<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/wannacry"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Wannacry ]]></title>
                <link>https://www.itpro.com/uk/tag/wannacry</link>
        <description><![CDATA[ All the latest wannacry content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Fri, 02 Sep 2022 06:30:10 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Podcast transcript: What did we learn from WannaCry? ]]></title>
                                                                                                <dc:content><![CDATA[ <p><em>This automatically-generated transcript is taken from the IT Pro Podcast episode ‘</em><a href="https://www.itpro.com/security/wannacry/368959/the-it-pro-podcast-what-did-we-learn-from-wannacry" data-original-url="https://www.itpro.com/security/wannacry/368959/the-it-pro-podcast-what-did-we-learn-from-wannacry">What did we learn from WannaCry?</a>’<em>. We apologise for any errors.</em></p><h3 class="article-body__section" id="section-adam-shepherd"><span>Adam Shepherd.</span></h3><p>Hi, I'm Adam Shepherd.</p><h3 class="article-body__section" id="section-connor-jones"><span>Connor Jones</span></h3><p>And I'm Connor Jones.</p><h3 class="article-body__section" id="section-adam"><span>Adam</span></h3><p>And you're listening to the IT Pro Podcast. This week: WannaCry.</p><h3 class="article-body__section" id="section-connor"><span>Connor</span></h3><p>It's been five years since the world was rocked by the outbreak of one of the most sudden and virulent ransomware infections in modern history. WannaCry was a particularly nasty piece of ransomware that took out a wide range of institutions from private businesses like Renault and FedEx to state institutions like the NHS.</p><h3 class="article-body__section" id="section-adam"><span>Adam</span></h3><p>The outbreak was stopped within days by the quick thinking of security researcher, Marcus Hutchins, but the impact it had was profound and far reaching. The estimated damage of the attack reaches into the billions and many organisations are still recovering from being hit.</p><h3 class="article-body__section" id="section-connor"><span>Connor</span></h3><p>Joining us on the podcast to talk about the fallout from the WannaCry incident, the lessons that have been learned from it, and whether we're likely to see another attack of that scale again, is Professor Kevin Curran, IEEE senior member and professor of cybersecurity at Ulster University. Kevin, welcome back to the podcast. </p><h3 class="article-body__section" id="section-kevin-curran"><span>Kevin Curran </span></h3><p>Thank you.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>So Kevin, last time, we had you on the show, we were speaking about digital privacy and surveillance in the workplace. This week, we've got a slightly less controversial topic, but one that's no less serious, I think. WannaCry, of course, was a massively devastating incident. How close are we to repairing the damage it caused five years on?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>What we've seen is, of course, that ransomware has gone nowhere, even with the crypto bubble busting at the moment, but again, because of the de facto way of being able to receive that ransom is through cryptocurrencies, and, of course, that they've moved on even to sometimes away from Bitcoin to Monero and other more anonymous cryptocurrencies, as well, but it remains, I mean, there is increases in the sectors which have been hit, I mean, generally it depends on which report you read, but it's really doubling year on year, really. And we're seeing a move even to small to medium size enterprises, again. There was a hiatus for a while there last year after the Irish government was attacked, for instance, that, that these people who generally ransomware as a service really would refrain from health services, but they've actually gone back on that, and we're seeing an increase in attacks on infrastructure, you know, of course, finance and, but also in healthcare as well. So ransomware is here for the foreseeable future. And, you know, anecdotally, whenever I talk to CISOs, and all that, that they will quite often tell me about, about their networks being compromised in the last year or so. So it really remains to be a large problem.</p><h3 class="article-body__section" id="section-ddam"><span>Ddam </span></h3><p>In your opinion, what were the main contributing factors that led to WannaCry being such a significant incident for really the global business community?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>It was such a problem, because we hadn't really any frameworks in place, not that there is an overriding framework, but we do know, we do have best practice recommendations for how to avoid ransomware, how to respond to it and how to recover from it. But a number of years ago, we didn't really have any mature capabilities, again, that of course, we've had frameworks which, you know, that enable us to setup, as best we can, best practice but it's only now that really two factor authentication, hardware keys, things like these, which do make make us more secure are now being rolled out kind of de facto. Before that it was only people perhaps in security, or people, you know, accessing sensitive documents. In other words, it was a small sector, which were really using these hardened down approaches, where most businesses would have been running Remote Desktop, for instance, might not be using multi factor authentication and didn't have any plans for how to recover as such, any incident plans really. So a lot of small businesses were just hammered by this really. Of course, backups are essential really, but it's simpler when a when you're talking about maybe someone's laptop or documents but enterprises again with all the mishmash of tools and software and devices and people and you know, remote access as well, that a system is not easily, you just can't just backup a complete system across databases, maybe in cloud and hybrid and whatever else and just have it back up and running in the morning, you have to take, you know, a structured approach to it really and know your assets for instance and have them all you know, ready for... Well, first of all, have them all backed up but have a plan in place to be able to get your infrastructure back again. And unfortunately, when this happened, really people, your average enterprise was not ready and not expecting something like this, which would basically encrypt all the network, all the computers. </p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>So it's interesting you say about backups not being easy and sort of it sort of being more more difficult and less sort of well known back then. Is there anything in the past few years that have made backups and recovering from these kinds of attacks easier for the smaller guys to implement? Or is it just sort of like, a case of the knowledge is there now that this is what you need to be doing?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>Yeah, I mean, there are automated tools. Again, you know, you can have, you know, in fact, one of the recommendations is, of course, you have automated patch management of your operating system, of your environments, and also of your software. As such, there are tools which can try to, and that do actually take snapshots of your systems again, and can restore them and again, I mean there's companies which specialise in that, really, that that they, whenever you're attacked, that they'll get your system up and running. I did a court case last year as an expert witness where a company who who had been paid for managing services of an enterprise really, and then the ransomware attack happened. And it turns out that they didn't have backups of key crucial databases. So then it came down to the requirements scope, and that's where I had to go because they said they would do X, Y, and Z but, but of course, it was left vague, that the company hadn't disclosed, you know, for whatever, you know, just simply forgot that they also had this database stored here, and it was accessing this here. And that wasn't part of the, of the remit of the company who was supposed to be protecting them. So hence, when the ransomware attack happened, they could only get a percentage of their system back really, because there was just a gap in the in the actual assets, which would have been monitored and backed up.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>Sure. Speaking on WannaCry more specifically, then - because obviously, we've talked about backups - is there anything that you think that organisations have learned specifically from the WannaCry attack, they're sort of taken into their incident response plans today, and how they sort of tackle cyber defence?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>Well obviously deploying the automated patches which happen, you know, afterwards again, so again, at the time it was Windows XP, or Windows 7, really, but, of course, Microsoft addressed it, addressed the actual issue, which led to the bug there, which was in the Server Message Block. Again, so that vulnerability had been fixed again, but of course, we don't know about the other zero days. And again, like the number one attack vector really is phishing, is how they're getting in really. And vulnerabilities and remote desktop protocol and Active Directory are common ways again, these common attack vectors that these groups use to be able to make it in. So again, we just got to be aware of that and have automated tools, which hopefully can scan a network and even spot zero days, depending on your baseline. But again, we're increasingly relying on AI in some ways, again, because networks have become so complex whenever you go across and go above a number of employees really and it's hard to monitor every single thing on the network. If, if you fire up something like Wireshark on your computer, which sniffs the packets on your network, mostly wireless, you'd be surprised to see how many requests are going out of just one PC or one laptop in in it in a few minutes. I mean, you have printers pooling, who's there, are you listening, you got the network itself, obviously, firing off packets, you have Dropbox in the background, you have Outlook, you have all these, again, all these, all this software, all these devices communicating across networks again, and then we start adding in our doorbells and our Wi Fi kettles and our phones and everything else, and you quickly get to a large, large number of packets going across even a home network again, so therefore you've got to analyse again. So where would you start if you're doing this manually, and wherever you spot the anomalies again? So there is software again, but of course not, the problem is a lot of small to medium sized enterprises don't really have the budget for a lot of the software, they don't really have the staff to run it. And then of course, you have, again, they do their risk assessment and to try to figure out well, is it worth it or not here? And there is no there is no rule of thumb really, there is no like how much should be spent on security and then where does security get mixed up with IT support and IT services again, so a lot of things get left.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Yeah, and while there are a huge variety of kind of software tools and services that can be used to to augment your security as a business and to help kind of detect and prevent threats, it feels like certainly back in 2017 when WannaCry hit, a large part of the problem was that organisations were neglecting the basics. I mean, you mentioned that the the main exploit that WannaCry used, or one of the main exploits was a problem in the SMB, the SMB kind of infrastructure in Windows, Server Message Block. And that was patched. But the problem was that a lot of organisations just hadn't applied the patch. And still to this, you know, to this day, there are a not insignificant number of computers out in the wild, that have not updated with that patch, even, you know, five plus years on. Have organisations on the whole kind of recognised the value post WannaCry of applying patches in a timely manner? Or is that still falling through the cracks to a greater or lesser extent?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>Again, it comes down to the resources of the company again, so, you know, we have matured as a society with regards, you know, with anything you know, so I've seen the maturity from years ago, where people didn't realise the importance of strong passwords, where now really everyone gets that, you know, we mature technologically as a society again. So, again, people are not, you know, it was very few people use hardware keys, you know, as a multi factor authentication token before, but whereas it's actually great practice to have it again, so we're seeing things gradually get there again. So, of course, most accounts now, which are important, people need to understand the need for multi factor authentication. And again, that there are services or even, you know, Microsofts or whatever will come along, and, you know, it's important to monitor your Active Directory to identify and fix any misconfigurations in there again, and, and also training of staff again, so there is, there is a need for user training again. So, of course, the people often are the weakest link, we say, again, so we don't train staff and how to spot phishing emails again. So it's, it's a different depends on tech savvy you are, because there is no, you just get a feeling for what is a phishing message. And everyone's seen that and, of course, then business email compromise is becoming the number one attack vector really, because it's the low hanging fruit again, so it doesn't require too much for people to be able to get people to click on something and install it, and then have the backdoor in again. So it's still user education is very important again, but you got to have regular audits of your equipment, see, you know, we talk about data classification as well, you know, least privilege, that's one of the key things in security; don't give people access to anything more than they need to do their job again. So it's the first. And of course, if we're giving people access to anything that you know, and then they're compromised again, so they move right across the network, as well. So we have to have all these things in place, but it's hard to manage every item because people now are bringing devices to work and such. So even though the the IT management and the CSO and his team might have locked down all the PCs and have it done so that no one's running admin and ran all the software, but then someone brings in their, their Windows XP laptop, and they put the database on there, or whatever else they're logging in. So it's very hard, with bring your own devices, you know, with that type of technology, again, to be able to monitor everything. And unfortunately, I've seen this increasingly, I've seen it in my own workplaces where the IT department locked down everything, and makes it almost impossible to do anything with the actual, with the supplied laptop you have or device, it's what people do just go to their own laptops and use a Wi-Fi and avoid what the actual security team have put in place really because it's too restrictive. Because, you know, really, you can say, well, there is a phone, how do I make a secure, my phone? Well, first of all, don't turn it on. But even then maybe the mike's on, you know, there's all these weird espionage things. So really, all I can do is take that phone and burn it to be sure that no one is accessing anything on there. And that's fine. But you know what, the phone is now useless to me. But I have made it secure and that's what a lot of IT company or a lot of a lot of companies are facing where the IT department again, the CSO's the first to get fired when it gets to the hack really. So again, they'll just do what they say is whatever, but you have to have a copy, you have to have kind of leeway between the security team which might try to bolt down everything, but we have to get our jobs done to, and there's a trade off again, otherwise we'd never cross the road or get into a car. But there has to be an acceptable level of risk somewhere again, but training is part of that.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>I mean, you mentioned kind of user training and strong passwords, multi factor authentication, all of this kind of best practice stuff. That is all really important and really valuable for companies to be implementing and to be aware of, but looking at flaws like WannaCry, WannaCry wasn't spread through phishing, or through kind of email compromise or anything like that; it was wormable. Right? It didn't require any user interaction, that's part of how it spread so quickly is that it could just kind of automatically and instantly go from one computer on a network to another, to another, to another, to another to another. How do you combat that, as an IT team through stuff like user training and best practices? Is it just a case of making sure that you're on top of kind of newly emerging zero days and things like that? Or are there other measures that can be implemented to prevent attacks like this?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>Yeah, I mean, first of all, you have to know your assets and what you're protecting, and then have the multi factor authentication in but you have to make sure that all your systems are patched and fully up to date. And then you want to have anti malware, anti spyware, you want to have real time analysis of the networks, again, you know, because they will be patched or they will be getting the updates from the Ciscos of this world or whoever else you actually hire services from, then you got to train your workforce to be able to recognise social engineering attacks again so that's part of it, but you have to run a large security awareness programme, as well as the IT department, making sure that things are are locked down, that people are using unique passwords and the firewall even, for instance, I was talking to a CSO today of a council here in Northern Ireland, and they were attacked by ransomware on the day before, Thursday before Easter. And they found out that the company they'd hired to literally do the firewalls for them had really nothing there in place. So now they did the simple thing, because it's a council website. And it's very important for the whole area here. But they simply made it non accessible outside the UK. And why? Because, okay, maybe someone's abroad? And they want to find out about the bins, but no, no, that's a simple way to do it. Just make it, use geolocation in that respect again, and maybe try to limit how many people come, but that doesn't work in all cases, in most sites, you want everyone around the world to see it, but you have to have people in charge as well. And what happens when the ransomware occurs as well, you know, is there a person, a designated person to be able to manage an incident handling or if you have a third party, which depending on how big you are, you might have BAE Systems coming in or you know, the big boys coming in and doing an analysis of it. But again, you have to someone designated to be able to handle that and do the reports and bring the system back on and looking at all the audit logs as well and be able to see where it came from. Because even though most ransomware is wormable, but most of it does come from, you know, someone clicking on something at the start again, but sometimes you can have the ways to be able to contain that as such.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>So obviously, WannaCry was, it certainly wasn't the first ransomware incident in cybersecurity history. However, it probably did mark sort of, you know, it kind of catalysed this big trend that's not really, like you said before, it hasn't really sort of ceased in the past five years. And obviously, everything's evolved since then. But one thing we do know is that businesses and organisations are starting to develop and sort of turn to these incident playbooks, right, so these blueprints on how to respond to an attack like this. So to that end, what role should these incident playbooks have in defending against ransomware?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>It's good to have a framework, at all times again, so with ransomware we're of course trying to protect against in the first place, identify when it comes and then also recover from it as well. But we do I mean, there's so many like, you know, NIST standards, National Institute of Standards Technology in the United States have some of the key frameworks that we follow when it comes to best practice and best cyber hygiene and cybersecurity again, so, all of these things are very useful again, so, and we you know, we have to just kind of, you kind of have to presume your network could be taken down again. So, what would you do, you know, so, again, there are there are actually you know, depending on how risky it is to any of your things, you can have anything from containers in your car park which drive in on trucks which they do occur, where you have a replica of your network, again, which has already been done before, but again, not many SMEs would be able to do that or, raise to that level again, and it's becoming a little bit increasingly more difficult as well. Where with the rise of the rise of cloud and hybrid environments as well, where you've lots of stuff now, even not even hosted in on premises again, but we just have to presume that we can identify it again and hopefully, just just be prepared.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>So let's look at the criminal community and how they've been affected by the WannaCry incident and the ongoing fallout from it, the way it's changed the security landscape. Are there any lessons, do you think, that the wider kind of criminal hacking community have taken away from both WannaCry and the global response to it that's informed how they conduct their operations?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>It's it Yeah, it's hard, like, we can only speculate because most of these, again, are coming from the Russias of this world, the Belaruses, Iran, North Korea again. So, again, this is notoriously, you know, that seems to be where they, you know, what they're looking for from these countries as well. But the problem is, of course, the cryptocurrencies, again, they don't want to be too successful, we found that with the, with the some of the larger attacks again, the Colonial Pipeline against the United States, and the, the, the Irish hospital system, which was brought to its knees again, so you'd want to be too successful, because then the authorities will come after you as well. So, of course, one lesson a lot of people have found is that Bitcoin isn't the anonymous cryptocurrency as many people thought it was; it was just quite good depending on you know, how you do it, and whether you put your, you put it through... what was the word again, your, if you want to be able to launder or wash it...</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>Tumbler.</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>Tumblers, yeah, you can put that through your tumbler again, coming up. But there are some network analysis tools, again, depending on how much you have in here, and again, it has to reside in some wallet somewhere. So there are pretty clever people out there who do who do the network analysis on the Bitcoin on the Bitcoin chain, and are able to see where the money goes to again, it's hard to always and again in some ways that we're still even though we think cryptocurrency is decentralised, and solves everything and removes it from the world. But no, you always have to come back out into fiat again, so the Coinbases of this world and wherever else, or Bitstamps or wherever else people store there or use for their transactions again, that the governments are able to go there. And it always come back to some accounts as well. And you're able to see where that goes. But your average cybercriminal who doesn't do anything, or just do something small attacks, even, even in the hundreds of thousands; they're unlikely to call it because police resources, police are swamped nowadays, because everything now, in the past you might have seen the police coming out of the house and carrying items; now they just bring out the devices again, and there's a lot and a chain of evidence has to be intact, and the police forces only have so many forensic experts as well. So the court cases, that's why there's such a backlog of court cases. And that's why because your jurisdictions as well, if someone steals something from you, and you know that they're in Lithuania, or well, you think they are, well, the police are not really going to be able to help you there because of the complexity involved, and the multi jurisdictional part again, but again, just if you really are intent on a life of crime, just don't presume that you won't, that your cryptocurrency won't be, won't lead back to you.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>I think it's interesting, you know, you noted about criminals wanting to be successful but not too successful. I mean, obviously with the likes of REvil and Darkside last year, we saw what can happen when when they when they do get a little bit too big for their boots. But I think one of the most interesting things for me about Wanna Cry was, was the payment system or lack thereof, because they're, in the sort of early stage of the infections, they had a lot of victims actually paying the ransom and then realising that the people who were running the operation didn't actually have a mechanism to determine who actually paid and who didn't. So no one was getting a response back. And, and people just cottoned on to that and people Yeah, stop paying. And then they're just sort of, along with the sort of technical shortcomings like the the so called Kill Switch, it was one of the things that really proved to be its downfall. And one of the things that, it's kind of like underpinned that part of ransomware, that trust relationship where, yes, it's bad to pay a ransomware actor, but you probably are going to get your files back because it's been done before where you don't get them back, and people just stopped paying, right. So I guess what, I guess the question is, what's the most interesting part about WannaCry for you?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>Yeah, the most important part would be, again, that I do remember the government invested in more in cybersecurity afterwards again, especially in the NHS. Again, like I said, it's always hard to justify to the C suite or whatever else, you know, your your need, because, of course, if the network's not down, but we have to have some kind of targets for how much a company should spend on cybersecurity, how much an organisation should, and the NHS is, is the sixth largest employer in the world, actually. </p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Oh, wow. </p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>Yeah, we forget how large it is as an organisation again, and you have all the, everything from MRI scanners right down to heart rate monitors and whatever else, and a lot of these were attacked again. So again, just it's kind of prepared us in some ways for for what could happen increasingly in the future given the the geopolitical landscape we're in at the moment, where nations will attack us and, and again, that they do have their their cyber armies again, like, you know, in the past, we're able to tell how big a country's arsenal is by being able to count the number of tanks and planes and make some estimate, again, but it's very hard to tell how big a country's offensive and defensive cyber security teams are. But we're seeing that more and more of the military will actually be wearing will actually probably, you know, will be using laptops, again, because of how much damage we can do just using devices again, and you know, being able to hack national infrastructure again. So I think a lot more will be put into it rather than the traditional things. We're seeing the failure in some ways of tanks and you know, the traditional warfare, but it's good to see to the government because it is crucial. My cousin is a nurse in the Irish government. And she said that the attack on the southern health system from ransomware, last year was, it actually was worse than COVID. In some ways, she said that they couldn't do anything. And they really had to go back to paper and pen.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Oh wow. I think that's one of the biggest takeaways from WannaCry for me was that, firstly, it really underlined what kind of impact a really serious cyber attack can have on not just an organisation, but on kind of critical infrastructure. You know, we've been talking for years in the wider cybersecurity community about the risk of critical infrastructure attacks. WannaCry, and later Colonial Pipeline, I think were, in some ways, the first real sort of illustrations of how bad it can potentially be. And, you know, that's not even close to as bad as it could potentially get with a more, more serious, more sustained attack. But one of the other real takeaways was, you can't protect everything. Like you mentioned, MRI scanners, a large part of the reason why the NHS was so badly hit is because they use a lot of embedded systems that physically can't be updated, you know, the systems running medical equipment, internally. They, in many cases, they can't physically be patched, you have to buy a new MRI machine, essentially. And there's just no way around that unless manufacturers design, you know, user upgrade functionality into their machines. And in many cases, the manufacturers that make these machines have come and gone in the time since institutions bought them. And it's a really difficult problem to grapple with. And you get the same issue in many cases in manufacturing, and in areas like that they use similar amount of embedded machinery.</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>Exactly, I mean, at least air gapped, I mean, that's always useful but um, yeah, but there is a bit of protection to having a heterogeneous network where you have all different types of devices again, so because usually an attack does usually target, it's usually platform specific, they can morph again but so if you got half of Macs or whatever, you know, a PC somewhere running X number version, you can be protected some degrees once it reaches some kind of system, which is Solaris or Linux or whatever else but but again, then with that, with with having multiple operating systems or in devices to support again, you can have a little bit more complexity there. But again, of course, as we know that the takeaway lesson really from WannaCrywas just patching in a timely manner, that if they had patched you know, there would have been protection really but again, that there are so many devices out there.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>So obviously WannaCry was largely driven by the the leak, the leaked, EternalBlue exploit, the former exploit sort of owned by the NSA. And since then, we've had I mean, arguably, you could you could argue that Colonial Pipeline was sort of on a level with WannaCry, but do you think we could ever see a cyber incident on the same level as WannaCry again? Given that, you know, it was largely driven by this freak leak of a one of a kind exploit?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>Oh, absolutely. You know, the, you know, we have zero days all the time. And of course, we don't know about most, but they're sold to regimes or used by organised crime syndicates as well. But absolutely, there is so many like, there's, like, no one even understands the code build, there's no one who could possibly be in Seattle in Microsoft who completely understand the entire operating system for Windows, for instance, I mean, we're talking about millions and millions and millions of lines of code developed over 30 years, whatever, you know, with all the, with all the add ons to that, which would happen, and we know that every patch Tuesday just before they do their fixes, you know, I think it was 119 vulnerabilities last month, that they honestly the administrators know what's going to be fixed, what's going to be changed in the coming weeks, you know, because network, IT departments were tearing their hair out at times, but you know, because they get the blame when the Microsoft patch screwed up something so they try to predict this now. But again, that's how many vulnerabilities were last week. So there always be exploits out there, there'll always be zero days, because and of course, we hope that they're not wormable again, but definitely that you know, that these can spread across. And we haven't really seen the nightmare scenario where you know, most of the world's computers or devices. But again, if we see it to the, you know, some of the or security tools have improved. But also, you know, the attacker is not letting up either, again, that we do have great automated tools now, which were able to detect and sometimes stop an active attack again. But I have no doubt that we'll see other, you know, other attacks, which take up to you know, take hundreds of millions of computers, really, especially the ones which are not patched really.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>And how can organisations try and get ahead of this eventuality?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>They have to implement best practice, which which is general, of course, the best practice kind of covers a host of attacks really, not just ransomware. And that's using multifactor authentication, strong passwords, using being able to identify all the resources on the network, auditing users, only giving them the privileges that they need, enable and disable Remote Desktop Protocol unless you don't use it. Use the appropriate software for scanning, do regular audits of your of your users again, and the software which is on your systems, if you don't use it, remove it again, and then plan for attacks and have desktop exercises as well and then have the strong incident response team. And also, of course, along the way, always educating your employees and users about the dangers of compromise really and what to look out for and have it updated as well. Because once people are trained, they do forget after a number of months again, so make it part of their, you know, their targeted work, you know, for what, because technology has become instrumental in our lives. You know, just a few years ago, there wasn't even an attack about a year and a half ago or two that the Visa network went down for about 24 hours in the United Kingdom. People were stuck without being able to get train tickets, they're not able to buy food, they couldn't get, you know, whatever because the actual Visa, because people increasingly do not carry cash anymore again. So again, what happens at networks when they go down at airports again, we're relying so much on technology again. So again, that there will come a time when we you know, unfortunately, we're going to see more and more infrastructure, and sometimes not even attacks, it's just because someone who you know flicked the wrong switch or else there's a cable a digger has dug up somewhere, again, maybe into a data centre, but we're increasingly reliant on technology. But there will be days in the future where we all are back to paper and pen, you know whenever some systems go down.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Well, that's it for this week's episode. Our thanks to Ulster University's Kevin Curran for being with us. </p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>Thank you.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>You can find links to all the topics we've spoken about today in the show notes and even more on our website at itpro.co.uk.</p><h3 class="article-body__section" id="section-adam"><span>Adam</span></h3><p>You can follow us on social media as well as subscribe to our daily newsletter.</p><p>And don't forget to subscribe to the IT Pro Podcast wherever you find your podcasts. And if you're enjoying the show, leave us a rating and review.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>We'll be back next week with more insight from the world of IT but until then, goodbye.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>Bye.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/wannacry/368960/podcast-transcript-what-did-we-learn-from-wannacry</link>
                                                                            <description>
                            <![CDATA[ Read the full transcript for this episode of the IT Pro Podcast ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qf7oQhQoAVLNRYDS9FX4po</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dJNHsuQaxKyncNZXUq7hxm-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 02 Sep 2022 06:30:10 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dJNHsuQaxKyncNZXUq7hxm-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Podcast transcript: What did we learn from WannaCry?]]></media:description>                                                            <media:text><![CDATA[Podcast transcript: What did we learn from WannaCry?]]></media:text>
                                <media:title type="plain"><![CDATA[Podcast transcript: What did we learn from WannaCry?]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dJNHsuQaxKyncNZXUq7hxm-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>This automatically-generated transcript is taken from the IT Pro Podcast episode ‘</em><a href="https://www.itpro.com/security/wannacry/368959/the-it-pro-podcast-what-did-we-learn-from-wannacry" data-original-url="https://www.itpro.com/security/wannacry/368959/the-it-pro-podcast-what-did-we-learn-from-wannacry">What did we learn from WannaCry?</a>’<em>. We apologise for any errors.</em></p><h3 class="article-body__section" id="section-adam-shepherd"><span>Adam Shepherd.</span></h3><p>Hi, I'm Adam Shepherd.</p><h3 class="article-body__section" id="section-connor-jones"><span>Connor Jones</span></h3><p>And I'm Connor Jones.</p><h3 class="article-body__section" id="section-adam"><span>Adam</span></h3><p>And you're listening to the IT Pro Podcast. This week: WannaCry.</p><h3 class="article-body__section" id="section-connor"><span>Connor</span></h3><p>It's been five years since the world was rocked by the outbreak of one of the most sudden and virulent ransomware infections in modern history. WannaCry was a particularly nasty piece of ransomware that took out a wide range of institutions from private businesses like Renault and FedEx to state institutions like the NHS.</p><h3 class="article-body__section" id="section-adam"><span>Adam</span></h3><p>The outbreak was stopped within days by the quick thinking of security researcher, Marcus Hutchins, but the impact it had was profound and far reaching. The estimated damage of the attack reaches into the billions and many organisations are still recovering from being hit.</p><h3 class="article-body__section" id="section-connor"><span>Connor</span></h3><p>Joining us on the podcast to talk about the fallout from the WannaCry incident, the lessons that have been learned from it, and whether we're likely to see another attack of that scale again, is Professor Kevin Curran, IEEE senior member and professor of cybersecurity at Ulster University. Kevin, welcome back to the podcast. </p><h3 class="article-body__section" id="section-kevin-curran"><span>Kevin Curran </span></h3><p>Thank you.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>So Kevin, last time, we had you on the show, we were speaking about digital privacy and surveillance in the workplace. This week, we've got a slightly less controversial topic, but one that's no less serious, I think. WannaCry, of course, was a massively devastating incident. How close are we to repairing the damage it caused five years on?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>What we've seen is, of course, that ransomware has gone nowhere, even with the crypto bubble busting at the moment, but again, because of the de facto way of being able to receive that ransom is through cryptocurrencies, and, of course, that they've moved on even to sometimes away from Bitcoin to Monero and other more anonymous cryptocurrencies, as well, but it remains, I mean, there is increases in the sectors which have been hit, I mean, generally it depends on which report you read, but it's really doubling year on year, really. And we're seeing a move even to small to medium size enterprises, again. There was a hiatus for a while there last year after the Irish government was attacked, for instance, that, that these people who generally ransomware as a service really would refrain from health services, but they've actually gone back on that, and we're seeing an increase in attacks on infrastructure, you know, of course, finance and, but also in healthcare as well. So ransomware is here for the foreseeable future. And, you know, anecdotally, whenever I talk to CISOs, and all that, that they will quite often tell me about, about their networks being compromised in the last year or so. So it really remains to be a large problem.</p><h3 class="article-body__section" id="section-ddam"><span>Ddam </span></h3><p>In your opinion, what were the main contributing factors that led to WannaCry being such a significant incident for really the global business community?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>It was such a problem, because we hadn't really any frameworks in place, not that there is an overriding framework, but we do know, we do have best practice recommendations for how to avoid ransomware, how to respond to it and how to recover from it. But a number of years ago, we didn't really have any mature capabilities, again, that of course, we've had frameworks which, you know, that enable us to setup, as best we can, best practice but it's only now that really two factor authentication, hardware keys, things like these, which do make make us more secure are now being rolled out kind of de facto. Before that it was only people perhaps in security, or people, you know, accessing sensitive documents. In other words, it was a small sector, which were really using these hardened down approaches, where most businesses would have been running Remote Desktop, for instance, might not be using multi factor authentication and didn't have any plans for how to recover as such, any incident plans really. So a lot of small businesses were just hammered by this really. Of course, backups are essential really, but it's simpler when a when you're talking about maybe someone's laptop or documents but enterprises again with all the mishmash of tools and software and devices and people and you know, remote access as well, that a system is not easily, you just can't just backup a complete system across databases, maybe in cloud and hybrid and whatever else and just have it back up and running in the morning, you have to take, you know, a structured approach to it really and know your assets for instance and have them all you know, ready for... Well, first of all, have them all backed up but have a plan in place to be able to get your infrastructure back again. And unfortunately, when this happened, really people, your average enterprise was not ready and not expecting something like this, which would basically encrypt all the network, all the computers. </p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>So it's interesting you say about backups not being easy and sort of it sort of being more more difficult and less sort of well known back then. Is there anything in the past few years that have made backups and recovering from these kinds of attacks easier for the smaller guys to implement? Or is it just sort of like, a case of the knowledge is there now that this is what you need to be doing?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>Yeah, I mean, there are automated tools. Again, you know, you can have, you know, in fact, one of the recommendations is, of course, you have automated patch management of your operating system, of your environments, and also of your software. As such, there are tools which can try to, and that do actually take snapshots of your systems again, and can restore them and again, I mean there's companies which specialise in that, really, that that they, whenever you're attacked, that they'll get your system up and running. I did a court case last year as an expert witness where a company who who had been paid for managing services of an enterprise really, and then the ransomware attack happened. And it turns out that they didn't have backups of key crucial databases. So then it came down to the requirements scope, and that's where I had to go because they said they would do X, Y, and Z but, but of course, it was left vague, that the company hadn't disclosed, you know, for whatever, you know, just simply forgot that they also had this database stored here, and it was accessing this here. And that wasn't part of the, of the remit of the company who was supposed to be protecting them. So hence, when the ransomware attack happened, they could only get a percentage of their system back really, because there was just a gap in the in the actual assets, which would have been monitored and backed up.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>Sure. Speaking on WannaCry more specifically, then - because obviously, we've talked about backups - is there anything that you think that organisations have learned specifically from the WannaCry attack, they're sort of taken into their incident response plans today, and how they sort of tackle cyber defence?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>Well obviously deploying the automated patches which happen, you know, afterwards again, so again, at the time it was Windows XP, or Windows 7, really, but, of course, Microsoft addressed it, addressed the actual issue, which led to the bug there, which was in the Server Message Block. Again, so that vulnerability had been fixed again, but of course, we don't know about the other zero days. And again, like the number one attack vector really is phishing, is how they're getting in really. And vulnerabilities and remote desktop protocol and Active Directory are common ways again, these common attack vectors that these groups use to be able to make it in. So again, we just got to be aware of that and have automated tools, which hopefully can scan a network and even spot zero days, depending on your baseline. But again, we're increasingly relying on AI in some ways, again, because networks have become so complex whenever you go across and go above a number of employees really and it's hard to monitor every single thing on the network. If, if you fire up something like Wireshark on your computer, which sniffs the packets on your network, mostly wireless, you'd be surprised to see how many requests are going out of just one PC or one laptop in in it in a few minutes. I mean, you have printers pooling, who's there, are you listening, you got the network itself, obviously, firing off packets, you have Dropbox in the background, you have Outlook, you have all these, again, all these, all this software, all these devices communicating across networks again, and then we start adding in our doorbells and our Wi Fi kettles and our phones and everything else, and you quickly get to a large, large number of packets going across even a home network again, so therefore you've got to analyse again. So where would you start if you're doing this manually, and wherever you spot the anomalies again? So there is software again, but of course not, the problem is a lot of small to medium sized enterprises don't really have the budget for a lot of the software, they don't really have the staff to run it. And then of course, you have, again, they do their risk assessment and to try to figure out well, is it worth it or not here? And there is no there is no rule of thumb really, there is no like how much should be spent on security and then where does security get mixed up with IT support and IT services again, so a lot of things get left.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Yeah, and while there are a huge variety of kind of software tools and services that can be used to to augment your security as a business and to help kind of detect and prevent threats, it feels like certainly back in 2017 when WannaCry hit, a large part of the problem was that organisations were neglecting the basics. I mean, you mentioned that the the main exploit that WannaCry used, or one of the main exploits was a problem in the SMB, the SMB kind of infrastructure in Windows, Server Message Block. And that was patched. But the problem was that a lot of organisations just hadn't applied the patch. And still to this, you know, to this day, there are a not insignificant number of computers out in the wild, that have not updated with that patch, even, you know, five plus years on. Have organisations on the whole kind of recognised the value post WannaCry of applying patches in a timely manner? Or is that still falling through the cracks to a greater or lesser extent?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>Again, it comes down to the resources of the company again, so, you know, we have matured as a society with regards, you know, with anything you know, so I've seen the maturity from years ago, where people didn't realise the importance of strong passwords, where now really everyone gets that, you know, we mature technologically as a society again. So, again, people are not, you know, it was very few people use hardware keys, you know, as a multi factor authentication token before, but whereas it's actually great practice to have it again, so we're seeing things gradually get there again. So, of course, most accounts now, which are important, people need to understand the need for multi factor authentication. And again, that there are services or even, you know, Microsofts or whatever will come along, and, you know, it's important to monitor your Active Directory to identify and fix any misconfigurations in there again, and, and also training of staff again, so there is, there is a need for user training again. So, of course, the people often are the weakest link, we say, again, so we don't train staff and how to spot phishing emails again. So it's, it's a different depends on tech savvy you are, because there is no, you just get a feeling for what is a phishing message. And everyone's seen that and, of course, then business email compromise is becoming the number one attack vector really, because it's the low hanging fruit again, so it doesn't require too much for people to be able to get people to click on something and install it, and then have the backdoor in again. So it's still user education is very important again, but you got to have regular audits of your equipment, see, you know, we talk about data classification as well, you know, least privilege, that's one of the key things in security; don't give people access to anything more than they need to do their job again. So it's the first. And of course, if we're giving people access to anything that you know, and then they're compromised again, so they move right across the network, as well. So we have to have all these things in place, but it's hard to manage every item because people now are bringing devices to work and such. So even though the the IT management and the CSO and his team might have locked down all the PCs and have it done so that no one's running admin and ran all the software, but then someone brings in their, their Windows XP laptop, and they put the database on there, or whatever else they're logging in. So it's very hard, with bring your own devices, you know, with that type of technology, again, to be able to monitor everything. And unfortunately, I've seen this increasingly, I've seen it in my own workplaces where the IT department locked down everything, and makes it almost impossible to do anything with the actual, with the supplied laptop you have or device, it's what people do just go to their own laptops and use a Wi-Fi and avoid what the actual security team have put in place really because it's too restrictive. Because, you know, really, you can say, well, there is a phone, how do I make a secure, my phone? Well, first of all, don't turn it on. But even then maybe the mike's on, you know, there's all these weird espionage things. So really, all I can do is take that phone and burn it to be sure that no one is accessing anything on there. And that's fine. But you know what, the phone is now useless to me. But I have made it secure and that's what a lot of IT company or a lot of a lot of companies are facing where the IT department again, the CSO's the first to get fired when it gets to the hack really. So again, they'll just do what they say is whatever, but you have to have a copy, you have to have kind of leeway between the security team which might try to bolt down everything, but we have to get our jobs done to, and there's a trade off again, otherwise we'd never cross the road or get into a car. But there has to be an acceptable level of risk somewhere again, but training is part of that.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>I mean, you mentioned kind of user training and strong passwords, multi factor authentication, all of this kind of best practice stuff. That is all really important and really valuable for companies to be implementing and to be aware of, but looking at flaws like WannaCry, WannaCry wasn't spread through phishing, or through kind of email compromise or anything like that; it was wormable. Right? It didn't require any user interaction, that's part of how it spread so quickly is that it could just kind of automatically and instantly go from one computer on a network to another, to another, to another, to another to another. How do you combat that, as an IT team through stuff like user training and best practices? Is it just a case of making sure that you're on top of kind of newly emerging zero days and things like that? Or are there other measures that can be implemented to prevent attacks like this?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>Yeah, I mean, first of all, you have to know your assets and what you're protecting, and then have the multi factor authentication in but you have to make sure that all your systems are patched and fully up to date. And then you want to have anti malware, anti spyware, you want to have real time analysis of the networks, again, you know, because they will be patched or they will be getting the updates from the Ciscos of this world or whoever else you actually hire services from, then you got to train your workforce to be able to recognise social engineering attacks again so that's part of it, but you have to run a large security awareness programme, as well as the IT department, making sure that things are are locked down, that people are using unique passwords and the firewall even, for instance, I was talking to a CSO today of a council here in Northern Ireland, and they were attacked by ransomware on the day before, Thursday before Easter. And they found out that the company they'd hired to literally do the firewalls for them had really nothing there in place. So now they did the simple thing, because it's a council website. And it's very important for the whole area here. But they simply made it non accessible outside the UK. And why? Because, okay, maybe someone's abroad? And they want to find out about the bins, but no, no, that's a simple way to do it. Just make it, use geolocation in that respect again, and maybe try to limit how many people come, but that doesn't work in all cases, in most sites, you want everyone around the world to see it, but you have to have people in charge as well. And what happens when the ransomware occurs as well, you know, is there a person, a designated person to be able to manage an incident handling or if you have a third party, which depending on how big you are, you might have BAE Systems coming in or you know, the big boys coming in and doing an analysis of it. But again, you have to someone designated to be able to handle that and do the reports and bring the system back on and looking at all the audit logs as well and be able to see where it came from. Because even though most ransomware is wormable, but most of it does come from, you know, someone clicking on something at the start again, but sometimes you can have the ways to be able to contain that as such.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>So obviously, WannaCry was, it certainly wasn't the first ransomware incident in cybersecurity history. However, it probably did mark sort of, you know, it kind of catalysed this big trend that's not really, like you said before, it hasn't really sort of ceased in the past five years. And obviously, everything's evolved since then. But one thing we do know is that businesses and organisations are starting to develop and sort of turn to these incident playbooks, right, so these blueprints on how to respond to an attack like this. So to that end, what role should these incident playbooks have in defending against ransomware?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>It's good to have a framework, at all times again, so with ransomware we're of course trying to protect against in the first place, identify when it comes and then also recover from it as well. But we do I mean, there's so many like, you know, NIST standards, National Institute of Standards Technology in the United States have some of the key frameworks that we follow when it comes to best practice and best cyber hygiene and cybersecurity again, so, all of these things are very useful again, so, and we you know, we have to just kind of, you kind of have to presume your network could be taken down again. So, what would you do, you know, so, again, there are there are actually you know, depending on how risky it is to any of your things, you can have anything from containers in your car park which drive in on trucks which they do occur, where you have a replica of your network, again, which has already been done before, but again, not many SMEs would be able to do that or, raise to that level again, and it's becoming a little bit increasingly more difficult as well. Where with the rise of the rise of cloud and hybrid environments as well, where you've lots of stuff now, even not even hosted in on premises again, but we just have to presume that we can identify it again and hopefully, just just be prepared.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>So let's look at the criminal community and how they've been affected by the WannaCry incident and the ongoing fallout from it, the way it's changed the security landscape. Are there any lessons, do you think, that the wider kind of criminal hacking community have taken away from both WannaCry and the global response to it that's informed how they conduct their operations?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>It's it Yeah, it's hard, like, we can only speculate because most of these, again, are coming from the Russias of this world, the Belaruses, Iran, North Korea again. So, again, this is notoriously, you know, that seems to be where they, you know, what they're looking for from these countries as well. But the problem is, of course, the cryptocurrencies, again, they don't want to be too successful, we found that with the, with the some of the larger attacks again, the Colonial Pipeline against the United States, and the, the, the Irish hospital system, which was brought to its knees again, so you'd want to be too successful, because then the authorities will come after you as well. So, of course, one lesson a lot of people have found is that Bitcoin isn't the anonymous cryptocurrency as many people thought it was; it was just quite good depending on you know, how you do it, and whether you put your, you put it through... what was the word again, your, if you want to be able to launder or wash it...</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>Tumbler.</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>Tumblers, yeah, you can put that through your tumbler again, coming up. But there are some network analysis tools, again, depending on how much you have in here, and again, it has to reside in some wallet somewhere. So there are pretty clever people out there who do who do the network analysis on the Bitcoin on the Bitcoin chain, and are able to see where the money goes to again, it's hard to always and again in some ways that we're still even though we think cryptocurrency is decentralised, and solves everything and removes it from the world. But no, you always have to come back out into fiat again, so the Coinbases of this world and wherever else, or Bitstamps or wherever else people store there or use for their transactions again, that the governments are able to go there. And it always come back to some accounts as well. And you're able to see where that goes. But your average cybercriminal who doesn't do anything, or just do something small attacks, even, even in the hundreds of thousands; they're unlikely to call it because police resources, police are swamped nowadays, because everything now, in the past you might have seen the police coming out of the house and carrying items; now they just bring out the devices again, and there's a lot and a chain of evidence has to be intact, and the police forces only have so many forensic experts as well. So the court cases, that's why there's such a backlog of court cases. And that's why because your jurisdictions as well, if someone steals something from you, and you know that they're in Lithuania, or well, you think they are, well, the police are not really going to be able to help you there because of the complexity involved, and the multi jurisdictional part again, but again, just if you really are intent on a life of crime, just don't presume that you won't, that your cryptocurrency won't be, won't lead back to you.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>I think it's interesting, you know, you noted about criminals wanting to be successful but not too successful. I mean, obviously with the likes of REvil and Darkside last year, we saw what can happen when when they when they do get a little bit too big for their boots. But I think one of the most interesting things for me about Wanna Cry was, was the payment system or lack thereof, because they're, in the sort of early stage of the infections, they had a lot of victims actually paying the ransom and then realising that the people who were running the operation didn't actually have a mechanism to determine who actually paid and who didn't. So no one was getting a response back. And, and people just cottoned on to that and people Yeah, stop paying. And then they're just sort of, along with the sort of technical shortcomings like the the so called Kill Switch, it was one of the things that really proved to be its downfall. And one of the things that, it's kind of like underpinned that part of ransomware, that trust relationship where, yes, it's bad to pay a ransomware actor, but you probably are going to get your files back because it's been done before where you don't get them back, and people just stopped paying, right. So I guess what, I guess the question is, what's the most interesting part about WannaCry for you?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>Yeah, the most important part would be, again, that I do remember the government invested in more in cybersecurity afterwards again, especially in the NHS. Again, like I said, it's always hard to justify to the C suite or whatever else, you know, your your need, because, of course, if the network's not down, but we have to have some kind of targets for how much a company should spend on cybersecurity, how much an organisation should, and the NHS is, is the sixth largest employer in the world, actually. </p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Oh, wow. </p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>Yeah, we forget how large it is as an organisation again, and you have all the, everything from MRI scanners right down to heart rate monitors and whatever else, and a lot of these were attacked again. So again, just it's kind of prepared us in some ways for for what could happen increasingly in the future given the the geopolitical landscape we're in at the moment, where nations will attack us and, and again, that they do have their their cyber armies again, like, you know, in the past, we're able to tell how big a country's arsenal is by being able to count the number of tanks and planes and make some estimate, again, but it's very hard to tell how big a country's offensive and defensive cyber security teams are. But we're seeing that more and more of the military will actually be wearing will actually probably, you know, will be using laptops, again, because of how much damage we can do just using devices again, and you know, being able to hack national infrastructure again. So I think a lot more will be put into it rather than the traditional things. We're seeing the failure in some ways of tanks and you know, the traditional warfare, but it's good to see to the government because it is crucial. My cousin is a nurse in the Irish government. And she said that the attack on the southern health system from ransomware, last year was, it actually was worse than COVID. In some ways, she said that they couldn't do anything. And they really had to go back to paper and pen.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Oh wow. I think that's one of the biggest takeaways from WannaCry for me was that, firstly, it really underlined what kind of impact a really serious cyber attack can have on not just an organisation, but on kind of critical infrastructure. You know, we've been talking for years in the wider cybersecurity community about the risk of critical infrastructure attacks. WannaCry, and later Colonial Pipeline, I think were, in some ways, the first real sort of illustrations of how bad it can potentially be. And, you know, that's not even close to as bad as it could potentially get with a more, more serious, more sustained attack. But one of the other real takeaways was, you can't protect everything. Like you mentioned, MRI scanners, a large part of the reason why the NHS was so badly hit is because they use a lot of embedded systems that physically can't be updated, you know, the systems running medical equipment, internally. They, in many cases, they can't physically be patched, you have to buy a new MRI machine, essentially. And there's just no way around that unless manufacturers design, you know, user upgrade functionality into their machines. And in many cases, the manufacturers that make these machines have come and gone in the time since institutions bought them. And it's a really difficult problem to grapple with. And you get the same issue in many cases in manufacturing, and in areas like that they use similar amount of embedded machinery.</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>Exactly, I mean, at least air gapped, I mean, that's always useful but um, yeah, but there is a bit of protection to having a heterogeneous network where you have all different types of devices again, so because usually an attack does usually target, it's usually platform specific, they can morph again but so if you got half of Macs or whatever, you know, a PC somewhere running X number version, you can be protected some degrees once it reaches some kind of system, which is Solaris or Linux or whatever else but but again, then with that, with with having multiple operating systems or in devices to support again, you can have a little bit more complexity there. But again, of course, as we know that the takeaway lesson really from WannaCrywas just patching in a timely manner, that if they had patched you know, there would have been protection really but again, that there are so many devices out there.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>So obviously WannaCry was largely driven by the the leak, the leaked, EternalBlue exploit, the former exploit sort of owned by the NSA. And since then, we've had I mean, arguably, you could you could argue that Colonial Pipeline was sort of on a level with WannaCry, but do you think we could ever see a cyber incident on the same level as WannaCry again? Given that, you know, it was largely driven by this freak leak of a one of a kind exploit?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>Oh, absolutely. You know, the, you know, we have zero days all the time. And of course, we don't know about most, but they're sold to regimes or used by organised crime syndicates as well. But absolutely, there is so many like, there's, like, no one even understands the code build, there's no one who could possibly be in Seattle in Microsoft who completely understand the entire operating system for Windows, for instance, I mean, we're talking about millions and millions and millions of lines of code developed over 30 years, whatever, you know, with all the, with all the add ons to that, which would happen, and we know that every patch Tuesday just before they do their fixes, you know, I think it was 119 vulnerabilities last month, that they honestly the administrators know what's going to be fixed, what's going to be changed in the coming weeks, you know, because network, IT departments were tearing their hair out at times, but you know, because they get the blame when the Microsoft patch screwed up something so they try to predict this now. But again, that's how many vulnerabilities were last week. So there always be exploits out there, there'll always be zero days, because and of course, we hope that they're not wormable again, but definitely that you know, that these can spread across. And we haven't really seen the nightmare scenario where you know, most of the world's computers or devices. But again, if we see it to the, you know, some of the or security tools have improved. But also, you know, the attacker is not letting up either, again, that we do have great automated tools now, which were able to detect and sometimes stop an active attack again. But I have no doubt that we'll see other, you know, other attacks, which take up to you know, take hundreds of millions of computers, really, especially the ones which are not patched really.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>And how can organisations try and get ahead of this eventuality?</p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>They have to implement best practice, which which is general, of course, the best practice kind of covers a host of attacks really, not just ransomware. And that's using multifactor authentication, strong passwords, using being able to identify all the resources on the network, auditing users, only giving them the privileges that they need, enable and disable Remote Desktop Protocol unless you don't use it. Use the appropriate software for scanning, do regular audits of your of your users again, and the software which is on your systems, if you don't use it, remove it again, and then plan for attacks and have desktop exercises as well and then have the strong incident response team. And also, of course, along the way, always educating your employees and users about the dangers of compromise really and what to look out for and have it updated as well. Because once people are trained, they do forget after a number of months again, so make it part of their, you know, their targeted work, you know, for what, because technology has become instrumental in our lives. You know, just a few years ago, there wasn't even an attack about a year and a half ago or two that the Visa network went down for about 24 hours in the United Kingdom. People were stuck without being able to get train tickets, they're not able to buy food, they couldn't get, you know, whatever because the actual Visa, because people increasingly do not carry cash anymore again. So again, what happens at networks when they go down at airports again, we're relying so much on technology again. So again, that there will come a time when we you know, unfortunately, we're going to see more and more infrastructure, and sometimes not even attacks, it's just because someone who you know flicked the wrong switch or else there's a cable a digger has dug up somewhere, again, maybe into a data centre, but we're increasingly reliant on technology. But there will be days in the future where we all are back to paper and pen, you know whenever some systems go down.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Well, that's it for this week's episode. Our thanks to Ulster University's Kevin Curran for being with us. </p><h3 class="article-body__section" id="section-kevin"><span>Kevin </span></h3><p>Thank you.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>You can find links to all the topics we've spoken about today in the show notes and even more on our website at itpro.co.uk.</p><h3 class="article-body__section" id="section-adam"><span>Adam</span></h3><p>You can follow us on social media as well as subscribe to our daily newsletter.</p><p>And don't forget to subscribe to the IT Pro Podcast wherever you find your podcasts. And if you're enjoying the show, leave us a rating and review.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>We'll be back next week with more insight from the world of IT but until then, goodbye.</p><h3 class="article-body__section" id="section-connor"><span>Connor </span></h3><p>Bye.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The IT Pro Podcast: What did we learn from WannaCry? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Five years ago, the security world was rocked by one of the most sudden and widespread ransomware outbreaks in history. Even now, organisations are still recovering from the damage done by WannaCry, and its shadow still looms large over the industry.</p><p>While ransomware has remained a major threat for organisations over the last half-decade, we haven’t seen anything as globally impactful as WannaCry since then - so what (if anything) has the industry learned from the incident, and are we likely to see anything on a similar scale again? IEEE senior member and professor of cybersecurity at Ulster University Kevin Curran joins us this week to talk about the legacy of WannaCry. </p><iframe frameborder="0" height="350px" width="100%" data-lazy-priority="high" data-lazy-src="https://widget.spreaker.com/player?episode_id=51108761&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true&color=ffe019"></iframe><h2 id="highlights">Highlights</h2><p>“First of all, you have to know your assets and what you're protecting, and then have the multi-factor authentication in, but you have to make sure that all your systems are patched and fully up to date. And then you want to have anti-malware, anti-spyware, you want to have real time analysis of the networks… Then you’ve got to train your workforce to be able to recognise social engineering attacks.” </p><p>“[Attackers] don't want to be too successful. We found that with the some of the larger attacks, the Colonial Pipeline [attack] against the United States, and the Irish hospital system, which was brought to its knees, so you don’t want to be too successful, because then the authorities will come after you as well.”</p><p>“One of the recommendations is, of course, you have automated patch management of your operating system, of your environments, and also of your software. As such, there are tools which can try to, and that do actually take snapshots of your systems, and can restore them… There's companies which specialise in that, whenever you're attacked, that they'll get your system up and running.”</p><p><a href="https://www.itpro.com/security/wannacry/368960/podcast-transcript-what-did-we-learn-from-wannacry" data-original-url="https://www.itpro.com/security/wannacry/368960/podcast-transcript-what-did-we-learn-from-wannacry"><em>Read the full transcript here.</em></a></p><h2 id="footnotes">Footnotes</h2><ul><li><a href="https://www.itpro.com/security/privacy/359444/the-it-pro-podcast-should-companies-spy-on-their-employees" data-original-url="https://www.itpro.com/security/privacy/359444/the-it-pro-podcast-should-companies-spy-on-their-employees">The IT Pro Podcast: Should companies spy on their employees? </a></li><li><a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" data-original-url="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">A month in the life of a social engineer – part one </a></li><li><a href="https://www.itpro.com/technology/cryptocurrencies/362037/cryptocom-confirms-34-million-hack-caused-by-2fa-bypass-exploit" data-original-url="https://www.itpro.com/technology/cryptocurrencies/362037/cryptocom-confirms-34-million-hack-caused-by-2fa-bypass-exploit">Crypto.com confirms $34 million hack caused by 2FA bypass exploit </a></li><li><a href="https://www.itpro.com/security/ransomware/359615/colonial-pipeline-ceo-confirms-the-company-paid-darkside-hackers-44" data-original-url="https://www.itpro.com/security/ransomware/359615/colonial-pipeline-ceo-confirms-the-company-paid-darkside-hackers-44">Colonial Pipeline CEO confirms $4.4 million payment to DarkSide hackers </a></li><li><a href="https://www.itpro.com/wannacry/34352/what-is-wannacry" data-original-url="https://www.itpro.com/wannacry/34352/what-is-wannacry">What is WannaCry? </a></li><li>WannaCry showed the world how not to write ransomware</li><li><a href="https://www.itpro.com/security/wannacry/359516/over-two-thirds-of-companies-still-run-software-with-wannacry-flaw" data-original-url="https://www.itpro.com/security/wannacry/359516/over-two-thirds-of-companies-still-run-software-with-wannacry-flaw">Over two-thirds of companies still run software with WannaCry flaw </a></li><li><a href="https://www.itpro.com/security/ransomware/367659/wannacry-five-years-on-part-two" data-original-url="https://www.itpro.com/security/ransomware/367659/wannacry-five-years-on-part-two">WannaCry's ghost is still wreaking havoc five years on </a></li><li><a href="https://www.itpro.com/security/ransomware/368827/calls-for-international-support-to-fight-uncontrollable-ransomware-surge-developing-countries" data-original-url="https://www.itpro.com/security/ransomware/368827/calls-for-international-support-to-fight-uncontrollable-ransomware-surge-developing-countries">Calls for international support to fight ‘uncontrollable’ ransomware surge in developing countries </a></li><li><a href="https://www.itpro.com/security/ransomware/359538/irish-health-service-executive-hit-by-ransomware-attack" data-original-url="https://www.itpro.com/security/ransomware/359538/irish-health-service-executive-hit-by-ransomware-attack">Irish Health Service hit by ransomware attack </a></li><li><a href="https://www.itpro.com/security/zero-day-exploit/368779/dogwalk-rce-variant-among-121-vulnerabilities-fixed-in-microsofts-patch-tuesday" data-original-url="https://www.itpro.com/security/zero-day-exploit/368779/dogwalk-rce-variant-among-121-vulnerabilities-fixed-in-microsofts-patch-tuesday">Dogwalk RCE variant among 121 vulnerabilities fixed in Microsoft's August Patch Tuesday </a></li><li><a href="https://www.itpro.com/it-infrastructure/31235/visa-pins-end-of-week-outage-on-hardware-failure" data-original-url="https://www.itpro.com/it-infrastructure/31235/visa-pins-end-of-week-outage-on-hardware-failure">Visa pins end-of-week outage on 'hardware failure' </a></li></ul><h3 class="article-body__section" id="section-subscribe"><span>Subscribe</span></h3><ul><li><a href="https://apple.sjv.io/c/221109/473657/7613?subId1=itpro-gb-1427089318478404400&sharedId=itpro-gb&u=https%3A%2F%2Fpodcasts.apple.com%2Fgb%2Fpodcast%2Fthe-itpro-podcast%2Fid1483810154">Subscribe to The IT Pro Podcast on Apple Podcasts</a></li><li><a href="https://podcasts.google.com/?feed=aHR0cHM6Ly9pdHByb3BvZGNhc3QubGlic3luLmNvbS9yc3M">Subscribe to The IT Pro Podcast on Google Podcasts</a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ">Subscribe to The IT Pro Podcast on Spotify</a></li><li><a href="https://www.itpro.com/newsletter-signup" data-original-url="https://www.itpro.com/newsletter-signup">Subscribe to the IT Pro newsletter</a></li><li><a href="https://www.itpro.com/magazine-signup" data-original-url="https://www.itpro.com/magazine-signup">Subscribe to IT Pro 20/20</a></li></ul> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/wannacry/368959/the-it-pro-podcast-what-did-we-learn-from-wannacry</link>
