IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Shadow Brokers: Microsoft Windows flaws were already patched

NSA allegedly had the ability to breach bank messaging system

NSA data

US spy agency the NSA allegedly had the tools to hack into interbank messaging system SWIFT via third party providers, according to documents released by hacking group Shadow Brokers last Friday.

SWIFT has since said there is no evidence suggesting its core messaging services or network have been compromised after Reuters reported that the Shadow Group documents indicated that the NSA had accessed SWIFT through service providers (service bureaux) that offer access to the system in the Middle East and Latin America.

In a media FAQ, the organisation said: "SWIFT is in close contact with the service bureaux concerned to verify that they are aware of the allegations and have appropriate preventative measures in place." The Belgium-based organisation allows over 200 organisations to send messages about financial transactions to each other and sends payment orders between institutions' accounts.

The tools were linked to vulnerabilities discovered in versions of Microsoft's Windows operating system. Cybersecurity expert Matt Suiche, of Comae Technologies, detailed in a blog post that "Windows Vista/2008 is out of support since Monday [12 April], and Windows XP/2003 has been unsupported for more than [three] years. This means that security vulnerabilities found on those systems will never be corrected."

However, Microsoft said in a security update that all but three of the published exploits had already been patched. Those three, 'EnglishmanDentist', 'EsteemAudit', and 'ExplodingCan', don't work on Windows operating systems that are still in support. But Microsoft has not announced how it learned of the vulnerabilities, though it usually gives credit to those who find bugs.

SWIFT said: "The allegations suggest there may have been attempts to gain unauthorised access to data at two service bureaux. The exploits do not target SWIFT's infrastructure or data. There is no impact on SWIFT's infrastructure or data, and there is no evidence to suggest that there has been any unauthorised access to SWIFT's network or messaging services.

"Customers should pay close attention their own security and take security into consideration when selecting a service bureau and working with other third party providers."

Featured Resources

Big data for finance

How to leverage big data analytics and AI in the finance sector

Free Download

Ten critical factors for cloud analytics success

Cloud-native, intelligent, and automated data management strategies to accelerate time to value and ROI

Free Download

Remove barriers and reconnect with your customers

The $260 billion dollar friction problem businesses don't know they have

Free Download

The future of work is already here. Now’s the time to secure it.

Robust security to protect and enable your business

Free Download

Recommended

The IT Pro Podcast: Enabling bilingual business
collaboration

The IT Pro Podcast: Enabling bilingual business

30 Sep 2022
Podcast transcript: Enabling bilingual business
collaboration

Podcast transcript: Enabling bilingual business

30 Sep 2022
Windows 11 Update 2022: The "first major" Windows 11 update brings slew of new business features
Microsoft Windows

Windows 11 Update 2022: The "first major" Windows 11 update brings slew of new business features

21 Sep 2022
Three critical vulnerabilities and one zero-day feature in Microsoft's September Patch Tuesday
Security

Three critical vulnerabilities and one zero-day feature in Microsoft's September Patch Tuesday

14 Sep 2022

Most Popular

How to secure your hybrid workforce
Advertisement Feature

How to secure your hybrid workforce

23 Sep 2022
What your hybrid workforce needs from their laptops
Advertisement Feature

What your hybrid workforce needs from their laptops

21 Sep 2022
Why collaboration is key to digital transformation
Sponsored

Why collaboration is key to digital transformation

13 Sep 2022