaCry is not even a new one. It know just "appeared" out there out of nowhere. Microtrend has a record of it dating weeks ago. What is gonna happen? Many companies will spend a lot of money to keep there business save and in a few weeks, we will start cutting down on maintenance, on updates and return to "back as usual". As usual.

To view or add a comment, sign in

More articles by Anthony Young FCIIS

  • We are Hiring - Senior Penetration Tester

    Background Bridewell Consulting is a fast growing Information Security Consultancy. Our Penetration Testing team are…

  • Information Security Service

    Bridewell Consulting is a specialist UK based Information Security and Risk Consultancy who work to protect their…

Others also viewed

Explore content categories