                                                                            <description>
                            <![CDATA[ Five years on, WannaCry still remains one of the most impactful security incidents in recent memory ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">omGy9fJnN9jBZydeUURSDm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RcyLdVTkQ5qmQoJeLgbSV8-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 02 Sep 2022 06:30:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RcyLdVTkQ5qmQoJeLgbSV8-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast: What did we learn from WannaCry?]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast: What did we learn from WannaCry?]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast: What did we learn from WannaCry?]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RcyLdVTkQ5qmQoJeLgbSV8-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Five years ago, the security world was rocked by one of the most sudden and widespread ransomware outbreaks in history. Even now, organisations are still recovering from the damage done by WannaCry, and its shadow still looms large over the industry.</p><p>While ransomware has remained a major threat for organisations over the last half-decade, we haven’t seen anything as globally impactful as WannaCry since then - so what (if anything) has the industry learned from the incident, and are we likely to see anything on a similar scale again? IEEE senior member and professor of cybersecurity at Ulster University Kevin Curran joins us this week to talk about the legacy of WannaCry. </p><iframe frameborder="0" height="350px" width="100%" data-lazy-priority="high" data-lazy-src="https://widget.spreaker.com/player?episode_id=51108761&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true&color=ffe019"></iframe><h2 id="highlights">Highlights</h2><p>“First of all, you have to know your assets and what you're protecting, and then have the multi-factor authentication in, but you have to make sure that all your systems are patched and fully up to date. And then you want to have anti-malware, anti-spyware, you want to have real time analysis of the networks… Then you’ve got to train your workforce to be able to recognise social engineering attacks.” </p><p>“[Attackers] don't want to be too successful. We found that with the some of the larger attacks, the Colonial Pipeline [attack] against the United States, and the Irish hospital system, which was brought to its knees, so you don’t want to be too successful, because then the authorities will come after you as well.”</p><p>“One of the recommendations is, of course, you have automated patch management of your operating system, of your environments, and also of your software. As such, there are tools which can try to, and that do actually take snapshots of your systems, and can restore them… There's companies which specialise in that, whenever you're attacked, that they'll get your system up and running.”</p><p><a href="https://www.itpro.com/security/wannacry/368960/podcast-transcript-what-did-we-learn-from-wannacry" data-original-url="https://www.itpro.com/security/wannacry/368960/podcast-transcript-what-did-we-learn-from-wannacry"><em>Read the full transcript here.</em></a></p><h2 id="footnotes">Footnotes</h2><ul><li><a href="https://www.itpro.com/security/privacy/359444/the-it-pro-podcast-should-companies-spy-on-their-employees" data-original-url="https://www.itpro.com/security/privacy/359444/the-it-pro-podcast-should-companies-spy-on-their-employees">The IT Pro Podcast: Should companies spy on their employees? </a></li><li><a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" data-original-url="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">A month in the life of a social engineer – part one </a></li><li><a href="https://www.itpro.com/technology/cryptocurrencies/362037/cryptocom-confirms-34-million-hack-caused-by-2fa-bypass-exploit" data-original-url="https://www.itpro.com/technology/cryptocurrencies/362037/cryptocom-confirms-34-million-hack-caused-by-2fa-bypass-exploit">Crypto.com confirms $34 million hack caused by 2FA bypass exploit </a></li><li><a href="https://www.itpro.com/security/ransomware/359615/colonial-pipeline-ceo-confirms-the-company-paid-darkside-hackers-44" data-original-url="https://www.itpro.com/security/ransomware/359615/colonial-pipeline-ceo-confirms-the-company-paid-darkside-hackers-44">Colonial Pipeline CEO confirms $4.4 million payment to DarkSide hackers </a></li><li><a href="https://www.itpro.com/wannacry/34352/what-is-wannacry" data-original-url="https://www.itpro.com/wannacry/34352/what-is-wannacry">What is WannaCry? </a></li><li>WannaCry showed the world how not to write ransomware</li><li><a href="https://www.itpro.com/security/wannacry/359516/over-two-thirds-of-companies-still-run-software-with-wannacry-flaw" data-original-url="https://www.itpro.com/security/wannacry/359516/over-two-thirds-of-companies-still-run-software-with-wannacry-flaw">Over two-thirds of companies still run software with WannaCry flaw </a></li><li><a href="https://www.itpro.com/security/ransomware/367659/wannacry-five-years-on-part-two" data-original-url="https://www.itpro.com/security/ransomware/367659/wannacry-five-years-on-part-two">WannaCry's ghost is still wreaking havoc five years on </a></li><li><a href="https://www.itpro.com/security/ransomware/368827/calls-for-international-support-to-fight-uncontrollable-ransomware-surge-developing-countries" data-original-url="https://www.itpro.com/security/ransomware/368827/calls-for-international-support-to-fight-uncontrollable-ransomware-surge-developing-countries">Calls for international support to fight ‘uncontrollable’ ransomware surge in developing countries </a></li><li><a href="https://www.itpro.com/security/ransomware/359538/irish-health-service-executive-hit-by-ransomware-attack" data-original-url="https://www.itpro.com/security/ransomware/359538/irish-health-service-executive-hit-by-ransomware-attack">Irish Health Service hit by ransomware attack </a></li><li><a href="https://www.itpro.com/security/zero-day-exploit/368779/dogwalk-rce-variant-among-121-vulnerabilities-fixed-in-microsofts-patch-tuesday" data-original-url="https://www.itpro.com/security/zero-day-exploit/368779/dogwalk-rce-variant-among-121-vulnerabilities-fixed-in-microsofts-patch-tuesday">Dogwalk RCE variant among 121 vulnerabilities fixed in Microsoft's August Patch Tuesday </a></li><li><a href="https://www.itpro.com/it-infrastructure/31235/visa-pins-end-of-week-outage-on-hardware-failure" data-original-url="https://www.itpro.com/it-infrastructure/31235/visa-pins-end-of-week-outage-on-hardware-failure">Visa pins end-of-week outage on 'hardware failure' </a></li></ul><h3 class="article-body__section" id="section-subscribe"><span>Subscribe</span></h3><ul><li><a href="https://apple.sjv.io/c/221109/473657/7613?subId1=itpro-gb-1427089318478404400&sharedId=itpro-gb&u=https%3A%2F%2Fpodcasts.apple.com%2Fgb%2Fpodcast%2Fthe-itpro-podcast%2Fid1483810154">Subscribe to The IT Pro Podcast on Apple Podcasts</a></li><li><a href="https://podcasts.google.com/?feed=aHR0cHM6Ly9pdHByb3BvZGNhc3QubGlic3luLmNvbS9yc3M">Subscribe to The IT Pro Podcast on Google Podcasts</a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ">Subscribe to The IT Pro Podcast on Spotify</a></li><li><a href="https://www.itpro.com/newsletter-signup" data-original-url="https://www.itpro.com/newsletter-signup">Subscribe to the IT Pro newsletter</a></li><li><a href="https://www.itpro.com/magazine-signup" data-original-url="https://www.itpro.com/magazine-signup">Subscribe to IT Pro 20/20</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Over two-thirds of companies still run software with WannaCry flaw ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Four years after the global <a href="https://www.itpro.com/wannacry/34352/what-is-wannacry" data-original-url="https://www.itpro.com/wannacry/34352/what-is-wannacry">WannaCry</a> and <a href="https://www.itpro.com/malware/34381/what-is-notpetya" data-original-url="https://www.itpro.com/malware/34381/what-is-notpetya">NotPetya</a> <a href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> attacks, two-thirds of companies still haven't patched the vulnerabilities that caused them, <a href="https://www.extrahop.com/resources/papers/insecure-protocols">according to cloud network detection and response company ExtraHop</a>.</p><p>The company investigated data from its Reveal(x) <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> platform in the first quarter of 2021 to determine which protocols its customers were running. It found that 88% of them were still running at least one device using SMBv1, which was a pivotal attack vector for the <a href="https://www.itpro.com/security/33716/us-security-agency-linked-to-baltimore-hack" data-original-url="https://www.itpro.com/security/33716/us-security-agency-linked-to-baltimore-hack">EternalBlue</a> exploit used in the two ransomware attacks. </p><p>Although a single device could mean a company is maintaining it just for use by an attack team, a more worrying statistic was that 67% of companies are running over 10 SMBv1-enabled devices. Over two-thirds (37%) were running more than 50, and 31% of companies checked had over 100 SMBv1 devices on their networks.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/358642/us-charges-three-north-koreans-for-sony-pictures-wannacry-attacks" data-original-url="/security/hacking/358642/us-charges-three-north-koreans-for-sony-pictures-wannacry-attacks">US charges three North Koreans for Sony Pictures, WannaCry attacks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/34751/spanish-ryuk-ransomware-attack-hints-at-new-wannacry" data-original-url="/wannacry/34751/spanish-ryuk-ransomware-attack-hints-at-new-wannacry">Spanish Ryuk ransomware attack hints at new WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/34352/what-is-wannacry" data-original-url="/wannacry/34352/what-is-wannacry">What is WannaCry?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-warfare/34282/wannacry-style-cyber-attack-could-trigger-full-nato-response-says-secretary" data-original-url="/cyber-warfare/34282/wannacry-style-cyber-attack-could-trigger-full-nato-response-says-secretary">WannaCry-style cyber attack could trigger full NATO response, says Secretary General</a></p></div></div><p>The report also highlighted heavy use of two other protocols in Windows servers. The first, called Local Loop Multicast Name Resolution (LLMNR), is an alternative to DNS for resolving basic names within a private network. It has a similar problem to Windows' old NetBIOS naming service, in that it communicates with all clients on the network rather than a specific server. </p><p>That enables an attacker to listen for and reply to access requests, creating a race condition to harvest the client's hashed credentials if it establishes a conversation quickly enough. It can then decrypt those credentials, giving an attacker access to a client's network account, or use them in a pass-the-hash attack.</p><p>The other protocol, New Technology LAN Manager (NTLM) v1, is a decades-old network authentication mechanism that has long been obsolete. Nevertheless, over a third (34%) of companies have over 10 devices using it, ExtraHop said. Almost one in five (19%) had over 100 devices using the protocol, despite Microsoft <a href="https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-ntlm-authentication-in-this-domain">advising</a> people to stop using it altogether in favor of the more secure Kerberos system.</p><p>The report also found that few companies had embraced using <a href="https://www.itpro.com/network-internet/30416/http-vs-https-what-difference-does-it-make-to-security" data-original-url="https://www.itpro.com/network-internet/30416/http-vs-https-what-difference-does-it-make-to-security">TLS encryption over HTTP (HTTPS)</a>, which browser vendors have <a href="https://www.itpro.com/security/30496/chrome-continues-http-phase-out-by-removing-secure-icon-from-https-sites" data-original-url="https://www.itpro.com/security/30496/chrome-continues-http-phase-out-by-removing-secure-icon-from-https-sites">aggressively enforced</a>. It found that 81% of enterprise environments were still using HTTP to send access credentials in plain text.</p><p>ExtraHop said it analyzed over four petabytes of traffic each day in its investigation of online protocol usage.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/wannacry/359516/over-two-thirds-of-companies-still-run-software-with-wannacry-flaw</link>
                                                                            <description>
                            <![CDATA[ Four years have passed, and many systems still need patching ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rj4KZLnPfmcnekvtbyYaAF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gP3dFYNfVq4PFcHmJivKUZ-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 May 2021 18:12:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gP3dFYNfVq4PFcHmJivKUZ-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Somebody sitting at their desk in front of various devices that have been locked by WannaCry]]></media:description>                                                            <media:text><![CDATA[Somebody sitting at their desk in front of various devices that have been locked by WannaCry]]></media:text>
                                <media:title type="plain"><![CDATA[Somebody sitting at their desk in front of various devices that have been locked by WannaCry]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gP3dFYNfVq4PFcHmJivKUZ-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Four years after the global <a href="https://www.itpro.com/wannacry/34352/what-is-wannacry" data-original-url="https://www.itpro.com/wannacry/34352/what-is-wannacry">WannaCry</a> and <a href="https://www.itpro.com/malware/34381/what-is-notpetya" data-original-url="https://www.itpro.com/malware/34381/what-is-notpetya">NotPetya</a> <a href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> attacks, two-thirds of companies still haven't patched the vulnerabilities that caused them, <a href="https://www.extrahop.com/resources/papers/insecure-protocols">according to cloud network detection and response company ExtraHop</a>.</p><p>The company investigated data from its Reveal(x) <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> platform in the first quarter of 2021 to determine which protocols its customers were running. It found that 88% of them were still running at least one device using SMBv1, which was a pivotal attack vector for the <a href="https://www.itpro.com/security/33716/us-security-agency-linked-to-baltimore-hack" data-original-url="https://www.itpro.com/security/33716/us-security-agency-linked-to-baltimore-hack">EternalBlue</a> exploit used in the two ransomware attacks. </p><p>Although a single device could mean a company is maintaining it just for use by an attack team, a more worrying statistic was that 67% of companies are running over 10 SMBv1-enabled devices. Over two-thirds (37%) were running more than 50, and 31% of companies checked had over 100 SMBv1 devices on their networks.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/358642/us-charges-three-north-koreans-for-sony-pictures-wannacry-attacks" data-original-url="/security/hacking/358642/us-charges-three-north-koreans-for-sony-pictures-wannacry-attacks">US charges three North Koreans for Sony Pictures, WannaCry attacks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/34751/spanish-ryuk-ransomware-attack-hints-at-new-wannacry" data-original-url="/wannacry/34751/spanish-ryuk-ransomware-attack-hints-at-new-wannacry">Spanish Ryuk ransomware attack hints at new WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/34352/what-is-wannacry" data-original-url="/wannacry/34352/what-is-wannacry">What is WannaCry?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-warfare/34282/wannacry-style-cyber-attack-could-trigger-full-nato-response-says-secretary" data-original-url="/cyber-warfare/34282/wannacry-style-cyber-attack-could-trigger-full-nato-response-says-secretary">WannaCry-style cyber attack could trigger full NATO response, says Secretary General</a></p></div></div><p>The report also highlighted heavy use of two other protocols in Windows servers. The first, called Local Loop Multicast Name Resolution (LLMNR), is an alternative to DNS for resolving basic names within a private network. It has a similar problem to Windows' old NetBIOS naming service, in that it communicates with all clients on the network rather than a specific server. </p><p>That enables an attacker to listen for and reply to access requests, creating a race condition to harvest the client's hashed credentials if it establishes a conversation quickly enough. It can then decrypt those credentials, giving an attacker access to a client's network account, or use them in a pass-the-hash attack.</p><p>The other protocol, New Technology LAN Manager (NTLM) v1, is a decades-old network authentication mechanism that has long been obsolete. Nevertheless, over a third (34%) of companies have over 10 devices using it, ExtraHop said. Almost one in five (19%) had over 100 devices using the protocol, despite Microsoft <a href="https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-ntlm-authentication-in-this-domain">advising</a> people to stop using it altogether in favor of the more secure Kerberos system.</p><p>The report also found that few companies had embraced using <a href="https://www.itpro.com/network-internet/30416/http-vs-https-what-difference-does-it-make-to-security" data-original-url="https://www.itpro.com/network-internet/30416/http-vs-https-what-difference-does-it-make-to-security">TLS encryption over HTTP (HTTPS)</a>, which browser vendors have <a href="https://www.itpro.com/security/30496/chrome-continues-http-phase-out-by-removing-secure-icon-from-https-sites" data-original-url="https://www.itpro.com/security/30496/chrome-continues-http-phase-out-by-removing-secure-icon-from-https-sites">aggressively enforced</a>. It found that 81% of enterprise environments were still using HTTP to send access credentials in plain text.</p><p>ExtraHop said it analyzed over four petabytes of traffic each day in its investigation of online protocol usage.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US charges three North Koreans for Sony Pictures, WannaCry attacks ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The US Department of Justice (DoJ) has charged three North Korean computer programmers with hacking offences related to a number of high profile data breaches, including an attack on <a href="https://www.itpro.com/security/23593/sony-pictures-hack-hackers-used-apple-ids-of-employees-to-gain-access-1" target="_blank" data-original-url="https://www.itpro.com/security/23593/sony-pictures-hack-hackers-used-apple-ids-of-employees-to-gain-access-1">Sony Pictures</a> in 2014.</p><p>The men have been accused of attempting to steal more than $1.3 billion in money and cryptocurrency from a number of businesses around the world, according to <a href="https://www.reuters.com/article/us-northkorea-cyber/u-s-charges-three-north-koreans-in-1-3-billion-hacking-spree-idUSKBN2AH2B5" target="_blank"><em>Reuters</em></a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack" data-original-url="/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack">Security experts uncover masterminds behind Sony Pictures hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/34352/what-is-wannacry" data-original-url="/wannacry/34352/what-is-wannacry">What is WannaCry?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/636781/student-accused-of-sony-pictures-hack-pleads-not-guilty" data-original-url="/636781/student-accused-of-sony-pictures-hack-pleads-not-guilty">Student accused of Sony Pictures hack pleads not guilty</a></p></div></div><p>The charge alleges that Jon Chang Hyok, Kim Il, and Park Jin Hyok conducted a series of attacks while working for North Korea's military intelligence agency. The attack on Sony Pictures Entertainment in 2014 was thought to have been retaliation for the launch of the '<em>The Interview</em>', a US action comedy film depicting the assassination of North Korean leader Kim Jong-un.</p><p>In the aftermath of that attack, security experts from companies including Kaspersky, Trend Micro, and Carbon Black conducted an <a href="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack" target="_blank" data-original-url="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack">operation to disrupt the Lazarus group</a>, which was believed to be responsible. The three men were not directly linked to the group in the indictment, however.</p><p>Similarly, the three men are also accused of targeting staff at AMC Theatres in the UK and breaking into computers that belonged to the Mammoth Screen production company. The firm was working on a drama series about North Korea, which is also thought to be the reason for the attack.</p><p>Park already has a 2018 indictment against his name, according to the DOJ, and the three are also thought to have been involved in the creation of <a href="https://www.itpro.com/wannacry/34352/what-is-wannacry" target="_blank" data-original-url="https://www.itpro.com/wannacry/34352/what-is-wannacry">WannaCry 2.0</a>. The ransomware attack crippled a number of other organisation across Europe in 2017, most notably the <a href="https://www.itpro.com/security/33953/nhs-must-spend-now-to-prevent-devastation-of-wannacry-20" target="_blank" data-original-url="https://www.itpro.com/security/33953/nhs-must-spend-now-to-prevent-devastation-of-wannacry-20">NHS,</a> which had to cancel around 19,000 appointments and lost around £92 million as a result.</p><p>The men have also been blamed for attacks on banks in Asia, Mexico, and Africa with the deployment of malicious applications that exploit <a href="https://www.itpro.com/development/34417/what-is-the-swift-programming-language-and-why-should-i-learn-it" target="_blank" data-original-url="https://www.itpro.com/development/34417/what-is-the-swift-programming-language-and-why-should-i-learn-it">SWIFT programming protocols</a>. The three are alleged to have stolen $81 million from a single attack in Bangladesh, according to the indictment.</p><p>"North Korea's operatives, using keyboards rather than guns, stealing digital wallets of cryptocurrency instead of sacks of cash, are the world's leading 21st-century nation-state bank robbers," US assistant attorney general John Demers said according to <em>Reuters</em>.</p><p>The three men are thought to be currently in North Korea, but officials also believe they have spent periods of time in other countries, such as China and Russia.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/hacking/358642/us-charges-three-north-koreans-for-sony-pictures-wannacry-attacks</link>
                                                                            <description>
                            <![CDATA[ The men are said to have been responsible for a $1.3 billion hacking spree ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oWBvcijFxiHYbq12gtNpJM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gnNsinZygen9veVhgSQTj4-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Feb 2021 11:38:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gnNsinZygen9veVhgSQTj4-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[North Korea hacker in the dark with the country&amp;#039;s flag in the background]]></media:description>                                                            <media:text><![CDATA[North Korea hacker in the dark with the country&amp;#039;s flag in the background]]></media:text>
                                <media:title type="plain"><![CDATA[North Korea hacker in the dark with the country&amp;#039;s flag in the background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gnNsinZygen9veVhgSQTj4-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US Department of Justice (DoJ) has charged three North Korean computer programmers with hacking offences related to a number of high profile data breaches, including an attack on <a href="https://www.itpro.com/security/23593/sony-pictures-hack-hackers-used-apple-ids-of-employees-to-gain-access-1" target="_blank" data-original-url="https://www.itpro.com/security/23593/sony-pictures-hack-hackers-used-apple-ids-of-employees-to-gain-access-1">Sony Pictures</a> in 2014.</p><p>The men have been accused of attempting to steal more than $1.3 billion in money and cryptocurrency from a number of businesses around the world, according to <a href="https://www.reuters.com/article/us-northkorea-cyber/u-s-charges-three-north-koreans-in-1-3-billion-hacking-spree-idUSKBN2AH2B5" target="_blank"><em>Reuters</em></a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack" data-original-url="/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack">Security experts uncover masterminds behind Sony Pictures hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/34352/what-is-wannacry" data-original-url="/wannacry/34352/what-is-wannacry">What is WannaCry?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/636781/student-accused-of-sony-pictures-hack-pleads-not-guilty" data-original-url="/636781/student-accused-of-sony-pictures-hack-pleads-not-guilty">Student accused of Sony Pictures hack pleads not guilty</a></p></div></div><p>The charge alleges that Jon Chang Hyok, Kim Il, and Park Jin Hyok conducted a series of attacks while working for North Korea's military intelligence agency. The attack on Sony Pictures Entertainment in 2014 was thought to have been retaliation for the launch of the '<em>The Interview</em>', a US action comedy film depicting the assassination of North Korean leader Kim Jong-un.</p><p>In the aftermath of that attack, security experts from companies including Kaspersky, Trend Micro, and Carbon Black conducted an <a href="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack" target="_blank" data-original-url="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack">operation to disrupt the Lazarus group</a>, which was believed to be responsible. The three men were not directly linked to the group in the indictment, however.</p><p>Similarly, the three men are also accused of targeting staff at AMC Theatres in the UK and breaking into computers that belonged to the Mammoth Screen production company. The firm was working on a drama series about North Korea, which is also thought to be the reason for the attack.</p><p>Park already has a 2018 indictment against his name, according to the DOJ, and the three are also thought to have been involved in the creation of <a href="https://www.itpro.com/wannacry/34352/what-is-wannacry" target="_blank" data-original-url="https://www.itpro.com/wannacry/34352/what-is-wannacry">WannaCry 2.0</a>. The ransomware attack crippled a number of other organisation across Europe in 2017, most notably the <a href="https://www.itpro.com/security/33953/nhs-must-spend-now-to-prevent-devastation-of-wannacry-20" target="_blank" data-original-url="https://www.itpro.com/security/33953/nhs-must-spend-now-to-prevent-devastation-of-wannacry-20">NHS,</a> which had to cancel around 19,000 appointments and lost around £92 million as a result.</p><p>The men have also been blamed for attacks on banks in Asia, Mexico, and Africa with the deployment of malicious applications that exploit <a href="https://www.itpro.com/development/34417/what-is-the-swift-programming-language-and-why-should-i-learn-it" target="_blank" data-original-url="https://www.itpro.com/development/34417/what-is-the-swift-programming-language-and-why-should-i-learn-it">SWIFT programming protocols</a>. The three are alleged to have stolen $81 million from a single attack in Bangladesh, according to the indictment.</p><p>"North Korea's operatives, using keyboards rather than guns, stealing digital wallets of cryptocurrency instead of sacks of cash, are the world's leading 21st-century nation-state bank robbers," US assistant attorney general John Demers said according to <em>Reuters</em>.</p><p>The three men are thought to be currently in North Korea, but officials also believe they have spent periods of time in other countries, such as China and Russia.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Tenable declares there are far worse security threats to fear than zero-day exploits ]]></title>
                                                                                                <dc:content><![CDATA[ <p>There's "a lot of bulls**t when it comes to cyber security" Gavin Millard, VP intelligence at Tenable, claimed at the company's Edge event, but chief among all of it is the unjustified fear of zero-day exploits.</p><p>There's a lot of focus on the potential catastrophe that can arise with a zero-day exploit inside a business' systems, and in the case of <a href="https://www.itpro.com/wannacry/34352/what-is-wannacry" target="_blank" data-original-url="https://www.itpro.com/wannacry/34352/what-is-wannacry">WannaCry</a>, entire countries. However, Millard noted that "in reality, it's the same stuff that's being leveraged all the time". This is evidenced by the top four vulnerabilities being targeted by attackers right now.</p><p>According to Oliver Rochford, director of research at Tenable, three of the most targeted vulnerabilities are in Adobe Flash - a technology most browsers have abandoned - and the last is in Internet Explorer, a browser which is due to go end-of-life next year and no longer ships as the default browser on Windows machines.</p><p>It's these unexceptional vulnerabilities that security teams need to be stressing over, not the "sexy" zero-days, as Millard put it.</p><p>Exemplifying this, the researchers discovered that attackers would have a working exploit a week before the defenders could even detect it in a scan. This was the case in 50 of the most critical vulnerabilities that featured in a recent Tenable study. "This just shows you that this focus on zero-days is kind of pointless," Rochford added.</p><p>In fact, it's the "three-month-days" that can be the most damaging, according to Millard. WannaCry is a good example of this as it exploited vulnerabilities that were disclosed and patched, supposedly, months before the attack took place.</p><p>The same goes for <a href="https://www.itpro.com/malware/34381/what-is-notpetya" target="_blank" data-original-url="https://www.itpro.com/malware/34381/what-is-notpetya">NotPetya</a>, both attacks can be traced back to one vulnerability (MS17-010) and in neither case was it a zero-day. This vulnerability was allegedly first discovered by the NSA but then was stolen by The Shadow Brokers (TSB), Millard said.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/34352/what-is-wannacry" data-original-url="/wannacry/34352/what-is-wannacry">What is WannaCry?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/33697/security-researcher-auctions-off-windows-10-zero-day-exploits" data-original-url="/security/33697/security-researcher-auctions-off-windows-10-zero-day-exploits">Security researcher auctions off Windows 10 zero-day exploits</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management" data-original-url="/security/27713/the-importance-and-benefits-of-effective-patch-management">Patch management vs vulnerability management</a></p></div></div><p>It's also alleged that the NSA tipped off Microsoft after it realised it had lost the exploits to TSB, allowing Microsoft to create a patch for it. Said patch was released on 14 March 2017, TSB disclosed the vulnerability a month later and then WannaCry hit on 12 May 2017, three months after Microsoft patched the issue.</p><p>Millard said the vulnerabilities were patched and organisations had tools that allowed them to identify the systems still open to attack, so nothing should have gone wrong, but it did.</p><p>The story of this vulnerability not only highlights how zero-days aren't the threats to be worried about but also <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management" target="_blank" data-original-url="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management">emphasises the importance of effective patch management</a>.</p><h3 class="article-body__section" id="section-malware-is-a-careful-craft"><span>Malware is a careful craft</span></h3><p>Away from the criticisms of security teams' beliefs, Rochford said that it doesn't matter how a vulnerability is exploited, it's going to happen; there's very little we can do stop it and cyber crime in general.</p><p>This is due to how lucrative the field is and the investment it would take to dwarf the revenue created by cyber crime. Citing statistics from Gartner, Rochford said cyber crime revenue is more than ten times the amount spent on cyber security, so the defenders must work smarter in order to keep up with the wealthy criminals.</p><p>The revenue generated by cyber crime is estimated at $1.5 trillion (1.17 trillion) while the amount spent to defend against the <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" target="_blank" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">black hats</a> is just $136 billion (105.7 billion). It's easy to see how lucrative the field is when you understand that even if just 0.05% of ransomware victims pay the criminals, their ROI soars to greater than 500%.</p><p>But it's not just enough to launch ransomware campaigns and expect massive payouts, it's important to create a campaign that's effective, but quiet enough to avoid too much attention. "There's a sweet spot in monetising it without wanting to be too public so that you can really sustain it," said Rochford.</p><p>Cyber crime is all about monetisation now, gone are the days where in the early 1990s people would just break into networks for fun. Millard mentioned Fluffy Bunny, a hacker in the late 90s who used to "pop really famous websites... and it was basically graffiti - there was no monetisation".</p><p>There's serious money to be made now. It's a trillion-dollar industry that isn't slowing down and cyber security teams are just playing catch up.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/34773/tenable-declares-there-are-far-worse-security-threats-to-fear-than-zero-day-exploits</link>
                                                                            <description>
                            <![CDATA[ ‘If you’re scared of zero-days, you don’t know what you’re talking about’ claims Tenable ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vAXhFcTBH9yvsu5WJgLg2W</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/67ruKnfnSzdt6EfPF2GfSZ-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 07 Nov 2019 11:11:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/67ruKnfnSzdt6EfPF2GfSZ-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[&amp;quot;ZERO DAY&amp;quot; in red on a white background]]></media:description>                                                            <media:text><![CDATA[&amp;quot;ZERO DAY&amp;quot; in red on a white background]]></media:text>
                                <media:title type="plain"><![CDATA[&amp;quot;ZERO DAY&amp;quot; in red on a white background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/67ruKnfnSzdt6EfPF2GfSZ-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There's "a lot of bulls**t when it comes to cyber security" Gavin Millard, VP intelligence at Tenable, claimed at the company's Edge event, but chief among all of it is the unjustified fear of zero-day exploits.</p><p>There's a lot of focus on the potential catastrophe that can arise with a zero-day exploit inside a business' systems, and in the case of <a href="https://www.itpro.com/wannacry/34352/what-is-wannacry" target="_blank" data-original-url="https://www.itpro.com/wannacry/34352/what-is-wannacry">WannaCry</a>, entire countries. However, Millard noted that "in reality, it's the same stuff that's being leveraged all the time". This is evidenced by the top four vulnerabilities being targeted by attackers right now.</p><p>According to Oliver Rochford, director of research at Tenable, three of the most targeted vulnerabilities are in Adobe Flash - a technology most browsers have abandoned - and the last is in Internet Explorer, a browser which is due to go end-of-life next year and no longer ships as the default browser on Windows machines.</p><p>It's these unexceptional vulnerabilities that security teams need to be stressing over, not the "sexy" zero-days, as Millard put it.</p><p>Exemplifying this, the researchers discovered that attackers would have a working exploit a week before the defenders could even detect it in a scan. This was the case in 50 of the most critical vulnerabilities that featured in a recent Tenable study. "This just shows you that this focus on zero-days is kind of pointless," Rochford added.</p><p>In fact, it's the "three-month-days" that can be the most damaging, according to Millard. WannaCry is a good example of this as it exploited vulnerabilities that were disclosed and patched, supposedly, months before the attack took place.</p><p>The same goes for <a href="https://www.itpro.com/malware/34381/what-is-notpetya" target="_blank" data-original-url="https://www.itpro.com/malware/34381/what-is-notpetya">NotPetya</a>, both attacks can be traced back to one vulnerability (MS17-010) and in neither case was it a zero-day. This vulnerability was allegedly first discovered by the NSA but then was stolen by The Shadow Brokers (TSB), Millard said.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/34352/what-is-wannacry" data-original-url="/wannacry/34352/what-is-wannacry">What is WannaCry?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/33697/security-researcher-auctions-off-windows-10-zero-day-exploits" data-original-url="/security/33697/security-researcher-auctions-off-windows-10-zero-day-exploits">Security researcher auctions off Windows 10 zero-day exploits</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management" data-original-url="/security/27713/the-importance-and-benefits-of-effective-patch-management">Patch management vs vulnerability management</a></p></div></div><p>It's also alleged that the NSA tipped off Microsoft after it realised it had lost the exploits to TSB, allowing Microsoft to create a patch for it. Said patch was released on 14 March 2017, TSB disclosed the vulnerability a month later and then WannaCry hit on 12 May 2017, three months after Microsoft patched the issue.</p><p>Millard said the vulnerabilities were patched and organisations had tools that allowed them to identify the systems still open to attack, so nothing should have gone wrong, but it did.</p><p>The story of this vulnerability not only highlights how zero-days aren't the threats to be worried about but also <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management" target="_blank" data-original-url="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management">emphasises the importance of effective patch management</a>.</p><h3 class="article-body__section" id="section-malware-is-a-careful-craft"><span>Malware is a careful craft</span></h3><p>Away from the criticisms of security teams' beliefs, Rochford said that it doesn't matter how a vulnerability is exploited, it's going to happen; there's very little we can do stop it and cyber crime in general.</p><p>This is due to how lucrative the field is and the investment it would take to dwarf the revenue created by cyber crime. Citing statistics from Gartner, Rochford said cyber crime revenue is more than ten times the amount spent on cyber security, so the defenders must work smarter in order to keep up with the wealthy criminals.</p><p>The revenue generated by cyber crime is estimated at $1.5 trillion (1.17 trillion) while the amount spent to defend against the <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" target="_blank" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">black hats</a> is just $136 billion (105.7 billion). It's easy to see how lucrative the field is when you understand that even if just 0.05% of ransomware victims pay the criminals, their ROI soars to greater than 500%.</p><p>But it's not just enough to launch ransomware campaigns and expect massive payouts, it's important to create a campaign that's effective, but quiet enough to avoid too much attention. "There's a sweet spot in monetising it without wanting to be too public so that you can really sustain it," said Rochford.</p><p>Cyber crime is all about monetisation now, gone are the days where in the early 1990s people would just break into networks for fun. Millard mentioned Fluffy Bunny, a hacker in the late 90s who used to "pop really famous websites... and it was basically graffiti - there was no monetisation".</p><p>There's serious money to be made now. It's a trillion-dollar industry that isn't slowing down and cyber security teams are just playing catch up.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Spanish Ryuk ransomware attack hints at new WannaCry ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A spate of cyber attacks on Spanish companies has raised fears of a repeat of the 2016 <a href="https://www.itpro.com/wannacry/34352/what-is-wannacry" target="_blank" data-original-url="https://www.itpro.com/wannacry/34352/what-is-wannacry">WannaCry</a> attacks, according to experts.</p><p>Spain's National Security Department, a radio station and a data centre have all reportedly been hit by the Ryuk ransomware, which has been heavily linked to a number of UK attacks.</p><p>Everis, which is a Spanish data centre, sent its workforce home following the attack, instructing staff not to use its mobile devices, according to <a href="https://www.xataka.com/seguridad/ciberataque-ransomware-deja-ko-sistemas-cadena-ser-everis" target="_blank"><em>Xataka</em></a>.</p><p>These fresh bouts of <a href="https://www.itpro.com/security/28084/what-is-ransomware" target="_blank" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> attacks against Spanish public and private organisations, including SER Radio, are certainly devastating, but unfortunately not surprising, according to Bill Conner CEO of SonicWall.</p><p>Conner, who is also a cyber security advisor to the UK and US governments, noted that the UK had seen a 195% hike in ransomware attacks in the first half of 2019.</p><p>"It's only to be expected that cybercriminals will try the same tactics in other countries," he said. "Spain, in this case, is where one of the first instances of WannaCry was documented and today's malware has remarkable similarities.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/34352/what-is-wannacry" data-original-url="/wannacry/34352/what-is-wannacry">What is WannaCry?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="/security/28084/what-is-ransomware">What is ransomware?</a></p></div></div><p>"Ryuk ransomware is specifically designed to harm business environments, and reportedly, the attackers have placed bitcoin ransoms between 1.7 BTC (12.2 thousand) and 99 BTC (713.7 thousand). This is another proof that attackers know perfectly well who to attack and how much they can afford to pay for the recovery of their files, and businesses should not underestimate their resources."</p><p>Conner added that with ransomware as a service kits going on sale for less than 30 in the Dark Web, anyone with very basic coding skills can deploy attacks like Ryuk.</p><p>"The only way for organisations to avoid suffering the same crippling effects is to implement and maintain a layered security solution able to withstand this type of hostile action and protect the organisation on all levels," he added.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/wannacry/34751/spanish-ryuk-ransomware-attack-hints-at-new-wannacry</link>
                                                                            <description>
                            <![CDATA[ Ryuk ransomware continues to be a big problem for businesses with reports of attacks on Spanish organisations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hnMMKDcJBvDwKsJSQ6DJm6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8LvWNeGiaSsFWshjGMbVxL-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 05 Nov 2019 11:58:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8LvWNeGiaSsFWshjGMbVxL-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spanish flag]]></media:description>                                                            <media:text><![CDATA[Spanish flag]]></media:text>
                                <media:title type="plain"><![CDATA[Spanish flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8LvWNeGiaSsFWshjGMbVxL-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A spate of cyber attacks on Spanish companies has raised fears of a repeat of the 2016 <a href="https://www.itpro.com/wannacry/34352/what-is-wannacry" target="_blank" data-original-url="https://www.itpro.com/wannacry/34352/what-is-wannacry">WannaCry</a> attacks, according to experts.</p><p>Spain's National Security Department, a radio station and a data centre have all reportedly been hit by the Ryuk ransomware, which has been heavily linked to a number of UK attacks.</p><p>Everis, which is a Spanish data centre, sent its workforce home following the attack, instructing staff not to use its mobile devices, according to <a href="https://www.xataka.com/seguridad/ciberataque-ransomware-deja-ko-sistemas-cadena-ser-everis" target="_blank"><em>Xataka</em></a>.</p><p>These fresh bouts of <a href="https://www.itpro.com/security/28084/what-is-ransomware" target="_blank" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> attacks against Spanish public and private organisations, including SER Radio, are certainly devastating, but unfortunately not surprising, according to Bill Conner CEO of SonicWall.</p><p>Conner, who is also a cyber security advisor to the UK and US governments, noted that the UK had seen a 195% hike in ransomware attacks in the first half of 2019.</p><p>"It's only to be expected that cybercriminals will try the same tactics in other countries," he said. "Spain, in this case, is where one of the first instances of WannaCry was documented and today's malware has remarkable similarities.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/34352/what-is-wannacry" data-original-url="/wannacry/34352/what-is-wannacry">What is WannaCry?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="/security/28084/what-is-ransomware">What is ransomware?</a></p></div></div><p>"Ryuk ransomware is specifically designed to harm business environments, and reportedly, the attackers have placed bitcoin ransoms between 1.7 BTC (12.2 thousand) and 99 BTC (713.7 thousand). This is another proof that attackers know perfectly well who to attack and how much they can afford to pay for the recovery of their files, and businesses should not underestimate their resources."</p><p>Conner added that with ransomware as a service kits going on sale for less than 30 in the Dark Web, anyone with very basic coding skills can deploy attacks like Ryuk.</p><p>"The only way for organisations to avoid suffering the same crippling effects is to implement and maintain a layered security solution able to withstand this type of hostile action and protect the organisation on all levels," he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is WannaCry?  ]]></title>
                                                                                                <dc:content><![CDATA[ <p>‘WannaCry’ is a term that’s likely to instil fear into IT departments across the country, even several years after the devastating effects of this devilish cyber threat. Although it’s been almost four years since the <a href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> first hit organisations in this country, we still look to WannaCry as an example of a real-life worst-case scenario.</p><p>The ransomware strain first rose to prominence in May 2017 when it began spreading between devices globally - seizing control of servers and files and demanding the payment of Bitcoin in exchange for their return.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/355041/critical-nhs-cyber-security-checks-suspended-due-to-coronavirus" data-original-url="/security/cyber-security/355041/critical-nhs-cyber-security-checks-suspended-due-to-coronavirus">Critical NHS cyber security checks suspended due to coronavirus response</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/34751/spanish-ryuk-ransomware-attack-hints-at-new-wannacry" data-original-url="/wannacry/34751/spanish-ryuk-ransomware-attack-hints-at-new-wannacry">Spanish Ryuk ransomware attack hints at new WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/33953/nhs-must-spend-now-to-prevent-devastation-of-wannacry-20" data-original-url="/security/33953/nhs-must-spend-now-to-prevent-devastation-of-wannacry-20">NHS must spend now to prevent devastation of ‘WannaCry 2.0’</a></p></div></div><p>This crypto-ransomware exploited a vulnerability in the Windows operating system using a tool called EternalBlue, supposedly developed by the US National Security Agency (NSA). While Microsoft had already launched a fix two months previously, many organisations that ran legacy versions of Windows, including Windows XP and <a href="https://www.itpro.com/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7" target="_blank" data-original-url="https://www.itpro.com/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7">Windows 7</a>, were still vulnerable. </p><p>Arguably, WannaCry’s largest victim was the National Health Service (NHS), with the ransomware strain disrupting the operations of roughly a third of Trusts. The attack resulted in roughly 19,000 cancelled appointments, and a bill for approximately £92 million.</p><p>Although the WannaCry outbreak was devastating, it didn’t last too long and was ended only a few days after it was found to have disrupted computer systems. Regardless, WannaCry represented a successful test case for the viability of ransomware as an effective method of cyber attack, with <a href="https://www.itpro.com/security/ransomware/356567/1212-million-ransomware-attacks-in-the-first-half-of-2020" data-original-url="https://www.itpro.com/security/ransomware/356567/1212-million-ransomware-attacks-in-the-first-half-of-2020">strings of cyber gangs pivoting towards it</a>.</p><h3 class="article-body__section" id="section-who-was-affected-by-wannacry"><span>Who was affected by WannaCry?</span></h3><p>WannaCry <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">made headlines after hitting multiple NHS organisations</a> across the country in May 2017. Systems across 16 NHS sites, including a third of hospital trusts and 5% of GP practices, were crippled by a sudden inability to access core functions, leading to severe delays and the cancellation of some 19,000 appointments.</p><p>Despite initial reports, the ransomware infections were not part of a larger coordinated attack against the NHS, as had been feared. In fact, it's believed that the NHS was simply caught in the crossfire of a particularly virulent strain of malware that targetted older systems.</p><p>Within hours of the first detection, there were reports of WannaCry infections in at least 11 countries. The malware would ultimately infect more than 200,000 systems across 150 countries, all within 24 hours. Some of the more high profile victims included Telefonica, FedEx, Deutsche Bahn.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="WXZgQTSHenuJb2Usx8kKB8" name="" alt="The NHS website as seen on an internet browser" src="https://cdn.mos.cms.futurecdn.net/WXZgQTSHenuJb2Usx8kKB8-1920-80.jpg" mos="https://cdn.mos.cms.futurecdn.net/WXZgQTSHenuJb2Usx8kKB8.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">The NHS was one of the largest victims of the attack </span><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>WannaCry is said to have caused <a href="https://www.symantec.com/blogs/feature-stories/wannacry-lessons-learned-1-year-later" target="_blank">an estimated $4 billion in losses</a>, including <a href="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates" target="_blank" data-original-url="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates">£92 million</a> for the NHS.</p><p>It was believed at the time that the worst hit organisations were those that relied on older versions of the Windows operating system, namely Windows XP. However, post-event analysis by Kaspersky revealed that the vast majority of infections (98%) were found on machines running Windows 7, an operating system that was still receiving extended security support from Microsoft at the time, with Windows XP infections making up just 0.1%.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/865562842149392384"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/865562842149392384"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Victims were urged not to pay the ransom demanded, and by the time WannaCry had stopped spreading, just 327 payments had been made to the hardcoded bitcoin wallet addresses associated with the malware. The total amount paid <a href="https://www.bbc.co.uk/news/technology-40811972" target="_blank">was around $140,000</a> when it was withdrawn from the wallets in August 2017.</p><p>It's believed that WannaCry had the potential to cause catastrophic damage had it been deliberately targetted against critical infrastructure, such as utility companies or the National Grid.</p><h3 class="article-body__section" id="section-what-vulnerabilities-did-wannacry-exploit"><span>What vulnerabilities did WannaCry exploit?</span></h3><p>Like all ransomware, WannaCry worked by gaining access to the target's computer, encrypting the contents of its hard drives and then extorting money from the victim in exchange for the decryption key. What made WannaCry unique was the way it spread.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="uZXV3vAfY2MsMRm4tSjJfE" name="uZXV3vAfY2MsMRm4tSjJfE.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/uZXV3vAfY2MsMRm4tSjJfE-1920-80.png" mos="https://cdn.mos.cms.futurecdn.net/uZXV3vAfY2MsMRm4tSjJfE.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The business guide to ransomware</strong></p><p class="fancy-box__body-text">Everything you need to know to keep your company afloat</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/357745/the-business-guide-to-ransomware" data-original-url="/security/ransomware/357745/the-business-guide-to-ransomware">FREE DOWNLOAD</a></p></div></div><p>The WannaCry package was comprised of two parts: the ransomware portion, which encrypted the target machine and threw up the ransom instructions, and a component which allowed it to quickly propagate throughout networks. It was this latter element which made it so devastating.</p><p>Based on a flaw in the Server Message Block (SMB) protocol of various versions of Windows, it scanned the local network that a machine was connected to, found other devices (including printers and other peripherals as well as PCs) with exposed SMB network ports, and then used specially-crafted packets to initiate a transfer and drop the payload on the new machine, whereupon the process would start all over again.</p><p>This process was based on an exploit known as '<a href="https://www.itpro.com/security/33716/us-security-agency-linked-to-baltimore-hack" target="_blank" data-original-url="https://www.itpro.com/security/33716/us-security-agency-linked-to-baltimore-hack">EternalBlue</a>', released by <a href="https://www.itpro.com/security/33581/chinese-hackers-used-stolen-nsa-tools-a-year-before-they-were-leaked-by-the-shadow" target="_blank" data-original-url="https://www.itpro.com/security/33581/chinese-hackers-used-stolen-nsa-tools-a-year-before-they-were-leaked-by-the-shadow">the Shadow Brokers</a> hacking group. This mysterious collective of hackers dumped a number of dangerous exploits for vulnerabilities in major systems (widely thought to have been created by the NSA) onto the public web, allowing the authors of WannaCry to incorporate it into their ransomware in order to make it wormable. WannaCry also used DOUBLEPULSAR, a backdoor injection tool that was also included in the Shadow Brokers' leaks, to aid in its spread.</p><p>The EternalBlue exploit that facilitated WannaCry's spread had actually been patched by Microsoft some months earlier, but widespread failure to apply the patch in a timely manner meant that victims were left at risk. Shortly following the outbreak, Microsoft also took the unusual step of releasing an emergency patch for affected operating systems that had already reached their end-of-life date.</p><h3 class="article-body__section" id="section-who-was-behind-wannacry"><span>Who was behind WannaCry?</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KZdka2h8CXxj3KKFA5JeQU" name="" alt="Abstract image showing a cyber criminal silhouetted against a North Korean flag" src="https://cdn.mos.cms.futurecdn.net/KZdka2h8CXxj3KKFA5JeQU-1920-80.jpg" mos="https://cdn.mos.cms.futurecdn.net/KZdka2h8CXxj3KKFA5JeQU.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Evidence suggests WannaCry was spearheaded by the North Korean-linked Lazarus Group </span><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Attributing cyber attacks to specific individuals, groups or nation-states is always difficult; it's an inexact science at best, and made all the more difficult by malware authors planting false flags to throw investigators off the scent. However, the general consensus among the security and intelligence community is that North Korean hackers were most likely to be behind WannaCry, probably working on behalf of the government.</p><p>This assessment is lent credence by the fact that metadata within the ransomware files indicated the author's computer was set to a Korean timezone, while it has been noted by both Symantec and Kaspersky that the code bears strong similarities to code used by the Lazarus Group. This group orchestrated the hack on Sony Pictures in 2014, and has also been <a href="https://www.itpro.com/security/33609/fbi-thwarts-lazarus-linked-north-korean-surveillance-malware" target="_blank" data-original-url="https://www.itpro.com/security/33609/fbi-thwarts-lazarus-linked-north-korean-surveillance-malware">linked to the North Korean state</a>.</p><p>The US government <a href="https://www.itpro.com/wannacry/31857/us-charges-north-korean-hacker-with-wannacry-and-sony-hack" target="_blank" data-original-url="https://www.itpro.com/wannacry/31857/us-charges-north-korean-hacker-with-wannacry-and-sony-hack">formally blamed North Korea for the attack</a> in September 2018 - a charge that various G20 allies, including the UK, have since echoed. North Korean authorities have always denied the allegations.</p><h3 class="article-body__section" id="section-how-was-wannacry-stopped"><span>How was WannaCry stopped?</span></h3><p>The spread of WannaCry was successfully halted less than a week after its initial emergence, thanks to the combined efforts of security researchers around the world. However, the biggest blow against the malware happened virtually by accident.</p><p>A security researcher going by the handle MalwareTech (later revealed to be British citizen Marcus Hutchins) found a URL hardcoded into the malware, which the malware would query prior to releasing its payload and encrypting the target machine.</p><p>After registering the domain, he discovered that this URL was effectively acting as a kill-switch; if the malware queried the domain and didn't find anything, it would drop the payload, but if it received a response, then it didn't trigger. Some initially suggested that this was included as a deliberate kill-switch, allowing the malware's creators to pull the plug if they needed to, but <a href="https://www.malwaretech.com/2017/05/how-to-accidentally-stop-a-global-cyber-attacks.html" target="_blank">Hutchins does not agree</a>.</p><p>Some <a href="https://www.itpro.com/security/33715/windows-10-security-focused-sandbox-broken-and-left-without-a-fix-for-a-month" target="_blank" data-original-url="https://www.itpro.com/security/33715/windows-10-security-focused-sandbox-broken-and-left-without-a-fix-for-a-month">sandbox environments</a>, which researchers use to analyse malware without risk of infecting their machine, will simulate a correct response for any URL lookup. Hutchins believes that the inclusion of a URL check is an attempt to stop it triggering in sandbox environments, making it harder for researchers to analyse and combat. The effect, however, was the same: once the domain had been registered, any new WannaCry infections would not initiate the encryption of the victim, effectively killing off its ability to spread further.</p><p>The hackers behind WannaCry attempted to launch new variants with different hard-coded domains, but they were quickly caught and registered. They also tried to knock Hutchins original domain offline via a <a href="https://www.itpro.com/security/33260/devastating-mirai-variant-is-back-on-the-hunt-for-businesses-to-infect" target="_blank" data-original-url="https://www.itpro.com/security/33260/devastating-mirai-variant-is-back-on-the-hunt-for-businesses-to-infect">Mirai-powered</a> DDoS attack, but were ultimately unsuccessful. The domain is currently being maintained by Kryptos Logic, Hutchins' employer.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/wannacry/34352/what-is-wannacry</link>
                                                                            <description>
                            <![CDATA[ The full story behind one of the worst ransomware outbreaks in history ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uG2fGQ68NLW8nvTwwRA7iU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gP3dFYNfVq4PFcHmJivKUZ-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 09 Sep 2019 09:02:00 +0000</pubDate>                                                                                                                                <updated>Thu, 04 Feb 2021 16:23:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gP3dFYNfVq4PFcHmJivKUZ-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[The NHS was one of the largest victims of the attack]]></media:description>                                                            <media:text><![CDATA[Somebody sitting at their desk in front of various devices that have been locked by WannaCry]]></media:text>
