Massive ransomware attack just took out my work and ukraine, anyone else affected?

Associate
Joined
6 Dec 2008
Posts
2,341
Location
Scotland
This line from the BBC article is a face-palm, imo:
Veteran security expert Chris Wysopal from Veracode said the malware seemed to be spreading via some of the same Windows code loopholes exploited by Wannacry. Many firms did not patch those holes because Wannacry was tackled so quickly, he added.

How does one become a veteran security expert? :D
 
Man of Honour
Joined
13 Oct 2006
Posts
91,285
This looks to be a pretty evolved piece of ransomware code!

These things will be ever evolving and increasing looking to exploit hardware at a low level which makes it hard to detect and remove the infection entirely. The seeming complacency towards the initial outbreak and attack vectors of wannacry I think is going to bite people in the rear down the line as well - nearly every security expert has concentrated on the ransomware it deployed, a few better ones have done some forensic examination of the dropper but it seems like pretty much no one is looking at it end to end in full detail and still lots of assumptions based on how previous malware worked and equating it with how those worked instead of looking at what it actually did.
 
Soldato
Joined
17 Jun 2007
Posts
9,304
Big Logistics company!!! No **** sherlock. I was thinking DPD,APC but this ones a little bigger Hope they get it sorted quick.
 
Soldato
Joined
23 Nov 2014
Posts
7,634
Location
The Cronx
Well in the case of email's, an admin should really be authorizing the use of the internet, or just closing the entire system off. Too many liberal users in company and too liberal an IT department are issues.

It's lack of knowledge like this that is part of the problem :D oh dear!

ETA should have included your 2FA post as its a classic.
 
Soldato
Joined
21 Aug 2010
Posts
5,798
Looks like Posteo have shutdown the ransomware e-mail account :eek:
Not sure I agree with that! I understand the whole not paying ransom logic but for some people it might be extremely important?!?!
 

SPG

SPG

Soldato
Joined
28 Jul 2010
Posts
10,264
Internet is no longer becoming fun... oh well was a fun time while it lasted I guess.

Back to rolling the dice for ADnD and going outside again :)
 
Soldato
Joined
16 Jun 2013
Posts
5,381
I am completely ignorant to these things, am I safe on my W10 laptop?

No such thing as safe. Just don't click on links/emails you don't trust and you should be good from the majority of it.

Best way to be "safe" is regular external backups. Doesnt really matter if you get infected then just restore from backups.
 
Caporegime
Joined
6 Dec 2005
Posts
37,574
Location
Birmingham
An accounting company in Ukraine was hacked and it has an auto updater in it's MeDoc software. :o



DDWM179V0AAMSTQ.jpg:large
 
Caporegime
Joined
29 Jan 2008
Posts
58,914
Well in the case of email's, an admin should really be authorizing the use of the internet, or just closing the entire system off. Too many liberal users in company and too liberal an IT department are issues.

oh great now we're blaming liberals for this too....
 
Back
Top Bottom