But it being spread by email has not been confirmed yet, only speculated because other types of attacks in the past have used email to spread. So far I've not read a single confirmed report that email is the initial attack vector. Even the Cisco Talos article linked earlier makes absolutely no mention of email. The dropper mechanism and infection using port 139 and port 445 have been, and these are what the MS updates protect you against, as well as blocking these ports within your router firewall, if they're open.