                                <media:title type="plain"><![CDATA[Somebody sitting at their desk in front of various devices that have been locked by WannaCry]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gP3dFYNfVq4PFcHmJivKUZ-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>‘WannaCry’ is a term that’s likely to instil fear into IT departments across the country, even several years after the devastating effects of this devilish cyber threat. Although it’s been almost four years since the <a href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> first hit organisations in this country, we still look to WannaCry as an example of a real-life worst-case scenario.</p><p>The ransomware strain first rose to prominence in May 2017 when it began spreading between devices globally - seizing control of servers and files and demanding the payment of Bitcoin in exchange for their return.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/355041/critical-nhs-cyber-security-checks-suspended-due-to-coronavirus" data-original-url="/security/cyber-security/355041/critical-nhs-cyber-security-checks-suspended-due-to-coronavirus">Critical NHS cyber security checks suspended due to coronavirus response</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/34751/spanish-ryuk-ransomware-attack-hints-at-new-wannacry" data-original-url="/wannacry/34751/spanish-ryuk-ransomware-attack-hints-at-new-wannacry">Spanish Ryuk ransomware attack hints at new WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/33953/nhs-must-spend-now-to-prevent-devastation-of-wannacry-20" data-original-url="/security/33953/nhs-must-spend-now-to-prevent-devastation-of-wannacry-20">NHS must spend now to prevent devastation of ‘WannaCry 2.0’</a></p></div></div><p>This crypto-ransomware exploited a vulnerability in the Windows operating system using a tool called EternalBlue, supposedly developed by the US National Security Agency (NSA). While Microsoft had already launched a fix two months previously, many organisations that ran legacy versions of Windows, including Windows XP and <a href="https://www.itpro.com/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7" target="_blank" data-original-url="https://www.itpro.com/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7">Windows 7</a>, were still vulnerable. </p><p>Arguably, WannaCry’s largest victim was the National Health Service (NHS), with the ransomware strain disrupting the operations of roughly a third of Trusts. The attack resulted in roughly 19,000 cancelled appointments, and a bill for approximately £92 million.</p><p>Although the WannaCry outbreak was devastating, it didn’t last too long and was ended only a few days after it was found to have disrupted computer systems. Regardless, WannaCry represented a successful test case for the viability of ransomware as an effective method of cyber attack, with <a href="https://www.itpro.com/security/ransomware/356567/1212-million-ransomware-attacks-in-the-first-half-of-2020" data-original-url="https://www.itpro.com/security/ransomware/356567/1212-million-ransomware-attacks-in-the-first-half-of-2020">strings of cyber gangs pivoting towards it</a>.</p><h3 class="article-body__section" id="section-who-was-affected-by-wannacry"><span>Who was affected by WannaCry?</span></h3><p>WannaCry <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">made headlines after hitting multiple NHS organisations</a> across the country in May 2017. Systems across 16 NHS sites, including a third of hospital trusts and 5% of GP practices, were crippled by a sudden inability to access core functions, leading to severe delays and the cancellation of some 19,000 appointments.</p><p>Despite initial reports, the ransomware infections were not part of a larger coordinated attack against the NHS, as had been feared. In fact, it's believed that the NHS was simply caught in the crossfire of a particularly virulent strain of malware that targetted older systems.</p><p>Within hours of the first detection, there were reports of WannaCry infections in at least 11 countries. The malware would ultimately infect more than 200,000 systems across 150 countries, all within 24 hours. Some of the more high profile victims included Telefonica, FedEx, Deutsche Bahn.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="WXZgQTSHenuJb2Usx8kKB8" name="" alt="The NHS website as seen on an internet browser" src="https://cdn.mos.cms.futurecdn.net/WXZgQTSHenuJb2Usx8kKB8-1920-80.jpg" mos="https://cdn.mos.cms.futurecdn.net/WXZgQTSHenuJb2Usx8kKB8.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">The NHS was one of the largest victims of the attack </span><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>WannaCry is said to have caused <a href="https://www.symantec.com/blogs/feature-stories/wannacry-lessons-learned-1-year-later" target="_blank">an estimated $4 billion in losses</a>, including <a href="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates" target="_blank" data-original-url="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates">£92 million</a> for the NHS.</p><p>It was believed at the time that the worst hit organisations were those that relied on older versions of the Windows operating system, namely Windows XP. However, post-event analysis by Kaspersky revealed that the vast majority of infections (98%) were found on machines running Windows 7, an operating system that was still receiving extended security support from Microsoft at the time, with Windows XP infections making up just 0.1%.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/865562842149392384"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/865562842149392384"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Victims were urged not to pay the ransom demanded, and by the time WannaCry had stopped spreading, just 327 payments had been made to the hardcoded bitcoin wallet addresses associated with the malware. The total amount paid <a href="https://www.bbc.co.uk/news/technology-40811972" target="_blank">was around $140,000</a> when it was withdrawn from the wallets in August 2017.</p><p>It's believed that WannaCry had the potential to cause catastrophic damage had it been deliberately targetted against critical infrastructure, such as utility companies or the National Grid.</p><h3 class="article-body__section" id="section-what-vulnerabilities-did-wannacry-exploit"><span>What vulnerabilities did WannaCry exploit?</span></h3><p>Like all ransomware, WannaCry worked by gaining access to the target's computer, encrypting the contents of its hard drives and then extorting money from the victim in exchange for the decryption key. What made WannaCry unique was the way it spread.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="uZXV3vAfY2MsMRm4tSjJfE" name="uZXV3vAfY2MsMRm4tSjJfE.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/uZXV3vAfY2MsMRm4tSjJfE-1920-80.png" mos="https://cdn.mos.cms.futurecdn.net/uZXV3vAfY2MsMRm4tSjJfE.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The business guide to ransomware</strong></p><p class="fancy-box__body-text">Everything you need to know to keep your company afloat</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/357745/the-business-guide-to-ransomware" data-original-url="/security/ransomware/357745/the-business-guide-to-ransomware">FREE DOWNLOAD</a></p></div></div><p>The WannaCry package was comprised of two parts: the ransomware portion, which encrypted the target machine and threw up the ransom instructions, and a component which allowed it to quickly propagate throughout networks. It was this latter element which made it so devastating.</p><p>Based on a flaw in the Server Message Block (SMB) protocol of various versions of Windows, it scanned the local network that a machine was connected to, found other devices (including printers and other peripherals as well as PCs) with exposed SMB network ports, and then used specially-crafted packets to initiate a transfer and drop the payload on the new machine, whereupon the process would start all over again.</p><p>This process was based on an exploit known as '<a href="https://www.itpro.com/security/33716/us-security-agency-linked-to-baltimore-hack" target="_blank" data-original-url="https://www.itpro.com/security/33716/us-security-agency-linked-to-baltimore-hack">EternalBlue</a>', released by <a href="https://www.itpro.com/security/33581/chinese-hackers-used-stolen-nsa-tools-a-year-before-they-were-leaked-by-the-shadow" target="_blank" data-original-url="https://www.itpro.com/security/33581/chinese-hackers-used-stolen-nsa-tools-a-year-before-they-were-leaked-by-the-shadow">the Shadow Brokers</a> hacking group. This mysterious collective of hackers dumped a number of dangerous exploits for vulnerabilities in major systems (widely thought to have been created by the NSA) onto the public web, allowing the authors of WannaCry to incorporate it into their ransomware in order to make it wormable. WannaCry also used DOUBLEPULSAR, a backdoor injection tool that was also included in the Shadow Brokers' leaks, to aid in its spread.</p><p>The EternalBlue exploit that facilitated WannaCry's spread had actually been patched by Microsoft some months earlier, but widespread failure to apply the patch in a timely manner meant that victims were left at risk. Shortly following the outbreak, Microsoft also took the unusual step of releasing an emergency patch for affected operating systems that had already reached their end-of-life date.</p><h3 class="article-body__section" id="section-who-was-behind-wannacry"><span>Who was behind WannaCry?</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KZdka2h8CXxj3KKFA5JeQU" name="" alt="Abstract image showing a cyber criminal silhouetted against a North Korean flag" src="https://cdn.mos.cms.futurecdn.net/KZdka2h8CXxj3KKFA5JeQU-1920-80.jpg" mos="https://cdn.mos.cms.futurecdn.net/KZdka2h8CXxj3KKFA5JeQU.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Evidence suggests WannaCry was spearheaded by the North Korean-linked Lazarus Group </span><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Attributing cyber attacks to specific individuals, groups or nation-states is always difficult; it's an inexact science at best, and made all the more difficult by malware authors planting false flags to throw investigators off the scent. However, the general consensus among the security and intelligence community is that North Korean hackers were most likely to be behind WannaCry, probably working on behalf of the government.</p><p>This assessment is lent credence by the fact that metadata within the ransomware files indicated the author's computer was set to a Korean timezone, while it has been noted by both Symantec and Kaspersky that the code bears strong similarities to code used by the Lazarus Group. This group orchestrated the hack on Sony Pictures in 2014, and has also been <a href="https://www.itpro.com/security/33609/fbi-thwarts-lazarus-linked-north-korean-surveillance-malware" target="_blank" data-original-url="https://www.itpro.com/security/33609/fbi-thwarts-lazarus-linked-north-korean-surveillance-malware">linked to the North Korean state</a>.</p><p>The US government <a href="https://www.itpro.com/wannacry/31857/us-charges-north-korean-hacker-with-wannacry-and-sony-hack" target="_blank" data-original-url="https://www.itpro.com/wannacry/31857/us-charges-north-korean-hacker-with-wannacry-and-sony-hack">formally blamed North Korea for the attack</a> in September 2018 - a charge that various G20 allies, including the UK, have since echoed. North Korean authorities have always denied the allegations.</p><h3 class="article-body__section" id="section-how-was-wannacry-stopped"><span>How was WannaCry stopped?</span></h3><p>The spread of WannaCry was successfully halted less than a week after its initial emergence, thanks to the combined efforts of security researchers around the world. However, the biggest blow against the malware happened virtually by accident.</p><p>A security researcher going by the handle MalwareTech (later revealed to be British citizen Marcus Hutchins) found a URL hardcoded into the malware, which the malware would query prior to releasing its payload and encrypting the target machine.</p><p>After registering the domain, he discovered that this URL was effectively acting as a kill-switch; if the malware queried the domain and didn't find anything, it would drop the payload, but if it received a response, then it didn't trigger. Some initially suggested that this was included as a deliberate kill-switch, allowing the malware's creators to pull the plug if they needed to, but <a href="https://www.malwaretech.com/2017/05/how-to-accidentally-stop-a-global-cyber-attacks.html" target="_blank">Hutchins does not agree</a>.</p><p>Some <a href="https://www.itpro.com/security/33715/windows-10-security-focused-sandbox-broken-and-left-without-a-fix-for-a-month" target="_blank" data-original-url="https://www.itpro.com/security/33715/windows-10-security-focused-sandbox-broken-and-left-without-a-fix-for-a-month">sandbox environments</a>, which researchers use to analyse malware without risk of infecting their machine, will simulate a correct response for any URL lookup. Hutchins believes that the inclusion of a URL check is an attempt to stop it triggering in sandbox environments, making it harder for researchers to analyse and combat. The effect, however, was the same: once the domain had been registered, any new WannaCry infections would not initiate the encryption of the victim, effectively killing off its ability to spread further.</p><p>The hackers behind WannaCry attempted to launch new variants with different hard-coded domains, but they were quickly caught and registered. They also tried to knock Hutchins original domain offline via a <a href="https://www.itpro.com/security/33260/devastating-mirai-variant-is-back-on-the-hunt-for-businesses-to-infect" target="_blank" data-original-url="https://www.itpro.com/security/33260/devastating-mirai-variant-is-back-on-the-hunt-for-businesses-to-infect">Mirai-powered</a> DDoS attack, but were ultimately unsuccessful. The domain is currently being maintained by Kryptos Logic, Hutchins' employer.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WannaCry warrior Marcus Hutchins free to return to UK ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Marcus Hutchins, the 25-year-old security researcher who was instrumental in stopping <a href="https://www.itpro.com/security/28992/only-50-of-cios-improve-cyber-security-after-wannacry" target="_blank" data-original-url="https://www.itpro.com/security/28992/only-50-of-cios-improve-cyber-security-after-wannacry">WannaCry</a>, has been spared from serving any additional jail time for his role in <a href="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges" target="_blank" data-original-url="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges">creating the Kronos banking trojan</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/34097/exploits-for-windows-bluekeep-vulnerability-commercially-available" data-original-url="/security/34097/exploits-for-windows-bluekeep-vulnerability-commercially-available">Exploits for Windows BlueKeep vulnerability commercially available</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry" data-original-url="/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry">Why we’re ignoring the real lesson of WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates" data-original-url="/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates">WannaCry cost the NHS £92 million, report estimates</a></p></div></div><p>Hutchins, also known by the handle MalwareTech, was sentenced on Friday by a US District Judge, after pleading guilty to two out of <a href="https://www.itpro.com/security/31265/wannacry-hero-marcus-hutchins-faces-four-new-charges" target="_blank" data-original-url="https://www.itpro.com/security/31265/wannacry-hero-marcus-hutchins-faces-four-new-charges">ten charges relating to the development and distribution</a> of the Kronos <a href="https://www.itpro.com/malware/28076/what-is-malware" target="_blank" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a>. The British researcher was sentenced to time served, with a year of supervised release. The maximum sentence included up to ten years imprisonment, as well as substantial fines.</p><p>Under US Federal law, a supervised release consists of a period following a prisoner's incarceration during which they must continue to check in with a probation officer to ensure good conduct. While Hutchins only served a few days of jail time immediately following his 2017 arrest, he has been forced to remain in the US under house arrest until the conclusion of his trial.</p><p>The judge ruled that Hutchins is not required to remain in the US as part of his supervised release, meaning that he is free to return to the UK. However, Hutchins has publicly expressed his worry that he will not be permitted to return to the US following his sentencing, effectively cutting him off from major security events including Black Hat USA, DefCon and RSA Conference.</p><p>As part of his closing statements, the judge praised Hutchins' actions during <a href="https://www.itpro.com/wannacry/31857/us-charges-north-korean-hacker-with-wannacry-and-sony-hack" target="_blank" data-original-url="https://www.itpro.com/wannacry/31857/us-charges-north-korean-hacker-with-wannacry-and-sony-hack">the WannaCry outbreak,</a> as well as his resilience during the course of the trial and his actions in recent years helping to stop cybercriminals. Prosecutors also credited his guilty plea and willingness to take responsibility for his previous actions.</p><p>Following the sentencing, Hutchins tweeted messages of thanks to his supporters, who have donated to legal funds and contributed letters of character support to the case. He also thanked his lawyers, who he said represented him pro bono. He said that after "things settle down", he aims to return his focus to educating people about cyber security.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1154823771452248065"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1154823771452248065"></a></p></blockquote></figure><div class="see-more__filter"></div></div> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/wannacry/34103/wannacry-warrior-marcus-hutchins-free-to-return-to-uk</link>
                                                                            <description>
                            <![CDATA[ Security researcher avoids jail time for role in creating the Kronos banking trojan ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dJ4zLsxdTkMBUosiN9xEHa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/U7UzUMbcTf8SSNut4D4EPW-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 29 Jul 2019 12:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/U7UzUMbcTf8SSNut4D4EPW-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/U7UzUMbcTf8SSNut4D4EPW-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Marcus Hutchins, the 25-year-old security researcher who was instrumental in stopping <a href="https://www.itpro.com/security/28992/only-50-of-cios-improve-cyber-security-after-wannacry" target="_blank" data-original-url="https://www.itpro.com/security/28992/only-50-of-cios-improve-cyber-security-after-wannacry">WannaCry</a>, has been spared from serving any additional jail time for his role in <a href="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges" target="_blank" data-original-url="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges">creating the Kronos banking trojan</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/34097/exploits-for-windows-bluekeep-vulnerability-commercially-available" data-original-url="/security/34097/exploits-for-windows-bluekeep-vulnerability-commercially-available">Exploits for Windows BlueKeep vulnerability commercially available</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry" data-original-url="/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry">Why we’re ignoring the real lesson of WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates" data-original-url="/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates">WannaCry cost the NHS £92 million, report estimates</a></p></div></div><p>Hutchins, also known by the handle MalwareTech, was sentenced on Friday by a US District Judge, after pleading guilty to two out of <a href="https://www.itpro.com/security/31265/wannacry-hero-marcus-hutchins-faces-four-new-charges" target="_blank" data-original-url="https://www.itpro.com/security/31265/wannacry-hero-marcus-hutchins-faces-four-new-charges">ten charges relating to the development and distribution</a> of the Kronos <a href="https://www.itpro.com/malware/28076/what-is-malware" target="_blank" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a>. The British researcher was sentenced to time served, with a year of supervised release. The maximum sentence included up to ten years imprisonment, as well as substantial fines.</p><p>Under US Federal law, a supervised release consists of a period following a prisoner's incarceration during which they must continue to check in with a probation officer to ensure good conduct. While Hutchins only served a few days of jail time immediately following his 2017 arrest, he has been forced to remain in the US under house arrest until the conclusion of his trial.</p><p>The judge ruled that Hutchins is not required to remain in the US as part of his supervised release, meaning that he is free to return to the UK. However, Hutchins has publicly expressed his worry that he will not be permitted to return to the US following his sentencing, effectively cutting him off from major security events including Black Hat USA, DefCon and RSA Conference.</p><p>As part of his closing statements, the judge praised Hutchins' actions during <a href="https://www.itpro.com/wannacry/31857/us-charges-north-korean-hacker-with-wannacry-and-sony-hack" target="_blank" data-original-url="https://www.itpro.com/wannacry/31857/us-charges-north-korean-hacker-with-wannacry-and-sony-hack">the WannaCry outbreak,</a> as well as his resilience during the course of the trial and his actions in recent years helping to stop cybercriminals. Prosecutors also credited his guilty plea and willingness to take responsibility for his previous actions.</p><p>Following the sentencing, Hutchins tweeted messages of thanks to his supporters, who have donated to legal funds and contributed letters of character support to the case. He also thanked his lawyers, who he said represented him pro bono. He said that after "things settle down", he aims to return his focus to educating people about cyber security.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1154823771452248065"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1154823771452248065"></a></p></blockquote></figure><div class="see-more__filter"></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Exploits for Windows BlueKeep vulnerability commercially available ]]></title>
                                                                                                <dc:content><![CDATA[ <p>An American cyber security company Immunity has made its working exploit for the Windows BlueKeep vulnerability commercially available as part of its penetration testing kit CANVAS.</p><p>BlueKeep has been dubbed the next big security threat and one that could rival the significance of WannaCry. It's a wormable remote code execution (RCE) exploit that can give attackers the highest possible privileges on a Windows system.</p><p>Immunity isn't the first to create a working exploit for BlueKeep, other security groups have claimed to have beaten them to the punch but refuse to release proof of concept code in fears of it falling into the wrong hands.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1153752470130221057"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1153752470130221057"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Accompanied by a demonstration video, the firm announced on Twitter its exploit would be included in its CANVAS toolkit which can cost tens of thousands of dollars.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/botnets/33799/goldbrute-botnet-targeting-windows-rdp-systems-in-brute-force-hacking-spree" data-original-url="/botnets/33799/goldbrute-botnet-targeting-windows-rdp-systems-in-brute-force-hacking-spree">GoldBrute botnet targeting Windows RDP systems in brute force hacking spree</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34033/why-the-telecoms-industry-is-particularly-vulnerable-to-bluekeep" data-original-url="/security/34033/why-the-telecoms-industry-is-particularly-vulnerable-to-bluekeep">Why the telecoms industry is particularly vulnerable to BlueKeep</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34029/nhs-systems-still-reliant-on-windows-xp" data-original-url="/security/34029/nhs-systems-still-reliant-on-windows-xp">NHS systems still reliant on Windows XP</a></p></div></div><p>It's the first instance of a working exploit being sold and although the price is high, the consequences of it getting in the wrong hands could be catastrophic.</p><p>"This vulnerability is no joke; BlueKeep has all the makings of becoming the next WannaCry or NotPetya," said Bob Huber, CSO, Tenable. "Patch now before it's too late."</p><p>BlueKeep was discovered in May 2019 and Microsoft released an emergency patch, even for old operating systems that had reached end of life. The vulnerability is found in the remote desktop protocol (RDP) service in many old versions of Windows including Windows 7, Windows Vista and Windows XP. Windows 10 users aren't vulnerable to BlueKeep.</p><p>Providing users patch their systems, BlueKeep cannot be exploited but it's well-documented that critical infrastructure is <a href="https://www.itpro.com/security/34029/nhs-systems-still-reliant-on-windows-xp" target="_blank" data-original-url="https://www.itpro.com/security/34029/nhs-systems-still-reliant-on-windows-xp">still reliant on legacy Windows operating systems</a>, such as certain hospital equipment which uses software that's incompatible with current and more secure versions of Windows.</p><p>"Just because a patch is available, it doesn't mean that all companies are in a position to patch immediately," said Javvad Malik, security awareness advocate at KnowBe4. "Patching can be a complex procedure in certain environments and can take a long time."</p><p>However, according to <a href="https://www.itpro.com/security/34033/why-the-telecoms-industry-is-particularly-vulnerable-to-bluekeep" target="_blank" data-original-url="https://www.itpro.com/security/34033/why-the-telecoms-industry-is-particularly-vulnerable-to-bluekeep">recent reports</a>, it's not the healthcare industry that needs to be worrying about BlueKeep the most. Since the vulnerability was released and national security agencies across the world including the NSA, the FBI and the Department of Homeland Security released their own warnings, researchers found that the telecoms sector was much more vulnerable than any other industry.</p><p>That has been largely attributed to the fact that telecoms companies often host end-customer systems they cannot upgrade themselves, meaning that in order to stay safe, their customers need to keep on top of their <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management" target="_blank" data-original-url="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management">patch management</a>.</p><p>When BlueKeep was first discovered, the number of affected systems was put at around one million globally. Following the research from BitSight in July, the authors claimed not much had been done to reduce the number of affected systems with the number thought to be around 800,000 at the time of publication.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/34097/exploits-for-windows-bluekeep-vulnerability-commercially-available</link>
                                                                            <description>
                            <![CDATA[ The issue has been dubbed 'the next WannaCry' and now attackers can have a copy of their own, for a price ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">er6VNVfiFJf8KUyvXajvbf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/J8JvaNRSjnbxgJrYer6Ee6-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 29 Jul 2019 09:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/J8JvaNRSjnbxgJrYer6Ee6-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Graphic of a cyber criminal or hacker]]></media:description>                                                            <media:text><![CDATA[Graphic of a cyber criminal or hacker]]></media:text>
                                <media:title type="plain"><![CDATA[Graphic of a cyber criminal or hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/J8JvaNRSjnbxgJrYer6Ee6-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>An American cyber security company Immunity has made its working exploit for the Windows BlueKeep vulnerability commercially available as part of its penetration testing kit CANVAS.</p><p>BlueKeep has been dubbed the next big security threat and one that could rival the significance of WannaCry. It's a wormable remote code execution (RCE) exploit that can give attackers the highest possible privileges on a Windows system.</p><p>Immunity isn't the first to create a working exploit for BlueKeep, other security groups have claimed to have beaten them to the punch but refuse to release proof of concept code in fears of it falling into the wrong hands.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1153752470130221057"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1153752470130221057"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Accompanied by a demonstration video, the firm announced on Twitter its exploit would be included in its CANVAS toolkit which can cost tens of thousands of dollars.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/botnets/33799/goldbrute-botnet-targeting-windows-rdp-systems-in-brute-force-hacking-spree" data-original-url="/botnets/33799/goldbrute-botnet-targeting-windows-rdp-systems-in-brute-force-hacking-spree">GoldBrute botnet targeting Windows RDP systems in brute force hacking spree</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34033/why-the-telecoms-industry-is-particularly-vulnerable-to-bluekeep" data-original-url="/security/34033/why-the-telecoms-industry-is-particularly-vulnerable-to-bluekeep">Why the telecoms industry is particularly vulnerable to BlueKeep</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34029/nhs-systems-still-reliant-on-windows-xp" data-original-url="/security/34029/nhs-systems-still-reliant-on-windows-xp">NHS systems still reliant on Windows XP</a></p></div></div><p>It's the first instance of a working exploit being sold and although the price is high, the consequences of it getting in the wrong hands could be catastrophic.</p><p>"This vulnerability is no joke; BlueKeep has all the makings of becoming the next WannaCry or NotPetya," said Bob Huber, CSO, Tenable. "Patch now before it's too late."</p><p>BlueKeep was discovered in May 2019 and Microsoft released an emergency patch, even for old operating systems that had reached end of life. The vulnerability is found in the remote desktop protocol (RDP) service in many old versions of Windows including Windows 7, Windows Vista and Windows XP. Windows 10 users aren't vulnerable to BlueKeep.</p><p>Providing users patch their systems, BlueKeep cannot be exploited but it's well-documented that critical infrastructure is <a href="https://www.itpro.com/security/34029/nhs-systems-still-reliant-on-windows-xp" target="_blank" data-original-url="https://www.itpro.com/security/34029/nhs-systems-still-reliant-on-windows-xp">still reliant on legacy Windows operating systems</a>, such as certain hospital equipment which uses software that's incompatible with current and more secure versions of Windows.</p><p>"Just because a patch is available, it doesn't mean that all companies are in a position to patch immediately," said Javvad Malik, security awareness advocate at KnowBe4. "Patching can be a complex procedure in certain environments and can take a long time."</p><p>However, according to <a href="https://www.itpro.com/security/34033/why-the-telecoms-industry-is-particularly-vulnerable-to-bluekeep" target="_blank" data-original-url="https://www.itpro.com/security/34033/why-the-telecoms-industry-is-particularly-vulnerable-to-bluekeep">recent reports</a>, it's not the healthcare industry that needs to be worrying about BlueKeep the most. Since the vulnerability was released and national security agencies across the world including the NSA, the FBI and the Department of Homeland Security released their own warnings, researchers found that the telecoms sector was much more vulnerable than any other industry.</p><p>That has been largely attributed to the fact that telecoms companies often host end-customer systems they cannot upgrade themselves, meaning that in order to stay safe, their customers need to keep on top of their <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management" target="_blank" data-original-url="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management">patch management</a>.</p><p>When BlueKeep was first discovered, the number of affected systems was put at around one million globally. Following the research from BitSight in July, the authors claimed not much had been done to reduce the number of affected systems with the number thought to be around 800,000 at the time of publication.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NHS systems still reliant on Windows XP ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Over 2,000 NHS systems are still running on Windows XP five years after it stopped receiving security updates.</p><p>It's the latest hammer blow to the NHS' reputation for being well behind the curve in terms of keeping its IT systems up-to-date and secure.</p><p>The figures were slammed by shadow Cabinet Office minister Jo Platt after they were revealed by Jackie Doyle-Price, parliamentary under secretary of state at the Department of Health.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/31095/one-year-on-from-wannacry-and-uk-firms-are-exposed-to-cyber-threats-more-than-ever" data-original-url="/security/31095/one-year-on-from-wannacry-and-uk-firms-are-exposed-to-cyber-threats-more-than-ever">One year on from WannaCry and UK firms are exposed to cyber threats more than ever</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/31496/the-nhs-still-owns-and-uses-almost-9000-fax-machines" data-original-url="/technology/31496/the-nhs-still-owns-and-uses-almost-9000-fax-machines">The NHS still owns - and uses - almost 9,000 fax machines</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/databases/32912/nhs-legacy-it-at-fault-for-mismanaged-health-screenings" data-original-url="/databases/32912/nhs-legacy-it-at-fault-for-mismanaged-health-screenings">NHS legacy IT at fault for mismanaged health screenings</a></p></div></div><p>"The government is seriously lacking the leadership, strategy and co-ordination we need across the public sector to keep us and our data safe and secure," said Platt. "How many more warnings will it take before they listen and take action?</p><p>"The next Labour government will provide not only the resourcing but also the vital leadership, organisation and dedication needed to get our public sector fit and resilient to fight the cyber-threats of the 21st century," she added.</p><p>It's not the first set of figures that illustrate an apparent disregard for cyber security in some parts of the National Health Service. In December 2018, a response to an FOI request revealed some NHS Trusts spend <a href="https://www.itpro.com/wannacry/32547/foi-reveals-nhs-trusts-spend-as-little-as-250-on-cyber-security" target="_blank" data-original-url="https://www.itpro.com/wannacry/32547/foi-reveals-nhs-trusts-spend-as-little-as-250-on-cyber-security">as little as 250</a> on cyber security.</p><p>Results of a different FOI request a year later revealed one NHS Trust in Cumbria was the victim of an <a href="https://www.itpro.com/security/32801/cumbria-nhs-trust-hit-with-extraordinary-amount-of-cyber-attacks-in-past-five-years" target="_blank" data-original-url="https://www.itpro.com/security/32801/cumbria-nhs-trust-hit-with-extraordinary-amount-of-cyber-attacks-in-past-five-years">"extraordinary" number of cyber attacks</a> and had spent 29,600 in 2017 alone to remedy the effects.</p><p>Doyle-Price was quick to dispel Platt's criticism, claiming that although the number of legacy systems was in the thousands, it only accounted for a small percentage of the total 1.4 million computers run by the NHS.</p><p>"This equates to 0.16% of the NHS estate," said Doyle-price. "We are supporting NHS organisations to upgrade their existing Microsoft Windows operating systems, allowing them to reduce potential vulnerabilities and increase cyber resilience."</p><p>In the wake of the WannaCry ransomware attack on the NHS in 2017, the National Audit Office revealed the NHS had been warned by the Department of Health as early as 2014 about the threat of cyber attacks and that it should <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">migrate from Windows XP by April 2015</a>.</p><p>Five years later, the upgrade process still hasn't been completed and after an attack that cost the NHS <a href="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates" target="_blank" data-original-url="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates">a reported 92 million</a>, it has led experts calling for better action to be taken.</p><p>"Considering the damage done by the WannaCry attack in 2017, it's appalling that the NHS hasn't finished upgrading its systems," said Paul Bischoff, privacy advocate at Comparitech.com. "Even if 2,300 computers is a small fraction of the total, hackers only need a single point of ingress to infect an entire network."</p><p>There are other reasons for running old software too."Often we see that companies are running old software that is no longer compatible with the newer operating systems, and therefore have to use older systems for this reason - but this does not make lower the risk of using those systems," said Boris Cipot, senior security engineer at Synopsys.</p><p>"For instance, it may have very expensive medical equipment that can only be controlled by software that runs on XP," said security analyst Graham Cluley. "So it's not just a case of updating a PC, but perhaps spending millions on a new MRI scanner."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/34029/nhs-systems-still-reliant-on-windows-xp</link>
                                                                            <description>
                            <![CDATA[ Government minister downplays significance of venerable OS' continued use ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6feen9xJTjverPMdbGMDpJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TcwjpdYjZHFBbmg5EmoP87-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Jul 2019 09:47:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TcwjpdYjZHFBbmg5EmoP87-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NHS building]]></media:description>                                                            <media:text><![CDATA[NHS building]]></media:text>
                                <media:title type="plain"><![CDATA[NHS building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TcwjpdYjZHFBbmg5EmoP87-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Over 2,000 NHS systems are still running on Windows XP five years after it stopped receiving security updates.</p><p>It's the latest hammer blow to the NHS' reputation for being well behind the curve in terms of keeping its IT systems up-to-date and secure.</p><p>The figures were slammed by shadow Cabinet Office minister Jo Platt after they were revealed by Jackie Doyle-Price, parliamentary under secretary of state at the Department of Health.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/31095/one-year-on-from-wannacry-and-uk-firms-are-exposed-to-cyber-threats-more-than-ever" data-original-url="/security/31095/one-year-on-from-wannacry-and-uk-firms-are-exposed-to-cyber-threats-more-than-ever">One year on from WannaCry and UK firms are exposed to cyber threats more than ever</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/31496/the-nhs-still-owns-and-uses-almost-9000-fax-machines" data-original-url="/technology/31496/the-nhs-still-owns-and-uses-almost-9000-fax-machines">The NHS still owns - and uses - almost 9,000 fax machines</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/databases/32912/nhs-legacy-it-at-fault-for-mismanaged-health-screenings" data-original-url="/databases/32912/nhs-legacy-it-at-fault-for-mismanaged-health-screenings">NHS legacy IT at fault for mismanaged health screenings</a></p></div></div><p>"The government is seriously lacking the leadership, strategy and co-ordination we need across the public sector to keep us and our data safe and secure," said Platt. "How many more warnings will it take before they listen and take action?</p><p>"The next Labour government will provide not only the resourcing but also the vital leadership, organisation and dedication needed to get our public sector fit and resilient to fight the cyber-threats of the 21st century," she added.</p><p>It's not the first set of figures that illustrate an apparent disregard for cyber security in some parts of the National Health Service. In December 2018, a response to an FOI request revealed some NHS Trusts spend <a href="https://www.itpro.com/wannacry/32547/foi-reveals-nhs-trusts-spend-as-little-as-250-on-cyber-security" target="_blank" data-original-url="https://www.itpro.com/wannacry/32547/foi-reveals-nhs-trusts-spend-as-little-as-250-on-cyber-security">as little as 250</a> on cyber security.</p><p>Results of a different FOI request a year later revealed one NHS Trust in Cumbria was the victim of an <a href="https://www.itpro.com/security/32801/cumbria-nhs-trust-hit-with-extraordinary-amount-of-cyber-attacks-in-past-five-years" target="_blank" data-original-url="https://www.itpro.com/security/32801/cumbria-nhs-trust-hit-with-extraordinary-amount-of-cyber-attacks-in-past-five-years">"extraordinary" number of cyber attacks</a> and had spent 29,600 in 2017 alone to remedy the effects.</p><p>Doyle-Price was quick to dispel Platt's criticism, claiming that although the number of legacy systems was in the thousands, it only accounted for a small percentage of the total 1.4 million computers run by the NHS.</p><p>"This equates to 0.16% of the NHS estate," said Doyle-price. "We are supporting NHS organisations to upgrade their existing Microsoft Windows operating systems, allowing them to reduce potential vulnerabilities and increase cyber resilience."</p><p>In the wake of the WannaCry ransomware attack on the NHS in 2017, the National Audit Office revealed the NHS had been warned by the Department of Health as early as 2014 about the threat of cyber attacks and that it should <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">migrate from Windows XP by April 2015</a>.</p><p>Five years later, the upgrade process still hasn't been completed and after an attack that cost the NHS <a href="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates" target="_blank" data-original-url="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates">a reported 92 million</a>, it has led experts calling for better action to be taken.</p><p>"Considering the damage done by the WannaCry attack in 2017, it's appalling that the NHS hasn't finished upgrading its systems," said Paul Bischoff, privacy advocate at Comparitech.com. "Even if 2,300 computers is a small fraction of the total, hackers only need a single point of ingress to infect an entire network."</p><p>There are other reasons for running old software too."Often we see that companies are running old software that is no longer compatible with the newer operating systems, and therefore have to use older systems for this reason - but this does not make lower the risk of using those systems," said Boris Cipot, senior security engineer at Synopsys.</p><p>"For instance, it may have very expensive medical equipment that can only be controlled by software that runs on XP," said security analyst Graham Cluley. "So it's not just a case of updating a PC, but perhaps spending millions on a new MRI scanner."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NHS must spend now to prevent devastation of ‘WannaCry 2.0’ ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The government must urgently pump more money into <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> within the NHS to plug gaps that render the healthcare system vulnerable to an attack <a href="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates" target="_blank" data-original-url="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates">more destructive than the WannaCry saga</a>.</p><p>Although many positive steps have been taken since the 2017 attack, a lack of investment, a deficit of skills and awareness, and the use of out-dated systems are putting patients at risk, according to the white paper prepared by the Institute of Global Health Innovation (IGHI).</p><p>These key areas must be addressed urgently or the consequences will be "catastrophic" as the NHS increasingly relies on technology. </p><p>"We are in the midst of a technological revolution that is transforming the way we deliver and receive care," said co-director for the IGHI Lord Darzi.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28196/the-cybersecurity-skills-your-business-needs" data-original-url="/security/28196/the-cybersecurity-skills-your-business-needs">The cyber security skills your business needs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/32960/robots-ai-and-alexa-to-transform-nhs" data-original-url="/business-strategy/32960/robots-ai-and-alexa-to-transform-nhs">Robots, AI and Alexa to transform NHS</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/digital-transformation/33033/what-businesses-can-learn-from-the-nhs-digital-transformation" data-original-url="/digital-transformation/33033/what-businesses-can-learn-from-the-nhs-digital-transformation">What businesses can learn from the NHS’ digital transformation rollercoaster</a></p></div></div><p>"But as we become increasingly reliant on technology in healthcare, we must address the emerging challenges that arise in parallel. For the safety of patients, it is critical to ensure that the data, devices and systems that uphold our NHS and therefore our nation's health are secure.</p><p>"This report highlights weaknesses that compromise patient safety and the integrity of health systems, so we are calling for greater investment in research to learn how we can better mitigate against the looming threats of cyber-attacks."</p><h3 class="article-body__section" id="section-three-key-areas-of-weakness"><span>Three key areas of weakness</span></h3><p>Healthcare IT has suffered from 'chronic underspending' compared with other sectors, the report claimed, with NHS organisations spending 1-2% of running costs on IT services compared with 4-10% elsewhere. This underlines a desperate situation in which more funding is urgently needed.</p><p>There is often a trade-off in all sectors when it comes to allocating funds, but the NHS generally does not see cyber security as a priority compared with other areas.</p><p>The IT landscape within the health sector, meanwhile, is inconsistent and patchy with several different networks and connections requiring different security approaches. It's not unusual, therefore, that old software is used as long as it is, the report found.</p><p>Critically, without asset inventories of what is on a network at any time, organisations may find themselves trying to patch "that which they don't know exists". This is because no cataloguing system exists to list all software and hardware deployed in the NHS.</p><p>Financial shortages are also leading to <a href="https://www.itpro.com/security/31932/has-demand-for-cyber-security-skills-hit-crisis-point" target="_blank" data-original-url="https://www.itpro.com/security/31932/has-demand-for-cyber-security-skills-hit-crisis-point">difficulties in hiring competent cyber security personnel</a> given the large pay gaps between the public and private sector.</p><h3 class="article-body__section" id="section-next-gen-health-and-social-care"><span>Next-gen health and social care</span></h3><p>The report also highlighted a number of emerging technologies that can improve practices and standards across the NHS, including <a href="https://www.itpro.com/machine-learning/31708/what-are-the-pros-and-cons-of-ai" target="_blank" data-original-url="https://www.itpro.com/machine-learning/31708/what-are-the-pros-and-cons-of-ai">algorithmic decision-making</a> and smart devices. But these simultaneously leave the health and social care sector more vulnerable to attack.</p><p>Electronic health records (EHRs), for example, will be the foundation of digital healthcare systems in future. But if the parameters for access and control for an individual are not configured properly, EHRs will be vulnerable to infiltration. The infrastructure for EHRs must provide secure flexibility so it can serve patients' needs while also speaking to a secure and hygienic data architecture.</p><p>Relying on third-parties to hold information in the cloud also comes with risks; namely, there is a spate of recorded incidents where data monitored by specialist third-party staff has been hacked and stolen. Moreover, despite <a href="https://www.itpro.com/cloud-security/31264/nhs-digital-blasted-for-dumping-responsibility-for-cloud-data-processing-on" target="_blank" data-original-url="https://www.itpro.com/cloud-security/31264/nhs-digital-blasted-for-dumping-responsibility-for-cloud-data-processing-on">NHS Digital guidance last year approving healthcare organisations' use of the cloud</a>, the fragmented structure of the health service means it's proven difficult to adopt cloud computing on any meaningful scale.</p><p>Robotics can transform the delivery of care by carrying out repetitive tasks and aiding a human surgeon, meanwhile. Removing the human factor from decision-making entirely, however, may have implications for clinical liability and accountability, and the health service is not yet prepared to manage this safely and securely at scale.</p><h3 class="article-body__section" id="section-improving-nhs-cyber-resilience"><span>Improving NHS cyber resilience</span></h3><p>The risks aren't exclusive to the NHS, but all healthcare institutions across the world. A recent study, however, found <a href="https://info.veracode.com/report-state-of-software-security-report-volume6.html" target="_blank">the health sector is the fastest industry when it comes to addressing common software flaws</a>.</p><p>Healthcare organisations took just six days to address a quarter of vulnerabilities in code, and just seven months to fix 75% of flaws. This is almost eight months faster than the average organisation, which takes 15 months.</p><p>In a positive light, the UK government has taken a number of steps to rectify the vulnerabilities exposed by the WannaCry attack over the last two years.</p><p><a href="https://www.itpro.com/wannacry/31020/nhs-aims-to-solve-cyber-security-issues-with-windows-10-migration-by-2020-deadline" target="_blank" data-original-url="https://www.itpro.com/wannacry/31020/nhs-aims-to-solve-cyber-security-issues-with-windows-10-migration-by-2020-deadline">Systems are expected to transition to Windows 10 by the end of 2019</a>, for example, after the NHS struck a deal with Microsoft to allow cost-free upgrades to Trusts that sign up to a special programme.</p><p>IBM was also recruited last July in a three-year deal worth 30 million which <a href="https://www.itpro.com/cyber-security/31423/nhs-asks-ibm-to-boost-its-cyber-security-defences-after-wannacry" target="_blank" data-original-url="https://www.itpro.com/cyber-security/31423/nhs-asks-ibm-to-boost-its-cyber-security-defences-after-wannacry">gives NHS Digital access to its advanced security services</a> such as scanning and malware analysis.</p><p>But the landscape set out by the IGHI for the UK's NHS is relatively dire and points largely towards a lack of funding needed to truly boost cyber resilience. One year after WannaCry, for instance, <a href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" target="_blank" data-original-url="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">not a single Trust passed the government's cyber security assessment</a>.</p><p>"Since the WannaCry attack in 2017, awareness of cyber-attack risk has significantly increased," said the lead author of the report Dr Saira Ghafur.</p><p>"However we still need further initiatives and awareness, and improved cyber security 'hygiene' to counteract the clear and present danger these incidents represent.</p><p>"The effects of these attacks can be far-reaching - from doctors being unable to access patients test results or scans, as we saw in WannaCry, to hackers gaining access to personal information, or even tampering with a person's medical record."</p><p>An NHSX spokesperson said: "The NHS is determined to keep its systems safe from cyber attack and every part of the NHS is given clear direction to protect their own systems and the information they hold whilst nationally cyber defences are in place, led by NHS Digital working closely with the National Cyber Security Centre.</p><p>"There is still much to do, which is why an extra 150m is boosting hospital defences alongside a national deal on Microsoft licences and NHSX will be setting national strategy and mandating cyber security standards so that local NHS and social care systems have security designed in from the start."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/33953/nhs-must-spend-now-to-prevent-devastation-of-wannacry-20</link>
                                                                            <description>
                            <![CDATA[ Positive moves are being made but they will count for nothing if a more sophisticated attack strikes ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mYtWsKqhrJZqm6WaUPQqAR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yqkzuSPijEywHtvSJPnUJn-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 04 Jul 2019 10:38:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/yqkzuSPijEywHtvSJPnUJn-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber security skull ]]></media:description>                                                            <media:text><![CDATA[Cyber security skull ]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber security skull ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yqkzuSPijEywHtvSJPnUJn-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The government must urgently pump more money into <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> within the NHS to plug gaps that render the healthcare system vulnerable to an attack <a href="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates" target="_blank" data-original-url="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates">more destructive than the WannaCry saga</a>.</p><p>Although many positive steps have been taken since the 2017 attack, a lack of investment, a deficit of skills and awareness, and the use of out-dated systems are putting patients at risk, according to the white paper prepared by the Institute of Global Health Innovation (IGHI).</p><p>These key areas must be addressed urgently or the consequences will be "catastrophic" as the NHS increasingly relies on technology. </p><p>"We are in the midst of a technological revolution that is transforming the way we deliver and receive care," said co-director for the IGHI Lord Darzi.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28196/the-cybersecurity-skills-your-business-needs" data-original-url="/security/28196/the-cybersecurity-skills-your-business-needs">The cyber security skills your business needs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/32960/robots-ai-and-alexa-to-transform-nhs" data-original-url="/business-strategy/32960/robots-ai-and-alexa-to-transform-nhs">Robots, AI and Alexa to transform NHS</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/digital-transformation/33033/what-businesses-can-learn-from-the-nhs-digital-transformation" data-original-url="/digital-transformation/33033/what-businesses-can-learn-from-the-nhs-digital-transformation">What businesses can learn from the NHS’ digital transformation rollercoaster</a></p></div></div><p>"But as we become increasingly reliant on technology in healthcare, we must address the emerging challenges that arise in parallel. For the safety of patients, it is critical to ensure that the data, devices and systems that uphold our NHS and therefore our nation's health are secure.</p><p>"This report highlights weaknesses that compromise patient safety and the integrity of health systems, so we are calling for greater investment in research to learn how we can better mitigate against the looming threats of cyber-attacks."</p><h3 class="article-body__section" id="section-three-key-areas-of-weakness"><span>Three key areas of weakness</span></h3><p>Healthcare IT has suffered from 'chronic underspending' compared with other sectors, the report claimed, with NHS organisations spending 1-2% of running costs on IT services compared with 4-10% elsewhere. This underlines a desperate situation in which more funding is urgently needed.</p><p>There is often a trade-off in all sectors when it comes to allocating funds, but the NHS generally does not see cyber security as a priority compared with other areas.</p><p>The IT landscape within the health sector, meanwhile, is inconsistent and patchy with several different networks and connections requiring different security approaches. It's not unusual, therefore, that old software is used as long as it is, the report found.</p><p>Critically, without asset inventories of what is on a network at any time, organisations may find themselves trying to patch "that which they don't know exists". This is because no cataloguing system exists to list all software and hardware deployed in the NHS.</p><p>Financial shortages are also leading to <a href="https://www.itpro.com/security/31932/has-demand-for-cyber-security-skills-hit-crisis-point" target="_blank" data-original-url="https://www.itpro.com/security/31932/has-demand-for-cyber-security-skills-hit-crisis-point">difficulties in hiring competent cyber security personnel</a> given the large pay gaps between the public and private sector.</p><h3 class="article-body__section" id="section-next-gen-health-and-social-care"><span>Next-gen health and social care</span></h3><p>The report also highlighted a number of emerging technologies that can improve practices and standards across the NHS, including <a href="https://www.itpro.com/machine-learning/31708/what-are-the-pros-and-cons-of-ai" target="_blank" data-original-url="https://www.itpro.com/machine-learning/31708/what-are-the-pros-and-cons-of-ai">algorithmic decision-making</a> and smart devices. But these simultaneously leave the health and social care sector more vulnerable to attack.</p><p>Electronic health records (EHRs), for example, will be the foundation of digital healthcare systems in future. But if the parameters for access and control for an individual are not configured properly, EHRs will be vulnerable to infiltration. The infrastructure for EHRs must provide secure flexibility so it can serve patients' needs while also speaking to a secure and hygienic data architecture.</p><p>Relying on third-parties to hold information in the cloud also comes with risks; namely, there is a spate of recorded incidents where data monitored by specialist third-party staff has been hacked and stolen. Moreover, despite <a href="https://www.itpro.com/cloud-security/31264/nhs-digital-blasted-for-dumping-responsibility-for-cloud-data-processing-on" target="_blank" data-original-url="https://www.itpro.com/cloud-security/31264/nhs-digital-blasted-for-dumping-responsibility-for-cloud-data-processing-on">NHS Digital guidance last year approving healthcare organisations' use of the cloud</a>, the fragmented structure of the health service means it's proven difficult to adopt cloud computing on any meaningful scale.</p><p>Robotics can transform the delivery of care by carrying out repetitive tasks and aiding a human surgeon, meanwhile. Removing the human factor from decision-making entirely, however, may have implications for clinical liability and accountability, and the health service is not yet prepared to manage this safely and securely at scale.</p><h3 class="article-body__section" id="section-improving-nhs-cyber-resilience"><span>Improving NHS cyber resilience</span></h3><p>The risks aren't exclusive to the NHS, but all healthcare institutions across the world. A recent study, however, found <a href="https://info.veracode.com/report-state-of-software-security-report-volume6.html" target="_blank">the health sector is the fastest industry when it comes to addressing common software flaws</a>.</p><p>Healthcare organisations took just six days to address a quarter of vulnerabilities in code, and just seven months to fix 75% of flaws. This is almost eight months faster than the average organisation, which takes 15 months.</p><p>In a positive light, the UK government has taken a number of steps to rectify the vulnerabilities exposed by the WannaCry attack over the last two years.</p><p><a href="https://www.itpro.com/wannacry/31020/nhs-aims-to-solve-cyber-security-issues-with-windows-10-migration-by-2020-deadline" target="_blank" data-original-url="https://www.itpro.com/wannacry/31020/nhs-aims-to-solve-cyber-security-issues-with-windows-10-migration-by-2020-deadline">Systems are expected to transition to Windows 10 by the end of 2019</a>, for example, after the NHS struck a deal with Microsoft to allow cost-free upgrades to Trusts that sign up to a special programme.</p><p>IBM was also recruited last July in a three-year deal worth 30 million which <a href="https://www.itpro.com/cyber-security/31423/nhs-asks-ibm-to-boost-its-cyber-security-defences-after-wannacry" target="_blank" data-original-url="https://www.itpro.com/cyber-security/31423/nhs-asks-ibm-to-boost-its-cyber-security-defences-after-wannacry">gives NHS Digital access to its advanced security services</a> such as scanning and malware analysis.</p><p>But the landscape set out by the IGHI for the UK's NHS is relatively dire and points largely towards a lack of funding needed to truly boost cyber resilience. One year after WannaCry, for instance, <a href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" target="_blank" data-original-url="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">not a single Trust passed the government's cyber security assessment</a>.</p><p>"Since the WannaCry attack in 2017, awareness of cyber-attack risk has significantly increased," said the lead author of the report Dr Saira Ghafur.</p><p>"However we still need further initiatives and awareness, and improved cyber security 'hygiene' to counteract the clear and present danger these incidents represent.</p><p>"The effects of these attacks can be far-reaching - from doctors being unable to access patients test results or scans, as we saw in WannaCry, to hackers gaining access to personal information, or even tampering with a person's medical record."</p><p>An NHSX spokesperson said: "The NHS is determined to keep its systems safe from cyber attack and every part of the NHS is given clear direction to protect their own systems and the information they hold whilst nationally cyber defences are in place, led by NHS Digital working closely with the National Cyber Security Centre.</p><p>"There is still much to do, which is why an extra 150m is boosting hospital defences alongside a national deal on Microsoft licences and NHSX will be setting national strategy and mandating cyber security standards so that local NHS and social care systems have security designed in from the start."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft fixes critical flaw in legacy Windows systems to prevent WannaCry-like attack ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Microsoft has released fixes for a critical remote-code execution (RCE) flaw affecting older Windows installations that could have allowed malware to spread between machines without any user interaction.</p><p>The vulnerability has been described as 'wormable' which means that any future malware exploiting this could spread from machine to machine in a similar way to the infamous WannaCry attack in 2017.</p><p>The flaw with Remote Desktop Services, a remote PC platform, affects users running legacy operating systems including Windows 7, Windows XP, Windows Server 2008, Windows Server 2008 R2, and Windows 2003.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7" data-original-url="/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7">What to do if you're still running Windows 7</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/microsoft-windows/32704/windows-7-users-report-network-errors-after-january-update" data-original-url="/microsoft-windows/32704/windows-7-users-report-network-errors-after-january-update">Windows 7 users report network errors after January update</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/microsoft-windows/32386/how-to-run-classic-versions-of-windows-on-modern-pcs" data-original-url="/microsoft-windows/32386/how-to-run-classic-versions-of-windows-on-modern-pcs">How to run classic versions of Windows on modern PCs</a></p></div></div><p>Microsoft confirmed the Remote Desktop Protocol itself is not vulnerable, and the issue is pre-authentication, meaning it requires no user interaction.</p><p>"While we have observed no exploitation of this vulnerability, it is highly likely that malicious actors will write an exploit for this vulnerability and incorporate it into their malware," <a href="https://blogs.technet.microsoft.com/msrc/2019/05/14/prevent-a-worm-by-updating-remote-desktop-services-cve-2019-0708" target="_blank">the Microsoft Security Response Centre (MSRC) said</a>.</p><p>"Customers running Windows 8 and Windows 10 are not affected by this vulnerability, and it is no coincidence that later versions of Windows are unaffected.</p><p>"Microsoft invests heavily in strengthening the security of its products, often through major architectural improvements that are not possible to backport to earlier versions of Windows."</p><p>Microsoft confirmed that users running Windows 7, Windows XP, Windows Server 2008 R2 and Windows Server 2008, as well as those still on Windows 2003 were at-risk of succumbing to the flaw.</p><p>Patches for the in-support systems, Windows 7 and both Server 2008 iterations, are available via the Microsoft Security Update Guide, or through automatic updates.</p><p>Out-of-support systems, including Windows XP and 2003 users, <a href="https://support.microsoft.com/en-gb/help/4500705/customer-guidance-for-cve-2019-0708" target="_blank">will also receive a special fix due to the severity of this issue</a>. But the firm has advised all its users who haven't yet upgraded to Windows 10 to do so as soon as possible as this is "the best way to address this vulnerability".</p><p>"It is highly likely that this vulnerability will be exploited in the wild in the near future as attackers develop exploit code," said senior research engineer with Tenable Satnam Narang.</p><p>"It is critically important for organisations and system administrators to apply patches as soon as possible to reduce their risk of compromise."</p><p>The WannaCry ransomware epidemic affected countless machines across the world, and in the UK became known for its devastating effects in the NHS. Research published in October <a href="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates" target="_blank" data-original-url="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates">estimated the cost to the health service was 92 million</a> and was primarily allowed to spread due to unpatched Windows XP and Windows 7 machines.</p><p>Although Windows 7 systems are to be taken out of Microsoft's support cycle by January 2020, the market share for this operating system <a href="https://www.itpro.com/microsoft-windows/33368/windows-7-market-share-finally-declines-ahead-of-january-2020-end-of-life" target="_blank" data-original-url="https://www.itpro.com/microsoft-windows/33368/windows-7-market-share-finally-declines-ahead-of-january-2020-end-of-life">only began its terminal decline as recently as April</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/cyber-attacks/33644/microsoft-fixes-critical-flaw-in-legacy-windows-systems-to-prevent-wannacry-like</link>
                                                                            <description>
                            <![CDATA[ Windows 7 and XP machines are at risk of autonomously spreading malware between PCs and networks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5bhY3etHtqg5HZHkTiauGo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GxmNcBsfrJugkyx3cfUav-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 May 2019 09:49:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GxmNcBsfrJugkyx3cfUav-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Red padlock representing a security hack]]></media:description>                                                            <media:text><![CDATA[Red padlock representing a security hack]]></media:text>
                                <media:title type="plain"><![CDATA[Red padlock representing a security hack]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GxmNcBsfrJugkyx3cfUav-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has released fixes for a critical remote-code execution (RCE) flaw affecting older Windows installations that could have allowed malware to spread between machines without any user interaction.</p><p>The vulnerability has been described as 'wormable' which means that any future malware exploiting this could spread from machine to machine in a similar way to the infamous WannaCry attack in 2017.</p><p>The flaw with Remote Desktop Services, a remote PC platform, affects users running legacy operating systems including Windows 7, Windows XP, Windows Server 2008, Windows Server 2008 R2, and Windows 2003.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7" data-original-url="/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7">What to do if you're still running Windows 7</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/microsoft-windows/32704/windows-7-users-report-network-errors-after-january-update" data-original-url="/microsoft-windows/32704/windows-7-users-report-network-errors-after-january-update">Windows 7 users report network errors after January update</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/microsoft-windows/32386/how-to-run-classic-versions-of-windows-on-modern-pcs" data-original-url="/microsoft-windows/32386/how-to-run-classic-versions-of-windows-on-modern-pcs">How to run classic versions of Windows on modern PCs</a></p></div></div><p>Microsoft confirmed the Remote Desktop Protocol itself is not vulnerable, and the issue is pre-authentication, meaning it requires no user interaction.</p><p>"While we have observed no exploitation of this vulnerability, it is highly likely that malicious actors will write an exploit for this vulnerability and incorporate it into their malware," <a href="https://blogs.technet.microsoft.com/msrc/2019/05/14/prevent-a-worm-by-updating-remote-desktop-services-cve-2019-0708" target="_blank">the Microsoft Security Response Centre (MSRC) said</a>.</p><p>"Customers running Windows 8 and Windows 10 are not affected by this vulnerability, and it is no coincidence that later versions of Windows are unaffected.</p><p>"Microsoft invests heavily in strengthening the security of its products, often through major architectural improvements that are not possible to backport to earlier versions of Windows."</p><p>Microsoft confirmed that users running Windows 7, Windows XP, Windows Server 2008 R2 and Windows Server 2008, as well as those still on Windows 2003 were at-risk of succumbing to the flaw.</p><p>Patches for the in-support systems, Windows 7 and both Server 2008 iterations, are available via the Microsoft Security Update Guide, or through automatic updates.</p><p>Out-of-support systems, including Windows XP and 2003 users, <a href="https://support.microsoft.com/en-gb/help/4500705/customer-guidance-for-cve-2019-0708" target="_blank">will also receive a special fix due to the severity of this issue</a>. But the firm has advised all its users who haven't yet upgraded to Windows 10 to do so as soon as possible as this is "the best way to address this vulnerability".</p><p>"It is highly likely that this vulnerability will be exploited in the wild in the near future as attackers develop exploit code," said senior research engineer with Tenable Satnam Narang.</p><p>"It is critically important for organisations and system administrators to apply patches as soon as possible to reduce their risk of compromise."</p><p>The WannaCry ransomware epidemic affected countless machines across the world, and in the UK became known for its devastating effects in the NHS. Research published in October <a href="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates" target="_blank" data-original-url="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates">estimated the cost to the health service was 92 million</a> and was primarily allowed to spread due to unpatched Windows XP and Windows 7 machines.</p><p>Although Windows 7 systems are to be taken out of Microsoft's support cycle by January 2020, the market share for this operating system <a href="https://www.itpro.com/microsoft-windows/33368/windows-7-market-share-finally-declines-ahead-of-january-2020-end-of-life" target="_blank" data-original-url="https://www.itpro.com/microsoft-windows/33368/windows-7-market-share-finally-declines-ahead-of-january-2020-end-of-life">only began its terminal decline as recently as April</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FOI reveals NHS Trusts spend as little as £250 on cyber security ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The NHS is struggling to retain critical cyber security expertise and expenditure is being allocated erratically, with some Trusts spending as little as 250 in the last year, it has emerged.</p><p>Despite the Department for Health and Social Care (DHSC) having committed an additional 150 million on NHS cyber security a year after the WannaCry attack, <a href="https://www.redscan.com/news/nhs-cybersecurity-skills-survey" target="_blank">research by Redscan</a> has exposed a prominent gap in both funding and staffing.</p><p>The average spend on data security training across 159 Trusts surveyed was 5,356 in the last 12 months, but this ranged widely from between 238 and 78,000 with no correlation to the size of Trust, or its location.</p><p>For a mid-sized Trust of between 3,000 and 4,000 employees, for example, training spend ranged from 500 to 33,000. But the research also notes a significant amount of training was conducted in-house using NHS Digital resources.</p><p>GDPR training was the most common programme taken up, with other prominent courses including BCS Practioner Certificate in Data Protection, and Senior Information Risk Owner.</p><p>However, it was found that NHS Trusts have only employed an average of one qualified security professional per 2,582 staff.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry" data-original-url="/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry">Why we’re ignoring the real lesson of WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" data-original-url="/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">One year after WannaCry, zero NHS trusts pass cyber security assessment</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-security/31423/nhs-asks-ibm-to-boost-its-cyber-security-defences-after-wannacry" data-original-url="/cyber-security/31423/nhs-asks-ibm-to-boost-its-cyber-security-defences-after-wannacry">NHS asks IBM to boost its cyber security defences after WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-security/31554/uk-government-lacks-urgency-in-tackling-cyber-security-skills-gap" data-original-url="/cyber-security/31554/uk-government-lacks-urgency-in-tackling-cyber-security-skills-gap">UK government 'lacks urgency' in tackling cyber security skills gap</a></p></div></div><p>Alarmingly, almost a quarter of Trusts, 24 out of 108, retain no staff with security qualifications despite some employing around 16,000 full-time and part-time workers. A handful of Trusts also reported having employees in the process of obtaining security qualifications.</p><p>"These findings shine a light on the cyber security failings of the NHS, which is struggling to implement a cohesive security strategy under difficult circumstances," said Redscan's director of cyber security Mark Nicholls.</p><p>"Individual trusts lack in-house cybersecurity talent and many are falling short of training targets; while investment in security and data protection training is patchy at best. The extent of discrepancies is alarming, as some NHS organisations are far better resourced, funded and trained than others."</p><p>The findings, released following a Freedom of Information (FOI) campaign which saw responses from 159 NHS Trusts, have been released a year-and-a-half after the devastating <a href="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates" target="_blank" data-original-url="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates">WannaCry attack that DHSC estimated to cost 92 million</a>.</p><p>Several parliamentary reports have since savaged the NHS' record on cyber security resilience, with among the latest in April showing <a href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" target="_blank" data-original-url="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">zero Trusts passed the government's cyber security assessments</a>.</p><p>A separate FOI request Redscan sent to NHS Digital revealed signs of improvement, as 139 Trusts had now undertaken a Data Security Onsite Assessment, compared to just 60 Trusts last year.</p><p>Beyond announcing an additional 150 million over the next three years, the DHSC also committed to <a href="https://www.itpro.com/wannacry/31020/nhs-aims-to-solve-cyber-security-issues-with-windows-10-migration-by-2020-deadline" target="_blank" data-original-url="https://www.itpro.com/wannacry/31020/nhs-aims-to-solve-cyber-security-issues-with-windows-10-migration-by-2020-deadline">upgrading all Windows XP devices to Windows 10 by 2020</a> in a deal struck with Microsoft earlier this year.</p><p>"Cyber security is a priority for this government and funding is provided to NHS Trusts based on their specific needs and capabilities," a DHSC spokesperson told <em>IT Pro</em>.</p><p>"Over 60m was invested last year for critical infrastructure, and there will be a further 150m over the next three to improve resilience across the health and care system.</p><p>"Where Trusts do not take sufficient action to secure their networks and systems, we will use strong enforcement powers to ensure they improve."</p><p>Redscan's Nicholls added that as the skills gap continues to grow, it'll become harder for organisations across all sectors to find the people with the right knowledge and expertise.</p><p>"It's even tougher for the NHS, which must compete with the private sector's bumper wages," he continued, "not to mention the fact that trusts outside of traditional tech hubs like London and Cambridge have a smaller talent pool from which to choose from."</p><p>Kaspersky's principal security researcher David Emm told <em>IT Pro</em> that given how very attractive health data is to criminals, it is vital the NHS invests money in robust protections.</p><p>"Healthcare providers must also work closely with their IT security teams to implement sophisticated, high-quality protection that will allow them to manage and protect customer data," he said.</p><p>"Not just for the sake of tick-box' compliance, or to avoid hefty fines and embarrassing, often irreparable reputational damage, but to enable them and their patients to reap the many rewards of advanced digital healthcare, confident in the knowledge that data, devices and networks are secure."</p><p><em>IT Pro</em> also approached NHS Digital, NHS England and NHS Improvement for comment.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/wannacry/32547/foi-reveals-nhs-trusts-spend-as-little-as-250-on-cyber-security</link>
                                                                            <description>
                            <![CDATA[ 'Alarming' spend and expertise discrepancies exposed as DHSC threatens enforcement action ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oJ3p2Mu2MpX9NPdkPyPBCK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mds3gPMjrWMfM9saHMdukW-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Dec 2018 10:43:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mds3gPMjrWMfM9saHMdukW-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mds3gPMjrWMfM9saHMdukW-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The NHS is struggling to retain critical cyber security expertise and expenditure is being allocated erratically, with some Trusts spending as little as 250 in the last year, it has emerged.</p><p>Despite the Department for Health and Social Care (DHSC) having committed an additional 150 million on NHS cyber security a year after the WannaCry attack, <a href="https://www.redscan.com/news/nhs-cybersecurity-skills-survey" target="_blank">research by Redscan</a> has exposed a prominent gap in both funding and staffing.</p><p>The average spend on data security training across 159 Trusts surveyed was 5,356 in the last 12 months, but this ranged widely from between 238 and 78,000 with no correlation to the size of Trust, or its location.</p><p>For a mid-sized Trust of between 3,000 and 4,000 employees, for example, training spend ranged from 500 to 33,000. But the research also notes a significant amount of training was conducted in-house using NHS Digital resources.</p><p>GDPR training was the most common programme taken up, with other prominent courses including BCS Practioner Certificate in Data Protection, and Senior Information Risk Owner.</p><p>However, it was found that NHS Trusts have only employed an average of one qualified security professional per 2,582 staff.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry" data-original-url="/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry">Why we’re ignoring the real lesson of WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" data-original-url="/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">One year after WannaCry, zero NHS trusts pass cyber security assessment</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-security/31423/nhs-asks-ibm-to-boost-its-cyber-security-defences-after-wannacry" data-original-url="/cyber-security/31423/nhs-asks-ibm-to-boost-its-cyber-security-defences-after-wannacry">NHS asks IBM to boost its cyber security defences after WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-security/31554/uk-government-lacks-urgency-in-tackling-cyber-security-skills-gap" data-original-url="/cyber-security/31554/uk-government-lacks-urgency-in-tackling-cyber-security-skills-gap">UK government 'lacks urgency' in tackling cyber security skills gap</a></p></div></div><p>Alarmingly, almost a quarter of Trusts, 24 out of 108, retain no staff with security qualifications despite some employing around 16,000 full-time and part-time workers. A handful of Trusts also reported having employees in the process of obtaining security qualifications.</p><p>"These findings shine a light on the cyber security failings of the NHS, which is struggling to implement a cohesive security strategy under difficult circumstances," said Redscan's director of cyber security Mark Nicholls.</p><p>"Individual trusts lack in-house cybersecurity talent and many are falling short of training targets; while investment in security and data protection training is patchy at best. The extent of discrepancies is alarming, as some NHS organisations are far better resourced, funded and trained than others."</p><p>The findings, released following a Freedom of Information (FOI) campaign which saw responses from 159 NHS Trusts, have been released a year-and-a-half after the devastating <a href="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates" target="_blank" data-original-url="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates">WannaCry attack that DHSC estimated to cost 92 million</a>.</p><p>Several parliamentary reports have since savaged the NHS' record on cyber security resilience, with among the latest in April showing <a href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" target="_blank" data-original-url="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">zero Trusts passed the government's cyber security assessments</a>.</p><p>A separate FOI request Redscan sent to NHS Digital revealed signs of improvement, as 139 Trusts had now undertaken a Data Security Onsite Assessment, compared to just 60 Trusts last year.</p><p>Beyond announcing an additional 150 million over the next three years, the DHSC also committed to <a href="https://www.itpro.com/wannacry/31020/nhs-aims-to-solve-cyber-security-issues-with-windows-10-migration-by-2020-deadline" target="_blank" data-original-url="https://www.itpro.com/wannacry/31020/nhs-aims-to-solve-cyber-security-issues-with-windows-10-migration-by-2020-deadline">upgrading all Windows XP devices to Windows 10 by 2020</a> in a deal struck with Microsoft earlier this year.</p><p>"Cyber security is a priority for this government and funding is provided to NHS Trusts based on their specific needs and capabilities," a DHSC spokesperson told <em>IT Pro</em>.</p><p>"Over 60m was invested last year for critical infrastructure, and there will be a further 150m over the next three to improve resilience across the health and care system.</p><p>"Where Trusts do not take sufficient action to secure their networks and systems, we will use strong enforcement powers to ensure they improve."</p><p>Redscan's Nicholls added that as the skills gap continues to grow, it'll become harder for organisations across all sectors to find the people with the right knowledge and expertise.</p><p>"It's even tougher for the NHS, which must compete with the private sector's bumper wages," he continued, "not to mention the fact that trusts outside of traditional tech hubs like London and Cambridge have a smaller talent pool from which to choose from."</p><p>Kaspersky's principal security researcher David Emm told <em>IT Pro</em> that given how very attractive health data is to criminals, it is vital the NHS invests money in robust protections.</p><p>"Healthcare providers must also work closely with their IT security teams to implement sophisticated, high-quality protection that will allow them to manage and protect customer data," he said.</p><p>"Not just for the sake of tick-box' compliance, or to avoid hefty fines and embarrassing, often irreparable reputational damage, but to enable them and their patients to reap the many rewards of advanced digital healthcare, confident in the knowledge that data, devices and networks are secure."</p><p><em>IT Pro</em> also approached NHS Digital, NHS England and NHS Improvement for comment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ It's now "impossible" to protect critical UK infrastructure from cyber attack ]]></title>
                                                                                                <dc:content><![CDATA[ <p>MPs and Lords have warned it's "impossible" to completely protect the UK's infrastructure from a WannaCry-scale cyber attack, with mitigation quickly-becoming a new normal'.</p><p>Several factors stand in the way of fully securing the UK's critical national infrastructure (CNI), including an increasingly complex security landscape, and the government's failure to define what it considers to be critical, according to the Joint Committee on the National Security Strategy (JCNSS).</p><p>In a report assessing the scale of threat the UK faces, the Parliamentary committee also said laws stemming from EU-wide regulations have been useful, but do not go far enough.</p><p>"'Critical' national infrastructure is, by definition, a priority for the Government and industry. However, as the economy becomes more interconnected, it is increasingly difficult to determine which elements are truly critical," the <a href="https://publications.parliament.uk/pa/jt201719/jtselect/jtnatsec/1708/170809.htm#_idTextAnchor063" target="_blank">JCNSS report said</a>.</p><p>"Fast-changing threats and the rapid emergence of new vulnerabilities make it impossible to secure CNI networks and systems completely.</p><p>"Continually updated plans for improving CNI defences and reducing the potential impact of attacks must therefore be the 'new normal' if the Government and operators are to be agile in responding to this changing environment and in taking advantage of constant technological innovation."</p><p>The committee raised concerns that the expectations for the National Cyber Security Centre (NCSC), formed to provide cyber training and leadership for UK organisations, is outrstripping its resources.</p><p>NHS Digital deputy chief executive Rob Shaw revealed in evidence that he had expected an "army" of experts to support the NHS through 2017's WannaCry attack, but soon learned the NCSC lacked staffing to help out on the ground.</p><p>JCNSS said it had concerns about the NCSC's capacity to meet growing demand for services and expertise, and that its effectiveness will be limited in future unless it can recruit at the appropriate scale.</p><p>The government must also publish a ten-year plan for the institutional development of the NCSC, setting out the resources and staffing levels it expects the organisation to need.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/national-cyber-security-centre-ncsc/31903/ncsc-challenges-business-leaders-to-learn-the-basics-of" data-original-url="/national-cyber-security-centre-ncsc/31903/ncsc-challenges-business-leaders-to-learn-the-basics-of">NCSC challenges business leaders to learn the 'basics' of cyber security</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry" data-original-url="/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry">Why we’re ignoring the real lesson of WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" data-original-url="/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">One year after WannaCry, zero NHS trusts pass cyber security assessment</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-security/31554/uk-government-lacks-urgency-in-tackling-cyber-security-skills-gap" data-original-url="/cyber-security/31554/uk-government-lacks-urgency-in-tackling-cyber-security-skills-gap">UK government 'lacks urgency' in tackling cyber security skills gap</a></p></div></div><p>The committee made several further recommendations for the government and for businesses, including instigating a cultural change among CNI-linked organisations, and for politicians and ministers to take initiative in making cyber resilience a priority.</p><p>Private sector companies overseeing CNI, as well as firms comprising the supply chain, should consider cyber security as another business risk, and proactively manage threats. This is especially true where "commercial interests may not always align with the demands of national security".</p><p>Moreover, the government needs to appoint a cabinet office minister charged with overseeing the resilience of CNI, instead of patchwork of multi-ministerial oversight that exists currently.</p><p>Under the current structure, each department would have a different approach to overseeing cyber security in its constituent sectors, with occasional overlap.</p><p>A more focused and proactive leadership from central government is needed to ensure cyber security is handled in a more consistent way, the report continued, and blasted the status quo of ministers only occasionally checking-in as "wholly inadequate".</p><p>"It's vital that that short-term memories and political distractions such as Brexit do not derail focus from these important initiatives," said Mimecast's cyber resilience expert Pete Banham</p><p>"Private sector businesses today need a risk and security champion in the boardroom; likewise, it's time Government had a cyber tsar in the Cabinet.</p><p>"Minimising the impact of attacks should be top priority as a defence-only strategy is doomed to fail. This should include regular fire drills' for all employees to respond to and recover to cyber-attacks.</p><p>"We've seen a growing number of CNI organisations, including the NHS, make determined moves to adopt more resilient postures in the last two years. WannaCry helped focus attention and budget allocation but still more needs to be done."</p><p>Stuart McKenzie, FireEye's vice president for EMEA, meanwhile warned much of the technology used within CNI remains fragile and relies on outdated standards of security.</p><p>"The threats facing CNI have constantly evolved, meaning that today's threat is something that wasn't imaginable when many of the systems were originally designed, leaving them increasingly vulnerable," he said.</p><p>"These are not quick problems to solve, but they are not insolvable. We would recommend that CNI organisations conduct a mapping exercise to understand their exposure and risk and put in place some controls to protect the most critical threats.</p><p>"With breaches becoming inevitable, organisations need to not only to set defences and identify attacks, but crucially to have a really clear understanding of what to do in the event of a breach - every organisation needs to have a really clear incident response plan that's well tested and regularly rehearsed."</p><p>Mandatory policy decisions should also be implemented, the report recommended, including a plan to roll-out penetration-testing for CNI-linked organisations, and continued membership in key EU groups and information-sharing schemes following Brexit.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/cyber-attacks/32391/its-now-impossible-to-protect-critical-uk-infrastructure-from-cyber-attack</link>
                                                                            <description>
                            <![CDATA[ Parliamentary committee warns that mitigating the effects of successful attacks is becoming a 'new normal' ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">erGv7mELTofG61f7Uf33g3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nTJvtqYKvzWnsYGW5W7rTW-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 19 Nov 2018 10:39:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nTJvtqYKvzWnsYGW5W7rTW-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Image of construction workers representing UK infrastructure]]></media:description>                                                            <media:text><![CDATA[Image of construction workers representing UK infrastructure]]></media:text>
                                <media:title type="plain"><![CDATA[Image of construction workers representing UK infrastructure]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nTJvtqYKvzWnsYGW5W7rTW-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>MPs and Lords have warned it's "impossible" to completely protect the UK's infrastructure from a WannaCry-scale cyber attack, with mitigation quickly-becoming a new normal'.</p><p>Several factors stand in the way of fully securing the UK's critical national infrastructure (CNI), including an increasingly complex security landscape, and the government's failure to define what it considers to be critical, according to the Joint Committee on the National Security Strategy (JCNSS).</p><p>In a report assessing the scale of threat the UK faces, the Parliamentary committee also said laws stemming from EU-wide regulations have been useful, but do not go far enough.</p><p>"'Critical' national infrastructure is, by definition, a priority for the Government and industry. However, as the economy becomes more interconnected, it is increasingly difficult to determine which elements are truly critical," the <a href="https://publications.parliament.uk/pa/jt201719/jtselect/jtnatsec/1708/170809.htm#_idTextAnchor063" target="_blank">JCNSS report said</a>.</p><p>"Fast-changing threats and the rapid emergence of new vulnerabilities make it impossible to secure CNI networks and systems completely.</p><p>"Continually updated plans for improving CNI defences and reducing the potential impact of attacks must therefore be the 'new normal' if the Government and operators are to be agile in responding to this changing environment and in taking advantage of constant technological innovation."</p><p>The committee raised concerns that the expectations for the National Cyber Security Centre (NCSC), formed to provide cyber training and leadership for UK organisations, is outrstripping its resources.</p><p>NHS Digital deputy chief executive Rob Shaw revealed in evidence that he had expected an "army" of experts to support the NHS through 2017's WannaCry attack, but soon learned the NCSC lacked staffing to help out on the ground.</p><p>JCNSS said it had concerns about the NCSC's capacity to meet growing demand for services and expertise, and that its effectiveness will be limited in future unless it can recruit at the appropriate scale.</p><p>The government must also publish a ten-year plan for the institutional development of the NCSC, setting out the resources and staffing levels it expects the organisation to need.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/national-cyber-security-centre-ncsc/31903/ncsc-challenges-business-leaders-to-learn-the-basics-of" data-original-url="/national-cyber-security-centre-ncsc/31903/ncsc-challenges-business-leaders-to-learn-the-basics-of">NCSC challenges business leaders to learn the 'basics' of cyber security</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry" data-original-url="/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry">Why we’re ignoring the real lesson of WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" data-original-url="/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">One year after WannaCry, zero NHS trusts pass cyber security assessment</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-security/31554/uk-government-lacks-urgency-in-tackling-cyber-security-skills-gap" data-original-url="/cyber-security/31554/uk-government-lacks-urgency-in-tackling-cyber-security-skills-gap">UK government 'lacks urgency' in tackling cyber security skills gap</a></p></div></div><p>The committee made several further recommendations for the government and for businesses, including instigating a cultural change among CNI-linked organisations, and for politicians and ministers to take initiative in making cyber resilience a priority.</p><p>Private sector companies overseeing CNI, as well as firms comprising the supply chain, should consider cyber security as another business risk, and proactively manage threats. This is especially true where "commercial interests may not always align with the demands of national security".</p><p>Moreover, the government needs to appoint a cabinet office minister charged with overseeing the resilience of CNI, instead of patchwork of multi-ministerial oversight that exists currently.</p><p>Under the current structure, each department would have a different approach to overseeing cyber security in its constituent sectors, with occasional overlap.</p><p>A more focused and proactive leadership from central government is needed to ensure cyber security is handled in a more consistent way, the report continued, and blasted the status quo of ministers only occasionally checking-in as "wholly inadequate".</p><p>"It's vital that that short-term memories and political distractions such as Brexit do not derail focus from these important initiatives," said Mimecast's cyber resilience expert Pete Banham</p><p>"Private sector businesses today need a risk and security champion in the boardroom; likewise, it's time Government had a cyber tsar in the Cabinet.</p><p>"Minimising the impact of attacks should be top priority as a defence-only strategy is doomed to fail. This should include regular fire drills' for all employees to respond to and recover to cyber-attacks.</p><p>"We've seen a growing number of CNI organisations, including the NHS, make determined moves to adopt more resilient postures in the last two years. WannaCry helped focus attention and budget allocation but still more needs to be done."</p><p>Stuart McKenzie, FireEye's vice president for EMEA, meanwhile warned much of the technology used within CNI remains fragile and relies on outdated standards of security.</p><p>"The threats facing CNI have constantly evolved, meaning that today's threat is something that wasn't imaginable when many of the systems were originally designed, leaving them increasingly vulnerable," he said.</p><p>"These are not quick problems to solve, but they are not insolvable. We would recommend that CNI organisations conduct a mapping exercise to understand their exposure and risk and put in place some controls to protect the most critical threats.</p><p>"With breaches becoming inevitable, organisations need to not only to set defences and identify attacks, but crucially to have a really clear understanding of what to do in the event of a breach - every organisation needs to have a really clear incident response plan that's well tested and regularly rehearsed."</p><p>Mandatory policy decisions should also be implemented, the report recommended, including a plan to roll-out penetration-testing for CNI-linked organisations, and continued membership in key EU groups and information-sharing schemes following Brexit.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Lazarus hackers engage in ‘FASTCash’ scheme to steal tens of millions of dollars from ATMs ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The North Korean hacking group behind the WannaCry ransomware attack that crippled the NHS has been stealing money from ATMs since at least 2016.</p><p>Cyber crime and espionage outfit Lazarus has gained a reputation for disruptive and politically-motivated attacks. But researchers have found evidence that reinforces claims the group has increasingly gravitated towards financial crime in recent years.</p><p>The group has been fraudulently emptying ATMs across Asia and Africa in an operation dubbed "FASTCash", according to Symantec, by breaching banks' networks, and injecting a malware into switch application servers that handle transactions.</p><p>The '<a href="https://www.symantec.com/security-center/writeup/2018-110615-2942-99" target="_blank">Trojan.Fastcash</a>' malware, previously unknown to security researchers, intercepts fraudulent Lazarus cash withdrawal requests and sends fake approval responses, which in turn allows the attackers to steal cash from ATMs.</p><p>The attacks have so far been confined to Africa and Asia, and directed at the financial sector, but that's not to say Lazarus won't target the UK at some future data, according to security threat researcher at Symantec Dick O'Brien.</p><p>"Lazarus has, since 2016, diversified into financially motivated attacks. It began first by directly attacking banks, such as the Bangladesh bank heist, which netted it $81 million," O'Brien told <em>IT Pro</em>.</p><p>"We don't know for sure why they've shifted to ATM attacks, but it's likely that most banks became wise to the tactics they used in 2016 bank heists and beefed up their security, prompting Lazarus to find an alternative means of attack, another weak point."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/31095/one-year-on-from-wannacry-and-uk-firms-are-exposed-to-cyber-threats-more-than-ever" data-original-url="/security/31095/one-year-on-from-wannacry-and-uk-firms-are-exposed-to-cyber-threats-more-than-ever">One year on from WannaCry and UK firms are exposed to cyber threats more than ever</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry" data-original-url="/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry">Why we’re ignoring the real lesson of WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/30526/mcafee-uncovers-aggressive-bitcoin-stealing-phishing-campaign-by-the-lazarus-cyber" data-original-url="/security/30526/mcafee-uncovers-aggressive-bitcoin-stealing-phishing-campaign-by-the-lazarus-cyber">McAfee uncovers 'aggressive' Bitcoin-stealing phishing campaign by the Lazarus cyber crooks</a></p></div></div><p>One incident in 2017 saw cash withdrawn simultaneously from ATMs in over 30 different countries, according to an official <a href="https://www.us-cert.gov/ncas/alerts/TA18-275A" target="_blank">US government alert issued earlier this month</a>. Another major incident this year saw cash taken from 23 countries simultaneously, with the total FASTCash haul estimated at tens of millions of dollars.</p><p>In order to carry out a successful attack, the hackers first inject their malware into banking application servers running unsupported versions of the AIX operating system. This allows Lazarus to intercept fraudulent transaction requests, prevent them from reaching the switch application that processes transactions, as well as generate fake approvals.</p><p>"The recent wave of FASTCash attacks demonstrates that financially motivated attacks are not simply a passing interest for the Lazarus group and can now be considered one of its core activities," Symantec's security response attack investigation team said.</p><p>"As with the 2016 series of virtual bank heists, including the Bangladesh Bank heist, FASTCash illustrates that Lazarus possesses an in-depth knowledge of banking systems and transaction processing protocols and has the expertise to leverage that knowledge in order to steal large sums from vulnerable banks."</p><p>Alongside disruptive operations such as the <a href="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack" target="_blank" data-original-url="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack">Sony Pictures hack</a>, and malware that struck the <a href="https://www.itpro.com/hacking/30510/kaspersky-north-korea-framed-for-winter-olympics-malware" target="_blank" data-original-url="https://www.itpro.com/hacking/30510/kaspersky-north-korea-framed-for-winter-olympics-malware">Winter Olympics</a>, Lazarus has often engaged in financially-motivated crime in recent years; most infamously the WannaCry ransomware attack.</p><p>The Department for Health and Social Care (DHSC) last month estimated the crippling attack cost the health service 92 million, with the vast majority of this sum spent on restoring services and recovering data.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/cyber-crime/32331/lazarus-hackers-engage-in-fastcash-scheme-to-steal-tens-of-millions-of-dollars</link>
                                                                            <description>
                            <![CDATA[ The notorious hackers have been striking ATMs since 2016 in a pivot from disruptive attacks such as WannaCry ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iVSB4vVPiUQdGfFC2h6uyg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NgpRy4A37BEXXARCnHEAvL-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 09 Nov 2018 11:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NgpRy4A37BEXXARCnHEAvL-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Person entering their PIN number into an ATM machine]]></media:description>                                                            <media:text><![CDATA[Person entering their PIN number into an ATM machine]]></media:text>
                                <media:title type="plain"><![CDATA[Person entering their PIN number into an ATM machine]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NgpRy4A37BEXXARCnHEAvL-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The North Korean hacking group behind the WannaCry ransomware attack that crippled the NHS has been stealing money from ATMs since at least 2016.</p><p>Cyber crime and espionage outfit Lazarus has gained a reputation for disruptive and politically-motivated attacks. But researchers have found evidence that reinforces claims the group has increasingly gravitated towards financial crime in recent years.</p><p>The group has been fraudulently emptying ATMs across Asia and Africa in an operation dubbed "FASTCash", according to Symantec, by breaching banks' networks, and injecting a malware into switch application servers that handle transactions.</p><p>The '<a href="https://www.symantec.com/security-center/writeup/2018-110615-2942-99" target="_blank">Trojan.Fastcash</a>' malware, previously unknown to security researchers, intercepts fraudulent Lazarus cash withdrawal requests and sends fake approval responses, which in turn allows the attackers to steal cash from ATMs.</p><p>The attacks have so far been confined to Africa and Asia, and directed at the financial sector, but that's not to say Lazarus won't target the UK at some future data, according to security threat researcher at Symantec Dick O'Brien.</p><p>"Lazarus has, since 2016, diversified into financially motivated attacks. It began first by directly attacking banks, such as the Bangladesh bank heist, which netted it $81 million," O'Brien told <em>IT Pro</em>.</p><p>"We don't know for sure why they've shifted to ATM attacks, but it's likely that most banks became wise to the tactics they used in 2016 bank heists and beefed up their security, prompting Lazarus to find an alternative means of attack, another weak point."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/31095/one-year-on-from-wannacry-and-uk-firms-are-exposed-to-cyber-threats-more-than-ever" data-original-url="/security/31095/one-year-on-from-wannacry-and-uk-firms-are-exposed-to-cyber-threats-more-than-ever">One year on from WannaCry and UK firms are exposed to cyber threats more than ever</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry" data-original-url="/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry">Why we’re ignoring the real lesson of WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/30526/mcafee-uncovers-aggressive-bitcoin-stealing-phishing-campaign-by-the-lazarus-cyber" data-original-url="/security/30526/mcafee-uncovers-aggressive-bitcoin-stealing-phishing-campaign-by-the-lazarus-cyber">McAfee uncovers 'aggressive' Bitcoin-stealing phishing campaign by the Lazarus cyber crooks</a></p></div></div><p>One incident in 2017 saw cash withdrawn simultaneously from ATMs in over 30 different countries, according to an official <a href="https://www.us-cert.gov/ncas/alerts/TA18-275A" target="_blank">US government alert issued earlier this month</a>. Another major incident this year saw cash taken from 23 countries simultaneously, with the total FASTCash haul estimated at tens of millions of dollars.</p><p>In order to carry out a successful attack, the hackers first inject their malware into banking application servers running unsupported versions of the AIX operating system. This allows Lazarus to intercept fraudulent transaction requests, prevent them from reaching the switch application that processes transactions, as well as generate fake approvals.</p><p>"The recent wave of FASTCash attacks demonstrates that financially motivated attacks are not simply a passing interest for the Lazarus group and can now be considered one of its core activities," Symantec's security response attack investigation team said.</p><p>"As with the 2016 series of virtual bank heists, including the Bangladesh Bank heist, FASTCash illustrates that Lazarus possesses an in-depth knowledge of banking systems and transaction processing protocols and has the expertise to leverage that knowledge in order to steal large sums from vulnerable banks."</p><p>Alongside disruptive operations such as the <a href="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack" target="_blank" data-original-url="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack">Sony Pictures hack</a>, and malware that struck the <a href="https://www.itpro.com/hacking/30510/kaspersky-north-korea-framed-for-winter-olympics-malware" target="_blank" data-original-url="https://www.itpro.com/hacking/30510/kaspersky-north-korea-framed-for-winter-olympics-malware">Winter Olympics</a>, Lazarus has often engaged in financially-motivated crime in recent years; most infamously the WannaCry ransomware attack.</p><p>The Department for Health and Social Care (DHSC) last month estimated the crippling attack cost the health service 92 million, with the vast majority of this sum spent on restoring services and recovering data.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WannaCry cost the NHS £92 million, report estimates ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The Department of Health and Social Care has estimated that the <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">WannaCry</a> ransomware attack cost the NHS a total of 92 million, as part of an update into its ongoing investigation of the incident.</p><p>Until now the NHS has failed to provide an exact figure on the damage sustained during the ransomware attack in May 2017, and the DHSC admits that the <a href="https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/747464/securing-cyber-resilience-in-health-and-care-september-2018-update.pdf" target="_blank">figures presented on Thursday</a> are a "broad estimate" covering the time during and immediately after the attack.</p><p>During the attack, in the period of 12 May to 18 May, it's estimated that around 19 million was lost in terms of patient care output, based on the findings that 1% of NHS services were disrupted over a one-week period. In addition to the lost services, it's believed a further 500,000 was spent on dealing with the immediate effects of the IT failure, including the hiring of additional consultants.</p><p>The biggest costs came in the June-July period immediately following WannaCry, which is estimated to have cost a further 72 million as the NHS worked to restore its services to full operation and to recover its data.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry" data-original-url="/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry">Why we’re ignoring the real lesson of WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" data-original-url="/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">One year after WannaCry, zero NHS trusts pass cyber security assessment</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a></p></div></div><p>The WannaCry <a href="https://www.itpro.com/security/28084/what-is-ransomware" target="_blank" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> attack, which is thought to have affected over 200,000 computer systems across the world, disrupted the services of one-third of the UK's hospital trusts, and approximately 8% of GP clinics. It's believed that around 19,000 hospital appointments were cancelled as a result.</p><p>Afflicted systems locked out their users and held hospital data to ransom, demanding a payment in the form of the <a href="https://www.itpro.com/strategy/28296/what-is-bitcoin" target="_blank" data-original-url="https://www.itpro.com/strategy/28296/what-is-bitcoin">Bitcoin</a> cryptocurrency. The ransomware also had self-propagating characteristics and was able to spread through a system automatically. The ease at which the ransomware spread has been blamed on an overreliance on outdated operating systems, including <a href="https://www.itpro.com/microsoft-windows/32086/how-to-securely-run-windows-xp-software" target="_blank" data-original-url="https://www.itpro.com/microsoft-windows/32086/how-to-securely-run-windows-xp-software">Microsoft's Windows XP</a>.</p><p>The DHSC says this is the best estimate it can provide at this time, as there has yet to be a systematic collection of data on the costs of recovering IT systems. "At the time, the focus nationally was on responding to the incident and remediation rather than collecting data, which would make an accurate retrospective data collection challenging," the report states.</p><p>Unfortunately, this is unlikely to happen any time soon, as attempts to gather such data would place a "disproportionate financial burden on the system".</p><p>The estimated losses come as part of an update to an earlier report released in February. Since that time, the DHSC has signed a deal with Microsoft to ease its migration from legacy operating systems to the Windows 10 platform.</p><p>It's also pledged to invest an additional 150 million into the system over the next three years, which will be used to protect key services from the effects of cyber attacks. This also includes further investment into the NHS Digital's Cyber Security Operations Centre, founded in November last year, which works to monitor the security of health services at a national level and provide advice to individual NHS organisations.</p><p>This means that over 250 million will have been invested to improve the security of the NHS by 2021.</p><p>"When ransomware hits an organization, much is discussed about the cost in terms of rebuilding infrastructure, restoring digital records and getting systems back online," said Matt Lock, director of sales engineers at Varonis.</p><p>"In the case of the NHS, we may never truly know or be able to quantify the ultimate cost of the WannaCry attack because human lives may have been affected by a delayed ambulance or incorrect treatment."</p><p>As part of the report, the CIO for NHS health and care has put forward 22 recommendations, which have now been agreed upon and will be rolled out over the coming years. These include a provision that forces all NHS organisations to adhere to the Cyber Essentials Plus Standard, a framework established by the UK's National Cyber Security Centre (NCSC).</p><p>All NHS organisations have also been given until 31 March 2019 to submit a record of compliance to NHS Digital under the Data Security and Protection Toolkit, which acts as a national framework for the data security and protection in healthcare in the UK and incorporates the key legal requirements set out by the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">General Data Protection Regulations (GDPR)</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates</link>
                                                                            <description>
                            <![CDATA[ An update to an earlier DHSC report estimates that £19 million was lost in patient care alone ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wcAjr4ggFuGxcpA8qdgeUd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PybWHukLGSRddY5VMGgMAb-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 Oct 2018 16:14:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PybWHukLGSRddY5VMGgMAb-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The NHS fell victim to the WannaCry ransomware in 2017]]></media:description>                                                            <media:text><![CDATA[The NHS fell victim to the WannaCry ransomware in 2017]]></media:text>
                                <media:title type="plain"><![CDATA[The NHS fell victim to the WannaCry ransomware in 2017]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PybWHukLGSRddY5VMGgMAb-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Department of Health and Social Care has estimated that the <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">WannaCry</a> ransomware attack cost the NHS a total of 92 million, as part of an update into its ongoing investigation of the incident.</p><p>Until now the NHS has failed to provide an exact figure on the damage sustained during the ransomware attack in May 2017, and the DHSC admits that the <a href="https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/747464/securing-cyber-resilience-in-health-and-care-september-2018-update.pdf" target="_blank">figures presented on Thursday</a> are a "broad estimate" covering the time during and immediately after the attack.</p><p>During the attack, in the period of 12 May to 18 May, it's estimated that around 19 million was lost in terms of patient care output, based on the findings that 1% of NHS services were disrupted over a one-week period. In addition to the lost services, it's believed a further 500,000 was spent on dealing with the immediate effects of the IT failure, including the hiring of additional consultants.</p><p>The biggest costs came in the June-July period immediately following WannaCry, which is estimated to have cost a further 72 million as the NHS worked to restore its services to full operation and to recover its data.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry" data-original-url="/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry">Why we’re ignoring the real lesson of WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" data-original-url="/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">One year after WannaCry, zero NHS trusts pass cyber security assessment</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a></p></div></div><p>The WannaCry <a href="https://www.itpro.com/security/28084/what-is-ransomware" target="_blank" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> attack, which is thought to have affected over 200,000 computer systems across the world, disrupted the services of one-third of the UK's hospital trusts, and approximately 8% of GP clinics. It's believed that around 19,000 hospital appointments were cancelled as a result.</p><p>Afflicted systems locked out their users and held hospital data to ransom, demanding a payment in the form of the <a href="https://www.itpro.com/strategy/28296/what-is-bitcoin" target="_blank" data-original-url="https://www.itpro.com/strategy/28296/what-is-bitcoin">Bitcoin</a> cryptocurrency. The ransomware also had self-propagating characteristics and was able to spread through a system automatically. The ease at which the ransomware spread has been blamed on an overreliance on outdated operating systems, including <a href="https://www.itpro.com/microsoft-windows/32086/how-to-securely-run-windows-xp-software" target="_blank" data-original-url="https://www.itpro.com/microsoft-windows/32086/how-to-securely-run-windows-xp-software">Microsoft's Windows XP</a>.</p><p>The DHSC says this is the best estimate it can provide at this time, as there has yet to be a systematic collection of data on the costs of recovering IT systems. "At the time, the focus nationally was on responding to the incident and remediation rather than collecting data, which would make an accurate retrospective data collection challenging," the report states.</p><p>Unfortunately, this is unlikely to happen any time soon, as attempts to gather such data would place a "disproportionate financial burden on the system".</p><p>The estimated losses come as part of an update to an earlier report released in February. Since that time, the DHSC has signed a deal with Microsoft to ease its migration from legacy operating systems to the Windows 10 platform.</p><p>It's also pledged to invest an additional 150 million into the system over the next three years, which will be used to protect key services from the effects of cyber attacks. This also includes further investment into the NHS Digital's Cyber Security Operations Centre, founded in November last year, which works to monitor the security of health services at a national level and provide advice to individual NHS organisations.</p><p>This means that over 250 million will have been invested to improve the security of the NHS by 2021.</p><p>"When ransomware hits an organization, much is discussed about the cost in terms of rebuilding infrastructure, restoring digital records and getting systems back online," said Matt Lock, director of sales engineers at Varonis.</p><p>"In the case of the NHS, we may never truly know or be able to quantify the ultimate cost of the WannaCry attack because human lives may have been affected by a delayed ambulance or incorrect treatment."</p><p>As part of the report, the CIO for NHS health and care has put forward 22 recommendations, which have now been agreed upon and will be rolled out over the coming years. These include a provision that forces all NHS organisations to adhere to the Cyber Essentials Plus Standard, a framework established by the UK's National Cyber Security Centre (NCSC).</p><p>All NHS organisations have also been given until 31 March 2019 to submit a record of compliance to NHS Digital under the Data Security and Protection Toolkit, which acts as a national framework for the data security and protection in healthcare in the UK and incorporates the key legal requirements set out by the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">General Data Protection Regulations (GDPR)</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US charges North Korean hacker with WannaCry and Sony hack ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The US Department of Justice has formally charged a North Korean government hacker with a series of major cyber attacks, including <a href="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack" target="_blank" data-original-url="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack">the Sony Pictures hack</a>, the theft of $81 million from the Bangladesh Bank and the WannaCry ransomware.</p><p>The <a href="https://assets.documentcloud.org/documents/4834314/Read-the-DOJ-s-criminal-complaint-against-an.pdf" target="_blank">charges</a> have been filed against North Korean programmer Park Jin Hyok, who the US claims was working as part of a North Korean government-backed hacking operation known commonly as Lazarus Group.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30510/kaspersky-north-korea-framed-for-winter-olympics-malware" data-original-url="/hacking/30510/kaspersky-north-korea-framed-for-winter-olympics-malware">Kaspersky: North Korea framed for Winter Olympics malware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry" data-original-url="/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry">Why we’re ignoring the real lesson of WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/31527/how-russia-hacked-the-2016-election" data-original-url="/security/31527/how-russia-hacked-the-2016-election">How Russia hacked the 2016 election</a></p></div></div><p>Park, who was educated at a North Korean university, spent a number of years employed by Chosun Expo Joint Venture, a company that is used as a front by the North Korean government and is allegedly used to fund a government cyber espionage division known as 'Lab 110'.</p><p>Through an elaborate network of dummy email addresses and social media accounts, network infrastructure paths and IP addresses, investigators say they have managed to link Park and a number of unnamed co-conspirators to key hacks - most notably, the WannaCry ransomware that temporarily crippled the NHS and caused global chaos.</p><p>Park and his colleagues were also linked to the 2014 attack on Sony Pictures, which saw caches of internal emails - as well as whole unreleased films - leaked online in retaliation for the release of Seth Rogen and James Franco's film The Interview, which mocks North Korean 'Supreme Leader' Kim Jong Un.</p><p>"The scope and damage of the computer intrusions perpetrated [by Park and his allies] is virtually unparalleled," said FBI Special Agent Nathan Shields as part of a sworn affidavit. "The attacks and intrusions described...would have each required the efforts of a well-resourced team of persons working in concert, each performing different tasks.</p><p>"The technical evidence... shows that those attacks and intrusions were carried out by a group of persons with access to the same email and social media accounts, computer infrastructure, and source code. Tracing connections back through the operational infrastructure reveals numerous connections between Park, his true-name email and social media accounts and the operational accounts used to conduct the cyber attacks."</p><p>While both the UK and the US have publicly <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">blamed North Korea for unleashing WannaCry</a>, this marks the first time that the US government has formally charged an operative of the Democratic People's Republic of Korea for hacking. It follows similar charges which have been levelled at Russian, Iranian and Chinese hackers over the last few years.</p><p>While it has no bearing on his own legal battle, the news has been greeted warmly by <a href="https://www.itpro.com/security/31265/wannacry-hero-marcus-hutchins-faces-four-new-charges" target="_blank" data-original-url="https://www.itpro.com/security/31265/wannacry-hero-marcus-hutchins-faces-four-new-charges">British malware researcher Marcus Hutchins</a>. Hutchins was the one who discovered the 'kill-switch' that was built into WannaCry, effectively halting the malware's devastating spread.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1037866475426467840"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1037866475426467840"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Although the US government has not charged him with any involvement in the creation of WannaCry, the allegations that he was involved with the Kronos banking Trojan has led some to accuse him of being part of WannaCry as well.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1037754488302399488"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1037754488302399488"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>"Law enforcement agencies and government officials around the world are challenged by the internet's invisible borders and its nameless perpetrators when it comes to pursuing or charging cybercriminals," said SonicWall CEO Bill Conner.</p><p>"While almost four years have passed since the communications giant sent notifications of its attacks, the U.S. Justice Department's actions are commendable and should serve as a reminder for consumers and organizations alike to remain vigilant."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/wannacry/31857/us-charges-north-korean-hacker-with-wannacry-and-sony-hack</link>
                                                                            <description>
                            <![CDATA[ A North Korean programmer is accused of conducting cyber attacks on behalf of the government ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tH9ccpLCiEKBfpJwYpvwvt</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zW5FHpNwsFKAPJ5XeTXpzD-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Sep 2018 09:36:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zW5FHpNwsFKAPJ5XeTXpzD-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[North Korea]]></media:description>                                                            <media:text><![CDATA[North Korea]]></media:text>
                                <media:title type="plain"><![CDATA[North Korea]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zW5FHpNwsFKAPJ5XeTXpzD-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US Department of Justice has formally charged a North Korean government hacker with a series of major cyber attacks, including <a href="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack" target="_blank" data-original-url="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack">the Sony Pictures hack</a>, the theft of $81 million from the Bangladesh Bank and the WannaCry ransomware.</p><p>The <a href="https://assets.documentcloud.org/documents/4834314/Read-the-DOJ-s-criminal-complaint-against-an.pdf" target="_blank">charges</a> have been filed against North Korean programmer Park Jin Hyok, who the US claims was working as part of a North Korean government-backed hacking operation known commonly as Lazarus Group.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30510/kaspersky-north-korea-framed-for-winter-olympics-malware" data-original-url="/hacking/30510/kaspersky-north-korea-framed-for-winter-olympics-malware">Kaspersky: North Korea framed for Winter Olympics malware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry" data-original-url="/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry">Why we’re ignoring the real lesson of WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/31527/how-russia-hacked-the-2016-election" data-original-url="/security/31527/how-russia-hacked-the-2016-election">How Russia hacked the 2016 election</a></p></div></div><p>Park, who was educated at a North Korean university, spent a number of years employed by Chosun Expo Joint Venture, a company that is used as a front by the North Korean government and is allegedly used to fund a government cyber espionage division known as 'Lab 110'.</p><p>Through an elaborate network of dummy email addresses and social media accounts, network infrastructure paths and IP addresses, investigators say they have managed to link Park and a number of unnamed co-conspirators to key hacks - most notably, the WannaCry ransomware that temporarily crippled the NHS and caused global chaos.</p><p>Park and his colleagues were also linked to the 2014 attack on Sony Pictures, which saw caches of internal emails - as well as whole unreleased films - leaked online in retaliation for the release of Seth Rogen and James Franco's film The Interview, which mocks North Korean 'Supreme Leader' Kim Jong Un.</p><p>"The scope and damage of the computer intrusions perpetrated [by Park and his allies] is virtually unparalleled," said FBI Special Agent Nathan Shields as part of a sworn affidavit. "The attacks and intrusions described...would have each required the efforts of a well-resourced team of persons working in concert, each performing different tasks.</p><p>"The technical evidence... shows that those attacks and intrusions were carried out by a group of persons with access to the same email and social media accounts, computer infrastructure, and source code. Tracing connections back through the operational infrastructure reveals numerous connections between Park, his true-name email and social media accounts and the operational accounts used to conduct the cyber attacks."</p><p>While both the UK and the US have publicly <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">blamed North Korea for unleashing WannaCry</a>, this marks the first time that the US government has formally charged an operative of the Democratic People's Republic of Korea for hacking. It follows similar charges which have been levelled at Russian, Iranian and Chinese hackers over the last few years.</p><p>While it has no bearing on his own legal battle, the news has been greeted warmly by <a href="https://www.itpro.com/security/31265/wannacry-hero-marcus-hutchins-faces-four-new-charges" target="_blank" data-original-url="https://www.itpro.com/security/31265/wannacry-hero-marcus-hutchins-faces-four-new-charges">British malware researcher Marcus Hutchins</a>. Hutchins was the one who discovered the 'kill-switch' that was built into WannaCry, effectively halting the malware's devastating spread.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1037866475426467840"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1037866475426467840"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Although the US government has not charged him with any involvement in the creation of WannaCry, the allegations that he was involved with the Kronos banking Trojan has led some to accuse him of being part of WannaCry as well.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1037754488302399488"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1037754488302399488"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>"Law enforcement agencies and government officials around the world are challenged by the internet's invisible borders and its nameless perpetrators when it comes to pursuing or charging cybercriminals," said SonicWall CEO Bill Conner.</p><p>"While almost four years have passed since the communications giant sent notifications of its attacks, the U.S. Justice Department's actions are commendable and should serve as a reminder for consumers and organizations alike to remain vigilant."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NHS asks IBM to boost its cyber security defences after WannaCry ]]></title>
                                                                                                <dc:content><![CDATA[ <p>NHS Digital has drafted in IBM in a bid to boost its cyber security defences in the wake of the devastating <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">WannaCry attack</a> that hit hospitals more than a year ago.</p><p>Under the three-year deal, <a href="https://www.digitalhealth.net/2018/02/nhs-digital-cybersecurity-contract" target="_blank">reportedly worth 30 million</a>, NHS Digital will gain access to a range of IBM's advanced cyber security services, such as vulnerability scanning and malware analysis, in an expansion to its Cyber Security Operations Centre (CSOC).</p><p>The CSOC, which monitors NHS networks for known threats and provides defensive support to health and social care organisations, will also be able to rely on IBM's X-Force repository of threat intelligence.</p><p>NHS Digital said this repository will provide insight, guidance, and can offer a wealth of advice to NHS organisations.</p><p>"This partnership will enhance our existing CSOC, which is delivered from NHS Digital's Data Security Centre," said Dan Taylor, programme director of the Data Security Centre at NHS Digital.</p><p>As part of the agreement, dedicated IBM engineers will offer the NHS extra support "during times of increased need".</p><p>"It will build on our existing ability to proactively monitor for security threats, risks, and emerging vulnerabilities, while supporting the development of new services for the future and enabling us to better support the existing needs of local organisations," Taylor added.</p><p>"This will ensure that we can evolve our security capability in line with the evolving cyber threat landscape."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-governance/30947/mps-slam-nhs-digital-for-home-office-data-sharing-deal" data-original-url="/data-governance/30947/mps-slam-nhs-digital-for-home-office-data-sharing-deal">MPs slam NHS Digital for Home Office data-sharing deal</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/31301/nhs-digital-awards-14m-to-fund-local-council-data-sharing-projects" data-original-url="/data-insights/31301/nhs-digital-awards-14m-to-fund-local-council-data-sharing-projects">NHS Digital awards £1.4m to fund local council data sharing projects</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/31365/nhs-digital-to-fund-digital-social-care-pilots-across-uk" data-original-url="/technology/31365/nhs-digital-to-fund-digital-social-care-pilots-across-uk">NHS Digital to fund digital social care pilots across UK</a></p></div></div><p>The deal will also encompass security monitoring pilots in select NHS organisations to test their cyber security capabilities, with a view to rolling the pilots out across the wider health service, as well as an 'innovation service' allowing NHS Digital to access new tools and expertise to address emerging threats as and when they arise.</p><p>Taylor added that while the partnership will strengthen the security of sensitive patient information it will also enable knowledge and skills-sharing between NHS and the industry, allowing the health service to continue developing its own cyber security expertise.</p><p>Scrutiny on the NHS's cyber security measures has increased since last summer's WannaCry attack. <a href="https://www.itpro.com/wannacry/30470/all-200-nhs-trusts-fail-latest-cybersecurity-standards" target="_blank" data-original-url="https://www.itpro.com/wannacry/30470/all-200-nhs-trusts-fail-latest-cybersecurity-standards">A</a><a href="https://www.itpro.com/wannacry/30470/all-200-nhs-trusts-fail-latest-cybersecurity-standards" target="_blank" data-original-url="https://www.itpro.com/wannacry/30470/all-200-nhs-trusts-fail-latest-cybersecurity-standards">ll 200 trusts failed to pass basic security standards</a> earlier this year despite getting 21 million from the Department for Health in July 2017 <a href="https://www.itpro.com/malware/29055/nhs-gets-21m-to-boost-cyber-defences-after-wannacry-ransomware" target="_blank" data-original-url="https://www.itpro.com/malware/29055/nhs-gets-21m-to-boost-cyber-defences-after-wannacry-ransomware">to improve its defences</a>.</p><p>The NHS has taken various measures to boost its security credentials in recent months, including reaching an agreement with Microsoft to <a href="https://www.itpro.com/wannacry/31020/nhs-aims-to-solve-cyber-security-issues-with-windows-10-migration-by-2020-deadline" target="_blank" data-original-url="https://www.itpro.com/wannacry/31020/nhs-aims-to-solve-cyber-security-issues-with-windows-10-migration-by-2020-deadline">upgrade legacy Windows operating systems</a> to Windows 10 by 2020.</p><p>IBM's deal comes as Privitar, the privacy engineering company, also <a href="https://www.itpro.com/technology/31422/nhs-digital-to-create-a-de-identification-system-to-protect-data-shared-across" target="_blank" data-original-url="https://www.itpro.com/technology/31422/nhs-digital-to-create-a-de-identification-system-to-protect-data-shared-across">won an NHS Digital contract to develop a de-identification software process</a>, dubbed De-ID, to enable the de-identification of patient records across the NHS, and protect patient identity.</p><p>NHS Digital's executive director of data, insights and statistics, Tom Denwood, said that De-ID will replace various de-identification methods across the NHS, bringing one consistent process to all patient data as it flows through different NHS systems.</p><p>It follows the introduction of NHS Digital's <a href="https://www.itpro.com/data-insights/31196/nhs-launches-data-sharing-opt-out-tool-for-patients-across-england" target="_blank" data-original-url="https://www.itpro.com/data-insights/31196/nhs-launches-data-sharing-opt-out-tool-for-patients-across-england">data-sharing opt-out tool</a> for patients across England who want to scrub their confidential information from being used for research and planning.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/cyber-security/31423/nhs-asks-ibm-to-boost-its-cyber-security-defences-after-wannacry</link>
                                                                            <description>
                            <![CDATA[ Health organisation calls in experts, having failed to meet basic security standards on its own ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sjgvvh7oBbAuEewy3sjmTF</guid>
                                                                                                                            <pubDate>Mon, 02 Jul 2018 09:53:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                                        <content:encoded >
                            <![CDATA[
                            <article>
                                <p>NHS Digital has drafted in IBM in a bid to boost its cyber security defences in the wake of the devastating <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">WannaCry attack</a> that hit hospitals more than a year ago.</p><p>Under the three-year deal, <a href="https://www.digitalhealth.net/2018/02/nhs-digital-cybersecurity-contract" target="_blank">reportedly worth 30 million</a>, NHS Digital will gain access to a range of IBM's advanced cyber security services, such as vulnerability scanning and malware analysis, in an expansion to its Cyber Security Operations Centre (CSOC).</p><p>The CSOC, which monitors NHS networks for known threats and provides defensive support to health and social care organisations, will also be able to rely on IBM's X-Force repository of threat intelligence.</p><p>NHS Digital said this repository will provide insight, guidance, and can offer a wealth of advice to NHS organisations.</p><p>"This partnership will enhance our existing CSOC, which is delivered from NHS Digital's Data Security Centre," said Dan Taylor, programme director of the Data Security Centre at NHS Digital.</p><p>As part of the agreement, dedicated IBM engineers will offer the NHS extra support "during times of increased need".</p><p>"It will build on our existing ability to proactively monitor for security threats, risks, and emerging vulnerabilities, while supporting the development of new services for the future and enabling us to better support the existing needs of local organisations," Taylor added.</p><p>"This will ensure that we can evolve our security capability in line with the evolving cyber threat landscape."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-governance/30947/mps-slam-nhs-digital-for-home-office-data-sharing-deal" data-original-url="/data-governance/30947/mps-slam-nhs-digital-for-home-office-data-sharing-deal">MPs slam NHS Digital for Home Office data-sharing deal</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/31301/nhs-digital-awards-14m-to-fund-local-council-data-sharing-projects" data-original-url="/data-insights/31301/nhs-digital-awards-14m-to-fund-local-council-data-sharing-projects">NHS Digital awards £1.4m to fund local council data sharing projects</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/31365/nhs-digital-to-fund-digital-social-care-pilots-across-uk" data-original-url="/technology/31365/nhs-digital-to-fund-digital-social-care-pilots-across-uk">NHS Digital to fund digital social care pilots across UK</a></p></div></div><p>The deal will also encompass security monitoring pilots in select NHS organisations to test their cyber security capabilities, with a view to rolling the pilots out across the wider health service, as well as an 'innovation service' allowing NHS Digital to access new tools and expertise to address emerging threats as and when they arise.</p><p>Taylor added that while the partnership will strengthen the security of sensitive patient information it will also enable knowledge and skills-sharing between NHS and the industry, allowing the health service to continue developing its own cyber security expertise.</p><p>Scrutiny on the NHS's cyber security measures has increased since last summer's WannaCry attack. <a href="https://www.itpro.com/wannacry/30470/all-200-nhs-trusts-fail-latest-cybersecurity-standards" target="_blank" data-original-url="https://www.itpro.com/wannacry/30470/all-200-nhs-trusts-fail-latest-cybersecurity-standards">A</a><a href="https://www.itpro.com/wannacry/30470/all-200-nhs-trusts-fail-latest-cybersecurity-standards" target="_blank" data-original-url="https://www.itpro.com/wannacry/30470/all-200-nhs-trusts-fail-latest-cybersecurity-standards">ll 200 trusts failed to pass basic security standards</a> earlier this year despite getting 21 million from the Department for Health in July 2017 <a href="https://www.itpro.com/malware/29055/nhs-gets-21m-to-boost-cyber-defences-after-wannacry-ransomware" target="_blank" data-original-url="https://www.itpro.com/malware/29055/nhs-gets-21m-to-boost-cyber-defences-after-wannacry-ransomware">to improve its defences</a>.</p><p>The NHS has taken various measures to boost its security credentials in recent months, including reaching an agreement with Microsoft to <a href="https://www.itpro.com/wannacry/31020/nhs-aims-to-solve-cyber-security-issues-with-windows-10-migration-by-2020-deadline" target="_blank" data-original-url="https://www.itpro.com/wannacry/31020/nhs-aims-to-solve-cyber-security-issues-with-windows-10-migration-by-2020-deadline">upgrade legacy Windows operating systems</a> to Windows 10 by 2020.</p><p>IBM's deal comes as Privitar, the privacy engineering company, also <a href="https://www.itpro.com/technology/31422/nhs-digital-to-create-a-de-identification-system-to-protect-data-shared-across" target="_blank" data-original-url="https://www.itpro.com/technology/31422/nhs-digital-to-create-a-de-identification-system-to-protect-data-shared-across">won an NHS Digital contract to develop a de-identification software process</a>, dubbed De-ID, to enable the de-identification of patient records across the NHS, and protect patient identity.</p><p>NHS Digital's executive director of data, insights and statistics, Tom Denwood, said that De-ID will replace various de-identification methods across the NHS, bringing one consistent process to all patient data as it flows through different NHS systems.</p><p>It follows the introduction of NHS Digital's <a href="https://www.itpro.com/data-insights/31196/nhs-launches-data-sharing-opt-out-tool-for-patients-across-england" target="_blank" data-original-url="https://www.itpro.com/data-insights/31196/nhs-launches-data-sharing-opt-out-tool-for-patients-across-england">data-sharing opt-out tool</a> for patients across England who want to scrub their confidential information from being used for research and planning.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NHS suffered more than 1,300 hours of downtime in the last three years, FOIs show ]]></title>
                                                                                                <dc:content><![CDATA[ <p>NHS Trusts across England experienced more than 1,300 hours' of downtime in the last three years, while a third of Trusts suffered a security breach.</p><p>Twenty-five of 80 NHS Trusts experienced the equivalent of 18 days of outage per year between January 2015 and February 2018, according to a Freedom of Information (FOI) survey submitted by specialist IT firm Intercity Technology, while a security breach was responsible for outages suffered by 14 of them.</p><p>Putting questions to 143 NHS Trusts in England, the company learned there had been 18 individual security breaches in that period, with one Trust suffering an average of one breach per year.</p><p>"NHS trusts across England are currently being pushed to the limit. It's not surprising that they often don't have the resources to dedicate 24/7 support to their IT systems, and the majority of these breaches could be an unfortunate consequence of this," said Intercity Technology's chief commercial officer Ian Jackson.</p><p>"Technology has proven to help facilitate the provision of care within the NHS, boost efficiencies and alleviate some of the strain on the system.</p><p>"However, if the benefits are to outweigh the potential risks, it's important to ensure that there are sufficient resources, whether in-house or external, to continuously monitor the network and address any issues before they impact daily activity."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" data-original-url="/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">One year after WannaCry, zero NHS trusts pass cyber security assessment</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud-security/31264/nhs-digital-blasted-for-dumping-responsibility-for-cloud-data-processing-on" data-original-url="/cloud-security/31264/nhs-digital-blasted-for-dumping-responsibility-for-cloud-data-processing-on">NHS Digital blasted for 'dumping responsibility' for cloud data processing on hospitals</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry" data-original-url="/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry">Why we’re ignoring the real lesson of WannaCry</a></p></div></div><p>Intercity Technology asked 143 NHS Trusts who was responsible for the security monitoring of their IT networks, how many times they had suffered a breach as a result of unpatched or outdated software, and whether they had suffered any downtime as a result of security issues, along with which parts of the IT infrastructure were affected, and for how long.</p><p>A handful of Trusts suffered an outage as a result of a security breach during this period cited the WanaCry ransomware attack as the main reason, while others responded saying they fell victim to the Locky and Zepto Viruses. The findings also showed that five trusts experienced downtime after they took their systems offline as a precaution after news of the WannaCry attack first broke.</p><p>Sharing specific details behind the outages, one Trust also outlined an issue in which an unauthorised device was plugged into a network which disrupted two wards last year, resulting in two hours' worth of time.</p><p>The company also learned that the overwhelming majority of NHS Trusts that suffered a blackout, 23 of the 25, relied on internally-based IT teams for the security monitoring of their networks.</p><p>A recent parliamentary report into the WannaCry attack found that <a href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" target="_blank" data-original-url="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">not one NHS Trust had passed the minimum cyber security standards</a>, in many cases because they had failed to apply critical patches to their systems.</p><p>Although some progress had been made since the ransomware wreaked havoc on NHS systems, including a nearly 200 million investment in improving the NHS' cyber security infrastructure, the report recommended further support and guidance must be offered to local healthcare organisations in pathing their systems, and that staffing plans must take into account the need to strengthen IT and cyber security teams.</p><p>In a bid resolve its longstanding security concerns, the Department for Health and Social Care (DHSC) earlier this year agreed on a deal with Microsoft to implement a long-awaited <a href="https://www.itpro.com/wannacry/31020/nhs-aims-to-solve-cyber-security-issues-with-windows-10-migration-by-2020-deadline" target="_blank" data-original-url="https://www.itpro.com/wannacry/31020/nhs-aims-to-solve-cyber-security-issues-with-windows-10-migration-by-2020-deadline">upgrade from legacy Windows operating systems to Windows 10 by 2020</a>.</p><p>As part of the deal, NHS devices will be upgraded to Windows 10, with Microsoft pushing the latest security updates to NHS machines as soon as they become available. Trusts will be allowed to upgrade their devices free of charge if they join a special service being set up to manage the rollout.</p><p>NHS Digital and NHS England were approached for comment but did notrespondd at the time of writing. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/31409/nhs-suffered-more-than-1300-hours-of-downtime-in-the-last-three-years-fois-show</link>
                                                                            <description>
                            <![CDATA[ The WannaCry ransomware attack was among the key factors behind network outages ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8GTRsNxpimbCLPuxPVsbbE</guid>
                                                                                                                            <pubDate>Fri, 29 Jun 2018 09:31:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                                        <content:encoded >
                            <![CDATA[
                            <article>
                                <p>NHS Trusts across England experienced more than 1,300 hours' of downtime in the last three years, while a third of Trusts suffered a security breach.</p><p>Twenty-five of 80 NHS Trusts experienced the equivalent of 18 days of outage per year between January 2015 and February 2018, according to a Freedom of Information (FOI) survey submitted by specialist IT firm Intercity Technology, while a security breach was responsible for outages suffered by 14 of them.</p><p>Putting questions to 143 NHS Trusts in England, the company learned there had been 18 individual security breaches in that period, with one Trust suffering an average of one breach per year.</p><p>"NHS trusts across England are currently being pushed to the limit. It's not surprising that they often don't have the resources to dedicate 24/7 support to their IT systems, and the majority of these breaches could be an unfortunate consequence of this," said Intercity Technology's chief commercial officer Ian Jackson.</p><p>"Technology has proven to help facilitate the provision of care within the NHS, boost efficiencies and alleviate some of the strain on the system.</p><p>"However, if the benefits are to outweigh the potential risks, it's important to ensure that there are sufficient resources, whether in-house or external, to continuously monitor the network and address any issues before they impact daily activity."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" data-original-url="/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">One year after WannaCry, zero NHS trusts pass cyber security assessment</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud-security/31264/nhs-digital-blasted-for-dumping-responsibility-for-cloud-data-processing-on" data-original-url="/cloud-security/31264/nhs-digital-blasted-for-dumping-responsibility-for-cloud-data-processing-on">NHS Digital blasted for 'dumping responsibility' for cloud data processing on hospitals</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry" data-original-url="/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry">Why we’re ignoring the real lesson of WannaCry</a></p></div></div><p>Intercity Technology asked 143 NHS Trusts who was responsible for the security monitoring of their IT networks, how many times they had suffered a breach as a result of unpatched or outdated software, and whether they had suffered any downtime as a result of security issues, along with which parts of the IT infrastructure were affected, and for how long.</p><p>A handful of Trusts suffered an outage as a result of a security breach during this period cited the WanaCry ransomware attack as the main reason, while others responded saying they fell victim to the Locky and Zepto Viruses. The findings also showed that five trusts experienced downtime after they took their systems offline as a precaution after news of the WannaCry attack first broke.</p><p>Sharing specific details behind the outages, one Trust also outlined an issue in which an unauthorised device was plugged into a network which disrupted two wards last year, resulting in two hours' worth of time.</p><p>The company also learned that the overwhelming majority of NHS Trusts that suffered a blackout, 23 of the 25, relied on internally-based IT teams for the security monitoring of their networks.</p><p>A recent parliamentary report into the WannaCry attack found that <a href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" target="_blank" data-original-url="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">not one NHS Trust had passed the minimum cyber security standards</a>, in many cases because they had failed to apply critical patches to their systems.</p><p>Although some progress had been made since the ransomware wreaked havoc on NHS systems, including a nearly 200 million investment in improving the NHS' cyber security infrastructure, the report recommended further support and guidance must be offered to local healthcare organisations in pathing their systems, and that staffing plans must take into account the need to strengthen IT and cyber security teams.</p><p>In a bid resolve its longstanding security concerns, the Department for Health and Social Care (DHSC) earlier this year agreed on a deal with Microsoft to implement a long-awaited <a href="https://www.itpro.com/wannacry/31020/nhs-aims-to-solve-cyber-security-issues-with-windows-10-migration-by-2020-deadline" target="_blank" data-original-url="https://www.itpro.com/wannacry/31020/nhs-aims-to-solve-cyber-security-issues-with-windows-10-migration-by-2020-deadline">upgrade from legacy Windows operating systems to Windows 10 by 2020</a>.</p><p>As part of the deal, NHS devices will be upgraded to Windows 10, with Microsoft pushing the latest security updates to NHS machines as soon as they become available. Trusts will be allowed to upgrade their devices free of charge if they join a special service being set up to manage the rollout.</p><p>NHS Digital and NHS England were approached for comment but did notrespondd at the time of writing. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WannaCry hero Marcus Hutchins faces four new charges ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Marcus Hutchins has been charged with four more offences by the US government, including lying to the FBI as well as the creation and sale of malware designed to harvest personal and financial information.</p><p>The fresh accusations have been issued as part of a '<a href="https://www.documentcloud.org/documents/4496027-Superseding-Indictment.html" target="_blank">superseding indictment</a>', which allows federal prosecutors to add new charges as more evidence becomes available. Hutchins is now charged with a total of 10 offences, including violation of the Computer Fraud and Abuse Act, wiretapping, conspiracy to commit wire fraud and giving false statements, all of which he denies.</p><p>Hutchins' lawyer called the new charges "meritless".</p><p>The security researcher, also known by his Twitter handle 'MalwareTech', was arrested last summer by US law enforcement while on a business trip to Las Vegas, and formally charged with creating and distributing the Kronos banking malware, shortly after shooting to fame for helping stop <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">the WannaCry ransomware outbreak</a>.</p><p>He denied the claims, saying that while elements of his code are present in the Kronos malware, he did not know what they were going to be used for when he wrote them.</p><p>The bulk of the new charges relate to the creation and sale of a piece of malware known as UPAS Kit, which was allegedly designed to intercept data that users type into online forms, such as login pages for banks. The new indictment comes just weeks after Hutchins' lawyers filed <a href="https://www.itpro.com/ransomware/31145/wannacry-hero-marcus-hutchins-wants-phone-transcript-suppressed" target="_blank" data-original-url="https://www.itpro.com/ransomware/31145/wannacry-hero-marcus-hutchins-wants-phone-transcript-suppressed">a motion to suppress a transcript</a> of a phone call Hutchins made while under arrest in which he allegedly discussed the incident.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="/641470/so-you-want-to-be-an-ethical-hacker">How do you become an ethical hacker?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry" data-original-url="/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry">Why we’re ignoring the real lesson of WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/30861/boeing-reportedly-hit-by-wannacry-attacks" data-original-url="/security/30861/boeing-reportedly-hit-by-wannacry-attacks">Boeing reportedly hit by WannaCry attacks</a></p></div></div><p>According to the indictment, Hutchins developed UPAS Kit at some point prior to July 2012, and provided it to an unnamed individual with the intention that this person would market, sell and distribute it. Prosecutors claim that this individual, who went by handles including 'VinnyK' and 'Aurora123', is the same person that Hutchins is accused of working with in the sale and promotion of Kronos in 2014.</p><p>The second component of the updated accusations is that Hutchins "knowingly and willfully made a materially false, fictitious, and fraudulent statement" to the FBI concerning his role in creating Kronos when he was brought in for interrogation last August.</p><p>According to the FBI, Hutchins claimed that the first time he was aware of his code being incorporated into Kronos was in 2016, but the agency said that its evidence shows that in November 2014, he was discussing his role in creating the malware with a cyber criminal that he knew to be involved in hacking ATMs and point-of-sale systems.</p><p>Hutchins' lawyer, Brian Klein, <a href="https://twitter.com/brianeklein/status/1004477905265659906" target="_blank">tweeted</a> that he was "disappointed" that the government had filed the indictment, which he called "meritless" and said "only serves to highlight the prosecution's serious flaws". Hutchins' legal team has previously argued that <a href="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges" target="_blank" data-original-url="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges">he was coerced</a> into making false confessions related to his alleged role in creating Kronos.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1004477905265659906"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1004477905265659906"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Klein is not the only legal mind who had taken issue with the indictment; civil rights expert <a href="https://www.emptywheel.net/2018/06/06/to-pre-empt-an-ass-handing-the-government-lards-on-problematic-new-charges-against-malwaretech" target="_blank">Marcy Wheeler has pointed out that</a>, given Hutchins' birth date of June 1994, if he did create UPAS Kit, he would have done so as a minor, and that the five-year statute of limitations on historic crimes would also have elapsed.</p><p>Hutchins has called the new charges f lying to the FBI <a href="https://twitter.com/MalwareTechBlog/status/1004420585869332480" target="_blank">"bullshit"</a>, and has asked fans and followers to donate to his crowdfunded legal defence, on which he says he has spent more than $100,000.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/31265/wannacry-hero-marcus-hutchins-faces-four-new-charges</link>
                                                                            <description>
                            <![CDATA[ MalwareTech security blogger's lawyer calls the new accusations "meritless" ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fvFdQTF3MWZF2q9NHZE92w</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6FucLP2936WFB9P4HQRzAX-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 07 Jun 2018 14:06:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6FucLP2936WFB9P4HQRzAX-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[gavel and handcuffs on keyboard]]></media:description>                                                            <media:text><![CDATA[gavel and handcuffs on keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[gavel and handcuffs on keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6FucLP2936WFB9P4HQRzAX-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Marcus Hutchins has been charged with four more offences by the US government, including lying to the FBI as well as the creation and sale of malware designed to harvest personal and financial information.</p><p>The fresh accusations have been issued as part of a '<a href="https://www.documentcloud.org/documents/4496027-Superseding-Indictment.html" target="_blank">superseding indictment</a>', which allows federal prosecutors to add new charges as more evidence becomes available. Hutchins is now charged with a total of 10 offences, including violation of the Computer Fraud and Abuse Act, wiretapping, conspiracy to commit wire fraud and giving false statements, all of which he denies.</p><p>Hutchins' lawyer called the new charges "meritless".</p><p>The security researcher, also known by his Twitter handle 'MalwareTech', was arrested last summer by US law enforcement while on a business trip to Las Vegas, and formally charged with creating and distributing the Kronos banking malware, shortly after shooting to fame for helping stop <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">the WannaCry ransomware outbreak</a>.</p><p>He denied the claims, saying that while elements of his code are present in the Kronos malware, he did not know what they were going to be used for when he wrote them.</p><p>The bulk of the new charges relate to the creation and sale of a piece of malware known as UPAS Kit, which was allegedly designed to intercept data that users type into online forms, such as login pages for banks. The new indictment comes just weeks after Hutchins' lawyers filed <a href="https://www.itpro.com/ransomware/31145/wannacry-hero-marcus-hutchins-wants-phone-transcript-suppressed" target="_blank" data-original-url="https://www.itpro.com/ransomware/31145/wannacry-hero-marcus-hutchins-wants-phone-transcript-suppressed">a motion to suppress a transcript</a> of a phone call Hutchins made while under arrest in which he allegedly discussed the incident.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="/641470/so-you-want-to-be-an-ethical-hacker">How do you become an ethical hacker?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry" data-original-url="/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry">Why we’re ignoring the real lesson of WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/30861/boeing-reportedly-hit-by-wannacry-attacks" data-original-url="/security/30861/boeing-reportedly-hit-by-wannacry-attacks">Boeing reportedly hit by WannaCry attacks</a></p></div></div><p>According to the indictment, Hutchins developed UPAS Kit at some point prior to July 2012, and provided it to an unnamed individual with the intention that this person would market, sell and distribute it. Prosecutors claim that this individual, who went by handles including 'VinnyK' and 'Aurora123', is the same person that Hutchins is accused of working with in the sale and promotion of Kronos in 2014.</p><p>The second component of the updated accusations is that Hutchins "knowingly and willfully made a materially false, fictitious, and fraudulent statement" to the FBI concerning his role in creating Kronos when he was brought in for interrogation last August.</p><p>According to the FBI, Hutchins claimed that the first time he was aware of his code being incorporated into Kronos was in 2016, but the agency said that its evidence shows that in November 2014, he was discussing his role in creating the malware with a cyber criminal that he knew to be involved in hacking ATMs and point-of-sale systems.</p><p>Hutchins' lawyer, Brian Klein, <a href="https://twitter.com/brianeklein/status/1004477905265659906" target="_blank">tweeted</a> that he was "disappointed" that the government had filed the indictment, which he called "meritless" and said "only serves to highlight the prosecution's serious flaws". Hutchins' legal team has previously argued that <a href="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges" target="_blank" data-original-url="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges">he was coerced</a> into making false confessions related to his alleged role in creating Kronos.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/1004477905265659906"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1004477905265659906"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Klein is not the only legal mind who had taken issue with the indictment; civil rights expert <a href="https://www.emptywheel.net/2018/06/06/to-pre-empt-an-ass-handing-the-government-lards-on-problematic-new-charges-against-malwaretech" target="_blank">Marcy Wheeler has pointed out that</a>, given Hutchins' birth date of June 1994, if he did create UPAS Kit, he would have done so as a minor, and that the five-year statute of limitations on historic crimes would also have elapsed.</p><p>Hutchins has called the new charges f lying to the FBI <a href="https://twitter.com/MalwareTechBlog/status/1004420585869332480" target="_blank">"bullshit"</a>, and has asked fans and followers to donate to his crowdfunded legal defence, on which he says he has spent more than $100,000.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why we’re ignoring the real lesson of WannaCry ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Saturday marks exactly <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">one year since the outbreak of the WannaCry ransomware epidemic</a> that hit more than 300,000 computers, affecting major organisations including the NHS, where more than 40 trusts were forced to delay or cancel operations.</p><p>WannaCry made headlines around the world, drawing the attention of governments and regulators to the often woeful lack of cyber security within many large businesses and public sector bodies.</p><p>But one year on, have we learned anything? The answer, I would argue, is no. Basic IT failures are still happening, stupid security mistakes are still being made and no one, it would seem, has learned a damn thing.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28992/only-50-of-cios-improve-cyber-security-after-wannacry" data-original-url="/security/28992/only-50-of-cios-improve-cyber-security-after-wannacry">Only 50% of CIOs improve cyber security after WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" data-original-url="/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">One year after WannaCry, zero NHS trusts pass cyber security assessment</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/31074/industry-collaboration-was-the-silver-lining-of-meltdown-and-spectre" data-original-url="/security/31074/industry-collaboration-was-the-silver-lining-of-meltdown-and-spectre">Industry collaboration was the "silver lining" of Meltdown and Spectre</a></p></div></div><p>As a case in point, let's take the WannaCry attack itself. As malware goes, WannaCry was not particularly sophisticated - at least, not from a technical standpoint. The reason it was able to spread so prolifically is that it took advantage of two pre-existing vulnerabilities: EternalBlue and DoublePulsar. These were critical vulnerabilities, allowing WannaCry to propagate itself exponentially.</p><p>Here's the rub, though: these exploits weren't zero-days. Microsoft had issued patches for them months before the outbreak even occurred. This, if nothing else, is the lesson of WannaCry: patch your damn systems. It shouldn't be that difficult, and it is one of the most basic steps that anyone can take to secure themselves. And yet, <a href="https://www.itpro.com/security/31095/one-year-on-from-wannacry-and-uk-firms-are-exposed-to-cyber-threats-more-than-ever" target="_blank" data-original-url="https://www.itpro.com/security/31095/one-year-on-from-wannacry-and-uk-firms-are-exposed-to-cyber-threats-more-than-ever">according to a Tanium study</a> marking the dubious anniversary, two-thirds of organisations have not improved their patch management systems in the wake of WannaCry.</p><p>Of course, part of the blame for why no lessons have been learnt from WannaCry can be laid squarely at the feet of the security industry. For a solid year, virtually every cyber security firm in the world has been using the WannaCry outbreak as a big, scary stick which it can use to beat people into purchasing its protections. "See," they say; "this is what happens when you don't have a polymorphic, exoplasmic, hyper-next-gen 360-degree threat neutralisation suite! That'll be $300,000 per year, please."</p><p>Security vendors are right, up to a point; threats like WannaCry are a big deal, and organisations need to do more to prepare for them. What the infosec companies are conveniently leaving out, however, is that a surprisingly large proportion of threats can be stymied simply by applying software patches as soon as they are available. This isn't a substitute for having a solid security system in place, admittedly. But then, having a security system is no excuse for neglecting to apply patches either.</p><p>Don't get me wrong, I understand that updating software can be a total pain in the neck. Like testing your smoke alarm every two weeks, it's something we know we should do, but don't. We've all been guilty of repeatedly postponing that earnest little alert informing us that honestly, it's really rather important that we apply this update - I've been ignoring one such update for about two weeks on the trot, because it keeps coming up at inconvenient times.</p><p>It's a bad habit, though, and it's one that security firms should be helping all of us to break. The simple fact is that, alongside good password hygiene, a disciplined update schedule is the foundation of effective security. Without it, even the most sophisticated security suite is little more than a castle built upon sand.</p><p>If the IT industry as a whole takes one lesson from WannaCry, let it be this: take the time to update your systems. Patch fully, and patch often.</p><p>You don't have to make it your number one priority (although by rights, it should be) but make sure it's at least in the top three. If you're considering shelling out for a new security package to fight the growing tide of ransomware threats, take a look at your patch procedure first, because if you take care of your patches, then in most cases, they'll take care of you.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/wannacry/31102/why-we-re-ignoring-the-real-lesson-of-wannacry</link>
                                                                            <description>
                            <![CDATA[ One year on, why does no one WannaLearn? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8xLThhrj2Rfy5e6wQKa6Jy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GxmNcBsfrJugkyx3cfUav-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 May 2018 14:53:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GxmNcBsfrJugkyx3cfUav-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Red padlock representing a security hack]]></media:description>                                                            <media:text><![CDATA[Red padlock representing a security hack]]></media:text>
                                <media:title type="plain"><![CDATA[Red padlock representing a security hack]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GxmNcBsfrJugkyx3cfUav-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Saturday marks exactly <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">one year since the outbreak of the WannaCry ransomware epidemic</a> that hit more than 300,000 computers, affecting major organisations including the NHS, where more than 40 trusts were forced to delay or cancel operations.</p><p>WannaCry made headlines around the world, drawing the attention of governments and regulators to the often woeful lack of cyber security within many large businesses and public sector bodies.</p><p>But one year on, have we learned anything? The answer, I would argue, is no. Basic IT failures are still happening, stupid security mistakes are still being made and no one, it would seem, has learned a damn thing.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28992/only-50-of-cios-improve-cyber-security-after-wannacry" data-original-url="/security/28992/only-50-of-cios-improve-cyber-security-after-wannacry">Only 50% of CIOs improve cyber security after WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" data-original-url="/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">One year after WannaCry, zero NHS trusts pass cyber security assessment</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/31074/industry-collaboration-was-the-silver-lining-of-meltdown-and-spectre" data-original-url="/security/31074/industry-collaboration-was-the-silver-lining-of-meltdown-and-spectre">Industry collaboration was the "silver lining" of Meltdown and Spectre</a></p></div></div><p>As a case in point, let's take the WannaCry attack itself. As malware goes, WannaCry was not particularly sophisticated - at least, not from a technical standpoint. The reason it was able to spread so prolifically is that it took advantage of two pre-existing vulnerabilities: EternalBlue and DoublePulsar. These were critical vulnerabilities, allowing WannaCry to propagate itself exponentially.</p><p>Here's the rub, though: these exploits weren't zero-days. Microsoft had issued patches for them months before the outbreak even occurred. This, if nothing else, is the lesson of WannaCry: patch your damn systems. It shouldn't be that difficult, and it is one of the most basic steps that anyone can take to secure themselves. And yet, <a href="https://www.itpro.com/security/31095/one-year-on-from-wannacry-and-uk-firms-are-exposed-to-cyber-threats-more-than-ever" target="_blank" data-original-url="https://www.itpro.com/security/31095/one-year-on-from-wannacry-and-uk-firms-are-exposed-to-cyber-threats-more-than-ever">according to a Tanium study</a> marking the dubious anniversary, two-thirds of organisations have not improved their patch management systems in the wake of WannaCry.</p><p>Of course, part of the blame for why no lessons have been learnt from WannaCry can be laid squarely at the feet of the security industry. For a solid year, virtually every cyber security firm in the world has been using the WannaCry outbreak as a big, scary stick which it can use to beat people into purchasing its protections. "See," they say; "this is what happens when you don't have a polymorphic, exoplasmic, hyper-next-gen 360-degree threat neutralisation suite! That'll be $300,000 per year, please."</p><p>Security vendors are right, up to a point; threats like WannaCry are a big deal, and organisations need to do more to prepare for them. What the infosec companies are conveniently leaving out, however, is that a surprisingly large proportion of threats can be stymied simply by applying software patches as soon as they are available. This isn't a substitute for having a solid security system in place, admittedly. But then, having a security system is no excuse for neglecting to apply patches either.</p><p>Don't get me wrong, I understand that updating software can be a total pain in the neck. Like testing your smoke alarm every two weeks, it's something we know we should do, but don't. We've all been guilty of repeatedly postponing that earnest little alert informing us that honestly, it's really rather important that we apply this update - I've been ignoring one such update for about two weeks on the trot, because it keeps coming up at inconvenient times.</p><p>It's a bad habit, though, and it's one that security firms should be helping all of us to break. The simple fact is that, alongside good password hygiene, a disciplined update schedule is the foundation of effective security. Without it, even the most sophisticated security suite is little more than a castle built upon sand.</p><p>If the IT industry as a whole takes one lesson from WannaCry, let it be this: take the time to update your systems. Patch fully, and patch often.</p><p>You don't have to make it your number one priority (although by rights, it should be) but make sure it's at least in the top three. If you're considering shelling out for a new security package to fight the growing tide of ransomware threats, take a look at your patch procedure first, because if you take care of your patches, then in most cases, they'll take care of you.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NHS aims to solve cyber security issues with Windows 10 migration by 2020 deadline ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The Department of Health has agreed a deal with Microsoft to roll Windows 10 out across the NHS by 2020 in a bid to bolster hospitals' cybersecurity defences, which have been savaged by experts in recent months.</p><p>The long-awaited upgrade from Windows XP, which Microsoft stopped supporting four years ago, comes almost a year after the WannaCry ransomware attack spread havoc across IT systems in the NHS.</p><p>As part of the deal, NHS devices will be upgraded to Windows 10, with Microsoft pushing the latest security updates to NHS machines as soon as they become available. </p><p>Trusts will be allowed to upgrade their devices to Windows 10 free of cost if they join a special service being set up to manage the rollout - but they must do so by January 14 2020.</p><p>This coincides with the date Microsoft will stop supporting Windows 7 with security updates. </p><p>"Central funding for Windows operating systems licenses will not be available to organisations who are not part of the service," an NHS Digital spokesperson said.</p><p>They added: "NHS organisations have already successfully migrated more than 100,000 NHS devices to the Windows 10 operating system, and guidance and support to help trusts with their migration will be provided as part of the service."</p><p>While Windows 10 boasts apps like SmartScreen and antivirus tools like Windows Defender to detect viruses, phishing and malware, as well as isolate infected machines and kill malicious processes before they are allowed to spread, the NHS has long been running XP, despite it reaching end-of-life in April 2014.</p><p>Trusts that upgrade will also get access to Windows Defender Advanced Threat Protection (WDATP), a security service that will allow NHS organisations to detect, investigate, and respond to advanced threats on their networks.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/30470/all-200-nhs-trusts-fail-latest-cybersecurity-standards" data-original-url="/wannacry/30470/all-200-nhs-trusts-fail-latest-cybersecurity-standards">All 200 NHS trusts fail latest cybersecurity standards</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" data-original-url="/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">One year after WannaCry, zero NHS trusts pass cyber security assessment</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/public-sector/27740/nine-in-10-nhs-trusts-still-use-windows-xp" data-original-url="/public-sector/27740/nine-in-10-nhs-trusts-still-use-windows-xp">Nine in 10 NHS trusts still use Windows XP</a></p></div></div><p>"We know cyber attacks are a growing threat, so it is vital our health and care organisations have secure systems which patients trust," said Jeremy Hunt, the government's health and social care secretary.</p><p>"We have been building the capability of NHS systems over a number of years, but there is always more to do to future-proof our NHS as far as reasonably possible against this threat. This new technology will ensure the NHS can use the latest and most resilient software available - something the public rightly expect."</p><p>The announcement comes a fortnight after Parliament's Public Accounts Committee (PAC) published a damning report revealing that <a href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" target="_blank" data-original-url="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">not a single NHS t</a><a href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" target="_blank" data-original-url="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">rust passed its cyber security assessment</a>, revealing that some trusts had failed "soley because they had not patched their systems - the main reason the NHS had been vulnerable to WannaCry". </p><p>WannaCry affected 300,000 computers across 150 countries in May last year. The National Audit Office (NAO) found that <a href="https://www.nao.org.uk/report/investigation-wannacry-cyber-attack-and-the-nhs" target="_blank">at least 34% of NHS trusts in the UK were disrupted by the attack</a>, leading to the cancellation of 6,900 appointments.</p><p>Although the NHS was not a target, it became swept up in the attack in light of its cyber security vulnerabilities, with critics pointing out that Windows XP is a major attack vector for hackers, given the lack of patches for security holes. However, an analysis of affected computers at the time, conducted by Kaspersky Lab, found that Windows 7 was responsible for 97% of infections, with Windows XP contributing a negligible number. Windows 10 was unaffected by WannaCry.</p><p>Shortly afterwards <a href="https://www.itpro.com/malware/29055/nhs-gets-21m-to-boost-cyber-defences-after-wannacry-ransomware" target="_blank" data-original-url="https://www.itpro.com/malware/29055/nhs-gets-21m-to-boost-cyber-defences-after-wannacry-ransomware">the Department of Health allocated 21 million to bolster the NHS' defences</a>, as the government accepted the recommendations set out by the National Data Guardian and Care Quality Commission reviews into security standards carried out before WannaCry - but the trusts still failed the recent PAC assessment.</p><p>Deputy chief executive of NHS Digital, Rob Shaw, said: "The new Windows operating system has a range of advancements in security and identity protection that will help us to support trusts to keep their data safe from attacks and which will cover both desktop and mobile devices.</p><p>"The additional funding will mean we can add an extra layer of protection, whilst boosting our existing services, with real-time monitoring of NHS networks and the ability to see potential threats right down to individual NHS organisations."</p><p>When XP fell out of support four years ago, the government signed a 5 million custom support deal for computers still running the aged OS in the NHS, police and other public bodies, an agreement <a href="https://www.itpro.com/operating-systems/24672/gov-ends-55m-xp-custom-support-contract" target="_blank" data-original-url="https://www.itpro.com/operating-systems/24672/gov-ends-55m-xp-custom-support-contract">that ended in May 2015</a> despite many machines still stuck on XP.</p><p>When <em>IT Pro</em> spoke to the Metropolitan Police's CIO, Angus McCallum, earlier this year, <a href="https://www.itpro.com/operating-systems/30310/met-police-set-to-finish-windows-xp-upgrade-in-may" target="_blank" data-original-url="https://www.itpro.com/operating-systems/30310/met-police-set-to-finish-windows-xp-upgrade-in-may">he claimed the last machines running XP would be upgraded by May</a>.</p><p>The Department of Health refused to disclose the cost of the Microsoft deal, saying this was commercially sensitivity information, but clarified it is not part of a wider 150 million investment over the next three years, announced this weekend, which includes money to set up a new NHS Digital Security Operations Centre. </p><p><em>IT Pro</em> has contacted NHS Digital about the number of devices the Windows 10 upgrade will apply to, and the timescale for the project.</p><p>"The importance of helping to protect the NHS from the growing threat of cyber-attacks cannot be overstated," said Cindy Rose, chief executive of Microsoft UK. "The introduction of a centralised Windows 10 agreement will ensure a consistent approach to security that also enables the NHS to rapidly modernise its IT infrastructure."</p><p><em>Picture: Shutterstock</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/wannacry/31020/nhs-aims-to-solve-cyber-security-issues-with-windows-10-migration-by-2020-deadline</link>
                                                                            <description>
                            <![CDATA[ Government deal with Microsoft will upgrade XP machines one year after WannaCry ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8cznYYH633QGDwuWuJqYHf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tXqJNLL29ZERv7RyA3pJuB-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 30 Apr 2018 09:43:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tXqJNLL29ZERv7RyA3pJuB-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A stethoscope on top of a MacBook keyboard]]></media:description>                                                            <media:text><![CDATA[A stethoscope on top of a MacBook keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A stethoscope on top of a MacBook keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tXqJNLL29ZERv7RyA3pJuB-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Department of Health has agreed a deal with Microsoft to roll Windows 10 out across the NHS by 2020 in a bid to bolster hospitals' cybersecurity defences, which have been savaged by experts in recent months.</p><p>The long-awaited upgrade from Windows XP, which Microsoft stopped supporting four years ago, comes almost a year after the WannaCry ransomware attack spread havoc across IT systems in the NHS.</p><p>As part of the deal, NHS devices will be upgraded to Windows 10, with Microsoft pushing the latest security updates to NHS machines as soon as they become available. </p><p>Trusts will be allowed to upgrade their devices to Windows 10 free of cost if they join a special service being set up to manage the rollout - but they must do so by January 14 2020.</p><p>This coincides with the date Microsoft will stop supporting Windows 7 with security updates. </p><p>"Central funding for Windows operating systems licenses will not be available to organisations who are not part of the service," an NHS Digital spokesperson said.</p><p>They added: "NHS organisations have already successfully migrated more than 100,000 NHS devices to the Windows 10 operating system, and guidance and support to help trusts with their migration will be provided as part of the service."</p><p>While Windows 10 boasts apps like SmartScreen and antivirus tools like Windows Defender to detect viruses, phishing and malware, as well as isolate infected machines and kill malicious processes before they are allowed to spread, the NHS has long been running XP, despite it reaching end-of-life in April 2014.</p><p>Trusts that upgrade will also get access to Windows Defender Advanced Threat Protection (WDATP), a security service that will allow NHS organisations to detect, investigate, and respond to advanced threats on their networks.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/30470/all-200-nhs-trusts-fail-latest-cybersecurity-standards" data-original-url="/wannacry/30470/all-200-nhs-trusts-fail-latest-cybersecurity-standards">All 200 NHS trusts fail latest cybersecurity standards</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" data-original-url="/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">One year after WannaCry, zero NHS trusts pass cyber security assessment</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/public-sector/27740/nine-in-10-nhs-trusts-still-use-windows-xp" data-original-url="/public-sector/27740/nine-in-10-nhs-trusts-still-use-windows-xp">Nine in 10 NHS trusts still use Windows XP</a></p></div></div><p>"We know cyber attacks are a growing threat, so it is vital our health and care organisations have secure systems which patients trust," said Jeremy Hunt, the government's health and social care secretary.</p><p>"We have been building the capability of NHS systems over a number of years, but there is always more to do to future-proof our NHS as far as reasonably possible against this threat. This new technology will ensure the NHS can use the latest and most resilient software available - something the public rightly expect."</p><p>The announcement comes a fortnight after Parliament's Public Accounts Committee (PAC) published a damning report revealing that <a href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" target="_blank" data-original-url="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">not a single NHS t</a><a href="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment" target="_blank" data-original-url="https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment">rust passed its cyber security assessment</a>, revealing that some trusts had failed "soley because they had not patched their systems - the main reason the NHS had been vulnerable to WannaCry". </p><p>WannaCry affected 300,000 computers across 150 countries in May last year. The National Audit Office (NAO) found that <a href="https://www.nao.org.uk/report/investigation-wannacry-cyber-attack-and-the-nhs" target="_blank">at least 34% of NHS trusts in the UK were disrupted by the attack</a>, leading to the cancellation of 6,900 appointments.</p><p>Although the NHS was not a target, it became swept up in the attack in light of its cyber security vulnerabilities, with critics pointing out that Windows XP is a major attack vector for hackers, given the lack of patches for security holes. However, an analysis of affected computers at the time, conducted by Kaspersky Lab, found that Windows 7 was responsible for 97% of infections, with Windows XP contributing a negligible number. Windows 10 was unaffected by WannaCry.</p><p>Shortly afterwards <a href="https://www.itpro.com/malware/29055/nhs-gets-21m-to-boost-cyber-defences-after-wannacry-ransomware" target="_blank" data-original-url="https://www.itpro.com/malware/29055/nhs-gets-21m-to-boost-cyber-defences-after-wannacry-ransomware">the Department of Health allocated 21 million to bolster the NHS' defences</a>, as the government accepted the recommendations set out by the National Data Guardian and Care Quality Commission reviews into security standards carried out before WannaCry - but the trusts still failed the recent PAC assessment.</p><p>Deputy chief executive of NHS Digital, Rob Shaw, said: "The new Windows operating system has a range of advancements in security and identity protection that will help us to support trusts to keep their data safe from attacks and which will cover both desktop and mobile devices.</p><p>"The additional funding will mean we can add an extra layer of protection, whilst boosting our existing services, with real-time monitoring of NHS networks and the ability to see potential threats right down to individual NHS organisations."</p><p>When XP fell out of support four years ago, the government signed a 5 million custom support deal for computers still running the aged OS in the NHS, police and other public bodies, an agreement <a href="https://www.itpro.com/operating-systems/24672/gov-ends-55m-xp-custom-support-contract" target="_blank" data-original-url="https://www.itpro.com/operating-systems/24672/gov-ends-55m-xp-custom-support-contract">that ended in May 2015</a> despite many machines still stuck on XP.</p><p>When <em>IT Pro</em> spoke to the Metropolitan Police's CIO, Angus McCallum, earlier this year, <a href="https://www.itpro.com/operating-systems/30310/met-police-set-to-finish-windows-xp-upgrade-in-may" target="_blank" data-original-url="https://www.itpro.com/operating-systems/30310/met-police-set-to-finish-windows-xp-upgrade-in-may">he claimed the last machines running XP would be upgraded by May</a>.</p><p>The Department of Health refused to disclose the cost of the Microsoft deal, saying this was commercially sensitivity information, but clarified it is not part of a wider 150 million investment over the next three years, announced this weekend, which includes money to set up a new NHS Digital Security Operations Centre. </p><p><em>IT Pro</em> has contacted NHS Digital about the number of devices the Windows 10 upgrade will apply to, and the timescale for the project.</p><p>"The importance of helping to protect the NHS from the growing threat of cyber-attacks cannot be overstated," said Cindy Rose, chief executive of Microsoft UK. "The introduction of a centralised Windows 10 agreement will ensure a consistent approach to security that also enables the NHS to rapidly modernise its IT infrastructure."</p><p><em>Picture: Shutterstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ One year after WannaCry, zero NHS trusts pass cyber security assessment ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The government's Public Accounts Committee has today released the findings of its <a href="https://publications.parliament.uk/pa/cm201719/cmselect/cmpubacc/787/78702.htm">report into the WannaCry ransomware</a> which hit the NHS in May 2017, revealing that not one NHS trust is up to an acceptable standard of cyber security.</p><p>Following <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">the WannaCry attack</a>, the report said, the NHS has assessed the cyber security level of 200 trusts. Disappointingly, however, every single trust failed the cyber security assessment - in some cases because they had failed to apply critical patches to their systems, which is the main reason WannaCry was able to spread so widely in the first place.</p><p>"The Department and NHS Digital told us that trusts had not passed the test, not because they had not done anything on cyber security, but rather that the Cyber Essentials Plus standard against which they are assessed is a high bar," the report said. "However, some trusts had failed the assessment solely because they had not patched their systems - the main reason the NHS had been vulnerable to WannaCry.</p><p>"NHS England told us that it is also concerned that trusts that were not infected by WannaCry could become complacent over cyber security and not keep on top of their cyber security risks."</p><p>On top of this, NHS Digital told the committee that it still lacks key information on the cyber security posture of local healthcare facilities, such as the use of anti-virus software and IP addresses.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges" data-original-url="/security/29172/marcus-hutchins-wannacry-kronos-charges">WannaCry 'hero' Marcus Hutchins 'was coerced' into Kronos confession</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/malware/29055/nhs-gets-21m-to-boost-cyber-defences-after-wannacry-ransomware" data-original-url="/malware/29055/nhs-gets-21m-to-boost-cyber-defences-after-wannacry-ransomware">NHS gets £21m to boost cyber defences after WannaCry ransomware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29863/notpetya-was-nastier-than-wannacry-ransomware-say-experts" data-original-url="/security/29863/notpetya-was-nastier-than-wannacry-ransomware-say-experts">NotPetya was nastier than WannaCry ransomware, say experts</a></p></div></div><p>"Applying patches, downloading securing updates and keeping passwords hard to guess are simple practices that can go a long way, but it seems like this isn't happening among healthcare organisations currently," said David Emm, principal security researcher at Kaspersky Lab.</p><p>"Health data is attractive to criminals, and the interconnected medical devices that we are increasingly seeing present across healthcare institutes are susceptible to the same security risks as traditional IT devices."</p><p>The report found that around 80 of England's 236 NHS trusts were affected by the ransomware, as well as more than 600 additional NHS organisations such as GP's practises. The incident - which was declared a major incident' by the NHS - resulted in the cancellation of almost 20,000 operations and hospital appointments.</p><p>Despite this, however, the DfH still has no estimate of how much money WannaCry cost the NHS, stating that its focus at the time was on caring for patients.</p><p>"We recognise that at the time of the attack the focus would have been on patient care rather than working out what WannaCry was costing the NHS," the report read. "However, an understanding of the financial impact on the NHS is also important to assess the seriousness of the attack and likely to be relevant to informing future investment decisions in cyber security."</p><p>Further facts about the NHS' troubling level of cyber security (both before and after WannaCry) were also revealed. For example, although the DfH, NHS England and NHS Improvement published a list of 22 recommendations for improving the NHS' cyber security back in February, plans to implement the recommendations have yet to be agreed upon, and the Department for Health still has no idea when it will happen or how much the process will cost.</p><p>One of the key issues faced by the NHS in keeping itself secure, the DfH told the committee, is that many local bodies are unable to apply updates and patches to IT systems without disrupting patient care, as many are interdependent on each other.</p><p>"Nearly one year on from the WannaCry cyber attack, it is clear that there is a need for constant vigilance within the NHS to ensure that patient data and vital systems are protected," said techUK's head of programme for Cyber and National Security, Talal Rajab.</p><p>"It is important to note that WannaCry was not just a wake-up call for the NHS, but for organisations across the public and private sector, to get their house in order and remain prepared in this era of heightened cyber tensions. Further sector-specific guidance can be found through the National Cyber Security Centre."</p><p>Some progress has been made, however; since WannaCry hit the NHS, the Department for Health has carved off nearly 200 million to invest in various improvements to cyber security up to 2020, including more support resources for vulnerable organisations, improvements to local infrastructure and addressing major security gaps in major trauma centres and ambulance trusts.</p><p>The committee set out a number of further recommendations for the Department for Health as part of the report, including that it should provide support and guidance for local healthcare organisations on how to efficiently patch systems with minimal disruption, as well as ensuring that staffing plans focus on IT and cyber security.</p><p>The report also recommended that all of the NHS' contracts IT and equipment vendors include guarantees for support and protection to guard against cyber attack.</p><p>Furthermore, the DfH is to provide the government by the end of June 2018 with an estimate for the cost of WannaCry to the NHS and a progress report on the implementation of the recommendations it made in February.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/wannacry/30956/one-year-after-wannacry-zero-nhs-trusts-pass-cyber-security-assessment</link>
                                                                            <description>
                            <![CDATA[ Damning government report reveals NHS still fails to meet cyber security requirements ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">58nwm4YnbfRFd4KiBWdR52</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tXqJNLL29ZERv7RyA3pJuB-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 18 Apr 2018 11:47:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tXqJNLL29ZERv7RyA3pJuB-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A stethoscope on top of a MacBook keyboard]]></media:description>                                                            <media:text><![CDATA[A stethoscope on top of a MacBook keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A stethoscope on top of a MacBook keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tXqJNLL29ZERv7RyA3pJuB-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The government's Public Accounts Committee has today released the findings of its <a href="https://publications.parliament.uk/pa/cm201719/cmselect/cmpubacc/787/78702.htm">report into the WannaCry ransomware</a> which hit the NHS in May 2017, revealing that not one NHS trust is up to an acceptable standard of cyber security.</p><p>Following <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">the WannaCry attack</a>, the report said, the NHS has assessed the cyber security level of 200 trusts. Disappointingly, however, every single trust failed the cyber security assessment - in some cases because they had failed to apply critical patches to their systems, which is the main reason WannaCry was able to spread so widely in the first place.</p><p>"The Department and NHS Digital told us that trusts had not passed the test, not because they had not done anything on cyber security, but rather that the Cyber Essentials Plus standard against which they are assessed is a high bar," the report said. "However, some trusts had failed the assessment solely because they had not patched their systems - the main reason the NHS had been vulnerable to WannaCry.</p><p>"NHS England told us that it is also concerned that trusts that were not infected by WannaCry could become complacent over cyber security and not keep on top of their cyber security risks."</p><p>On top of this, NHS Digital told the committee that it still lacks key information on the cyber security posture of local healthcare facilities, such as the use of anti-virus software and IP addresses.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges" data-original-url="/security/29172/marcus-hutchins-wannacry-kronos-charges">WannaCry 'hero' Marcus Hutchins 'was coerced' into Kronos confession</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/malware/29055/nhs-gets-21m-to-boost-cyber-defences-after-wannacry-ransomware" data-original-url="/malware/29055/nhs-gets-21m-to-boost-cyber-defences-after-wannacry-ransomware">NHS gets £21m to boost cyber defences after WannaCry ransomware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29863/notpetya-was-nastier-than-wannacry-ransomware-say-experts" data-original-url="/security/29863/notpetya-was-nastier-than-wannacry-ransomware-say-experts">NotPetya was nastier than WannaCry ransomware, say experts</a></p></div></div><p>"Applying patches, downloading securing updates and keeping passwords hard to guess are simple practices that can go a long way, but it seems like this isn't happening among healthcare organisations currently," said David Emm, principal security researcher at Kaspersky Lab.</p><p>"Health data is attractive to criminals, and the interconnected medical devices that we are increasingly seeing present across healthcare institutes are susceptible to the same security risks as traditional IT devices."</p><p>The report found that around 80 of England's 236 NHS trusts were affected by the ransomware, as well as more than 600 additional NHS organisations such as GP's practises. The incident - which was declared a major incident' by the NHS - resulted in the cancellation of almost 20,000 operations and hospital appointments.</p><p>Despite this, however, the DfH still has no estimate of how much money WannaCry cost the NHS, stating that its focus at the time was on caring for patients.</p><p>"We recognise that at the time of the attack the focus would have been on patient care rather than working out what WannaCry was costing the NHS," the report read. "However, an understanding of the financial impact on the NHS is also important to assess the seriousness of the attack and likely to be relevant to informing future investment decisions in cyber security."</p><p>Further facts about the NHS' troubling level of cyber security (both before and after WannaCry) were also revealed. For example, although the DfH, NHS England and NHS Improvement published a list of 22 recommendations for improving the NHS' cyber security back in February, plans to implement the recommendations have yet to be agreed upon, and the Department for Health still has no idea when it will happen or how much the process will cost.</p><p>One of the key issues faced by the NHS in keeping itself secure, the DfH told the committee, is that many local bodies are unable to apply updates and patches to IT systems without disrupting patient care, as many are interdependent on each other.</p><p>"Nearly one year on from the WannaCry cyber attack, it is clear that there is a need for constant vigilance within the NHS to ensure that patient data and vital systems are protected," said techUK's head of programme for Cyber and National Security, Talal Rajab.</p><p>"It is important to note that WannaCry was not just a wake-up call for the NHS, but for organisations across the public and private sector, to get their house in order and remain prepared in this era of heightened cyber tensions. Further sector-specific guidance can be found through the National Cyber Security Centre."</p><p>Some progress has been made, however; since WannaCry hit the NHS, the Department for Health has carved off nearly 200 million to invest in various improvements to cyber security up to 2020, including more support resources for vulnerable organisations, improvements to local infrastructure and addressing major security gaps in major trauma centres and ambulance trusts.</p><p>The committee set out a number of further recommendations for the Department for Health as part of the report, including that it should provide support and guidance for local healthcare organisations on how to efficiently patch systems with minimal disruption, as well as ensuring that staffing plans focus on IT and cyber security.</p><p>The report also recommended that all of the NHS' contracts IT and equipment vendors include guarantees for support and protection to guard against cyber attack.</p><p>Furthermore, the DfH is to provide the government by the end of June 2018 with an estimate for the cost of WannaCry to the NHS and a progress report on the implementation of the recommendations it made in February.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Scale of cyber risk to UK businesses is "bigger than ever" ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Reports out today have revealed the scale and severity of cybercrime threats facing UK businesses - with spyware the number one threat but ransomware and cryptomining detections rising sharply.</p><p>The National Cyber Security Centre (NCSC) and National Crime Agency (NCA) counted 34 significant attacks that required a cross-government response between October 2016 and the end of 2017, in addition to 762 less severe attacks across this period, in <a href="https://www.ncsc.gov.uk/cyberthreat" target="_blank">a joint report</a> released today.</p><p>Their report, titled 'The cyber threat to UK businesses 2017-2018', said 2018 would bring further attacks; warning vulnerabilities in Internet of Things (IoT) devices will grow, as well as highlighting the increased threat of crypto-jacking - where hackers force victims' computers <a href="https://www.itpro.com/web-browser/30780/is-your-browser-secretly-mining-cryptocurrencies" target="_blank" data-original-url="https://www.itpro.com/web-browser/30780/is-your-browser-secretly-mining-cryptocurrencies">to unwittingly mine cryptocurrencies</a> - and the growing temptation for attackers to target sensitive information stored on cloud services.</p><p>Major incidents in 2017 included ransomware and distributed denial of service (DDoS) attacks, massive data breaches, supply chain compromises, as well as fake news and information operations.</p><p>The NCSC said the risk to UK companies is "bigger than ever", and Ciaran Martin, NCSC chief executive, emphasised the need for public organisations to share knowledge to fend off attacks.</p><p>"We are fortunate to be able to draw on the cyber crime fighting expertise of our law enforcement colleagues in the National Crime Agency," he said. "This joint report brings together the combined expertise of the NCA and the NCSC. The key to better cyber security is understanding the problem and taking practical steps to reduce risk."</p><p>Raj Samani, chief scientist and fellow at cybersecurity firm McAfee, said sharing knowledge should extend to the private sector too. He said: "The NCSC rightly highlights the importance of collaboration in underpinning the UK's response to cyberattacks. One way to do this in in adopting threat intelligence sharing. In learning about the attacks that other similar organisations are facing, IT and security professionals can ensure that they are prepared to defend against the popular attacks of the day."</p><p><strong>Ransomware</strong></p><p>Verizon also released its 11th annual Data Breach Investigations Report today, the findings of which may prove somewhat unsurprising for those who have been keeping an eye on the security landscape over the last few years.</p><p>Predictably, ransomware was one of the biggest threats, becoming the most commonly-seen form of malware over the course of 2017, up from fourth place the previous year. One notable change, however, is that ransomware infections are increasingly affecting business-critical systems rather than just desktops.</p><p>Ali Neal, director of international security solutions at Verizon, told <em>IT Pro </em>that although these results may not be surprising, they are still significant. "We have to call out things whether they're obvious or slightly better-hidden; the ransomware piece is obviously something that's probably pretty obvious to everyone, but it has been notable in the number of incidents that it created."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/security/29614/ncsc-uk-hit-by-590-significant-cyber-attacks-last-year" data-original-url="/security/security/29614/ncsc-uk-hit-by-590-significant-cyber-attacks-last-year">NCSC: UK hit by 590 "significant" cyber attacks last year</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="/malware/28076/what-is-malware">What is malware?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-crime/30831/crypto-jacking-cyber-attacks-up-by-8500-says-symantec" data-original-url="/cyber-crime/30831/crypto-jacking-cyber-attacks-up-by-8500-says-symantec">'Crypto jacking' cyber attacks up by 8,500%, says Symantec</a></p></div></div><p>Also out today was Malwarebytes' <a href="https://blog.malwarebytes.com/malwarebytes-news/2018/04/labs-ctnt-report-shows-shift-in-threat-landscape-to-cryptomining" target="_blank">quarterly cybercrime report</a>, which outlined that while ransomware detections were up 28% between January and March 2018, it was only the sixth-highest detected threat with the overall volume remaining low - in contrast with the prominence placed on ransomware by the Verizon and NCSC reports, the latter of which highlighted <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">the WannaCry attack</a> as a high-profile example. Among consumers, ransomware detections actually declined 35%, according to Malwarebytes.</p><p>Malwarebytes' report said: "If you look at business detections after January, it looks like all malware activity has dropped off the side of a cliff. Spyware and riskware tools plummeted, though spyware retained the top spot by the hair of its chin."</p><p><strong>Cryptomining</strong></p><p>Among consumers, adware remains the key threat, while cryptomining saw a dramatic increase among business users - with incidents rising a staggering 4,000%, according to Malwarebytes.</p><p>The NCSC also identified the growing threat, writing: "We assume the majority of cryptojacking is carried out by cyber criminals, but website owners have also targeted visitors to their website and used the processing power of visitors' CPUs, without their knowledge or consent, to mine cryptocurrency for their own financial gain."</p><p>Bitcoin-mining hackers <a href="https://www.itpro.com/digital-currency/30511/bitcoin-mining-hackers-hit-government-websites" target="_blank" data-original-url="https://www.itpro.com/digital-currency/30511/bitcoin-mining-hackers-hit-government-websites">hit thousands of government websites</a>, including the Student Loans Company and other UK government bodies, it was revealed in March.</p><p><strong>Phishing</strong></p><p>Verizon found that phishing attacks remain a huge attack vector, and combined with financial pretexting, phishing tactics played a part in more than 90% of all breaches investigated last year. In fact, Verizon's report found that businesses are three times more likely to be compromised by a social engineering attack like phishing than by a technical vulnerability in their security.</p><p>Neal stated that businesses should be doing more to protect themselves, given that the same attack patterns and trends keep recurring, but noted that the area is a complex one.</p><p>"I don't think there's one answer," he said. "Better training has probably got to be point number one, because ultimately it's humans, and that goes to executives who are going to be particularly targeted. I think there is an opportunity to look at better email scanning, better policy enforcement, and there's also a number of technologies out there that can be implemented."</p><p>The NCSC highlighted business email compromise (BEC) as a form of phishing attack targeting senior business executives, where hackers <a href="https://www.itpro.com/security/29875/art-galleries-defrauded-by-simple-email-scam" target="_blank" data-original-url="https://www.itpro.com/security/29875/art-galleries-defrauded-by-simple-email-scam">impersonate business leaders</a> in an attempt to trick customers, vendors or staff to transfer funds and sensitive information.</p><p>"BEC scams are a serious threat to organisations of all sizes and across all sectors, including non-profit organisations and government. It represents one of the fastest growing, lowest cost, highest return cyber crime operations," the report said.</p><p><em>Image: Bigstock</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/cyber-crime/30911/scale-of-cyber-risk-to-uk-businesses-is-bigger-than-ever</link>
                                                                            <description>
                            <![CDATA[ Reports chart rise of ransomware and crypto-mining attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rDXqX9nfDdPNZ9wpXhXv3n</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CqULgbJTEkSR6HXKv8N3Cg-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 10 Apr 2018 11:01:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/CqULgbJTEkSR6HXKv8N3Cg-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber crime]]></media:description>                                                            <media:text><![CDATA[Cyber crime]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber crime]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CqULgbJTEkSR6HXKv8N3Cg-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Reports out today have revealed the scale and severity of cybercrime threats facing UK businesses - with spyware the number one threat but ransomware and cryptomining detections rising sharply.</p><p>The National Cyber Security Centre (NCSC) and National Crime Agency (NCA) counted 34 significant attacks that required a cross-government response between October 2016 and the end of 2017, in addition to 762 less severe attacks across this period, in <a href="https://www.ncsc.gov.uk/cyberthreat" target="_blank">a joint report</a> released today.</p><p>Their report, titled 'The cyber threat to UK businesses 2017-2018', said 2018 would bring further attacks; warning vulnerabilities in Internet of Things (IoT) devices will grow, as well as highlighting the increased threat of crypto-jacking - where hackers force victims' computers <a href="https://www.itpro.com/web-browser/30780/is-your-browser-secretly-mining-cryptocurrencies" target="_blank" data-original-url="https://www.itpro.com/web-browser/30780/is-your-browser-secretly-mining-cryptocurrencies">to unwittingly mine cryptocurrencies</a> - and the growing temptation for attackers to target sensitive information stored on cloud services.</p><p>Major incidents in 2017 included ransomware and distributed denial of service (DDoS) attacks, massive data breaches, supply chain compromises, as well as fake news and information operations.</p><p>The NCSC said the risk to UK companies is "bigger than ever", and Ciaran Martin, NCSC chief executive, emphasised the need for public organisations to share knowledge to fend off attacks.</p><p>"We are fortunate to be able to draw on the cyber crime fighting expertise of our law enforcement colleagues in the National Crime Agency," he said. "This joint report brings together the combined expertise of the NCA and the NCSC. The key to better cyber security is understanding the problem and taking practical steps to reduce risk."</p><p>Raj Samani, chief scientist and fellow at cybersecurity firm McAfee, said sharing knowledge should extend to the private sector too. He said: "The NCSC rightly highlights the importance of collaboration in underpinning the UK's response to cyberattacks. One way to do this in in adopting threat intelligence sharing. In learning about the attacks that other similar organisations are facing, IT and security professionals can ensure that they are prepared to defend against the popular attacks of the day."</p><p><strong>Ransomware</strong></p><p>Verizon also released its 11th annual Data Breach Investigations Report today, the findings of which may prove somewhat unsurprising for those who have been keeping an eye on the security landscape over the last few years.</p><p>Predictably, ransomware was one of the biggest threats, becoming the most commonly-seen form of malware over the course of 2017, up from fourth place the previous year. One notable change, however, is that ransomware infections are increasingly affecting business-critical systems rather than just desktops.</p><p>Ali Neal, director of international security solutions at Verizon, told <em>IT Pro </em>that although these results may not be surprising, they are still significant. "We have to call out things whether they're obvious or slightly better-hidden; the ransomware piece is obviously something that's probably pretty obvious to everyone, but it has been notable in the number of incidents that it created."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/security/29614/ncsc-uk-hit-by-590-significant-cyber-attacks-last-year" data-original-url="/security/security/29614/ncsc-uk-hit-by-590-significant-cyber-attacks-last-year">NCSC: UK hit by 590 "significant" cyber attacks last year</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="/malware/28076/what-is-malware">What is malware?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-crime/30831/crypto-jacking-cyber-attacks-up-by-8500-says-symantec" data-original-url="/cyber-crime/30831/crypto-jacking-cyber-attacks-up-by-8500-says-symantec">'Crypto jacking' cyber attacks up by 8,500%, says Symantec</a></p></div></div><p>Also out today was Malwarebytes' <a href="https://blog.malwarebytes.com/malwarebytes-news/2018/04/labs-ctnt-report-shows-shift-in-threat-landscape-to-cryptomining" target="_blank">quarterly cybercrime report</a>, which outlined that while ransomware detections were up 28% between January and March 2018, it was only the sixth-highest detected threat with the overall volume remaining low - in contrast with the prominence placed on ransomware by the Verizon and NCSC reports, the latter of which highlighted <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">the WannaCry attack</a> as a high-profile example. Among consumers, ransomware detections actually declined 35%, according to Malwarebytes.</p><p>Malwarebytes' report said: "If you look at business detections after January, it looks like all malware activity has dropped off the side of a cliff. Spyware and riskware tools plummeted, though spyware retained the top spot by the hair of its chin."</p><p><strong>Cryptomining</strong></p><p>Among consumers, adware remains the key threat, while cryptomining saw a dramatic increase among business users - with incidents rising a staggering 4,000%, according to Malwarebytes.</p><p>The NCSC also identified the growing threat, writing: "We assume the majority of cryptojacking is carried out by cyber criminals, but website owners have also targeted visitors to their website and used the processing power of visitors' CPUs, without their knowledge or consent, to mine cryptocurrency for their own financial gain."</p><p>Bitcoin-mining hackers <a href="https://www.itpro.com/digital-currency/30511/bitcoin-mining-hackers-hit-government-websites" target="_blank" data-original-url="https://www.itpro.com/digital-currency/30511/bitcoin-mining-hackers-hit-government-websites">hit thousands of government websites</a>, including the Student Loans Company and other UK government bodies, it was revealed in March.</p><p><strong>Phishing</strong></p><p>Verizon found that phishing attacks remain a huge attack vector, and combined with financial pretexting, phishing tactics played a part in more than 90% of all breaches investigated last year. In fact, Verizon's report found that businesses are three times more likely to be compromised by a social engineering attack like phishing than by a technical vulnerability in their security.</p><p>Neal stated that businesses should be doing more to protect themselves, given that the same attack patterns and trends keep recurring, but noted that the area is a complex one.</p><p>"I don't think there's one answer," he said. "Better training has probably got to be point number one, because ultimately it's humans, and that goes to executives who are going to be particularly targeted. I think there is an opportunity to look at better email scanning, better policy enforcement, and there's also a number of technologies out there that can be implemented."</p><p>The NCSC highlighted business email compromise (BEC) as a form of phishing attack targeting senior business executives, where hackers <a href="https://www.itpro.com/security/29875/art-galleries-defrauded-by-simple-email-scam" target="_blank" data-original-url="https://www.itpro.com/security/29875/art-galleries-defrauded-by-simple-email-scam">impersonate business leaders</a> in an attempt to trick customers, vendors or staff to transfer funds and sensitive information.</p><p>"BEC scams are a serious threat to organisations of all sizes and across all sectors, including non-profit organisations and government. It represents one of the fastest growing, lowest cost, highest return cyber crime operations," the report said.</p><p><em>Image: Bigstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A quarter of UK councils 'have been hacked' ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Over a quarter of all UK councils have had their IT systems breached in the past five years, according to privacy campaign group Big Brother Watch.</p><p><a href="https://www.itpro.com/policy-legislation/30218/what-is-a-freedom-of-information-foi-request" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/30218/what-is-a-freedom-of-information-foi-request">Freedom of information requests</a> sent by the group found that 114 councils experienced at least one incident between 2013 and 2017, as well as more than 98 million cyber attacks on local councils in total across the country.</p><p>This amounts to 37 cyber attacks launched every minute on the local governments, with successful attempts potentially giving hackers access to the sensitive and personal information of UK citizens, said <a href="https://bigbrotherwatch.org.uk/about">Big Brother Watch</a> in its <em><a href="https://bigbrotherwatch.org.uk/wp-content/uploads/2018/02/Cyber-attacks-in-local-authorities.pdf" target="_blank">'Cyber attacks in local authorities'</a></em> report.</p><p>Worst yet, the report uncovers the councils' failure to report losses and breaches of data - <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">which organisations must do within 72 hours under GDPR</a>, though currently do not have to under UK law - as well as shortcomings in staff training.</p><p>It found that despite human error being the main factor in a successful hack, 75% of local authorities said their staff don't undergo compulsory cyber security training.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/30470/all-200-nhs-trusts-fail-latest-cybersecurity-standards" data-original-url="/wannacry/30470/all-200-nhs-trusts-fail-latest-cybersecurity-standards">All 200 NHS trusts fail latest cybersecurity standards</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29075/newcastle-city-council-blames-human-error-for-data-breach" data-original-url="/security/29075/newcastle-city-council-blames-human-error-for-data-breach">Newcastle City Council blames human error for data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28844/gloucester-city-council-fined-100000-over-heartbleed-hack" data-original-url="/security/28844/gloucester-city-council-fined-100000-over-heartbleed-hack">Gloucester City Council fined £100,000 over Heartbleed hack</a></p></div></div><p>Jennifer Krueckeberg, lead researcher at Big Brother Watch, said: "With councils hit by over 19 million cyber attacks every year, one would assume that they would be doing their utmost to protect citizens' sensitive information.</p><p>"We are shocked to discover that the majority of councils' data breaches go unreported and that staff often lack basic training in cyber security. Local authorities need to take urgent action and make sure they fulfil their responsibilities to protect citizens."</p><p>Newcastle City Council blamed human error <a href="https://www.itpro.com/security/29075/newcastle-city-council-blames-human-error-for-data-breach" target="_blank" data-original-url="https://www.itpro.com/security/29075/newcastle-city-council-blames-human-error-for-data-breach">for a breach that saw thousands of adopted children's data leaked</a> in an email attachment last summer, while <a href="https://www.itpro.com/security/28844/gloucester-city-council-fined-100000-over-heartbleed-hack" target="_blank" data-original-url="https://www.itpro.com/security/28844/gloucester-city-council-fined-100000-over-heartbleed-hack">the Information Commissioner's Office (ICO) fined Gloucester City Council 100,000</a> for falling foul of the Heartbleed hack in 2014.</p><p>Raj Samani, chief scientist and fellow at McAfee, criticised the councils for failing to inform citizens of breaches.</p><p>"Unless made aware, potential victims the citizens that they're serving are unable to protect themselves, whether by changing passwords or more closely monitoring for instances of fraud," he said.</p><p>"That said, we will gain nothing by pointing the finger at the IT and security teams. Managing the growing and evolving against a background backdrop of squeezed budgets, local authorities are having to make difficult choices about where their investments should be made."</p><p>Samani added that one solution to this is through automating certain processes, such as removing simple repetitive activities that enable them to put their energy into planning their defences against the wider threat landscape.</p><p>The failure of local authorities to protect against malicious online activity against them comes just after the <a href="https://www.itpro.com/wannacry/30470/all-200-nhs-trusts-fail-latest-cybersecurity-standards" target="_blank" data-original-url="https://www.itpro.com/wannacry/30470/all-200-nhs-trusts-fail-latest-cybersecurity-standards">UK's Department of Health admitted</a> that all 200 NHS trusts assessed for cyber security vulnerabilities failed to meet the required standards, following the devastating <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">WannaCry ransomware attack</a> last summer.</p><p>The malware affected 300,000 computers in 150 countries in May last year, including 48 NHS trusts, also shutting down multiple hospital IT systems as well as companies and universities elsewhere.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/data-breaches/30583/a-quarter-of-uk-councils-have-been-hacked</link>
                                                                            <description>
                            <![CDATA[ Local authorities experience 19 million cyber attacks every year, finds report ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gJesr5d6zpSXTh8gcAGwkS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CmhCUGwY8B2Bo8TuWuApnV-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 20 Feb 2018 11:37:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Lee Bell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/CmhCUGwY8B2Bo8TuWuApnV-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CmhCUGwY8B2Bo8TuWuApnV-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Over a quarter of all UK councils have had their IT systems breached in the past five years, according to privacy campaign group Big Brother Watch.</p><p><a href="https://www.itpro.com/policy-legislation/30218/what-is-a-freedom-of-information-foi-request" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/30218/what-is-a-freedom-of-information-foi-request">Freedom of information requests</a> sent by the group found that 114 councils experienced at least one incident between 2013 and 2017, as well as more than 98 million cyber attacks on local councils in total across the country.</p><p>This amounts to 37 cyber attacks launched every minute on the local governments, with successful attempts potentially giving hackers access to the sensitive and personal information of UK citizens, said <a href="https://bigbrotherwatch.org.uk/about">Big Brother Watch</a> in its <em><a href="https://bigbrotherwatch.org.uk/wp-content/uploads/2018/02/Cyber-attacks-in-local-authorities.pdf" target="_blank">'Cyber attacks in local authorities'</a></em> report.</p><p>Worst yet, the report uncovers the councils' failure to report losses and breaches of data - <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">which organisations must do within 72 hours under GDPR</a>, though currently do not have to under UK law - as well as shortcomings in staff training.</p><p>It found that despite human error being the main factor in a successful hack, 75% of local authorities said their staff don't undergo compulsory cyber security training.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/wannacry/30470/all-200-nhs-trusts-fail-latest-cybersecurity-standards" data-original-url="/wannacry/30470/all-200-nhs-trusts-fail-latest-cybersecurity-standards">All 200 NHS trusts fail latest cybersecurity standards</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29075/newcastle-city-council-blames-human-error-for-data-breach" data-original-url="/security/29075/newcastle-city-council-blames-human-error-for-data-breach">Newcastle City Council blames human error for data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28844/gloucester-city-council-fined-100000-over-heartbleed-hack" data-original-url="/security/28844/gloucester-city-council-fined-100000-over-heartbleed-hack">Gloucester City Council fined £100,000 over Heartbleed hack</a></p></div></div><p>Jennifer Krueckeberg, lead researcher at Big Brother Watch, said: "With councils hit by over 19 million cyber attacks every year, one would assume that they would be doing their utmost to protect citizens' sensitive information.</p><p>"We are shocked to discover that the majority of councils' data breaches go unreported and that staff often lack basic training in cyber security. Local authorities need to take urgent action and make sure they fulfil their responsibilities to protect citizens."</p><p>Newcastle City Council blamed human error <a href="https://www.itpro.com/security/29075/newcastle-city-council-blames-human-error-for-data-breach" target="_blank" data-original-url="https://www.itpro.com/security/29075/newcastle-city-council-blames-human-error-for-data-breach">for a breach that saw thousands of adopted children's data leaked</a> in an email attachment last summer, while <a href="https://www.itpro.com/security/28844/gloucester-city-council-fined-100000-over-heartbleed-hack" target="_blank" data-original-url="https://www.itpro.com/security/28844/gloucester-city-council-fined-100000-over-heartbleed-hack">the Information Commissioner's Office (ICO) fined Gloucester City Council 100,000</a> for falling foul of the Heartbleed hack in 2014.</p><p>Raj Samani, chief scientist and fellow at McAfee, criticised the councils for failing to inform citizens of breaches.</p><p>"Unless made aware, potential victims the citizens that they're serving are unable to protect themselves, whether by changing passwords or more closely monitoring for instances of fraud," he said.</p><p>"That said, we will gain nothing by pointing the finger at the IT and security teams. Managing the growing and evolving against a background backdrop of squeezed budgets, local authorities are having to make difficult choices about where their investments should be made."</p><p>Samani added that one solution to this is through automating certain processes, such as removing simple repetitive activities that enable them to put their energy into planning their defences against the wider threat landscape.</p><p>The failure of local authorities to protect against malicious online activity against them comes just after the <a href="https://www.itpro.com/wannacry/30470/all-200-nhs-trusts-fail-latest-cybersecurity-standards" target="_blank" data-original-url="https://www.itpro.com/wannacry/30470/all-200-nhs-trusts-fail-latest-cybersecurity-standards">UK's Department of Health admitted</a> that all 200 NHS trusts assessed for cyber security vulnerabilities failed to meet the required standards, following the devastating <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">WannaCry ransomware attack</a> last summer.</p><p>The malware affected 300,000 computers in 150 countries in May last year, including 48 NHS trusts, also shutting down multiple hospital IT systems as well as companies and universities elsewhere.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NotPetya ransomware: White House joins UK in blaming Russia for NotPetya cyberattack ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The US White House joined the UK in blaming Russia for the malicious NotPetya ransomware attack on Ukraine that crippled parts of the country's infrastructure before spreading globally last year.</p><p>The White House's Press Secretary Sarah Sanders said the attack, launched in June 2017 by the Russian military, "spread worldwide, causing billions of dollars in damage across Europe, Asia and the Americas", according to <a href="https://uk.reuters.com/article/uk-britain-russia-cyber/white-house-blames-russia-for-reckless-notpetya-cyber-attack-idUKKCN1FZ0PR">Reuters</a>.</p><p>"It was part of the Kremlin's ongoing effort to destabilise Ukraine and demonstrates ever more clearly Russia's involvement in the ongoing conflict. This was also a reckless and indiscriminate cyber attack that will be met with international consequences," Sanders added. </p><p>The White House's statement is the first time the US has blamed Russia for what is considered one of the worst cyber attacks ever recorded, while many other security experts had pointed the finger at Moscow months ago. It comes just days after US intelligence agency leaders warned that Russia is likely to try and use cyber attacks as a means to meddle in the US midterm elections in November.</p><p>A senior White House official added that the US government is now "reviewing a range of options" in how to respond to the findings. </p><p>The NotPetya attack, as with the WannaCry attack which also caused major damage last year, demonstrated the need for organisations to be vigilant, keep their systems updated and incorporate a visibility-based security posture. </p><p>"Companies need greater visibility into their networks to detect and remediate incidents and malware attacks," said security architect at <a href="http://www.gigamon.com" target="_blank" rel="noopener noreferrer">Gigamon</a>, Simon Gibson, at the time. "The inability to investigate and detect the spread of the attack across computer networks is greatly impacting critical infrastructures."</p><p>He warned that organisations need to ensure they have complete visibility over their networks so that they can assess vulnerabilities and detect outdated SMB running on a network.</p><p>"To build better defenses, a visibility platform enables better detection and remediation from security tools. Organisations need to be able to get the right information to the right security tools so they can better detect and rapidly respond to ransomware attacks," noted Gibson. </p><p><strong>15/02/2018: UK publicly blames Russia for NotPetya ransomware campaign</strong></p><p>The UK Foreign Office has publicly blamed Russia for the NotPetya ransomware attack that infected companies and public services across Europe and the US last summer.</p><p>The ransomware first emerged in June when Ukrainian banks, government facilities and corporate systems were hit by a coordinated cyber attack, only for it then to spread to sites in Germany, Italy, Poland, the UK, the US, and Russia.</p><p>The UK <a href="https://www.gov.uk/government/news/foreign-office-minister-condemns-russia-for-notpetya-attacks" target="_blank">now believes</a> that the Russian military was responsible for the attack, adding that it would not tolerate such malicious cyber activity.</p><p>UK-based Reckitt Benckiser, which produces brands such as Dettol and Durex, was hit by the ransomware in late June, and has estimated a 100 million loss as a result of system downtime and disrupted manufacturing output.</p><p>Courier service TNT was also locked out of its systems during the campaign, with sources inside the company revealing to <em>the</em> <em>Guardian</em> at the time that a "significant portion" of operations were having to be handled manually.</p><p>"The UK Government judges that the Russian Government, specifically the Russian military, was responsible for the destructive NotPetya cyber-attack of June 2017," said Foreign Office minister Lord Ahmad. "The attack showed a continued disregard for Ukrainian sovereignty. Its reckless release disrupted organisations across Europe costing hundreds of millions of pounds."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack" data-original-url="/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack">No-one is blameless when it comes to the NHS WannaCry hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched" data-original-url="/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched">Shadow Brokers: Microsoft Windows flaws were already patched</a></p></div></div><p>"The Kremlin has positioned Russia in direct opposition to the West yet it doesn't have to be that way. We call upon Russia to be the responsible member of the international community it claims to be rather then (sic) secretly trying to undermine it."</p><p>Research by the National Cyber Security Centre concluded that the Russian military was "almost certainly responsible" for the ransomware attack, which was enough for the UK to publicly blame its government.</p><p>The attacks were largely seen as being politically motivated, having started on the eve of Ukraine's Constitution Day. As such, Ukraine was quick to publicly blame Russia for the attacks and claimed its internal security service, the SBU, obtained evidence that the ransomware attack was deliberately designed to look like a global virus while specifically targeting Ukrainian systems.</p><p>Russia has always denied responsibility for the <a href="https://www.itpro.com/security/28084/what-is-ransomware" target="_blank" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> and has pointed to the fact that Russian systems were also targeted in the attack.</p><p>The attack was initially thought to have used the Petya malware, which first emerged in 2016, however, analysis of the strain found it to be an entirely different family that had been designed to spread far more quickly between targets.</p><p>Kaspersky Lab believes around 2,000 attacks were launched using the malware, with as much as 80% of these being in Ukraine or Russia.</p><p>Defence secretary Gavin Williamson described the attacks as being part of a "new era of warfare" that Britain needed to be ready to respond to.</p><p>"Russia is ripping up the rulebook by undermining democracy, wrecking livelihoods by targeting critical infrastructure and weaponising information." said Williamson, in a statement to the press. "We must be primed and ready to tackle these stark and intensifying threats."</p><p>Parliament's Intelligence and Security Committee revealed in November that it was considering launching an investigation into Russian activity against the UK, including allegations of Russian meddling during the Brexit referendum.</p><p><strong>25/07/2017: TNT customers experience delivery delays after cyber attack</strong></p><p>TNT is reportedly still suffering from the effects of the NotPetya cyber attack last month, with customers being told that parcels are "going up to the ceiling" at some delivery centres.</p><p>The FedEx-owned shipping firm was one of thousands of businesses affected by the ransomware attack in June, which left computer systems crippled and many customers facing severe delays in receiving parcels.</p><p>In a <a href="http://about.van.fedex.com/newsroom/global-english/fedex-files-10-k-additional-disclosure-cyber-attack-affecting-tnt-express-systems" target="_blank">statement</a> released on 17 July, FedEx said that TNT systems had been compromised after an initial infection of its Ukraine operations had spread throughout its network. FedEx also said that all TNT depots, hubs and facilities had since resumed normal service, although a "significant portion of TNT operations and customer service functions" were being handled manually.</p><p>"We cannot yet estimate how long it will take to restore the systems that were impacted, and it is reasonably possible that TNT will be unable to fully restore all of the affected systems and recover all of the critical business data that was encrypted by the virus," added FedEx.</p><p>A week later, it appears that the company is still struggling to deal with the backlog of deliveries, as customers have now been told by TNT staff that consignments are "going up to the ceiling" at its East Midlands hub, according to the <a href="https://www.theguardian.com/money/2017/jul/25/tnt-parcels-cyber-attack-courier-fedex-notpetya" target="_blank"><em>Guardian</em></a>.</p><p>"TNT tell me they have had no computer systems since the end of June and there is no estimate for when their systems will be fixed," said TNT customer Peter Blohm, speaking to the <em>Guardian</em>.</p><p>"This means there are many thousands of parcels which have like mine been waiting for weeks to be processed by hand with pen and paper. The staff sound harassed, but cannot estimate when my parcel will be delivered, because they simply do not know."</p><p>A TNT spokesperson declined to comment on these reports when contacted by <em>IT Pro</em>, adding that there were no further updates from the statement released last week.</p><p>FedEx, which agreed to buy TNT in 2015, said it was still trying to establish the financial impact of NotPetya, admitting that it did not have adequate insurance policies in place to cover an attack of this kind.</p><p>"Although we cannot currently quantify the amounts, we have experienced loss of revenue due to decreased volumes at TNT and incremental costs associated with the implementation of contingency plans and the remediation of affected systems," said FedEx.</p><p>A recent <a href="https://www.itpro.com/security/29064/cyber-attacks-could-cost-the-global-economy-40-billion" target="_blank" data-original-url="https://www.itpro.com/security/29064/cyber-attacks-could-cost-the-global-economy-40-billion">report by Lloyd's of London</a> said that a major global cyber attack could cost the world economy 40 billion, but because companies are 'underinsuring' their systems, as much as 34 billion of that may not be covered.</p><p><strong>10/07/2017:</strong> Germany's federal cyber agency said that the threat posed to firms by the Petya ransomware was greater than expected, warning that data backups carried out since April should be considered compromised.</p><p>The BSI (Federal Office for Information Security) said in a statement that computer experts had discovered the waves of attacks had been launched via software updates of the MeDoc accounting software dating back to April, as reported by <a href="https://www.reuters.com/article/us-cyber-attack-ukraine-germany-idUSKBN19S1EU" target="_blank"><em>Reuters</em></a>.</p><p>Companies using this software may have been infected even if there were no obvious signs of a breach, the BSI added, with any data backups carried out after 13 April potentially an issue.</p><p>BSI president Arne Schoenbohm said: "Some German firms have seen production and other critical processes laid still for over a week." He added: "It has resulted in millions of euros of damage, and this in a case where Germany got off lightly."</p><p>Schoenbohm stated that the attacks were at least as harmful as the <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">WannaCry ransomware attacks</a> from May.</p><p>The agency has urged German companies to separate networks which had the MeDoc software installed, to increase network surveillance and to look out for any signs of compromise. It also underlined the importance of changing passwords and updating software for all infected networks.</p><p>Police last week seized servers from which they believe the ransomware attack originated. They belong to the Ukrainian software firm that created MeDoc, though the company disputes whether its software carried Petya.</p><p>"We studied and analysed our product for signs of hacking," Intellect Service's managing partner Olesya Linnik said in an interview with <em>Reuters</em>. "It is not infected with a virus and everything is fine, it is safe".</p><p>"The update package, which was sent out long before the virus was spread," she said, "we checked it 100 times and everything is fine."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack" data-original-url="/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack">No-one is blameless when it comes to the NHS WannaCry hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched" data-original-url="/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched">Shadow Brokers: Microsoft Windows flaws were already patched</a></p></div></div><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/882683628504977411"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/882683628504977411"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Police launched an operation on Intellect Service, publisher of Ukraine's popular accounting software, MeDoc. The servers were seized and the police warned the company and its employees may face criminal charges over the attack.</p><p>German security officials are still investigating the origin of the attack and do not have evidence to confirm the claim by the Ukrainian government that Russia was behind it.</p><p><strong>06/07/2017: </strong>Nurofen and Dettol maker estimates 100m loss from Petya</p><p>Reckitt Benckiser, the maker of Nurofen painkillers, said it estimates a 100m loss in revenue as a result of the Petya ransomware attack.</p><p>The company, which also manufactures Durex condoms and Dettol cleaning products, said the attack on 27 June affected a number of its production plants, preventing the company from fulfilling orders.</p><p>"Consequently, we were unable to ship and invoice some orders to customers prior to the close of the quarter," the UK-based company said a widely reported statement. "Some of our factories are currently still not operating normally but plans are in place to return to full operation."</p><p>"We expect that some of the revenue lost from the second quarter will be recovered in the third quarter," the company added. "However, the continued production difficulties in some factories mean that we also expect to lose some further revenue permanently."</p><p>While the ransom demand was only $300, the news demonstrates the wider ranging impact that a malware attack can have on a company's systems - in this case, a catastrophic failure of a supply network.</p><p>Shares in the company fell as much as 3% following today's news, and are still 1.5% down at the time of writing. Reckitt said it's still assessing the long-term financial impact of the attack.</p><p>Reckitt Benckiser, which is headquartered in Slough, employs around 37,000 people through operations in more than 60 countries, although its products are available in over 200. It also counts Harpic, Cilit Bang, Strepsils and Clearasil among the brands it currently manufactures and recently acquired US-based children's formula maker Mead Johnson for $16.6 billion.</p><p>Some of the world's largest companies were hit by the attack, including Russian oil giant Rosneft, international shipping firm Maersk, and a number of Ukrainian banks.</p><p><strong>05/07/2017: Ukraine cyber police seizes suspected Petya servers</strong></p><p>Servers linked to the global spread of the Petya ransomware outbreak have been seized <a href="https://cyberpolice.gov.ua/news/prykryttyam-najmasshtabnishoyi-kiberataky-v-istoriyi-ukrayiny-stav-virus-diskcoderc-881" target="_blank">by the Ukrainian police's cybercrime division</a>, after the malware was traced back to a small Ukrainian software firm.</p><p>Police swooped on the small family-run business Intellect Service, publisher of Ukraine's popular accounting software, MeDoc. Seizing the firm's servers, police warned that the company and its employees may face criminal charges over the attack.</p><p>While Intellect Service is not accused of being the architects behind the ransomware outbreak, experts have pointed to the company as being 'patient zero', acting as the source of the epidemic.</p><p>The authors of the ransomware likely hacked Intellect Service and used MeDoc's automatic update feature in order to spread the infection, according to <a href="https://www.malwaretech.com/2017/06/petya-ransomware-attack-whats-known.html" target="_blank">multiple security firms and malware researchers</a>.</p><p>However, some suggest the malware MeDoc allegedly spread wasn't Petya, but a similar variation upon it, designed to destroy Ukraine organisations' data.</p><p>The head of Ukraine's cybercrime unit, Colonel Serhiy Demydiuk stated that Intellect Service was warned multiple times by security experts that their IT systems were at risk of a security breach.</p><p>"They knew about it," he told the <a href="https://apnews.com/8b02768224de485eb4e7b33ae55b02f2" target="_blank"><em>Associated Press</em></a>. "They were told many times by various antivirus firms... For this neglect, the people in this case will face criminal responsibility."</p><p>"We have issues with the company's leadership, because they knew there was a virus in their software but didn't do anything," Demydiuk told <a href="http://www.reuters.com/article/us-cyber-attack-ukraine-software-idUSKBN19O2DK?il=0" target="_blank"><em>Reuters</em></a>.</p><p>"We studied and analysed our product for signs of hacking," Intellect Service's managing partner Olesya Linnik said in an interview with <em>Reuters</em>. "It is not infected with a virus and everything is fine, it is safe".</p><p>"The update package, which was sent out long before the virus was spread," she said, "we checked it 100 times and everything is fine."</p><p>"Cyberpolice Department strongly recommends all users at the time of the investigation, to stop using the software "MEDoc" and turn off the computer on which it is installed on the network," Ukraine's Cyberpolice unit said in a <a href="https://cyberpolice.gov.ua/news/prykryttyam-najmasshtabnishoyi-kiberataky-v-istoriyi-ukrayiny-stav-virus-diskcoderc-881" target="_blank">statement</a>. "You must also change their passwords and electronic digital signatures, due to the fact that these data could be compromised.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack" data-original-url="/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack">No-one is blameless when it comes to the NHS WannaCry hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched" data-original-url="/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched">Shadow Brokers: Microsoft Windows flaws were already patched</a></p></div></div><p><strong>03/07/2017: Ukraine blames Russian security forces for Petya ransomware</strong></p><p>Ukraine claimed that the Russian security services were behind the Petya cyber attack which affected businesses worldwide last week.</p><p>Ukraine's security service, the SBU, has linked Petya to the December 2016 cyber attack in Ukraine where the <a href="https://www.itpro.com/malware/25804/ukrainian-power-grid-downed-by-cyber-attack" target="_blank" data-original-url="https://www.itpro.com/malware/25804/ukrainian-power-grid-downed-by-cyber-attack">power grid was downed</a> and affected roughly 700,000 homes. The SBU has obtained data from various international anti-virus companies which links the two attacks.</p><p>The security service also stated that the attack was designed to creat the impression of a ransomware virus, but was an attack specifically targeted at Ukraine. The SBU said: "In fact, the virus is a cover of [a] large-scale attack, oriented against Ukraine."</p><p>It said the main target of the virus was to destroy important data and create disorder in Ukraine in order to spread panic.</p><p>According to <a href="https://uk.reuters.com/article/us-cyber-attack-ukraine-idUKKBN19M39P" target="_blank"><em>Reuters</em></a>, various cyber security researchers have suggested Moscow was not behind the attack as some major Russian firms were affected by the ransomware. Moscow has also denied any involvement, which a Kremlin spokesperson dismissed as "unfounded blanket accusations".</p><p>The cyberattack, which has various names including Petya and NotPetya, locked down corporate computers in Europe and the US last week. It demanded $300 in Bitcoin payment for a user to unlock their files, but the attackers' email account was shut down meaning victims probably won't get their data decrypted. A number of experts have said that the attack was deliberately malicious and spread fast to cause damage using the cover of ransomware.</p><p><strong>28/06/2017: Vaccine may hinder Petya spread</strong></p><p>Security researchers have chanced upon a workaround solution that disables the Petya ransomware that's wreaked havoc on computers around the world.</p><p>According to a <a href="https://www.cybereason.com/blog-cybereason-discovers-notpetya-kill-switch">blog post</a> by IT security firm Cybereason, its principle security researcher Amit Serper discovered that creating a file named "perfc", with no extension name and placing it in the C:\windows\ folder. The file has to be read-only for the method to work.</p><p>The ransomware searches for its own filename in the C:\windows\ folder, and if it is found, will cease running, according to security researchers.</p><p>Cybereason said that once the original file name was found and verified by two different sources, Serper was able to piece together a kill switch that should work for any instance of the original ransomware infection. While this does not stop the ransomware if it is already running, it will act as a vaccination, stopping it from ever trying to encrypt files.</p><p>While Petya infects PCs around the world, Kroll Ontrack believed that some data may still be salvaged from infected computers without paying a ransom. </p><p>According to Phil Bridge, managing director, Western Europe of Data & Storage Technologies at Kroll Ontrack, said that the malware does not encrypt all the files on your computer but instead attacks a part of the operating system called the Master File Table (MFT), an essential index' for the computer system to locate files on the computer.</p><p>"Attacking one part of the system (the MFT) is much faster than targeting all the individual files but the result is as if each file had been locked separately," he said.</p><p>He added that there is a method to decrypt the original Petya ransomware, but one has not yet been released for the updated version. He said that "some data may still be salvaged from infected computers with the use of specialist data recovery techniques.</p><p><strong>28/06/2017: Petya ransomware: attack hits global companies</strong></p><p>A ransomware attack has locked down corporate computers throughout Europe and the US, a month after the NHS and other organisations <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">were knocked offline by WannaCry</a>. </p><p>Called Petya as well as NotPetya by some, <a href="https://www.itpro.com/malware/27866/goldeneye-ransomware-disguised-as-job-application" data-original-url="https://www.itpro.com/malware/27866/goldeneye-ransomware-disguised-as-job-application">and Goldeneye, by others</a> has reportedly hit thousands of machines, including at advertising giant WPP, Danish transport firm AP Moller-Maersk, and Russian oil firm Rosneft, as well as at least one hospital firm in the US.</p><p>It appears to have initially infected machines via accounting software that companies use to link to the Ukrainian government, with huge swathes of that country's companies and government bodies wiped offline. While the country's Twitter feed made light of the situation, some of the shutdown was alarming including Chernobyl radiation monitoring being done by hand.</p><p>Once in, Petya then spreads via the EternalBlue vulnerability in Windows that has been patched but given the carnage, it appears not everyone has updated. That was the same exploit used by WannaCry's hackers, and was developed by the NSA <a href="https://www.itpro.com/security/27114/cisco-confirms-shadow-brokers-vulnerabilities-are-real" data-original-url="https://www.itpro.com/security/27114/cisco-confirms-shadow-brokers-vulnerabilities-are-real">but leaked in April</a>.</p><p>"As far as the EternalBlue exploit, the worm code appears to heavily borrow from WannaCry, including taking advantage of the same EternalBlue exploit code to move around once it is inside the network," said Allan Liska, intelligence architect at Recorded Future. "In addition to the EternalBlue exploit, the new attack appears to take advantage of WMIC for lateral movement. WMIC (Windows Management Instrumentation Command-line) is a command line tool that is used to execute system management commands on Windows."</p><p>One difference with WannaCry is it lacks an apparent "kill switch" that halted May's ransomware outbreak. "Some are comparing this to WannaCry 2.0 but this version does not have the "kill-switch" that the original WannaCry did. Thus, we should not expect any oddity like that to slow this attack," said Brian Hussey, VP of cyber threat detection and response at Trustwave.</p><p>This variant demands $300 in Bitcoin payment from users of infected machines as ransom to unlock their data. However, the <a href="https://motherboard.vice.com/en_us/article/new8xw/hacker-behind-massive-ransomware-outbreak-cant-get-emails-from-victims-who-paid">German email provider, Posteo, that runs the attackers' email account, has shut it down</a>, so victims likely won't be getting their data decrypted.</p><p>To Nicholas Weaver, security researcher at the International Computer Science Institute, that suggests there may be more to Petya. "I'm willing to say with at least moderate confidence that this was a deliberate, malicious, destructive attack or perhaps a test disguised as ransomware," <a href="https://krebsonsecurity.com/2017/06/petya-ransomware-outbreak-goes-global">Weaver told <em>KrebsonSecurity</em></a>. "The best way to put it is that Petya's payment infrastructure is a fecal theater."</p><p>Matthew Hickley, co-founder of My HackerHouse, said if your computer does force a reboot and show the following screen, turn your PC off to halt the encryption process.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/879793827267174400"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/879793827267174400"></a></p></blockquote></figure><div class="see-more__filter"></div></div><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack" data-original-url="/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack">No-one is blameless when it comes to the NHS WannaCry hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched" data-original-url="/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched">Shadow Brokers: Microsoft Windows flaws were already patched</a></p></div></div> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/28940/notpetya-ransomware</link>
                                                                            <description>
                            <![CDATA[ US government claims to be “reviewing a range of options" in response to the findings ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tPdYLugg5DCRTJhgwPYtsd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/svUVsAqkmkk66YmdyykvXJ-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 Feb 2018 09:41:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Lee Bell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/svUVsAqkmkk66YmdyykvXJ-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A padlock laid on top of a circuit board.]]></media:description>                                                            <media:text><![CDATA[A padlock laid on top of a circuit board.]]></media:text>
                                <media:title type="plain"><![CDATA[A padlock laid on top of a circuit board.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/svUVsAqkmkk66YmdyykvXJ-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US White House joined the UK in blaming Russia for the malicious NotPetya ransomware attack on Ukraine that crippled parts of the country's infrastructure before spreading globally last year.</p><p>The White House's Press Secretary Sarah Sanders said the attack, launched in June 2017 by the Russian military, "spread worldwide, causing billions of dollars in damage across Europe, Asia and the Americas", according to <a href="https://uk.reuters.com/article/uk-britain-russia-cyber/white-house-blames-russia-for-reckless-notpetya-cyber-attack-idUKKCN1FZ0PR">Reuters</a>.</p><p>"It was part of the Kremlin's ongoing effort to destabilise Ukraine and demonstrates ever more clearly Russia's involvement in the ongoing conflict. This was also a reckless and indiscriminate cyber attack that will be met with international consequences," Sanders added. </p><p>The White House's statement is the first time the US has blamed Russia for what is considered one of the worst cyber attacks ever recorded, while many other security experts had pointed the finger at Moscow months ago. It comes just days after US intelligence agency leaders warned that Russia is likely to try and use cyber attacks as a means to meddle in the US midterm elections in November.</p><p>A senior White House official added that the US government is now "reviewing a range of options" in how to respond to the findings. </p><p>The NotPetya attack, as with the WannaCry attack which also caused major damage last year, demonstrated the need for organisations to be vigilant, keep their systems updated and incorporate a visibility-based security posture. </p><p>"Companies need greater visibility into their networks to detect and remediate incidents and malware attacks," said security architect at <a href="http://www.gigamon.com" target="_blank" rel="noopener noreferrer">Gigamon</a>, Simon Gibson, at the time. "The inability to investigate and detect the spread of the attack across computer networks is greatly impacting critical infrastructures."</p><p>He warned that organisations need to ensure they have complete visibility over their networks so that they can assess vulnerabilities and detect outdated SMB running on a network.</p><p>"To build better defenses, a visibility platform enables better detection and remediation from security tools. Organisations need to be able to get the right information to the right security tools so they can better detect and rapidly respond to ransomware attacks," noted Gibson. </p><p><strong>15/02/2018: UK publicly blames Russia for NotPetya ransomware campaign</strong></p><p>The UK Foreign Office has publicly blamed Russia for the NotPetya ransomware attack that infected companies and public services across Europe and the US last summer.</p><p>The ransomware first emerged in June when Ukrainian banks, government facilities and corporate systems were hit by a coordinated cyber attack, only for it then to spread to sites in Germany, Italy, Poland, the UK, the US, and Russia.</p><p>The UK <a href="https://www.gov.uk/government/news/foreign-office-minister-condemns-russia-for-notpetya-attacks" target="_blank">now believes</a> that the Russian military was responsible for the attack, adding that it would not tolerate such malicious cyber activity.</p><p>UK-based Reckitt Benckiser, which produces brands such as Dettol and Durex, was hit by the ransomware in late June, and has estimated a 100 million loss as a result of system downtime and disrupted manufacturing output.</p><p>Courier service TNT was also locked out of its systems during the campaign, with sources inside the company revealing to <em>the</em> <em>Guardian</em> at the time that a "significant portion" of operations were having to be handled manually.</p><p>"The UK Government judges that the Russian Government, specifically the Russian military, was responsible for the destructive NotPetya cyber-attack of June 2017," said Foreign Office minister Lord Ahmad. "The attack showed a continued disregard for Ukrainian sovereignty. Its reckless release disrupted organisations across Europe costing hundreds of millions of pounds."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack" data-original-url="/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack">No-one is blameless when it comes to the NHS WannaCry hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched" data-original-url="/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched">Shadow Brokers: Microsoft Windows flaws were already patched</a></p></div></div><p>"The Kremlin has positioned Russia in direct opposition to the West yet it doesn't have to be that way. We call upon Russia to be the responsible member of the international community it claims to be rather then (sic) secretly trying to undermine it."</p><p>Research by the National Cyber Security Centre concluded that the Russian military was "almost certainly responsible" for the ransomware attack, which was enough for the UK to publicly blame its government.</p><p>The attacks were largely seen as being politically motivated, having started on the eve of Ukraine's Constitution Day. As such, Ukraine was quick to publicly blame Russia for the attacks and claimed its internal security service, the SBU, obtained evidence that the ransomware attack was deliberately designed to look like a global virus while specifically targeting Ukrainian systems.</p><p>Russia has always denied responsibility for the <a href="https://www.itpro.com/security/28084/what-is-ransomware" target="_blank" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> and has pointed to the fact that Russian systems were also targeted in the attack.</p><p>The attack was initially thought to have used the Petya malware, which first emerged in 2016, however, analysis of the strain found it to be an entirely different family that had been designed to spread far more quickly between targets.</p><p>Kaspersky Lab believes around 2,000 attacks were launched using the malware, with as much as 80% of these being in Ukraine or Russia.</p><p>Defence secretary Gavin Williamson described the attacks as being part of a "new era of warfare" that Britain needed to be ready to respond to.</p><p>"Russia is ripping up the rulebook by undermining democracy, wrecking livelihoods by targeting critical infrastructure and weaponising information." said Williamson, in a statement to the press. "We must be primed and ready to tackle these stark and intensifying threats."</p><p>Parliament's Intelligence and Security Committee revealed in November that it was considering launching an investigation into Russian activity against the UK, including allegations of Russian meddling during the Brexit referendum.</p><p><strong>25/07/2017: TNT customers experience delivery delays after cyber attack</strong></p><p>TNT is reportedly still suffering from the effects of the NotPetya cyber attack last month, with customers being told that parcels are "going up to the ceiling" at some delivery centres.</p><p>The FedEx-owned shipping firm was one of thousands of businesses affected by the ransomware attack in June, which left computer systems crippled and many customers facing severe delays in receiving parcels.</p><p>In a <a href="http://about.van.fedex.com/newsroom/global-english/fedex-files-10-k-additional-disclosure-cyber-attack-affecting-tnt-express-systems" target="_blank">statement</a> released on 17 July, FedEx said that TNT systems had been compromised after an initial infection of its Ukraine operations had spread throughout its network. FedEx also said that all TNT depots, hubs and facilities had since resumed normal service, although a "significant portion of TNT operations and customer service functions" were being handled manually.</p><p>"We cannot yet estimate how long it will take to restore the systems that were impacted, and it is reasonably possible that TNT will be unable to fully restore all of the affected systems and recover all of the critical business data that was encrypted by the virus," added FedEx.</p><p>A week later, it appears that the company is still struggling to deal with the backlog of deliveries, as customers have now been told by TNT staff that consignments are "going up to the ceiling" at its East Midlands hub, according to the <a href="https://www.theguardian.com/money/2017/jul/25/tnt-parcels-cyber-attack-courier-fedex-notpetya" target="_blank"><em>Guardian</em></a>.</p><p>"TNT tell me they have had no computer systems since the end of June and there is no estimate for when their systems will be fixed," said TNT customer Peter Blohm, speaking to the <em>Guardian</em>.</p><p>"This means there are many thousands of parcels which have like mine been waiting for weeks to be processed by hand with pen and paper. The staff sound harassed, but cannot estimate when my parcel will be delivered, because they simply do not know."</p><p>A TNT spokesperson declined to comment on these reports when contacted by <em>IT Pro</em>, adding that there were no further updates from the statement released last week.</p><p>FedEx, which agreed to buy TNT in 2015, said it was still trying to establish the financial impact of NotPetya, admitting that it did not have adequate insurance policies in place to cover an attack of this kind.</p><p>"Although we cannot currently quantify the amounts, we have experienced loss of revenue due to decreased volumes at TNT and incremental costs associated with the implementation of contingency plans and the remediation of affected systems," said FedEx.</p><p>A recent <a href="https://www.itpro.com/security/29064/cyber-attacks-could-cost-the-global-economy-40-billion" target="_blank" data-original-url="https://www.itpro.com/security/29064/cyber-attacks-could-cost-the-global-economy-40-billion">report by Lloyd's of London</a> said that a major global cyber attack could cost the world economy 40 billion, but because companies are 'underinsuring' their systems, as much as 34 billion of that may not be covered.</p><p><strong>10/07/2017:</strong> Germany's federal cyber agency said that the threat posed to firms by the Petya ransomware was greater than expected, warning that data backups carried out since April should be considered compromised.</p><p>The BSI (Federal Office for Information Security) said in a statement that computer experts had discovered the waves of attacks had been launched via software updates of the MeDoc accounting software dating back to April, as reported by <a href="https://www.reuters.com/article/us-cyber-attack-ukraine-germany-idUSKBN19S1EU" target="_blank"><em>Reuters</em></a>.</p><p>Companies using this software may have been infected even if there were no obvious signs of a breach, the BSI added, with any data backups carried out after 13 April potentially an issue.</p><p>BSI president Arne Schoenbohm said: "Some German firms have seen production and other critical processes laid still for over a week." He added: "It has resulted in millions of euros of damage, and this in a case where Germany got off lightly."</p><p>Schoenbohm stated that the attacks were at least as harmful as the <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">WannaCry ransomware attacks</a> from May.</p><p>The agency has urged German companies to separate networks which had the MeDoc software installed, to increase network surveillance and to look out for any signs of compromise. It also underlined the importance of changing passwords and updating software for all infected networks.</p><p>Police last week seized servers from which they believe the ransomware attack originated. They belong to the Ukrainian software firm that created MeDoc, though the company disputes whether its software carried Petya.</p><p>"We studied and analysed our product for signs of hacking," Intellect Service's managing partner Olesya Linnik said in an interview with <em>Reuters</em>. "It is not infected with a virus and everything is fine, it is safe".</p><p>"The update package, which was sent out long before the virus was spread," she said, "we checked it 100 times and everything is fine."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack" data-original-url="/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack">No-one is blameless when it comes to the NHS WannaCry hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched" data-original-url="/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched">Shadow Brokers: Microsoft Windows flaws were already patched</a></p></div></div><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/882683628504977411"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/882683628504977411"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Police launched an operation on Intellect Service, publisher of Ukraine's popular accounting software, MeDoc. The servers were seized and the police warned the company and its employees may face criminal charges over the attack.</p><p>German security officials are still investigating the origin of the attack and do not have evidence to confirm the claim by the Ukrainian government that Russia was behind it.</p><p><strong>06/07/2017: </strong>Nurofen and Dettol maker estimates 100m loss from Petya</p><p>Reckitt Benckiser, the maker of Nurofen painkillers, said it estimates a 100m loss in revenue as a result of the Petya ransomware attack.</p><p>The company, which also manufactures Durex condoms and Dettol cleaning products, said the attack on 27 June affected a number of its production plants, preventing the company from fulfilling orders.</p><p>"Consequently, we were unable to ship and invoice some orders to customers prior to the close of the quarter," the UK-based company said a widely reported statement. "Some of our factories are currently still not operating normally but plans are in place to return to full operation."</p><p>"We expect that some of the revenue lost from the second quarter will be recovered in the third quarter," the company added. "However, the continued production difficulties in some factories mean that we also expect to lose some further revenue permanently."</p><p>While the ransom demand was only $300, the news demonstrates the wider ranging impact that a malware attack can have on a company's systems - in this case, a catastrophic failure of a supply network.</p><p>Shares in the company fell as much as 3% following today's news, and are still 1.5% down at the time of writing. Reckitt said it's still assessing the long-term financial impact of the attack.</p><p>Reckitt Benckiser, which is headquartered in Slough, employs around 37,000 people through operations in more than 60 countries, although its products are available in over 200. It also counts Harpic, Cilit Bang, Strepsils and Clearasil among the brands it currently manufactures and recently acquired US-based children's formula maker Mead Johnson for $16.6 billion.</p><p>Some of the world's largest companies were hit by the attack, including Russian oil giant Rosneft, international shipping firm Maersk, and a number of Ukrainian banks.</p><p><strong>05/07/2017: Ukraine cyber police seizes suspected Petya servers</strong></p><p>Servers linked to the global spread of the Petya ransomware outbreak have been seized <a href="https://cyberpolice.gov.ua/news/prykryttyam-najmasshtabnishoyi-kiberataky-v-istoriyi-ukrayiny-stav-virus-diskcoderc-881" target="_blank">by the Ukrainian police's cybercrime division</a>, after the malware was traced back to a small Ukrainian software firm.</p><p>Police swooped on the small family-run business Intellect Service, publisher of Ukraine's popular accounting software, MeDoc. Seizing the firm's servers, police warned that the company and its employees may face criminal charges over the attack.</p><p>While Intellect Service is not accused of being the architects behind the ransomware outbreak, experts have pointed to the company as being 'patient zero', acting as the source of the epidemic.</p><p>The authors of the ransomware likely hacked Intellect Service and used MeDoc's automatic update feature in order to spread the infection, according to <a href="https://www.malwaretech.com/2017/06/petya-ransomware-attack-whats-known.html" target="_blank">multiple security firms and malware researchers</a>.</p><p>However, some suggest the malware MeDoc allegedly spread wasn't Petya, but a similar variation upon it, designed to destroy Ukraine organisations' data.</p><p>The head of Ukraine's cybercrime unit, Colonel Serhiy Demydiuk stated that Intellect Service was warned multiple times by security experts that their IT systems were at risk of a security breach.</p><p>"They knew about it," he told the <a href="https://apnews.com/8b02768224de485eb4e7b33ae55b02f2" target="_blank"><em>Associated Press</em></a>. "They were told many times by various antivirus firms... For this neglect, the people in this case will face criminal responsibility."</p><p>"We have issues with the company's leadership, because they knew there was a virus in their software but didn't do anything," Demydiuk told <a href="http://www.reuters.com/article/us-cyber-attack-ukraine-software-idUSKBN19O2DK?il=0" target="_blank"><em>Reuters</em></a>.</p><p>"We studied and analysed our product for signs of hacking," Intellect Service's managing partner Olesya Linnik said in an interview with <em>Reuters</em>. "It is not infected with a virus and everything is fine, it is safe".</p><p>"The update package, which was sent out long before the virus was spread," she said, "we checked it 100 times and everything is fine."</p><p>"Cyberpolice Department strongly recommends all users at the time of the investigation, to stop using the software "MEDoc" and turn off the computer on which it is installed on the network," Ukraine's Cyberpolice unit said in a <a href="https://cyberpolice.gov.ua/news/prykryttyam-najmasshtabnishoyi-kiberataky-v-istoriyi-ukrayiny-stav-virus-diskcoderc-881" target="_blank">statement</a>. "You must also change their passwords and electronic digital signatures, due to the fact that these data could be compromised.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack" data-original-url="/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack">No-one is blameless when it comes to the NHS WannaCry hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched" data-original-url="/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched">Shadow Brokers: Microsoft Windows flaws were already patched</a></p></div></div><p><strong>03/07/2017: Ukraine blames Russian security forces for Petya ransomware</strong></p><p>Ukraine claimed that the Russian security services were behind the Petya cyber attack which affected businesses worldwide last week.</p><p>Ukraine's security service, the SBU, has linked Petya to the December 2016 cyber attack in Ukraine where the <a href="https://www.itpro.com/malware/25804/ukrainian-power-grid-downed-by-cyber-attack" target="_blank" data-original-url="https://www.itpro.com/malware/25804/ukrainian-power-grid-downed-by-cyber-attack">power grid was downed</a> and affected roughly 700,000 homes. The SBU has obtained data from various international anti-virus companies which links the two attacks.</p><p>The security service also stated that the attack was designed to creat the impression of a ransomware virus, but was an attack specifically targeted at Ukraine. The SBU said: "In fact, the virus is a cover of [a] large-scale attack, oriented against Ukraine."</p><p>It said the main target of the virus was to destroy important data and create disorder in Ukraine in order to spread panic.</p><p>According to <a href="https://uk.reuters.com/article/us-cyber-attack-ukraine-idUKKBN19M39P" target="_blank"><em>Reuters</em></a>, various cyber security researchers have suggested Moscow was not behind the attack as some major Russian firms were affected by the ransomware. Moscow has also denied any involvement, which a Kremlin spokesperson dismissed as "unfounded blanket accusations".</p><p>The cyberattack, which has various names including Petya and NotPetya, locked down corporate computers in Europe and the US last week. It demanded $300 in Bitcoin payment for a user to unlock their files, but the attackers' email account was shut down meaning victims probably won't get their data decrypted. A number of experts have said that the attack was deliberately malicious and spread fast to cause damage using the cover of ransomware.</p><p><strong>28/06/2017: Vaccine may hinder Petya spread</strong></p><p>Security researchers have chanced upon a workaround solution that disables the Petya ransomware that's wreaked havoc on computers around the world.</p><p>According to a <a href="https://www.cybereason.com/blog-cybereason-discovers-notpetya-kill-switch">blog post</a> by IT security firm Cybereason, its principle security researcher Amit Serper discovered that creating a file named "perfc", with no extension name and placing it in the C:\windows\ folder. The file has to be read-only for the method to work.</p><p>The ransomware searches for its own filename in the C:\windows\ folder, and if it is found, will cease running, according to security researchers.</p><p>Cybereason said that once the original file name was found and verified by two different sources, Serper was able to piece together a kill switch that should work for any instance of the original ransomware infection. While this does not stop the ransomware if it is already running, it will act as a vaccination, stopping it from ever trying to encrypt files.</p><p>While Petya infects PCs around the world, Kroll Ontrack believed that some data may still be salvaged from infected computers without paying a ransom. </p><p>According to Phil Bridge, managing director, Western Europe of Data & Storage Technologies at Kroll Ontrack, said that the malware does not encrypt all the files on your computer but instead attacks a part of the operating system called the Master File Table (MFT), an essential index' for the computer system to locate files on the computer.</p><p>"Attacking one part of the system (the MFT) is much faster than targeting all the individual files but the result is as if each file had been locked separately," he said.</p><p>He added that there is a method to decrypt the original Petya ransomware, but one has not yet been released for the updated version. He said that "some data may still be salvaged from infected computers with the use of specialist data recovery techniques.</p><p><strong>28/06/2017: Petya ransomware: attack hits global companies</strong></p><p>A ransomware attack has locked down corporate computers throughout Europe and the US, a month after the NHS and other organisations <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">were knocked offline by WannaCry</a>. </p><p>Called Petya as well as NotPetya by some, <a href="https://www.itpro.com/malware/27866/goldeneye-ransomware-disguised-as-job-application" data-original-url="https://www.itpro.com/malware/27866/goldeneye-ransomware-disguised-as-job-application">and Goldeneye, by others</a> has reportedly hit thousands of machines, including at advertising giant WPP, Danish transport firm AP Moller-Maersk, and Russian oil firm Rosneft, as well as at least one hospital firm in the US.</p><p>It appears to have initially infected machines via accounting software that companies use to link to the Ukrainian government, with huge swathes of that country's companies and government bodies wiped offline. While the country's Twitter feed made light of the situation, some of the shutdown was alarming including Chernobyl radiation monitoring being done by hand.</p><p>Once in, Petya then spreads via the EternalBlue vulnerability in Windows that has been patched but given the carnage, it appears not everyone has updated. That was the same exploit used by WannaCry's hackers, and was developed by the NSA <a href="https://www.itpro.com/security/27114/cisco-confirms-shadow-brokers-vulnerabilities-are-real" data-original-url="https://www.itpro.com/security/27114/cisco-confirms-shadow-brokers-vulnerabilities-are-real">but leaked in April</a>.</p><p>"As far as the EternalBlue exploit, the worm code appears to heavily borrow from WannaCry, including taking advantage of the same EternalBlue exploit code to move around once it is inside the network," said Allan Liska, intelligence architect at Recorded Future. "In addition to the EternalBlue exploit, the new attack appears to take advantage of WMIC for lateral movement. WMIC (Windows Management Instrumentation Command-line) is a command line tool that is used to execute system management commands on Windows."</p><p>One difference with WannaCry is it lacks an apparent "kill switch" that halted May's ransomware outbreak. "Some are comparing this to WannaCry 2.0 but this version does not have the "kill-switch" that the original WannaCry did. Thus, we should not expect any oddity like that to slow this attack," said Brian Hussey, VP of cyber threat detection and response at Trustwave.</p><p>This variant demands $300 in Bitcoin payment from users of infected machines as ransom to unlock their data. However, the <a href="https://motherboard.vice.com/en_us/article/new8xw/hacker-behind-massive-ransomware-outbreak-cant-get-emails-from-victims-who-paid">German email provider, Posteo, that runs the attackers' email account, has shut it down</a>, so victims likely won't be getting their data decrypted.</p><p>To Nicholas Weaver, security researcher at the International Computer Science Institute, that suggests there may be more to Petya. "I'm willing to say with at least moderate confidence that this was a deliberate, malicious, destructive attack or perhaps a test disguised as ransomware," <a href="https://krebsonsecurity.com/2017/06/petya-ransomware-outbreak-goes-global">Weaver told <em>KrebsonSecurity</em></a>. "The best way to put it is that Petya's payment infrastructure is a fecal theater."</p><p>Matthew Hickley, co-founder of My HackerHouse, said if your computer does force a reboot and show the following screen, turn your PC off to halt the encryption process.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/879793827267174400"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/879793827267174400"></a></p></blockquote></figure><div class="see-more__filter"></div></div><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack" data-original-url="/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack">No-one is blameless when it comes to the NHS WannaCry hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched" data-original-url="/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched">Shadow Brokers: Microsoft Windows flaws were already patched</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cryptocurrency miners: the latest tool for cyber criminals ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Due to the growing popularity and market value (at the time of writing!) of cryptocurrencies, it is no surprise that there has been a surge in the number of malicious attacks using cryptominers.</p><p>In its latest report into <a href="https://dennistrk.cvtr.io/click?pid=87&lid=4522&sid=&utm_content=30516-top">Cybercrime tactics and techniques: 2017 state of malware'</a>, Malwarebytes claims to have blocked an average of 8 million drive-by mining attempts from websites and visitors all over the world.</p><p>Drive-by mining is a revival of an old concept of browser-based mining using JavaScript. A new venture called Coinhive revived this method late last year, providing a simple API for webmasters to add to their website, which would turn any visitor into a miner for the Monero digital currency.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29204/how-can-you-protect-your-business-from-crypto-ransomware" data-original-url="/security/29204/how-can-you-protect-your-business-from-crypto-ransomware">How can you protect your business from crypto-ransomware?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28170/what-is-cyber-warfare" data-original-url="/security/28170/what-is-cyber-warfare">What is cyber warfare?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining" data-original-url="/digital-currency/30249/what-is-cryptocurrency-mining">What is cryptocurrency mining?</a></p></div></div><p>Predictably, this technology was immediately abused by webmasters that ran it silently, therefore exploiting the visitor's CPU for their own gain. Eventually, criminals also took note and started compromising websites with cryptomining code. This means that the system resources of unsuspecting victims can be harnessed without authorisation in order to mine cryptocurrency.</p><p>The most popular currency for drive-by mining in 2017 is Monero, most likely due to the higher speed with which transactions are processed, even of small amounts. Criminals also benefit from the anonymity automatically incorporated into the Monero blockchain, and the fact that the mining algorithm doesn't favour specialised chips.</p><h2 id="popular-attack-methods">Popular attack methods</h2><p><strong>PUP wrappers:</strong> Several bundlers and PUP wrappers have been found to install miners, and they appear to be replacing adware as a payment method. IStartSurf, a PUP well known for its browser hijackers, has started to include miners in its silent installs.</p><p><strong>Exploit kits and malvertising:</strong> The payload of the RIG exploit kit now includes cryptominers. Even the EternalBlue exploit (of WannaCry fame) was used to spread a miner that used Windows Management Instrumentation for a fileless, persistent infection.</p><p><strong>Malicious spam:</strong> Cryptocurrencies are easy pickings for spammers. They often use Bitcoin value fluctuations as a means for phishing, while sending out cryptominers or installers for these miners as malspam.</p><p><strong>Social engineering:</strong> This is an increasingly popular method of attack used for drive-by mining. Some campaigns are run by convincing people they need to install a new font, when in fact they are being served a cryptominer. Some miners are also being offered as cracked versions of popular software.</p><p><strong>Bitcoin wallet theft:</strong> Banking Trojans have expanded their working field into stealing cryptocurrencies right out of people's virtual wallets. Coinbase is a cryptowallet that trades in several cryptocurrencies, including Bitcoin. A Trickbot variant was spotted that includes the Coinbase exchange to steal credentials from the sites it monitors.</p><p>Other Trojans have been spotted that steal cryptocurrencies on the fly, including one that monitors a user's clipboard. As soon as it spots the address of a cryptocurrency wallet on the clipboard, it replaces the address with that of the threat actor.</p><p>Attacks like this can be virtually impossible to detect, and few people would expect something they had just copied to change before being pasted into an address bar.</p><p>It is likely that as cryptocurrency fever continues, drive-by mining will evolve as new mining platforms are utilised - such as Android and IoT devices - and new forms of malware are developed to mine and steal cryptocurrency.</p><p><em>Picture: Shutterstock</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/digital-currency/30516/cryptocurrency-miners-the-latest-tool-for-cyber-criminals</link>
                                                                            <description>
                            <![CDATA[ Learn more about the new form of cyber crime that is being driven by cryptocurrency fever ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6drvxWAVutGyTidWKeoE67</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qU9iNG5RKZj3yFgnmYq2Nc-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 13 Feb 2018 10:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Esther Kezia Thorpe ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPPgWan5PqHyFNtSS9gnbR-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qU9iNG5RKZj3yFgnmYq2Nc-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qU9iNG5RKZj3yFgnmYq2Nc-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Due to the growing popularity and market value (at the time of writing!) of cryptocurrencies, it is no surprise that there has been a surge in the number of malicious attacks using cryptominers.</p><p>In its latest report into <a href="https://dennistrk.cvtr.io/click?pid=87&lid=4522&sid=&utm_content=30516-top">Cybercrime tactics and techniques: 2017 state of malware'</a>, Malwarebytes claims to have blocked an average of 8 million drive-by mining attempts from websites and visitors all over the world.</p><p>Drive-by mining is a revival of an old concept of browser-based mining using JavaScript. A new venture called Coinhive revived this method late last year, providing a simple API for webmasters to add to their website, which would turn any visitor into a miner for the Monero digital currency.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29204/how-can-you-protect-your-business-from-crypto-ransomware" data-original-url="/security/29204/how-can-you-protect-your-business-from-crypto-ransomware">How can you protect your business from crypto-ransomware?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28170/what-is-cyber-warfare" data-original-url="/security/28170/what-is-cyber-warfare">What is cyber warfare?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining" data-original-url="/digital-currency/30249/what-is-cryptocurrency-mining">What is cryptocurrency mining?</a></p></div></div><p>Predictably, this technology was immediately abused by webmasters that ran it silently, therefore exploiting the visitor's CPU for their own gain. Eventually, criminals also took note and started compromising websites with cryptomining code. This means that the system resources of unsuspecting victims can be harnessed without authorisation in order to mine cryptocurrency.</p><p>The most popular currency for drive-by mining in 2017 is Monero, most likely due to the higher speed with which transactions are processed, even of small amounts. Criminals also benefit from the anonymity automatically incorporated into the Monero blockchain, and the fact that the mining algorithm doesn't favour specialised chips.</p><h2 id="popular-attack-methods">Popular attack methods</h2><p><strong>PUP wrappers:</strong> Several bundlers and PUP wrappers have been found to install miners, and they appear to be replacing adware as a payment method. IStartSurf, a PUP well known for its browser hijackers, has started to include miners in its silent installs.</p><p><strong>Exploit kits and malvertising:</strong> The payload of the RIG exploit kit now includes cryptominers. Even the EternalBlue exploit (of WannaCry fame) was used to spread a miner that used Windows Management Instrumentation for a fileless, persistent infection.</p><p><strong>Malicious spam:</strong> Cryptocurrencies are easy pickings for spammers. They often use Bitcoin value fluctuations as a means for phishing, while sending out cryptominers or installers for these miners as malspam.</p><p><strong>Social engineering:</strong> This is an increasingly popular method of attack used for drive-by mining. Some campaigns are run by convincing people they need to install a new font, when in fact they are being served a cryptominer. Some miners are also being offered as cracked versions of popular software.</p><p><strong>Bitcoin wallet theft:</strong> Banking Trojans have expanded their working field into stealing cryptocurrencies right out of people's virtual wallets. Coinbase is a cryptowallet that trades in several cryptocurrencies, including Bitcoin. A Trickbot variant was spotted that includes the Coinbase exchange to steal credentials from the sites it monitors.</p><p>Other Trojans have been spotted that steal cryptocurrencies on the fly, including one that monitors a user's clipboard. As soon as it spots the address of a cryptocurrency wallet on the clipboard, it replaces the address with that of the threat actor.</p><p>Attacks like this can be virtually impossible to detect, and few people would expect something they had just copied to change before being pasted into an address bar.</p><p>It is likely that as cryptocurrency fever continues, drive-by mining will evolve as new mining platforms are utilised - such as Android and IoT devices - and new forms of malware are developed to mine and steal cryptocurrency.</p><p><em>Picture: Shutterstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ All 200 NHS trusts fail latest cybersecurity standards ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Despite attempts for improved security provision, the UK's Department of Health has admitted that all 200 NHS trusts assessed for cybersecurity vulnerabilities have failed to meet the standard required.</p><p>Civil servants revealed the news in a parliamentary hearing earlier this week, which heard of the effects of the <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack/page/0/4">WannaCry ransomware attack</a> on parts of the NHS last year.</p><p>The malware affected 300,000 computers in 150 countries in May last year, including 48 NHS trusts, also shutting down multiple hospital IT systems as well as companies and universities elsewhere.</p><p>At the time, NHS Digital said the NHS itself was not specifically the target of the attack but part of a wider "Wanna Decryptor" ransomware campaign that was only thwarted when a security researcher discovered a 'kill switch' that stopped the attack in its tracks.</p><p>However, hospital trusts across England and Scotland admitted they'd been caught up in the attack, with appointments cancelled, phone lines down and ambulances diverted. Doctors and other staff had also been sharing further details on Twitter, with one screenshot suggesting the ransomware was demanding $300 in Bitcoin to decrypt files, with the price doubling after three days.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29863/notpetya-was-nastier-than-wannacry-ransomware-say-experts" data-original-url="/security/29863/notpetya-was-nastier-than-wannacry-ransomware-say-experts">NotPetya was nastier than WannaCry ransomware, say experts</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges" data-original-url="/security/29172/marcus-hutchins-wannacry-kronos-charges">WannaCry 'hero' Marcus Hutchins 'was coerced' into Kronos confession</a></p></div></div><p>Appearing before the Commons' Public Accounts Committee on Monday, NHS Digital deputy chief executive Rob Shaw said trusts were still failing to meet cyber security standards since the WannaCry debacle, admitting some have a "considerable amount" of work to do.</p><p>"The amount of effort it takes from NHS providers in such a complex estate to reach the Cyber Essentials Plus standard that we assess against as per the recommendation in Dame Fiona Caldicott's report, is quite a high bar. So some of them have failed purely on patching, which is what the vulnerability was around WannaCry," he said.</p><p>Simon Stevens, the chief executive of NHS England, added: "A whole bunch of things need to change."</p><p>The total cost of the impact on the NHS is still unknown, as and may never be, attendees heard.</p><p>The UK's Foreign Office officially blamed North Korea for the WannaCry campaign in December, <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack/page/0/4">though the country's regime denies involvement</a>.</p><p>Following WannaCry, officials set aside 20 million for the NHS to create a security centre designed to constantly probe the organisation's cyber defences using ethical hackers, as well as issuing best practice guidance around cybersecurity incidents.</p><p>The National Audit Office (NAO) slammed the NHS's security in October last year, saying "basic IT security" measures would have prevented WannaCry from causing the chaos it did. </p><p>"It was a relatively unsophisticated attack and could have been prevented by the NHS following basic IT security best practice. There are more sophisticated cyber threats out there than WannaCry so the department and the NHS need to get their act together to ensure the NHS is better protected against future attacks," said Amyas Morse, head of the NAO, at the time.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/wannacry/30470/all-200-nhs-trusts-fail-latest-cybersecurity-standards</link>
                                                                            <description>
                            <![CDATA[ Little has improved since WannaCry debacle, parliamentary committee hears ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">q1SRMY1NKJjfHKE95LXPLs</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iZTvxTK6bAx3Z4BHJQpFge-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 07 Feb 2018 10:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Lee Bell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iZTvxTK6bAx3Z4BHJQpFge-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iZTvxTK6bAx3Z4BHJQpFge-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Despite attempts for improved security provision, the UK's Department of Health has admitted that all 200 NHS trusts assessed for cybersecurity vulnerabilities have failed to meet the standard required.</p><p>Civil servants revealed the news in a parliamentary hearing earlier this week, which heard of the effects of the <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack/page/0/4">WannaCry ransomware attack</a> on parts of the NHS last year.</p><p>The malware affected 300,000 computers in 150 countries in May last year, including 48 NHS trusts, also shutting down multiple hospital IT systems as well as companies and universities elsewhere.</p><p>At the time, NHS Digital said the NHS itself was not specifically the target of the attack but part of a wider "Wanna Decryptor" ransomware campaign that was only thwarted when a security researcher discovered a 'kill switch' that stopped the attack in its tracks.</p><p>However, hospital trusts across England and Scotland admitted they'd been caught up in the attack, with appointments cancelled, phone lines down and ambulances diverted. Doctors and other staff had also been sharing further details on Twitter, with one screenshot suggesting the ransomware was demanding $300 in Bitcoin to decrypt files, with the price doubling after three days.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29863/notpetya-was-nastier-than-wannacry-ransomware-say-experts" data-original-url="/security/29863/notpetya-was-nastier-than-wannacry-ransomware-say-experts">NotPetya was nastier than WannaCry ransomware, say experts</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges" data-original-url="/security/29172/marcus-hutchins-wannacry-kronos-charges">WannaCry 'hero' Marcus Hutchins 'was coerced' into Kronos confession</a></p></div></div><p>Appearing before the Commons' Public Accounts Committee on Monday, NHS Digital deputy chief executive Rob Shaw said trusts were still failing to meet cyber security standards since the WannaCry debacle, admitting some have a "considerable amount" of work to do.</p><p>"The amount of effort it takes from NHS providers in such a complex estate to reach the Cyber Essentials Plus standard that we assess against as per the recommendation in Dame Fiona Caldicott's report, is quite a high bar. So some of them have failed purely on patching, which is what the vulnerability was around WannaCry," he said.</p><p>Simon Stevens, the chief executive of NHS England, added: "A whole bunch of things need to change."</p><p>The total cost of the impact on the NHS is still unknown, as and may never be, attendees heard.</p><p>The UK's Foreign Office officially blamed North Korea for the WannaCry campaign in December, <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack/page/0/4">though the country's regime denies involvement</a>.</p><p>Following WannaCry, officials set aside 20 million for the NHS to create a security centre designed to constantly probe the organisation's cyber defences using ethical hackers, as well as issuing best practice guidance around cybersecurity incidents.</p><p>The National Audit Office (NAO) slammed the NHS's security in October last year, saying "basic IT security" measures would have prevented WannaCry from causing the chaos it did. </p><p>"It was a relatively unsophisticated attack and could have been prevented by the NHS following basic IT security best practice. There are more sophisticated cyber threats out there than WannaCry so the department and the NHS need to get their act together to ensure the NHS is better protected against future attacks," said Amyas Morse, head of the NAO, at the time.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cybersecurity experts to enjoy highest salary increase in 2018 ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Cybersecurity experts will see the highest salary increases among IT professionals this year, a report by recruitment consultancy Robert Walters has found.</p><p>Infosec specialists will see a 7% pay rise this year compared to 2017, the 2018 Salary Survey revealed, which is apparently due to the growing number of high-profile data leaks and related cyberattacks of the last year.</p><p>Developers and infrastructure staff will also see salary rises, but of less than half that of cybersecurity experts, at 3%.</p><p>Ahsan Iqbal, associate director at Robert Walters, argued that this salary surge will make it harder for employers to secure skilled IT staff, and that they should consider other ways in which to attract and retain the best talent.</p><p>"Salaries for IT professionals are highly inflated, with employers having to compete to secure top talent," Iqbal said. "In this context, the increases for cybersecurity specialists are particularly noteworthy. In addition to technical skills, employers are keen to secure professionals who can demonstrate communication and project management skills as they look to more closely integrate their IT function into the wider business.</p><p>"For many IT professionals, while a high salary is important, there are other incentives which can attract them to a role. In particular, flexibility is regarded as highly important, with many IT specialists looking to work for employers who are open to remote working and flexible hours. The nature of the projects they will be working on is also considered important to many IT professionals, as is the working culture of the organisation they are joining."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28170/what-is-cyber-warfare" data-original-url="/security/28170/what-is-cyber-warfare">What is cyber warfare?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud-computing/29962/google-beefs-up-job-search-tool-with-salary-data" data-original-url="/cloud-computing/29962/google-beefs-up-job-search-tool-with-salary-data">Google beefs up job search tool with salary data</a></p></div></div><p>However, Tim Helming, director of product management at DomainTools, said the survey is "a welcome recognition" of the importance of cybersecurity specialists to corporations and individuals in 2018.</p><p>"As data breaches, high profile ransomware attacks and other forms of cybercrime become more common, sophisticated and easy to pursue, the need for cybersecurity professionals to be incentivised to stay in the industry is crucial," he said.</p><p>"What's more, a visible industry-wide average salary increase could help to draw more talented people into the cybersecurity industry, as well as engaging with the flexible working practices outlined in the survey."</p><p>He added that the dangers of cybercrime are only likely to increase in the coming years, as <a href="https://www.itpro.com/security/28170/what-is-cyber-warfare" target="_blank" data-original-url="https://www.itpro.com/security/28170/what-is-cyber-warfare">nation states begin to engage in cyber warfare</a> as a viable alternative to traditional military action, so ensuring this talent pool is satisfied is "crucial for all of us".</p><p>It was only last week that it was revealed the UK is now the <a href="https://www.itpro.com/security/30395/uk-is-now-the-most-targeted-nation-for-cyber-attacks-says-malwarebytes" target="_blank" data-original-url="https://www.itpro.com/security/30395/uk-is-now-the-most-targeted-nation-for-cyber-attacks-says-malwarebytes">most targeted region in the world</a> for cyber threats following a 134% rise in hijacking attempts against British machines and soaring ransomware attacks.</p><p>Malwarebytes' annual State of Malware report revealed UK-bound ransomware has increased by 165% over the last year, having accelerated at a pace almost double that of the US.</p><p>These attacks peaked in May during the height of <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">the WannaCry ransomware campaign</a>, which also helped contribute to a 700% global rise in ransomware threats between July and September 2017, according to Malwarebytes' telemetry, a 10-time increase on the monthly rate of ransomware attacks in 2016.</p><p>Ransomware across the globe saw a 90% hike against businesses and a 93% increase against consumers over the course of 2017.</p><p><em>Picture: Bigstock</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/business-strategy/careers-training/30433/cybersecurity-experts-to-enjoy-highest-salary-increase-in</link>
                                                                            <description>
                            <![CDATA[ Recruitment firm predicts higher wages for developers and infrastructure specialists are also on the horizon ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tjrCkYQs8AX2EcBfUuG8a4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/XBy5LAyLDqZck7MBLAVS9K-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 31 Jan 2018 12:22:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Lee Bell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/XBy5LAyLDqZck7MBLAVS9K-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract cyber security image of a man holding a symbol of a padlock inside a shield]]></media:description>                                                            <media:text><![CDATA[Abstract cyber security image of a man holding a symbol of a padlock inside a shield]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract cyber security image of a man holding a symbol of a padlock inside a shield]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/XBy5LAyLDqZck7MBLAVS9K-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cybersecurity experts will see the highest salary increases among IT professionals this year, a report by recruitment consultancy Robert Walters has found.</p><p>Infosec specialists will see a 7% pay rise this year compared to 2017, the 2018 Salary Survey revealed, which is apparently due to the growing number of high-profile data leaks and related cyberattacks of the last year.</p><p>Developers and infrastructure staff will also see salary rises, but of less than half that of cybersecurity experts, at 3%.</p><p>Ahsan Iqbal, associate director at Robert Walters, argued that this salary surge will make it harder for employers to secure skilled IT staff, and that they should consider other ways in which to attract and retain the best talent.</p><p>"Salaries for IT professionals are highly inflated, with employers having to compete to secure top talent," Iqbal said. "In this context, the increases for cybersecurity specialists are particularly noteworthy. In addition to technical skills, employers are keen to secure professionals who can demonstrate communication and project management skills as they look to more closely integrate their IT function into the wider business.</p><p>"For many IT professionals, while a high salary is important, there are other incentives which can attract them to a role. In particular, flexibility is regarded as highly important, with many IT specialists looking to work for employers who are open to remote working and flexible hours. The nature of the projects they will be working on is also considered important to many IT professionals, as is the working culture of the organisation they are joining."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28170/what-is-cyber-warfare" data-original-url="/security/28170/what-is-cyber-warfare">What is cyber warfare?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud-computing/29962/google-beefs-up-job-search-tool-with-salary-data" data-original-url="/cloud-computing/29962/google-beefs-up-job-search-tool-with-salary-data">Google beefs up job search tool with salary data</a></p></div></div><p>However, Tim Helming, director of product management at DomainTools, said the survey is "a welcome recognition" of the importance of cybersecurity specialists to corporations and individuals in 2018.</p><p>"As data breaches, high profile ransomware attacks and other forms of cybercrime become more common, sophisticated and easy to pursue, the need for cybersecurity professionals to be incentivised to stay in the industry is crucial," he said.</p><p>"What's more, a visible industry-wide average salary increase could help to draw more talented people into the cybersecurity industry, as well as engaging with the flexible working practices outlined in the survey."</p><p>He added that the dangers of cybercrime are only likely to increase in the coming years, as <a href="https://www.itpro.com/security/28170/what-is-cyber-warfare" target="_blank" data-original-url="https://www.itpro.com/security/28170/what-is-cyber-warfare">nation states begin to engage in cyber warfare</a> as a viable alternative to traditional military action, so ensuring this talent pool is satisfied is "crucial for all of us".</p><p>It was only last week that it was revealed the UK is now the <a href="https://www.itpro.com/security/30395/uk-is-now-the-most-targeted-nation-for-cyber-attacks-says-malwarebytes" target="_blank" data-original-url="https://www.itpro.com/security/30395/uk-is-now-the-most-targeted-nation-for-cyber-attacks-says-malwarebytes">most targeted region in the world</a> for cyber threats following a 134% rise in hijacking attempts against British machines and soaring ransomware attacks.</p><p>Malwarebytes' annual State of Malware report revealed UK-bound ransomware has increased by 165% over the last year, having accelerated at a pace almost double that of the US.</p><p>These attacks peaked in May during the height of <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">the WannaCry ransomware campaign</a>, which also helped contribute to a 700% global rise in ransomware threats between July and September 2017, according to Malwarebytes' telemetry, a 10-time increase on the monthly rate of ransomware attacks in 2016.</p><p>Ransomware across the globe saw a 90% hike against businesses and a 93% increase against consumers over the course of 2017.</p><p><em>Picture: Bigstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Russian cyber attack would cripple UK infrastructure, warns defence secretary ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The UK's defence secretary has warned that a cyber attack by Russia could cripple Britain's infrastructure and cause "thousands and thousands and thousands of deaths".</p><p>Gavin Williamson told <a href="http://www.telegraph.co.uk/news/2018/01/25/crippling-russian-attack-britains-infrastructure-could-kill" target="_blank"><em>The Telegraph</em></a> that the Russian government has been researching the UK's energy supply and supporting infrastructure, which if it were to launch a cyber attack against would cause "total chaos" for Britain.</p><p>Williamson noted that a cyber attack from Russian is the "real threat" the UK is currently facing, noting that an attack from Moscow would come from the digital not physical world.</p><p>"The plan for the Russians won't be for landing craft to appear in the South Bay in Scarborough, and off Brighton beach," Williamson told the Telegraph.</p><p>"They are going to be thinking, 'how can we just cause so much pain to Britain?</p><p>"Damage its economy, rip its infrastructure apart, actually cause thousands and thousands and thousands of deaths, but actually have an element of creating total chaos within the country."</p><p>Such comments may be seen as hyperbolic and paranoia tinged, but Williamson statements were backed up by security minister Lord West, who also serves as Britain's First Seal Lord. West said he was "absolutely certain" Russia has been looking at how it could access the UK's critical infrastructure.</p><p>Moscow has not responded to Williamson's claims at the time of writing.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/27824/researchers-confirm-that-ukraine-outage-was-cyber-attack" data-original-url="/security/27824/researchers-confirm-that-ukraine-outage-was-cyber-attack">Researchers confirm that Ukraine outage was cyber attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/government-it-strategy/28301/france-withdraws-electronic-vote-over-hacking-fears" data-original-url="/government-it-strategy/28301/france-withdraws-electronic-vote-over-hacking-fears">France withdraws electronic vote over hacking fears</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/social-media/30339/russian-bots-shared-trumps-election-tweets-500k-times" data-original-url="/social-media/30339/russian-bots-shared-trumps-election-tweets-500k-times">Russian bots shared Trump's election tweets 500k times</a></p></div></div><p><strong>23/01/18: NCSC: </strong><strong>Severe cyber attack on UK is unavoidable</strong></p><p>A serious cyber attack on the UK's vital infrastructure is inevitable, according to the head of the National Cyber Security Centre (NCSC).</p><p>The UK has been lucky to avoid such an attack while the US, France, and Ukraine have all suffered this kind of interference, but that luck won't last forever, said Ciaran Martin in an interview with the <a href="https://www.theguardian.com/technology/2018/jan/22/cyber-attack-on-uk-matter-of-when-not-if-says-security-chief-ciaran-martin" target="_blank"><em>Guardian</em></a>.</p><p>"It is a matter of when, not if and we will be fortunate to come to the end of the decade without having to trigger a category one attack," he said.</p><p>"Some attacks will get through. What you need to do is cauterise the damage."</p><p>Category one attacks include any hacks that can damage or bring down infrastructure like energy grids, financial services or even elections.</p><p>The US is still investigating the extent of suspected Russian interference in its 2016 presidential election, while <a href="https://www.itpro.com/security/27824/researchers-confirm-that-ukraine-outage-was-cyber-attack" target="_blank" data-original-url="https://www.itpro.com/security/27824/researchers-confirm-that-ukraine-outage-was-cyber-attack">France withdrew an electronic vote over hacking fears in June last year</a>. Ukraine's power grid was brought down by a hack known as BlackEnergy in 2015, and <a href="https://www.itpro.com/government-it-strategy/28301/france-withdraws-electronic-vote-over-hacking-fears" target="_blank" data-original-url="https://www.itpro.com/government-it-strategy/28301/france-withdraws-electronic-vote-over-hacking-fears">suffered a similar power cut a year later</a>.</p><p>The NCSC is due to publish a report on how successful its security strategies have proved since it opened in October 2016, according to the <em>Guardian</em>.</p><p>The dossier will include a ranking of cyber attacks, which sees the WannaCry ransomware that targeted businesses but also hospitals classed as a category two attack, partly because it presented no risk to life, though it caused widespread delays to hospital operations.</p><p>There were 32 such category two attacks, the NCSC told the publication, and 762 category three attacks.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/national-cyber-security-centre-ncsc/30355/russian-cyber-attack-would-cripple-uk-infrastructure-warns</link>
                                                                            <description>
                            <![CDATA[ An attack would cause "thousands and thousands of deaths" says Gavin Williamson ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2ctTce8tYY6qUUF46vE66W</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RR4yyJ3MSiTXdxerjiScdd-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Jan 2018 09:58:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Roland Moore-Colyer ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RR4yyJ3MSiTXdxerjiScdd-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[UK business]]></media:description>                                                            <media:text><![CDATA[UK business]]></media:text>
                                <media:title type="plain"><![CDATA[UK business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RR4yyJ3MSiTXdxerjiScdd-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK's defence secretary has warned that a cyber attack by Russia could cripple Britain's infrastructure and cause "thousands and thousands and thousands of deaths".</p><p>Gavin Williamson told <a href="http://www.telegraph.co.uk/news/2018/01/25/crippling-russian-attack-britains-infrastructure-could-kill" target="_blank"><em>The Telegraph</em></a> that the Russian government has been researching the UK's energy supply and supporting infrastructure, which if it were to launch a cyber attack against would cause "total chaos" for Britain.</p><p>Williamson noted that a cyber attack from Russian is the "real threat" the UK is currently facing, noting that an attack from Moscow would come from the digital not physical world.</p><p>"The plan for the Russians won't be for landing craft to appear in the South Bay in Scarborough, and off Brighton beach," Williamson told the Telegraph.</p><p>"They are going to be thinking, 'how can we just cause so much pain to Britain?</p><p>"Damage its economy, rip its infrastructure apart, actually cause thousands and thousands and thousands of deaths, but actually have an element of creating total chaos within the country."</p><p>Such comments may be seen as hyperbolic and paranoia tinged, but Williamson statements were backed up by security minister Lord West, who also serves as Britain's First Seal Lord. West said he was "absolutely certain" Russia has been looking at how it could access the UK's critical infrastructure.</p><p>Moscow has not responded to Williamson's claims at the time of writing.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/27824/researchers-confirm-that-ukraine-outage-was-cyber-attack" data-original-url="/security/27824/researchers-confirm-that-ukraine-outage-was-cyber-attack">Researchers confirm that Ukraine outage was cyber attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/government-it-strategy/28301/france-withdraws-electronic-vote-over-hacking-fears" data-original-url="/government-it-strategy/28301/france-withdraws-electronic-vote-over-hacking-fears">France withdraws electronic vote over hacking fears</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/social-media/30339/russian-bots-shared-trumps-election-tweets-500k-times" data-original-url="/social-media/30339/russian-bots-shared-trumps-election-tweets-500k-times">Russian bots shared Trump's election tweets 500k times</a></p></div></div><p><strong>23/01/18: NCSC: </strong><strong>Severe cyber attack on UK is unavoidable</strong></p><p>A serious cyber attack on the UK's vital infrastructure is inevitable, according to the head of the National Cyber Security Centre (NCSC).</p><p>The UK has been lucky to avoid such an attack while the US, France, and Ukraine have all suffered this kind of interference, but that luck won't last forever, said Ciaran Martin in an interview with the <a href="https://www.theguardian.com/technology/2018/jan/22/cyber-attack-on-uk-matter-of-when-not-if-says-security-chief-ciaran-martin" target="_blank"><em>Guardian</em></a>.</p><p>"It is a matter of when, not if and we will be fortunate to come to the end of the decade without having to trigger a category one attack," he said.</p><p>"Some attacks will get through. What you need to do is cauterise the damage."</p><p>Category one attacks include any hacks that can damage or bring down infrastructure like energy grids, financial services or even elections.</p><p>The US is still investigating the extent of suspected Russian interference in its 2016 presidential election, while <a href="https://www.itpro.com/security/27824/researchers-confirm-that-ukraine-outage-was-cyber-attack" target="_blank" data-original-url="https://www.itpro.com/security/27824/researchers-confirm-that-ukraine-outage-was-cyber-attack">France withdrew an electronic vote over hacking fears in June last year</a>. Ukraine's power grid was brought down by a hack known as BlackEnergy in 2015, and <a href="https://www.itpro.com/government-it-strategy/28301/france-withdraws-electronic-vote-over-hacking-fears" target="_blank" data-original-url="https://www.itpro.com/government-it-strategy/28301/france-withdraws-electronic-vote-over-hacking-fears">suffered a similar power cut a year later</a>.</p><p>The NCSC is due to publish a report on how successful its security strategies have proved since it opened in October 2016, according to the <em>Guardian</em>.</p><p>The dossier will include a ranking of cyber attacks, which sees the WannaCry ransomware that targeted businesses but also hospitals classed as a category two attack, partly because it presented no risk to life, though it caused widespread delays to hospital operations.</p><p>There were 32 such category two attacks, the NCSC told the publication, and 762 category three attacks.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Met Police set to finish Windows XP upgrade in May ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The London Metropolitan police is on track to finish upgrading from Windows XP by May this year, marking the end of a rollout that has been underway for more than three years.</p><p>Despite the fact that Windows XP reached its end-of-life in 2014, the Met was still using the operating system on more than 35,000 computers in April 2015, and more than 18,000 machines in June of last year.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28956/met-police-runs-18000-xp-machines" data-original-url="/security/28956/met-police-runs-18000-xp-machines">Met Police runs 18,000 XP machines</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/desktop-software/24510/met-police-still-using-xp-on-35000-computers" data-original-url="/desktop-software/24510/met-police-still-using-xp-on-35000-computers">Met Police still using XP on 35,000 computers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/29384/met-police-chooses-box-to-spur-evidence-sharing" data-original-url="/cloud/29384/met-police-chooses-box-to-spur-evidence-sharing">Met Police chooses Box to spur evidence sharing</a></p></div></div><p>However, the project is finally on the verge of completion. The Met's CIO Angus McCallum told <em>IT Pro</em> that the migration from Windows XP is at an "advanced" stage, with the process of replacing older XP machines with newer devices set to be completed in around three months.</p><p>"The tablet and laptop rollout ... will finish around the April-May time [and] we will be off XP then. We might have the odd machine that's still on it, but it won't be on the network, it'll just be running some software that at this time we cannot run on anything else," McCallum said. "We won't have any networked machines at that time."</p><p>The Met is currently in the process of refreshing its IT estate and by the end of the upgrade cycle it will include around 50,000 devices all of which, McCallum assured <em>IT Pro</em>, will be running Windows 10. "To give you an idea of the speed of the rollout, last week we rolled out 1,687 tablets," he said, "so we're moving at pace now."</p><p>"We've categorised officers as 'operational', so you have a tablet, 'flexi', which for staff is people like me that move around various stations and places, and for certain more senior officers who are moving around, they've got laptops. And then some roles, you cannot physically move from the desk, so you've got a fixed machine."</p><p>Client endpoints are not the only area in which the organisation is investing the Met is also deploying Box's cloud collaboration tools to all of its staff. The partnership was announced six months ago, and McCallum said that after the completion of a successful pilot programme, deployment is now fully underway and is expected to be completed by the end of Q2.</p><p>The main thing that drove the Met to choose Box, he revealed, was ease-of-use. Not only does Box make sharing content within the organisation easier, McCallum said, it also greatly speeds up the sharing of intelligence with external agencies and partners.</p><p>"What we really wanted was a collaboration tool so we can share securely information with third-parties that can be structured appropriately. We can make sure it's in the right folders, we can make sure it's not being stored in email, et cetera."</p><p>"Rather than them saying 'I've seen something on the CCTV, do you want to come and collect a CD', they send us a link. That saves a lot of time, it's just sent electronically to our control room. They can even annotate it and say 'look at 13.00 to 13.30'," explained McCallum. "The officer picks it up straight away, he can look at it, he can determine if there's a crime there or not."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/operating-systems/30310/met-police-set-to-finish-windows-xp-upgrade-in-may</link>
                                                                            <description>
                            <![CDATA[ The rollout process has been ongoing for more than three years ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4qJsY7Jzy6tcsPRnThpmUp</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WzkSquXiTf8L2SekBCpT4R-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Jan 2018 14:13:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Windows]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Microsoft]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WzkSquXiTf8L2SekBCpT4R-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft ghost]]></media:description>                                                            <media:text><![CDATA[Microsoft ghost]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft ghost]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WzkSquXiTf8L2SekBCpT4R-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The London Metropolitan police is on track to finish upgrading from Windows XP by May this year, marking the end of a rollout that has been underway for more than three years.</p><p>Despite the fact that Windows XP reached its end-of-life in 2014, the Met was still using the operating system on more than 35,000 computers in April 2015, and more than 18,000 machines in June of last year.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28956/met-police-runs-18000-xp-machines" data-original-url="/security/28956/met-police-runs-18000-xp-machines">Met Police runs 18,000 XP machines</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/desktop-software/24510/met-police-still-using-xp-on-35000-computers" data-original-url="/desktop-software/24510/met-police-still-using-xp-on-35000-computers">Met Police still using XP on 35,000 computers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/29384/met-police-chooses-box-to-spur-evidence-sharing" data-original-url="/cloud/29384/met-police-chooses-box-to-spur-evidence-sharing">Met Police chooses Box to spur evidence sharing</a></p></div></div><p>However, the project is finally on the verge of completion. The Met's CIO Angus McCallum told <em>IT Pro</em> that the migration from Windows XP is at an "advanced" stage, with the process of replacing older XP machines with newer devices set to be completed in around three months.</p><p>"The tablet and laptop rollout ... will finish around the April-May time [and] we will be off XP then. We might have the odd machine that's still on it, but it won't be on the network, it'll just be running some software that at this time we cannot run on anything else," McCallum said. "We won't have any networked machines at that time."</p><p>The Met is currently in the process of refreshing its IT estate and by the end of the upgrade cycle it will include around 50,000 devices all of which, McCallum assured <em>IT Pro</em>, will be running Windows 10. "To give you an idea of the speed of the rollout, last week we rolled out 1,687 tablets," he said, "so we're moving at pace now."</p><p>"We've categorised officers as 'operational', so you have a tablet, 'flexi', which for staff is people like me that move around various stations and places, and for certain more senior officers who are moving around, they've got laptops. And then some roles, you cannot physically move from the desk, so you've got a fixed machine."</p><p>Client endpoints are not the only area in which the organisation is investing the Met is also deploying Box's cloud collaboration tools to all of its staff. The partnership was announced six months ago, and McCallum said that after the completion of a successful pilot programme, deployment is now fully underway and is expected to be completed by the end of Q2.</p><p>The main thing that drove the Met to choose Box, he revealed, was ease-of-use. Not only does Box make sharing content within the organisation easier, McCallum said, it also greatly speeds up the sharing of intelligence with external agencies and partners.</p><p>"What we really wanted was a collaboration tool so we can share securely information with third-parties that can be structured appropriately. We can make sure it's in the right folders, we can make sure it's not being stored in email, et cetera."</p><p>"Rather than them saying 'I've seen something on the CCTV, do you want to come and collect a CD', they send us a link. That saves a lot of time, it's just sent electronically to our control room. They can even annotate it and say 'look at 13.00 to 13.30'," explained McCallum. "The officer picks it up straight away, he can look at it, he can determine if there's a crime there or not."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WannaCry 'hero' Marcus Hutchins 'was coerced' into Kronos confession ]]></title>
                                                                                                <dc:content><![CDATA[ <p>WannaCry 'hero' Marcus Hutchins was allegedly coerced into confessing that he authored the Kronos banking malware, according to his US lawyers.</p><p>The computer researcher, who found the 'kill switch' for the WannaCry ransomware that forced the NHS to cancel or postpone thousands of operations last May, has pleaded not guilty to US charges of creating and distributing a banking malware called Kronos.</p><p>Arrested at Las Vegas airport after attending an IT security convention in August 2017, Hutchins now faces six charges related to the bank detail-stealing malware between 2014 and 2015.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28992/only-50-of-cios-improve-cyber-security-after-wannacry" data-original-url="/security/28992/only-50-of-cios-improve-cyber-security-after-wannacry">Only 50% of CIOs improve cyber security after WannaCry</a></p></div></div><p>Prosecutors allege that Hutchins confessed to creating Kronos during interrogation, but his lawyers filed a document on Friday outlining their argument that Hutchins' confession was coerced, according to <a href="http://www.dailymail.co.uk/news/article-5242269/My-confession-coerced-British-cyber-expert-claims.html" target="_blank"><em>The Daily Mail</em></a>.</p><p>"The defence intends to argue that the government coerced Mr Hutchins, who was sleep-deprived and intoxicated, to talk," the filing read.</p><p>"As such, his decision to speak with the agents was not knowing, intelligent, and made in full awareness of the nature of the right given up and the consequences of giving up that right, as the law requires."</p><p>They claimed Hutchins was probably under surveillance leading up to his arrest, meaning prosecutors knew that he was "exhausted and intoxicated".</p><p>UK spy agency GCHQ knew that Hutchins was going to be arrested in the US, but did not warn him in order to avoid a lengthy extradition process, according to the <em>Sunday Times</em>.</p><p>Hutchins is currently on bail in Los Angeles, and no date for his trial in Wisconsin has yet been set.</p><p><em>Picture: Bigstock</em></p><p><strong>22/08/2017:GCHQ 'knew in advance' about US plan to arrest WannaCry hero</strong></p><p>GCHQ was reportedlyaware in advance that WannaCry 'hero' and suspected malware author Marcus Hutchins would be arrested in the US, but chose not to warn him to avoid a lengthy extradition process, according to the <a href="https://www.thetimes.co.uk/article/british-spy-chiefs-knew-of-fbi-sting-on-nhs-hack-attack-hero-marcus-hutchins-hctlgbvrr" target="_blank"><em>Sunday Times</em></a>.</p><p>Officials at the UK's spy agency knew that Hutchins, also known as MalwareTech, was under surveillance by the US and that the FBI would detain him once he left the Defcon security conference in Las Vegas, which he flew out to attend in late July, the publication reported.</p><p>GCHQ decided not to warn the 23-year-old before he left the UK to avoid the "headache of an extradition battle", according to anonymous<em>Sunday Times</em>sources familiar with the case.</p><p>Hutchins was praised by the National Cyber Security Centre, a branch of GCHQ, when he helped stop the WannaCry ransomware outbreak in May, which affected over 200,000 computers in more than 150 countries, including NHS systems.</p><p>However, the US has accused Hutchins of creating and distributing the 'Kronos' banking malware, which scalps personal banking information from infected PCs. He has pleaded not guilty to six charges relating to computer misuse, and could spent up to 40 years in prison if found guilty.</p><p>Sources speaking to the <em>Sunday Times</em> said: "Our US partners aren't impressed that some people who they believe to have cases against [them] for computer-related offences have managed to avoid extradition. Hutchins' arrest free[s] the British government and intelligence agencies from yet another headache of an extradition battle."</p><p>The UK has previously fought with the US over the extradition of suspected computer hackers, including 51-year-old <a href="https://www.itpro.com/644716/cps-confirms-gary-mckinnon-will-not-face-charges-in-the-uk" target="_blank" data-original-url="https://www.itpro.com/644716/cps-confirms-gary-mckinnon-will-not-face-charges-in-the-uk">Gary McKinnon</a>, who gained unauthorised access to US government systems in 2012. McKinnon, who suffers from Asperger's syndrome, avoided extradition after a 10-year battle after he was deemed too ill to travel.</p><p>Laurie Love, a 32-year-old activist who also suffers from Asperger's syndrome, <a href="https://www.itpro.com/hacking/27254/lauri-love-wins-right-to-appeal-extradition-order" target="_blank" data-original-url="https://www.itpro.com/hacking/27254/lauri-love-wins-right-to-appeal-extradition-order">won the right to appeal his US extradition</a> in April this year. He is charged with hacking into US military systems and NASA.</p><p>Hutchins has been free on bail since 5 August, but he is unable to leave the US and has been placed under electronic surveillance.</p><p><em>IT Pro</em> has approached the National Cyber Security Centre for comment. At the time of Hutchins' arrest, a spokesman for the organisation told the<a href="http://www.bbc.co.uk/news/uk-england-40820837" target="_blank"><em>BBC</em></a> that it was aware of the situation, adding:"This is a law enforcement matter and it would be inappropriate to comment further."</p><p><strong>15/08/2017:</strong> Marcus Hutchins, the cyber security researcher who put a stop to the global WannaCry ransomware attack, has pleaded not guilty to involvement in the creation and distribution of another malware, Kronos.</p><p>Hutchins, a 23-year-old UK national, was arrested at Las Vegas McCarran Airport on 2 August as he attempted to leave the US after attending Def Con cyber security conferences. He was then charged approximately 48 hours later on six counts relating to the creation and distribution of a banking Trojan known as Kronos.</p><p>This is the second time Hutchins has pleaded not guilty to the charges against him. Yesterday, he appeared in a court in Milwaukee, where the charges were actually filed, but he initially appeared in court in Las Vegas on 6 August, before being flown to Wisconsin.</p><p>The judge trying the case, which has been brought by the FBI, has set a trial date for October and permitted Hutchins to use the internet something he had been banned from doing until now although he's banned from accessing the server he used to kill off the WannaCry attack. He also has to remain in the US under house arrest until his trial and, <a href="http://www.bbc.co.uk/news/technology-40923065" target="_blank">according to <em>BBC News</em></a>, will have to surrender his passport to the authorities and be tracked by GPS until his trial.</p><p>Hutchins took to Twitter to thank his supporters.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/897185734100221952"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/897185734100221952"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>He also stated that while he would like to talk openly about his experience, he can't as the case is ongoing, so cracked some jokes instead, including a list of <a href="https://twitter.com/MalwareTechBlog/status/897180606005694464" target="_blank">"what to do during Def Con"</a> (which refers back to some of the earlier charges he faced that have since been dropped, including visiting a firing range) and a short review of <a href="https://twitter.com/MalwareTechBlog/status/897308297270874113" target="_blank">UberEATS</a>.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/893624617142759425"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/893624617142759425"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>His lawyer, Adrian Lobo, <a href="https://www.facebook.com/ChristyNews3LV/videos/1746478715365613" target="_blank">addressed reporters</a> outside of court on Friday following a bail hearing, saying the judge set bail at $30,000, but that the clerk's office closed shortly after the hearing, meaning Hutchins was forced to spend the weekend in jail.</p><p>Lobo said the money is coming "from a variety of sources; he has tremendous community support, local and abroad, and in the computer world".</p><p>Mabbitt, along with fellow security researcher Tarah M Wheeler, are among the people attempting to raise money for his bail and other legal expenses via crowdfunding. It's unclear how much has been raised so far, although it's anticipated that Hutchins will be able to post bail today.</p><p>Other conditions of Hutchins' bail are that he must surrender his passport, remain in the US, be held under house arrest and not attempt to use the internet. He will <a href="http://www.telegraph.co.uk/news/2017/08/05/wannacry-hero-marcus-hutchins-admitted-creating-code-harvest" target="_blank">reportedly appear in a Wisconsin court</a>, where a grand jury indicted him, tomorrow, where he is expected to formally enter his pleas to the specific charges.</p><p>Hutchins was hailed a hero after stopping the spread of the WannaCry ransomware in May, after finding a kill-switch in its code.</p><p><strong>04/08/2017: US charges WannaCry 'hero' with creating Kronos banking Trojan</strong></p><p>A British security researcher who stopped the <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">WannaCry ransomware attack</a>in its tracks has been charged with creating and distributing the Kronos banking Trojan.</p><p>Marcus Hutchins, 23, also known as MalwareTech, was detained on Wednesday 2 August at Las Vegas McCarran airport as he tried to leave the country, having spent the first half of the week at the Black Hat and Defcon security conferences in the city. He was then charged either the same day or on Thursday 3 August the exact timing is not currently clear.</p><p>The US Department of Justice (DoJ) said in a statement: "Marcus Hutchins... a citizen and resident of the United Kingdom, was arrested in the United States on 2 August, 2017, in Las Vegas, Nevada, after a grand jury in the Eastern District of Wisconsin returned a six-count indictment against Hutchins for his role in creating and distributing the Kronos banking Trojan.</p><p>"The charges against Hutchins, and for which he was arrested, relate to alleged conduct that occurred between in or around July 2014 and July 2015."</p><p>Kronos, which steals banking logins from users, was largely marketed and distributed through a dark website hosted on Tor called AlphaBay, and the DoJ announced on 20 July that the US and other countries had successfully shut it down.</p><p>The DoJ said it's been used to steal banking logins from Canada, Poland, Germany, the UK and France.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/890448472322842624"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/890448472322842624"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p><em>Marcus Hutchins in Las Vegas last week</em></p><p>Hutchins was charged with one count of conspiracy to commit computer fraud and abuse, three counts of distributing and advertising an electronic communication interception device, one count of endeavouring to intercept electronic communications, and one count of attempting to access a computer without authorisation.</p><p>Another person has also been arrested and faces the same charges, however no details have so far been released about them. They are both due to appear in court later today.</p><p>A spokesperson for the Foreign and Commonwealth Office told<em>IT Pro</em>: "We are in contact with the local authorities in Las Vegas following the arrest of a British man, and are providing support to his family."</p><p><em><strong><a href="http://www.alphr.com/security/1006529/kronos-malware-banking-trojan">For more information about what Kronos is, head over to our sister title Alphr's explainer article.</a></strong></em></p><p>It's not clear where Hutchins is being held, having apparently been moved on from the Henderson Detention Center in Nevada at some point on Thursday.</p><p><em>IT Pro</em> also contacted the FBI in Las Vegas for clarification of what role that agency has had in the arrest, if any, and was awaiting a response at the time of publication.The Henderson Detention Center couldn't be contacted.</p><p>"Cybercrime remains a top priority for the FBI," said Justin Tolomeo, the FBI's special agent in charge. "Cybercriminals cost our economy billions in loses each year. The FBI will continue to work with our partners, both domestic and international, to bring offenders to justice."</p><p>Hutchins shot to famein May 2017 when he managed to put a stop to the WannaCry ransomware attack accidentally by registering a website found in the malware's code. It was claimed by <em><a href="http://www.telegraph.co.uk/news/2017/05/14/revealed-22-year-old-expert-saved-world-ransomware-virus-lives" target="_blank">The Telegraph</a></em>that Hutchins began working with the National Cyber Crime Unit of the National Crime Agency, but this hasn't been confirmed.</p><p><em>Main image credit: Bigstock</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges</link>
                                                                            <description>
                            <![CDATA[ Lawyers will argue that US prosecutors knew Hutchins was exhausted and intoxicated ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hqJKFSosjnZkAVzsEH6EUf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8Znfw7fa3nJR5AYbNVnahh-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 09 Jan 2018 10:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8Znfw7fa3nJR5AYbNVnahh-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[law]]></media:description>                                                            <media:text><![CDATA[law]]></media:text>
                                <media:title type="plain"><![CDATA[law]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8Znfw7fa3nJR5AYbNVnahh-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>WannaCry 'hero' Marcus Hutchins was allegedly coerced into confessing that he authored the Kronos banking malware, according to his US lawyers.</p><p>The computer researcher, who found the 'kill switch' for the WannaCry ransomware that forced the NHS to cancel or postpone thousands of operations last May, has pleaded not guilty to US charges of creating and distributing a banking malware called Kronos.</p><p>Arrested at Las Vegas airport after attending an IT security convention in August 2017, Hutchins now faces six charges related to the bank detail-stealing malware between 2014 and 2015.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28992/only-50-of-cios-improve-cyber-security-after-wannacry" data-original-url="/security/28992/only-50-of-cios-improve-cyber-security-after-wannacry">Only 50% of CIOs improve cyber security after WannaCry</a></p></div></div><p>Prosecutors allege that Hutchins confessed to creating Kronos during interrogation, but his lawyers filed a document on Friday outlining their argument that Hutchins' confession was coerced, according to <a href="http://www.dailymail.co.uk/news/article-5242269/My-confession-coerced-British-cyber-expert-claims.html" target="_blank"><em>The Daily Mail</em></a>.</p><p>"The defence intends to argue that the government coerced Mr Hutchins, who was sleep-deprived and intoxicated, to talk," the filing read.</p><p>"As such, his decision to speak with the agents was not knowing, intelligent, and made in full awareness of the nature of the right given up and the consequences of giving up that right, as the law requires."</p><p>They claimed Hutchins was probably under surveillance leading up to his arrest, meaning prosecutors knew that he was "exhausted and intoxicated".</p><p>UK spy agency GCHQ knew that Hutchins was going to be arrested in the US, but did not warn him in order to avoid a lengthy extradition process, according to the <em>Sunday Times</em>.</p><p>Hutchins is currently on bail in Los Angeles, and no date for his trial in Wisconsin has yet been set.</p><p><em>Picture: Bigstock</em></p><p><strong>22/08/2017:GCHQ 'knew in advance' about US plan to arrest WannaCry hero</strong></p><p>GCHQ was reportedlyaware in advance that WannaCry 'hero' and suspected malware author Marcus Hutchins would be arrested in the US, but chose not to warn him to avoid a lengthy extradition process, according to the <a href="https://www.thetimes.co.uk/article/british-spy-chiefs-knew-of-fbi-sting-on-nhs-hack-attack-hero-marcus-hutchins-hctlgbvrr" target="_blank"><em>Sunday Times</em></a>.</p><p>Officials at the UK's spy agency knew that Hutchins, also known as MalwareTech, was under surveillance by the US and that the FBI would detain him once he left the Defcon security conference in Las Vegas, which he flew out to attend in late July, the publication reported.</p><p>GCHQ decided not to warn the 23-year-old before he left the UK to avoid the "headache of an extradition battle", according to anonymous<em>Sunday Times</em>sources familiar with the case.</p><p>Hutchins was praised by the National Cyber Security Centre, a branch of GCHQ, when he helped stop the WannaCry ransomware outbreak in May, which affected over 200,000 computers in more than 150 countries, including NHS systems.</p><p>However, the US has accused Hutchins of creating and distributing the 'Kronos' banking malware, which scalps personal banking information from infected PCs. He has pleaded not guilty to six charges relating to computer misuse, and could spent up to 40 years in prison if found guilty.</p><p>Sources speaking to the <em>Sunday Times</em> said: "Our US partners aren't impressed that some people who they believe to have cases against [them] for computer-related offences have managed to avoid extradition. Hutchins' arrest free[s] the British government and intelligence agencies from yet another headache of an extradition battle."</p><p>The UK has previously fought with the US over the extradition of suspected computer hackers, including 51-year-old <a href="https://www.itpro.com/644716/cps-confirms-gary-mckinnon-will-not-face-charges-in-the-uk" target="_blank" data-original-url="https://www.itpro.com/644716/cps-confirms-gary-mckinnon-will-not-face-charges-in-the-uk">Gary McKinnon</a>, who gained unauthorised access to US government systems in 2012. McKinnon, who suffers from Asperger's syndrome, avoided extradition after a 10-year battle after he was deemed too ill to travel.</p><p>Laurie Love, a 32-year-old activist who also suffers from Asperger's syndrome, <a href="https://www.itpro.com/hacking/27254/lauri-love-wins-right-to-appeal-extradition-order" target="_blank" data-original-url="https://www.itpro.com/hacking/27254/lauri-love-wins-right-to-appeal-extradition-order">won the right to appeal his US extradition</a> in April this year. He is charged with hacking into US military systems and NASA.</p><p>Hutchins has been free on bail since 5 August, but he is unable to leave the US and has been placed under electronic surveillance.</p><p><em>IT Pro</em> has approached the National Cyber Security Centre for comment. At the time of Hutchins' arrest, a spokesman for the organisation told the<a href="http://www.bbc.co.uk/news/uk-england-40820837" target="_blank"><em>BBC</em></a> that it was aware of the situation, adding:"This is a law enforcement matter and it would be inappropriate to comment further."</p><p><strong>15/08/2017:</strong> Marcus Hutchins, the cyber security researcher who put a stop to the global WannaCry ransomware attack, has pleaded not guilty to involvement in the creation and distribution of another malware, Kronos.</p><p>Hutchins, a 23-year-old UK national, was arrested at Las Vegas McCarran Airport on 2 August as he attempted to leave the US after attending Def Con cyber security conferences. He was then charged approximately 48 hours later on six counts relating to the creation and distribution of a banking Trojan known as Kronos.</p><p>This is the second time Hutchins has pleaded not guilty to the charges against him. Yesterday, he appeared in a court in Milwaukee, where the charges were actually filed, but he initially appeared in court in Las Vegas on 6 August, before being flown to Wisconsin.</p><p>The judge trying the case, which has been brought by the FBI, has set a trial date for October and permitted Hutchins to use the internet something he had been banned from doing until now although he's banned from accessing the server he used to kill off the WannaCry attack. He also has to remain in the US under house arrest until his trial and, <a href="http://www.bbc.co.uk/news/technology-40923065" target="_blank">according to <em>BBC News</em></a>, will have to surrender his passport to the authorities and be tracked by GPS until his trial.</p><p>Hutchins took to Twitter to thank his supporters.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/897185734100221952"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/897185734100221952"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>He also stated that while he would like to talk openly about his experience, he can't as the case is ongoing, so cracked some jokes instead, including a list of <a href="https://twitter.com/MalwareTechBlog/status/897180606005694464" target="_blank">"what to do during Def Con"</a> (which refers back to some of the earlier charges he faced that have since been dropped, including visiting a firing range) and a short review of <a href="https://twitter.com/MalwareTechBlog/status/897308297270874113" target="_blank">UberEATS</a>.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/893624617142759425"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/893624617142759425"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>His lawyer, Adrian Lobo, <a href="https://www.facebook.com/ChristyNews3LV/videos/1746478715365613" target="_blank">addressed reporters</a> outside of court on Friday following a bail hearing, saying the judge set bail at $30,000, but that the clerk's office closed shortly after the hearing, meaning Hutchins was forced to spend the weekend in jail.</p><p>Lobo said the money is coming "from a variety of sources; he has tremendous community support, local and abroad, and in the computer world".</p><p>Mabbitt, along with fellow security researcher Tarah M Wheeler, are among the people attempting to raise money for his bail and other legal expenses via crowdfunding. It's unclear how much has been raised so far, although it's anticipated that Hutchins will be able to post bail today.</p><p>Other conditions of Hutchins' bail are that he must surrender his passport, remain in the US, be held under house arrest and not attempt to use the internet. He will <a href="http://www.telegraph.co.uk/news/2017/08/05/wannacry-hero-marcus-hutchins-admitted-creating-code-harvest" target="_blank">reportedly appear in a Wisconsin court</a>, where a grand jury indicted him, tomorrow, where he is expected to formally enter his pleas to the specific charges.</p><p>Hutchins was hailed a hero after stopping the spread of the WannaCry ransomware in May, after finding a kill-switch in its code.</p><p><strong>04/08/2017: US charges WannaCry 'hero' with creating Kronos banking Trojan</strong></p><p>A British security researcher who stopped the <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">WannaCry ransomware attack</a>in its tracks has been charged with creating and distributing the Kronos banking Trojan.</p><p>Marcus Hutchins, 23, also known as MalwareTech, was detained on Wednesday 2 August at Las Vegas McCarran airport as he tried to leave the country, having spent the first half of the week at the Black Hat and Defcon security conferences in the city. He was then charged either the same day or on Thursday 3 August the exact timing is not currently clear.</p><p>The US Department of Justice (DoJ) said in a statement: "Marcus Hutchins... a citizen and resident of the United Kingdom, was arrested in the United States on 2 August, 2017, in Las Vegas, Nevada, after a grand jury in the Eastern District of Wisconsin returned a six-count indictment against Hutchins for his role in creating and distributing the Kronos banking Trojan.</p><p>"The charges against Hutchins, and for which he was arrested, relate to alleged conduct that occurred between in or around July 2014 and July 2015."</p><p>Kronos, which steals banking logins from users, was largely marketed and distributed through a dark website hosted on Tor called AlphaBay, and the DoJ announced on 20 July that the US and other countries had successfully shut it down.</p><p>The DoJ said it's been used to steal banking logins from Canada, Poland, Germany, the UK and France.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/890448472322842624"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/890448472322842624"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p><em>Marcus Hutchins in Las Vegas last week</em></p><p>Hutchins was charged with one count of conspiracy to commit computer fraud and abuse, three counts of distributing and advertising an electronic communication interception device, one count of endeavouring to intercept electronic communications, and one count of attempting to access a computer without authorisation.</p><p>Another person has also been arrested and faces the same charges, however no details have so far been released about them. They are both due to appear in court later today.</p><p>A spokesperson for the Foreign and Commonwealth Office told<em>IT Pro</em>: "We are in contact with the local authorities in Las Vegas following the arrest of a British man, and are providing support to his family."</p><p><em><strong><a href="http://www.alphr.com/security/1006529/kronos-malware-banking-trojan">For more information about what Kronos is, head over to our sister title Alphr's explainer article.</a></strong></em></p><p>It's not clear where Hutchins is being held, having apparently been moved on from the Henderson Detention Center in Nevada at some point on Thursday.</p><p><em>IT Pro</em> also contacted the FBI in Las Vegas for clarification of what role that agency has had in the arrest, if any, and was awaiting a response at the time of publication.The Henderson Detention Center couldn't be contacted.</p><p>"Cybercrime remains a top priority for the FBI," said Justin Tolomeo, the FBI's special agent in charge. "Cybercriminals cost our economy billions in loses each year. The FBI will continue to work with our partners, both domestic and international, to bring offenders to justice."</p><p>Hutchins shot to famein May 2017 when he managed to put a stop to the WannaCry ransomware attack accidentally by registering a website found in the malware's code. It was claimed by <em><a href="http://www.telegraph.co.uk/news/2017/05/14/revealed-22-year-old-expert-saved-world-ransomware-virus-lives" target="_blank">The Telegraph</a></em>that Hutchins began working with the National Cyber Crime Unit of the National Crime Agency, but this hasn't been confirmed.</p><p><em>Main image credit: Bigstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NHS ransomware: UK government says it's North Korea's fault WannaCry happened ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The UK's Foreign Office has said it too blames North Korea for the WannaCry ransomware campaign that brought the majority of the NHS and other public sector organisations to their knees back in May.</p><p>"The UK's National Cyber Security Centre assesses it is highly likely that North Korean actors known as the Lazarus Group were behind the WannaCry ransomware campaign one of the most significant to hit the UK in terms of scale and disruption," Foreign Office Minister Lord Ahmad of Wimbledon said in a statement.</p><p>The official announcement follows comments by Security Minister Ben Wallace in October that suggested the government believed a nation-state was responsible for WannaCry campaign, and that it was "as sure as possible" that state was North Korea.</p><p>He said, like the US authorities, the UK government would "identify, pursue and respond" to malicious activity and wants to make it clear it will not tolerate malicious cyber activity of any kind, wherever it may originate and however severe the impact. It will impose costs on the responsible parties, preventing them from launching further attacks and using them as an example to deter other potential criminals.</p><p>"We condemn these actions and commit ourselves to working with all responsible states to combat destructive criminal use of cyber space," he added. "The indiscriminate use of the WannaCry ransomware demonstrates North Korean actors using their cyber programme to circumvent sanctions."</p><p>Lord Ahmad added that the UK authorities will work closely with other organisations around the world to "uphold a free, open, peaceful and secure cyberspace."</p><p>The WannaCry attacks affected 300,000 computers in 150 countries, including 48 NHS trusts, the government said. Users were told they needed to pay a ransom to get their machines unlocked and data restored.</p><p><strong>19/12/2017: NHS ransomware: US blames North Korea for "cowardly" WannaCry attack</strong></p><p>The US government has officially blamed North Korea for the devastating WannaCry ransomware campaign that crippled public services and infrastructure in more than 35 countries in May.</p><p>The announcement, made by Homeland Security Advisor Thomas Bossert in the <a href="https://www.wsj.com/articles/its-official-north-korea-is-behind-wannacry-1513642537" target="_blank"><em>New York Times</em></a>, is the first time the US has formally blamed a nation-state for the attack which hit the NHS, Spain's Telefonica, FedEx and German rail company Deutsche Bahn.</p><p>"After careful investigation, the US today publicly attributes the massive 'WannaCry' cyber attack to North Korea," said Bossert. "It encrypted and rendered useless hundreds of thousands of computers in hospitals, schools, businesses and homes. While victims received ransom demands, paying did not unlock their computers."</p><p>"It was cowardly, costly and careless," added Bossert. "The attack was widespread and cost billions, and North Korea is directly responsible."</p><p>North Korea became a suspect almost immediately following an initial investigation into the attack, particularly as the malware shared a number of similarities with the <a href="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack" target="_blank" data-original-url="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack">attack on Sony Pictures</a>, widely thought to have been carried out by the North Korean-based "Lazarus Group".</p><p>The WannaCry campaign is thought to have affected around 300,000 computer systems across the world, propagated through a vulnerability in Windows XP and Windows Server 2003. The attack was eventually halted when security researcher <a href="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges" target="_blank" data-original-url="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges">Marcus Hutchins</a> discovered a 'kill switch' in the malware that shut down the malware before it delivered its payload.</p><p>The US stance comes almost three months after the UK government and Microsoft officially blamed North Korea for the attack. "North Korea was the state that we believe was involved in this worldwide attack on our systems," said security minister Ben Wallace, speaking to <a href="http://www.bbc.co.uk/programmes/b099v37j" target="_blank"><em>BBC Radio 4</em></a>. "It is widely believed across the community and in a number of countries that North Korea had taken this role."</p><p>As well as officially blaming Pyongyang for the attack, Bossert took the opportunity to highlight recent bolstering of IT defences by the Trump administration.</p><p>"(Trump's) continued sanctions on Russian hackers and directed the most transparent and effective government effort in the world to find and share vulnerabilities in important software," said Bossert, almost certainly referring to the recent <a href="https://www.itpro.com/technology/blockchain" target="_blank" data-original-url="https://www.itpro.com/antivirus/28647/USKasperskyBan">ban on Kaspersky products</a> from all government departments.</p><p>Bossert added that the US was now calling on the private sector to "increase its accountability in the cyber realm by taking actions that deny North Korea and other bad actors the ability to launch reckless and destructive cyber attacks."</p><p>North Korea has always denied its involvement in the WannaCry attack, and labelled the UK's accusation as a "wicked attempt" to enact tougher sanctions against the country.</p><p>Speaking to the Korean Central News Agency, a spokesperson for the Korea-Europe Association said at the time: "It does not make any sense that the DPRK, which gives the highest priority to the life and health of its people, would carry out a cyber attack on the UK health service."</p><p><strong>28/11/2017: NHS to hire ethical hackers in 20m cyber security boost</strong></p><p>The NHS has set aside 20 million to establish a new security centre designed to constantly probe the organisation's cyber defences using ethical hackers.</p><p>The Security Operations Centre (SOC) will operate throughout all NHS sites across the UK, providing monitoring services and guidance on how to handle cyber security incidents to local departments.</p><p>Part of its remit will be to employ 'white-hat' hackers to test the NHS' ability to prevent a data breach or a repeat of the style of attacks seen during the WannaCry ransomware campaign, which hit over one-third of health trusts earlier this year.</p><p>Dan Taylor, head of the Digital Security Centre at NHS Digital, <a href="https://digital.nhs.uk/article/8058/New-cyber-security-service-to-boost-NHS-protection-">said</a> that the new centre will provide a "near-real-time monitoring and alerting service that covers the whole health and care system"</p><p>"The Security Operations Centre will enhance NHS Digital's current data security services that support the health and care system in protecting sensitive patient information," he added.</p><p>"The partnership will provide access to extra specialist resources during peak periods and enable the team to proactively monitor the web for security threats and emerging vulnerabilities.</p><p>"It will also allow us to improve our current capabilities in ethical hacking, vulnerability testing and the forensic analysis of malicious software, and will improve our ability to anticipate future vulnerabilities while supporting health and care in remediating current known threats."</p><p>Taylor said the centre would "drive economies of scale, giving health and care organisations additional intelligence and support services that they might not otherwise be able to access".</p><p>NHS Digital also said it's seeking a partner to provide advice and help run the project, a contract for which is tendered to run for three to five years.</p><p>It's not the first time a public body has turned to ethical hacking to probe its defences. In July, it was revealed that the Met Office had previously asked cloud security firm Cloudreach to <a href="http://www.cloudpro.co.uk/hr/training/6904/met-office-asks-cloudreach-to-purposefully-break-its-systems">purposefully break its systems</a> in an effort to test how well its teams were able to deal with major outages.</p><p>The move is the latest attempt to try and overhaul the NHS' outdated IT systems, which were considered to have been a soft target for the WannaCry malware. A recent report by the National Audit Office found that "basic IT security" could have prevented the spread of the ransomware, and that the NHS had been warned previously about its reliance on the outdated Windows XP operating system.</p><p>"Given the impact of the WannaCry attack, one must ask why it has taken them so long to create an SOC," said Matt Lock, director of sales engineers at Varonis, in a statement to <em>IT Pro</em>.</p><p>"The new centre must be a part of an ongoing effort to keep up with the latest attacks from extremely well-funded and experienced criminals intent on compromising the NHS system.</p><p>"An SOC is an important piece of the overall security posture for large organizations, but continuous improvement and advancements are critical parts of the equation."</p><p><strong>31/10/2017: North Korea denies it created the WannaCry ransomware</strong></p><p>North Korea yesterday denied being behind the devastating WannaCry attack, after the UK government identified the nation as the creator of the ransomware.</p><p>Home Office Minister Ben Wallace told the <em><a href="http://www.bbc.co.uk/news/technology-41753022%5D">BBC</a> </em>last week that the government was "as sure as possible" that North Korea was behind the cyber attack in May, which caused chaos among NHS hospitals, dozens of which had to suspend and postpone appointments and operations.</p><p>But a spokesperson for the North's Korea-Europe Association denounced this as a "wicked attempt" to toughen sanctions against the country, which is currently embroiled in a war of words with the US over its nuclear tests.</p><p>In the statement, published on the <em>Korean Central News Agency</em>, the spokesperson <a href="http://www.kcna.kp/kcna.user.article.retrieveNewsViewInfoList.kcmsf#this">said</a>: "It does not make any sense that the DPRK, which gives the highest priority to the life and health of its people, would carry out a cyber attack on the UK health service.</p><p>"The moves of the UK government to doggedly associate the DPRK with the cyber attack cannot be interpreted in any other way than a wicked attempt to lure the international community into harbouring greater mistrust of the DPRK and further tighten sanctions and pressure against the latter."</p><p>The spokesperson added: "This is an act beyond the limit of our tolerance and it makes us question the real purpose behind the UK's move."</p><p>Along with the UK government, Microsoft also said it believed North Korea was behind the WannaCry attack. Brad Smith, Microsoft's president and chief legal officer, said that the attack was carried out by the country using cyber tools stolen from the NSA in the US.</p><p>An investigation into the ransomware attack found that the NHS failed to follow basic IT security principles that could have prevented the malware from taking effect, such as upgrading from the unsupported Windows XP operating system.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="/security/28084/what-is-ransomware">What is ransomware?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/28070/best-ransomware-removal-tools" data-original-url="/security/ransomware/28070/best-ransomware-removal-tools">Best ransomware removal tools</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/malware/28153/whats-the-difference-between-antimalware-and-antivirus" data-original-url="/malware/28153/whats-the-difference-between-antimalware-and-antivirus">What's the difference between antimalware and antivirus?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack" data-original-url="/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack">No-one is blameless when it comes to the NHS WannaCry hack</a></p></div></div><p><strong>27/10/2017: NHS ransomware: "Basic IT security" could've prevented WannaCry</strong></p><p>A report conducted by the National Audit Office found that the NHS was informed by the Department of Health and the Cabinet as early as 2014 about the dangers of cyber attacks and were encouraged to make plans to move away from old software like Windows XP by April 2015.</p><p>Despite the NHS's critical alerts telling organisations to patch their system to prevent the spread of WannaCry ransomware, the department had "no formal mechanism for assessing whether local NHS organisations had complied with their advice and guidance and whether they were prepared for a cyber attack".</p><p>"The WannaCry cyber attack had potentially serious implications for the NHS and its ability to provide care to patients. It was a relatively unsophisticated attack and could have been prevented by the NHS following basic IT security best practice. There are more sophisticated cyber threats out there than WannaCry so the department and the NHS need to get their act together to ensure the NHS is better protected against future attacks," said Amyas Morse, head of the National Audit Office.</p><p>The attack, which occurred on 12 May 2017, affected 81 out of 236 NHS organisations in England. It also lead to the cancellation of 19,500 medical appointments, the locking of 600 GP surgeries, and the diversion of ambulances from five hospitals, according to <a href="https://www.nao.org.uk/report/investigation-wannacry-cyber-attack-and-the-nhs">the report</a>.</p><p>Although the department, NHS England, and the National Crime Agency said that no NHS organisation paid the ransom, the report found that the department does not know how much the attacks cost the NHS when considering costs such as the cancelled appointments, IT support and consultants, along with the restoration of data.</p><p>"What the NHS needed was the ability to detect and put a stop to malicious behaviour as early as possible in the kill chain," Nick Pollard, security intelligence and analytics director at Nuix said.</p><p>He suggested the use of next-generation endpoint security, which "can analyse unknown processes and terminates those that exhibit bad behaviours, keeping end users from clicking on unusual and potentially harmful attachments and applications even before they knew you were in danger".</p><p>The report said that the NHS has learned from WannaCry and is taking action to secure local firewalls by asking hospital trust boards to make sure they have implemented measures outlined in all alerts issued between March and May 2017.</p><p><strong>16/10/17: Microsoft says North Korea was behind WannaCry attack</strong></p><p>Microsoft's president and chief legal officer has said that North Korea was behind the WannaCry attack that affected companies worldwide.</p><p>Brad Smith told <a href="http://www.itv.com/news/2017-10-13/hacking-threat-is-as-serious-as-terrorism-says-microsoft-boss"><em>ITV News</em></a>: "I think at this point that all observers in the know have concluded that WannaCry was caused by North Korea using cyber tools or weapons that were stolen from the National Security Agency in the United States."</p><p>Smith also said cyber-attacks conducted by nation-states have become more frequent and more severe. He added that governments around the world should do more to protect people from harm.</p><p>"We need governments to come together as they did in Geneva in 1949 and adopt a new digital Geneva Convention that makes clear that these cyber-attacks against civilians, especially in times of peace, are off-limits and a violation of international law," said Smith.</p><p>He addressed criticism over the fact that Microsoft left Windows XP vulnerable to attackers since it had withdrawn support for the operating system. "When there's a broad attack, we provide patches for [all versions of Windows]," he said. "We did so with WannaCry, we did it again in June when Ukraine was attacked."</p><p>He added: "At the same time we repeatedly asked people, we explained to people, we virtually pleaded with people 'please don't rely on software that now belongs in a museum'."</p><p>Smith underlined that hospitals need to give more priority to upgrading their IT systems. "When hospitals think about the equipment that is critical to protecting their patients they've got to think not only about the beds...Computers play a fundamental role in the delivery of healthcare and patients shouldn't have to rely on healthcare based on an old computer."</p><p>WannaCry affected over 200,000 computers in 150 countries and demanded money for users to access their files.</p><p>Marcus Hutchins, the British security researcher who stopped the attack, <a href="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges" data-original-url="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges">was charged by US authorities with creating and distributing the Kronos banking Trojan in August.</a></p><p>At IP Expo 2017, Microsoft's Brad Anderson told <em>IT Pro</em> that <a href="https://www.itpro.com/security/29632/microsoft-sees-300-increase-in-cyber-attacks-in-the-last-year" data-original-url="https://www.itpro.com/security/29632/microsoft-sees-300-increase-in-cyber-attacks-in-the-last-year">the company had seen a 300% increase in cyber attacks in the last year</a>. The sophistication of the attacks have increased and the most sophisticated ones he has seen are from nation-states.</p><p><strong>18/08/2017: 'WannaCry' ransomware hits LG self-service kiosks</strong></p><p>Electronics giant LG has likely become the latest victim of the WannaCry ransomware, which infected self-service kiosks found at its service centres.</p><p>LG has yet to confirm the infection was definitely the WannaCry ransomware, but a spokesperson told <a href="http://www.koreaherald.com/view.php?ud=20170816000700"><em>The Korea Herald</em></a> that the malware bears a strong resemblance to WannaCry, which caused widespread chaos when it targeted NHS hospitals and businesses in May.</p><p>"The problem was found to be caused by ransomware. There was no damage such as data encryption or asking for money, as we immediately shut down the service centre network," the spokesperson said.</p><p>The infection was reported to the state-run Korean Internet & Security Agency, which noted that it had found samples of code in the LG kiosks that were identical to code used in the original WannaCry ransomware campaign.</p><p>LG moved to quickly shut down the kiosks and pushed out a security update for them, and said that all the of the kiosks are now back up and running.</p><p>Dean Ferrando, EMEA manager at cyber security firm Tripwire, suggested that the infection of LG's kiosks is down to the company failing to apply a security update to the vulnerable machines.</p><p>"Reports suggest that the company had not applied all the security updates available from Microsoft. This highlights something that we already knew - many organisations are not good at applying software security updates," he said.</p><p>"Applying available patches is one of the easiest ways to keep an organisation safe from new attacks however, the unfortunate truth is that, despite the warnings and advisories to patch and secure the systems, there will always be a system that is missed."</p><p><strong>17/08/2017: WannaCry paralyses 200 computers in Delhi</strong></p><p>WannaCry has infected over 200 computers belonging to book publishing company Rachna Sagar in the Indian capital New Delhi.</p><p>The attack was reported on 9 August as staff found they could no longer access their user accounts, according to <em><a href="http://indianexpress.com/article/cities/delhi/200-accounts-locked-in-delhis-first-wannacry-attack-publishing-firm-hit-4800160">The</a> </em><em><a href="http://indianexpress.com/article/cities/delhi/200-accounts-locked-in-delhis-first-wannacry-attack-publishing-firm-hit-4800160">Indian Express</a></em>.</p><p>Users were faced with a message demanding $800-$1000 US dollars in <a href="https://www.itpro.com/strategy/28261/bitcoin-news" data-original-url="https://www.itpro.com/strategy/28261/bitcoin-news">Bitcoin</a> in order to unlock their computers.</p><p>A complaint filed by the company at the Darya Ganj police station read: "This morning, when we started our work and opened Busy software, we received a text message which said our files are encrypted. The message said we have to pay money to enable decryption of our files."</p><p>The company uses "Busy" accounting software where employees have two accounts: live and busy. In order to conduct business, they need to access their live account which has been blocked by hackers.</p><p>A source told <em>The Indian Express</em>: "The hackers have locked out their data since April. Employees have not been able to conduct any business since the day of the cyber attack. Their billing process has been delayed and they are even scared to use net banking as they fear online payment systems may be compromised."</p><p><em>IT Pro</em> has contacted Rachna Sagar for comment.</p><p>This isn't the first WannaCry attack to hit India. There were isolated incidents reported in Andhra Pradesh, Gujarat, Kerala and West Bengal, but it is the capital's first attack.</p><p>Marcus Hutchins, the British national who stopped the initial spread of WannaCry, was arrested in Las Vegas charged on six counts relating to the <a href="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges" data-original-url="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges">creation and distribution of a banking Trojan known as Kronos</a>. The judge has set a trial date for October and released Hutchins on bail. He's not allowed to access the server he used to prevent WannaCry from spreading and must remain under house arrest.</p><p><strong>04/08/2017: WannaCry hackers 'blocked' from cashing ransomware bitcoins</strong></p><p>WannaCry hackers who tried to launder their ransom money have been blacklisted by the exchange they used, digital asset exchange ShapeShift, according to <a href="https://www.forbes.com/sites/thomasbrewster/2017/08/03/wannacry-hackers-use-shapeshift-to-launder-bitcoin/#2e33961b3d0d"><em>Forbes</em></a>.</p><p>ShapeShift allows customers to change Bitcoin into an alternative cryptocurrency without creating an account, but said the attackers' attempt to use the service to convert their bitcoins into Monero, an allegedly <a href="https://getmonero.org">secure, private, and untraceable currency</a>, broke its terms of service.</p><p>A spokesperson for ShapeShift told<em>Forbes</em>: "As of today, we have taken measures to blacklist all addresses associated with the WannaCry attackers that are known to the ShapeShift team, as is our policy for any transactions we deem breach our terms of service. We are closely watching the situation as it continues to unfold as to block any further addresses associated."</p><p>The hackers, who leveraged WannaCry against NHS hospitals and other business targets, attempted to move $36,922 of the $140,000, according to Chainalysis co-founder Jonathan Levin, speaking to <em>Forbes</em>.</p><p>The Shapeshift spokesperson added: "Any transactions made through ShapeShift can not be hidden or obscured and are thus 100% transparent, making laundering of any digital tokens impossible.</p><p>"Additionally, we are engaging directly with law enforcement involved with the WannaCry case and will assist them with any needs they may request to apprehend the perpetrators."</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/893443412137062401"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/893443412137062401"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>The WannaCry attack affected over 200,000 computers in 150 countries and demanded money for users to access their files.</p><p>Marcus Hutchins, the British security researcher who stopped the WannaCry attack, <a href="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges" data-original-url="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges">was charged by US authorities with creating and distributing the Kronos banking Trojan</a>this week. Hutchins, 23, tried to leave the US after attending the Black Hat and Defcon security conferences in Las Vegas, but was arrested at the airport.</p><p><strong>03/08/2017: WannaCry's $140,000 Bitcoin wallets are emptied</strong></p><p>More than $140,000 in bitcoins paid by victims of the WannaCry attack have been moved from their online wallets.</p><p>Keith Collins, a technology reporter at Quartz, set up an online Twitter bot called "actual ransom" to monitor three Bitcoin wallets tied to the WannaCry attack which would post whenever money was moved from the wallets.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/892946969152434176"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/892946969152434176"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>At 3 am today, it reported the wallets held $142,361.51 which they had collected through 338 payments.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/892945778041380864"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/892945778041380864"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Starting at 4:10 am, there were a series of seven tweets saying that different amounts of money had been taken out, ranging from $19,318.06 to $27,514.04. The balance of the wallets are now zero.</p><p>Now, the money may be sent through a Bitcoin mixer which will help to obscure its trail. This mixer sends the money to a high volume address, such as an exchange, where legitimate money frequently passes. This is carried out in order to hide where the ransomware money eventually goes, as reported <a href="https://qz.com/1028936/watch-these-bitcoin-ransom-payments-get-lost-in-the-expanse-of-the-blockchain">by Collins</a>. The purpose of this is to confuse and obscure anyone who is following the money trail and can be thought of as "online laundering".</p><p>WannaCry affected more than 200,000 computers in 150 countries and blocked users from accessing their files. The files were only recoverable through a $300 to $600 Bitcoin payment. This ransomware exploited vulnerabilities in the Microsoft Cryptographic API built into Windows to create and hide a decryption key.</p><p><strong>29/06/2017: WannaCry was "inevitable" due to NHS underfunding, says BCS</strong></p><p>The NHS has been criticised for a lack of investment and accountability in IT security measures that allegedly led to the widespread Wannacry outbreak last month.</p><p>The Chartered Institute for IT (BCS) said that despite efforts with limited resources available, some hospital IT teams lacked access to trained, registered and accountable cyber security professionals with the power to assure hospital boards that computer systems were fit for purpose.</p><p>David Evans, director of community and policy at The Chartered Institute for IT, said that the healthcare sector has struggled to keep pace with cyber security best practice, and with a systemic lack of investment, ultimately, the Wannacry attack was an "inevitability".</p><p>"Patients should be able to trust that hospital computer systems are as solid as the first-class doctors and nurses that make our NHS the envy of the world," he said.</p><p>"Unfortunately, without the necessary IT professionals, proper investment and training the damage caused by the Wannacry ransomware virus was an inevitability, but with the roadmap we are releasing today, [that] will make it less likely that such an attack will have the same impact in the future."</p><p>BCS has joined forces with the Patient's Association, the Royal College of Nursing, BT and Microsoft to produce a blueprint that outlines steps NHS trusts should take to avoid another crippling cyber attack.</p><p>Most important was ensuring there are clearly laid out standards for accrediting relevant IT professionals. NHS boards are being urged to ensure they understand their responsibilities, and how to make use of registered cyber security experts. The blueprint also states that the number of properly qualified and registered IT professionals needs to be increased.</p><p>Almost 50 NHS Trusts were hit last month by Wannacry, with the ransomware encrypting computers and leaving them unusable in many areas of the health service, with hackers threatening that valuable files would be lost forever unless a ransom was paid.</p><p><strong>23/06/2017: </strong>WannaCry isn't over. Honda was forced to shut a car manufacturing plant in Japan after being struck by the ransomware, while reports suggest Australian traffic cameras were knocked offline by the attack.</p><p>Honda shut its Sayama plant on Monday after being hit by the ransomware over the weekend, which then spread across the car maker's networks. The factory was back online the next day. It produces about 1,000 cars a day.</p><p>The car maker didn't say how it was infected, or why its systems were still at risk several weeks after the initial attack, which was halted when a security engineer triggered a kill switch. Microsoft has since released patches to prevent infection.</p><p>Honda isn't the only organisation to still be reeling from WannaCry. An Australian traffic control system was infected by the ransomware, though the 55 cameras continued working throughout the attack.</p><p>In this case, the spread of WannaCry was human error, after a contractor working for the government connected an infected device to the camera network. A patch is being rolled out to stop the infection, and any fines that are mistakenly doled out as a result of the incident will be refunded, the department of justice in Victoria said.</p><p><strong>30/05/2017: Why WannaCry's creator could be Chinese</strong></p><p>The creator of WannaCry may be Chinese, according to a fresh analysis of the notices sent to victims of the ransomware, including NHS trusts, earlier this month.</p><p>Flashpoint's research concludes that the native language of the author, or authors, may have been Chinese, and that while they were familiar with the English language, were not native speakers.</p><p>The security firm's analysis found that nearly all of the ransom notes for WannaCry were translated using Google Translate and that only three languages; English and the two Chinese versions (simplified and traditional) were likely to have been written by a human, instead of translated by a machine.</p><p>The researchers deduced that the English note appeared to be written by someone with a strong command of English, although it apparently contained a glaring grammatical error (which Flashpoint did not detail) suggesting the speaker is non-native or poorly educated.</p><p>They also found that while the English note was the source text for machine translation into the other languages, the Chinese ransom note served as the original source for the English version, because it "contains content not in any of the others, though no other notes contain content not in the Chinese".</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/867788636409823234"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/867788636409823234"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>This means it's possible that Chinese is the writer or writers' native tongue, but other languages cannot be ruled out. Flashpoint added: "It is also possible that the malware author(s)' intentionally used a machine translation of their native tongue to mask their identity. It is worth noting that characteristics marking the Chinese note as authentic are subtle. It is thus possible, though unlikely, that they were intentionally included to mislead.</p><p>Experts had previously pointed to North Korea as the creator of the ransomware that shut down NHS hospitals earlier this month, though a think tank last week aired its doubts over this attribution, questioning suspect the Lazarus Group's alleged links to the country.</p><p>The cyber attack infected more than 200,000 computers in 150 countries. The FBI, Europol and the UK's National Crime Agency are investigating who was responsible for the attack.</p><p>Multiple security experts have said that the majority of computers infected by WannaCry were running Windows 7, in contrast to previous assumptions that it was unpatched XP machines responsible for the quick spread of the ransomware.</p><p>WannaCry blocked users from accessing files which were only recoverable through a $300 to $600 Bitcoin payment. The ransomware exploited vulnerabilities in the Microsoft Cryptographic API built into Windows to create and hide a decryption key.</p><p><strong>24/05/2017: North Korea may not be behind WannaCry</strong></p><p>As experts point to North Korea as the creator of WannaCry ransomware that shut down NHS hospitals earlier this month, one sceptical note still sounds.</p><p>Cyber security vendors including Symantec have linked WannaCry to the Lazarus Group, allegedly a group of North Korean hackers, but a think tank has called for caution amid the finger-pointing.</p><p>"To be abundantly clear, the recent speculation concerning WannaCry attributes the malware to the Lazarus Group, not to North Korea, and even those connections are premature and not wholly convincing," wrote James Scott, a senior fellow at the Instiutute for Critical Infrastructure Technology (ICIT).</p><p>He added: "Lazarus itself has never been definitively proven to be a North Korean state-sponsored advanced persistent threat."</p><p>The comments follow multiple vendors blaming North Korea for initiating the ransomware, which locked files and demanding Bitcoin payments to release them at 16 NHS organisations, among other targets, though the NHS initially found no evidence of personal data being compromised.</p><p>"From all that we see, the technical evidence points to the fact that this is Lazarus," Symantec investigator Eric Chien told the <a href="https://www.nytimes.com/2017/05/22/technology/north-korea-ransomware-attack.html"><em>New York Times</em></a> on Monday.</p><p>The publication referred to "digital crumbs" that the cyber security firm had traced to previous attacks widely attributed to North Korea, like <a href="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack" data-original-url="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack">the Sony Pictures hack in late 2014</a>.</p><p>Symantec also found similar tools and computer code in the WannaCry attack to previous hacks on South Korean targets.</p><p>But ICIT claimed the Lazarus Group was a "cyber-mercenary" outfit, and Scott said of the similarity between the malware tools used in WannaCry and previous attacks: "These claims should not be seen as overly definitive despite their presentation because Lazarus was known for borrowing code from other malware and because it remains possible that outdated Lazarus malware was captured by the WannaCry threat actors and occasionally used as a template for their less sophisticated malware development."</p><p>He added: "At best, WannaCry either borrowed heavily from outdated Lazarus code and failed to change elements, such as calls to C2 servers, or WannaCry was a side campaign of a minuscule subcontractor or group within the massive cybercriminal Lazarus APT."</p><p><strong>22/05/2017: NHS ransomware: Wannacry spread via Windows 7, not XP</strong></p><p>The majority of computers infected by WannaCry were running Windows 7, according to multiple security experts - and contrary to assumptions that unpatched XP machines were to blame for the ransomware's quick spread.</p><p>When the ransomware shut down NHS hospital systems on 12 May, Microsoft had already issued a patch for the vulnerability being abused to spread the infection, but Windows XP users only got that patch if they were paying for custom support, as the two-decade-old OS is out of standard support.That left many assuming XP was the main attack vector, with 90% of NHS trusts <a href="https://www.itpro.com/public-sector/27740/nine-in-10-nhs-trusts-still-use-windows-xp" data-original-url="https://www.itpro.com/public-sector/27740/nine-in-10-nhs-trusts-still-use-windows-xp">still using the OS at the end of last year</a>.</p><p>However, it instead appears to be down to organisations and individuals failing to run keep Windows up to date.</p><p>Kaspersky Labs <a href="https://twitter.com/craiu/status/865562842149392384">released data</a> showing Windows 7 dominated infections at 97%, with negligible numbers of Windows XP infections. Windows 10 was unaffected, as the vulnerability didn't infect the latest OS. Those figures are for PCs running Kaspersky software.</p><p>That data was backed up by a <em><a href="http://www.reuters.com/article/us-cyber-attack-failures-idUSKCN18E2SG">Reuters</a></em>-commissioned report by BitSight, which suggested two-thirds of PCs infected by WannaCry were running Windows 7 without the latest security patches. The report suggested XP could be infected, but didn't help spread the ransomware, with the OS handily crashing before WannaCry can spread.</p><p>Hackers have been trying to restart the WannaCry attack by targeting the domain that acted as a kill-switch and was set up by a 22-year-old British security researcher, who goes by MalwareTech online. They've been using <a href="https://twitter.com/MalwareTechBlog/status/866313617658060801">Mirai botnets to run a DDoS attack</a> to target the servers, he noted.</p><p><strong>19/05/2017: Researcher claims to have bypassed WannaCry encryption</strong></p><p>Victims hit by the recent WannaCry attack may be able to avoid paying the $300 to $600 ransom demand, as a researcher says he has found a way to access the secret decryption key.</p><p>Adrien Guinet of France-based research firm Quarkslab has made software available that he says granted him access to the decryption key on a system running Windows XP, allowing him to bypass the payment demand and recover his files.</p><p>"This software has only been tested and known to work under Windows XP," wrote Guinet, <a href="https://github.com/aguinet/wannakey">in a message alongside his GitHub post</a>. "In order to work, your computer must not have been rebooted after being infected. Please also note that you need some luck for this to work and so it might not work in every case!"</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/865168794586632192"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/865168794586632192"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>So far it appears the software, known as WannaKey, hasn't been tested fully in the wild so it's difficult to say whether it's a reliable work around.</p><p>WannaCry is the most recent widespread ransomware campaign, which infected and encrypted data on networks across the world last week, most notably the NHS. The infection is able to block users from accessing files that are normally only recoverable through a $300 to $600 payment. WannaCry exploited vulnerabilities in the Microsoft Cryptographic API built into Windows to create and hide a decryption key.</p><p>More modern versions of Windows erase this key through memory cleanups, however, a flaw in Windows XP allows for some instances where WannaKey is able to scour the system memory for traces of the variables used to generate the key. Importantly, this only works if the computer has not been powered down, so it is advised that affected machines are left running.</p><p>If a match is found during the scan, a key will be generated which can then be used to decrypt affected files."If you are lucky (that is the associated memory hasn't been reallocated and erased), these prime numbers might still be in memory," added Guinet.</p><p>As the software makes use of an oversight on Windows XP, those affected users running later operating systems will need to look elsewhere for a solution. The advice is to leave affected machines powered on and wait to see if a work around becomes available.</p><p><strong>Update:</strong> A second WannaCry software workaround appears to have been successful at sourcing the decryption key on a Windows 7 machine. Matt Suiche, researcher and founder of Comae Technologies, reports that a tool known as <a href="https://blog.comae.io/wannacry-decrypting-files-with-wanakiwi-demo-86bafb81112d">WannaKiwi</a>, which works in a similar way to Wannakey, has been able to decrypt data on a machine running Windows 7.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/865443334550036481"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/865443334550036481"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p><strong>16/05/2017: WannaCry attackers may be North Korean</strong></p><p>Similarities between the WannaCry ransomware attack that knocked NHS hospitals offline and previous cyber incidents suggest the culprits are based in North Korea, security experts have said.</p><p>The evidence is not conclusive, but multiple security researchers have discovered similarities between the code used in early versions of the WannaCry ransomware and attacks on targets including Bangladeshi and Polish banks and Sony Pictures - attacks that were later attributed to North Korea. "The scale of the Lazarus operations is shocking," Kaspersky Lab researchers <a href="https://securelist.com/blog/research/78431/wannacry-and-lazarus-group-the-missing-link">said in a blog post</a>.</p><p>These links were pointed out by a <a href="https://twitter.com/neelmehta/status/864164081116225536">Google</a> researcher on Twitter, and the <em><a href="https://www.nytimes.com/2017/05/15/us/nsa-hacking-shadow-brokers.html?smid=tw-nytimesworld&smtyp=cur">New York Times</a> </em>reports that they were corroborated by Symantec. However, Kaspersky researchers noted that this could be a 'false flag operation', designed to trick experts into thinking the attacks were carried out by someone else.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/864164081116225536"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/864164081116225536"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>It was also spotted that the code linking WannaCry to the Lazarus attacks was not present in the latest sample of the malware, meaning that the perpetrators could be trying to cover their tracks. Kaspersky Labs called for further scrutiny. "For now, more research is required into older versions of Wannacry," the post said. "We believe this might hold the key to solve some of the mysteries around this attack."</p><p>Indeed, others noted that such code overlap doesn't prove anything other than the fact hackers borrow and steal from each other."The similarities we see between malware linked to that group and WannaCry are not unique enough to be strongly suggestive of a common operator," FireEye researcher John Miller told <a href="http://www.newsweek.com/north-korea-behind-cyber-attack-reseear-609692"><em>Newsweek</em></a>.</p><p>Whoever the culprits are, they haven't made much cash from the disruption their hack has caused. A White House spokesperson said yesterday that while 300,000 computers in 150 countries were infected, only about $70,000 in ransom had been paid, according to a <a href="http://www.reuters.com/article/us-cyber-attack-ransom-idUSKCN18B2DG">Reuters</a> report.</p><p><strong>15/05/2017: Labour says NHS is 'wide open' to cyber attacks</strong></p><p>The government's response to the recent NHS cyber attack has been described as 'chaotic' by Labour, arguing that recent cuts have left hospitals 'wide open' to hacks.</p><p>Shadow health secretary Jon Ashworth has said Labour would invest an extra 5 billion into new IT infrastructure for the NHS, after hospitals and services were affected by the widespread ransomware attack on Friday.</p><p>Speaking to <em>Sky News</em>, Ashworth said: "The truth is, if you're going to cut infrastructure budgets and if you're not going to allow the NHS to invest in upgrading its IT, then you are going to leave hospitals wide open to this sort of attack."</p><p>The comments coincide with allegations that health secretary Jeremy Hunt was previously warned that the NHS was susceptible to cyber attacks of this kind, following an assessment he commissioned last year, according to the <em>BBC</em>.Diane Fiona Caldicott and the Care Quality Commission assessed the cybersecurity capabilities of 60 hospitals throughout the UK, which found that not only were many sites still using outdated IT systems, but the report identified an increasing number cases where malware was being sent by email.</p><p>However, security minister Ben Wallace claimed the NHS were following "pretty good procedures" for dealing with the cyber attack, and insisted that affected trusts had enough resources to deal with attacks of this kind.</p><p>"We make sure the trusts are aware of their vulnerabilities and ask them to make sure they keep themselves up to date. What we don't do in our NHS is micromanage it from the desk," said Wallace, speaking to BBC Breakfast.</p><p>It is thought 47 NHS trusts were affected by the ransomware attack, which will continue to cause disruption through the coming week.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/864046955344875520"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/864046955344875520"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>United Lincolnshire Trust said it has been forced to cancel all routine appointments in its hospitals on Monday, while Northumbria Healthcare has postponed all CT and MRI scans until further notice. Southport and Ormskirk Hospital Trust will run GP appointments as normal on Monday throughout West Lancashire, however it is advising patients to expect severe delays.</p><p><strong>15/05/2017: Microsoft points to NSA leaks for NHS ransomware</strong></p><p>Microsoft has confirmed the exploits that took out NHS networks and others around the world last week were stolen from the US National Security Agency, as security experts warned the ransomware could start spreading again today as workers startup their computers.</p><p>On Friday, the WannaCrypt or WannaDecryptor malware exploded across networks, including 16 NHS systems, leading to ambulances being diverted and some appointments being cancelled. The ransomware wasn't specifically targeted at the NHS, but part of a wider attack that took in organisations around the world.</p><p>The spread of the ransomware was partially halted by one British security researcher, who bought a domain listed in software and was rewarded for their efforts by having their identity revealed by British tabloids.</p><p>Microsoft also released a patch for XP, which is no longer being supported except by special arrangement and extra fees, which the British government decided against paying. NHS Direct said fewer than 4.7% of its devices use XP, and that includes "expensive hardware" such as MRI scanners that aren't easily updated.</p><p>In a <a href="https://blogs.microsoft.com/on-the-issues/2017/05/14/need-urgent-collective-action-keep-people-safe-online-lessons-last-weeks-cyberattack/#sm.0000549eh513wf1lqak1dyomgv7vv">blog post</a>, Microsoft's legal counsel Brad Smith said companies like his own were "increasingly among the first responders" in such attacks, and that online security is a "shared responsibility between tech companies and customers".</p><p>Customers, be they individuals or corporations, need to keep their machines updated, but Smith admitted that's not always easy, adding "we are dedicated to developing further steps to help ensure security updates are applied immediately to all IT environments".</p><p>Such work is made harder when governments are stockpiling and then losing vulnerabilities, he added, confirming that the exploits abused to infect the NHS and the other organisations on Friday were indeed those stolen by the NSA earlier this year.</p><p>"We have seen vulnerabilities stored by the CIA show up on WikiLeaks, and now this vulnerability stolen from the NSA has affected customers around the world," he said. "Repeatedly, exploits in the hands of governments have leaked into the public domain and caused widespread damage. An equivalent scenario with conventional weapons would be the US military having some of its Tomahawk missiles stolen."</p><p>Smith said the attack should be a "wake-up call" to governments on cybersecurity. "They need to take a different approach and adhere in cyberspace to the same rules applied to weapons in the physical world," he said. "We need governments to consider the damage to civilians that comes from hoarding these vulnerabilities and the use of these exploits."</p><p><strong>12/05/2017: NHS hospitals targeted by ransomware attack</strong></p><p>The NHS has been hit by a major ransomware attack, shutting down multiple hospital IT systems - as well as companies and universities elsewhere.</p><p>NHS Digital said the NHS itself was not specifically the target of the attack but part of a wider "Wanna Decryptor" ransomware campaign. <a href="https://www.bleepingcomputer.com/news/security/telefonica-tells-employees-to-shut-down-computers-amid-massive-ransomware-outbreak">Telefonica was also hit by a similar attack</a> as well as a <a href="http://uk.reuters.com/article/uk-spain-cyber-idUKKBN1881TI">range of other Spanish organisations</a>, and reports on Twitter suggest <a href="https://twitter.com/laurabailey/status/863047235084455938">universities are facing similar malware</a>.</p><p>Hospital trusts across England and Scotland have admitted they've been caught up in the attack, with appointments cancelled, phone lines down and ambulances diverted. Doctors and other staff have also been sharing further details on Twitter, with one screenshot suggesting the ransomware is demanding $300 in bitcoin to decrypt files, with the price doubling after three days.</p><p>NHS Digital confirmed the attacks, with a spokesperson saying 16 NHS organisations had reported they've been impacted by ransomware. "The investigation is at an early stage but we believe the malware variant is Wanna Decryptor," the spokesperson said. "At this stage we do not have any evidence that patient data has been accessed. We will continue to work with affected organisations to confirm this."</p><p>The statement added: "This attack was not specifically targeted at the NHS and is affecting organisations from across a range of sectors. Our focus is on supporting organisations to manage the incident swiftly and decisively, but we will continue to communicate with NHS colleagues and will share more information as it becomes available."</p><p>The East and North Hertfordshire NHS trust confirmed it was hit by the attack.</p><p>"Immediately on discovery of the problem, the trust acted to protect its IT systems by shutting them down; it also meant that the trust's telephone system is not able to accept incoming calls," a spokesperson said in a statement. "The trust is postponing all non-urgent activity for today and is asking people not to come to A&E - please ring NHS 111 for urgent medical advice or 999 if it is a life-threatening emergency."</p><p>"To ensure that all back-up processes and procedures were put in place quickly, the trust declared a major internal incident to make sure that patients already in the trust's hospitals continued to receive the care they need," it added.</p><p>Blackpool Teaching Hospitals tweeted that it was having "issues with our computer system", asking people not to come to A&E unless it's an emergency, while North Staffordshire and Barts Health Trust in London have also said they've been hit by the ransomware.</p><p>"We are experiencing a major IT disruption and there are delays at all of our hospitals. We have activated our major incident plan to make sure we can maintain the safety and welfare of patients," a <a href="http://bartshealth.nhs.uk/media/latest-news/2017/may/it-disruption">statement from Barts said</a>. "We are very sorry that we have to cancel routine appointments, and would ask members of the public to use other NHS services wherever possible. Ambulances are being diverted to neighbouring hospitals. The problem is also affecting the switchboard at Newham hospital but direct line phones are working. All our staff are working hard to minimise the impact and we will post regular updates on the website."</p><p>Others have shared images of the screenshot that shows the ransom demand.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/863032679595421696"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/863032679595421696"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>In a security alert, the Spanish National Centre for Cryptology stated: "The ransomware, a version of WannaCry, infects a computer, encrypting all its files and, using a remote code execution vulnerability through the SMB (server message block), distributes itself to the rest of the Windows machines connected to the same network."</p><p>The organisation stated that Windows Vista SP2 through to Windows 10, including RT 8.1, are all affected by the vulnerability that allows computers to be infected by the malware. Windows Server 2008 SP2 and SP1 through to Server 2016 are also affected.</p><p>Microsoft <a href="https://technet.microsoft.com/en-us/library/security/ms17-010">issued a patch for the vulnerability in March</a>, but it would appear it hasn't been rolled out across all organisations. Windows XP isn't listed as one of the operating systems affected, however as support for the aged operating system ended in 2014, it's possible the vulnerability also affects that OS and will never be patched.</p><p>The researchers at MalwareHunterTeam <a href="https://twitter.com/malwrhunterteam/status/862994000420188160">reported earlier today</a> that the particular strain of ransomware was quickly spreading, spotted in 11 countries within a few hours - and that's before the NHS attacks.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/862988042231054338"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/862988042231054338"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Research last year revealed that 90% of <a href="https://www.itpro.com/public-sector/27740/nine-in-10-nhs-trusts-still-use-windows-xp" data-original-url="https://www.itpro.com/public-sector/27740/nine-in-10-nhs-trusts-still-use-windows-xp">NHS trusts still used no-longer-supported Windows XP in some way</a>, but it remains unclear how this ransomware infected the hospital trusts. Wanna Decryptor is also known as WannaCry or WCry. These attacks appear to be using the second version of the ransomware, based on the screenshots, which spreads via dodgy attachments in email.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/28648/nhs-ransomware-attack</link>
                                                                            <description>
                            <![CDATA[ The Foreign Office said it will find, pursue and respond to the malicious activity ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">r2u4mdy73MYKt59vFNS25t</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VGLGy8xHqUWB2uNTZoNJyQ-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 20 Dec 2017 06:47:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VGLGy8xHqUWB2uNTZoNJyQ-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[hospital]]></media:description>                                                            <media:text><![CDATA[hospital]]></media:text>
                                <media:title type="plain"><![CDATA[hospital]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VGLGy8xHqUWB2uNTZoNJyQ-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK's Foreign Office has said it too blames North Korea for the WannaCry ransomware campaign that brought the majority of the NHS and other public sector organisations to their knees back in May.</p><p>"The UK's National Cyber Security Centre assesses it is highly likely that North Korean actors known as the Lazarus Group were behind the WannaCry ransomware campaign one of the most significant to hit the UK in terms of scale and disruption," Foreign Office Minister Lord Ahmad of Wimbledon said in a statement.</p><p>The official announcement follows comments by Security Minister Ben Wallace in October that suggested the government believed a nation-state was responsible for WannaCry campaign, and that it was "as sure as possible" that state was North Korea.</p><p>He said, like the US authorities, the UK government would "identify, pursue and respond" to malicious activity and wants to make it clear it will not tolerate malicious cyber activity of any kind, wherever it may originate and however severe the impact. It will impose costs on the responsible parties, preventing them from launching further attacks and using them as an example to deter other potential criminals.</p><p>"We condemn these actions and commit ourselves to working with all responsible states to combat destructive criminal use of cyber space," he added. "The indiscriminate use of the WannaCry ransomware demonstrates North Korean actors using their cyber programme to circumvent sanctions."</p><p>Lord Ahmad added that the UK authorities will work closely with other organisations around the world to "uphold a free, open, peaceful and secure cyberspace."</p><p>The WannaCry attacks affected 300,000 computers in 150 countries, including 48 NHS trusts, the government said. Users were told they needed to pay a ransom to get their machines unlocked and data restored.</p><p><strong>19/12/2017: NHS ransomware: US blames North Korea for "cowardly" WannaCry attack</strong></p><p>The US government has officially blamed North Korea for the devastating WannaCry ransomware campaign that crippled public services and infrastructure in more than 35 countries in May.</p><p>The announcement, made by Homeland Security Advisor Thomas Bossert in the <a href="https://www.wsj.com/articles/its-official-north-korea-is-behind-wannacry-1513642537" target="_blank"><em>New York Times</em></a>, is the first time the US has formally blamed a nation-state for the attack which hit the NHS, Spain's Telefonica, FedEx and German rail company Deutsche Bahn.</p><p>"After careful investigation, the US today publicly attributes the massive 'WannaCry' cyber attack to North Korea," said Bossert. "It encrypted and rendered useless hundreds of thousands of computers in hospitals, schools, businesses and homes. While victims received ransom demands, paying did not unlock their computers."</p><p>"It was cowardly, costly and careless," added Bossert. "The attack was widespread and cost billions, and North Korea is directly responsible."</p><p>North Korea became a suspect almost immediately following an initial investigation into the attack, particularly as the malware shared a number of similarities with the <a href="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack" target="_blank" data-original-url="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack">attack on Sony Pictures</a>, widely thought to have been carried out by the North Korean-based "Lazarus Group".</p><p>The WannaCry campaign is thought to have affected around 300,000 computer systems across the world, propagated through a vulnerability in Windows XP and Windows Server 2003. The attack was eventually halted when security researcher <a href="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges" target="_blank" data-original-url="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges">Marcus Hutchins</a> discovered a 'kill switch' in the malware that shut down the malware before it delivered its payload.</p><p>The US stance comes almost three months after the UK government and Microsoft officially blamed North Korea for the attack. "North Korea was the state that we believe was involved in this worldwide attack on our systems," said security minister Ben Wallace, speaking to <a href="http://www.bbc.co.uk/programmes/b099v37j" target="_blank"><em>BBC Radio 4</em></a>. "It is widely believed across the community and in a number of countries that North Korea had taken this role."</p><p>As well as officially blaming Pyongyang for the attack, Bossert took the opportunity to highlight recent bolstering of IT defences by the Trump administration.</p><p>"(Trump's) continued sanctions on Russian hackers and directed the most transparent and effective government effort in the world to find and share vulnerabilities in important software," said Bossert, almost certainly referring to the recent <a href="https://www.itpro.com/technology/blockchain" target="_blank" data-original-url="https://www.itpro.com/antivirus/28647/USKasperskyBan">ban on Kaspersky products</a> from all government departments.</p><p>Bossert added that the US was now calling on the private sector to "increase its accountability in the cyber realm by taking actions that deny North Korea and other bad actors the ability to launch reckless and destructive cyber attacks."</p><p>North Korea has always denied its involvement in the WannaCry attack, and labelled the UK's accusation as a "wicked attempt" to enact tougher sanctions against the country.</p><p>Speaking to the Korean Central News Agency, a spokesperson for the Korea-Europe Association said at the time: "It does not make any sense that the DPRK, which gives the highest priority to the life and health of its people, would carry out a cyber attack on the UK health service."</p><p><strong>28/11/2017: NHS to hire ethical hackers in 20m cyber security boost</strong></p><p>The NHS has set aside 20 million to establish a new security centre designed to constantly probe the organisation's cyber defences using ethical hackers.</p><p>The Security Operations Centre (SOC) will operate throughout all NHS sites across the UK, providing monitoring services and guidance on how to handle cyber security incidents to local departments.</p><p>Part of its remit will be to employ 'white-hat' hackers to test the NHS' ability to prevent a data breach or a repeat of the style of attacks seen during the WannaCry ransomware campaign, which hit over one-third of health trusts earlier this year.</p><p>Dan Taylor, head of the Digital Security Centre at NHS Digital, <a href="https://digital.nhs.uk/article/8058/New-cyber-security-service-to-boost-NHS-protection-">said</a> that the new centre will provide a "near-real-time monitoring and alerting service that covers the whole health and care system"</p><p>"The Security Operations Centre will enhance NHS Digital's current data security services that support the health and care system in protecting sensitive patient information," he added.</p><p>"The partnership will provide access to extra specialist resources during peak periods and enable the team to proactively monitor the web for security threats and emerging vulnerabilities.</p><p>"It will also allow us to improve our current capabilities in ethical hacking, vulnerability testing and the forensic analysis of malicious software, and will improve our ability to anticipate future vulnerabilities while supporting health and care in remediating current known threats."</p><p>Taylor said the centre would "drive economies of scale, giving health and care organisations additional intelligence and support services that they might not otherwise be able to access".</p><p>NHS Digital also said it's seeking a partner to provide advice and help run the project, a contract for which is tendered to run for three to five years.</p><p>It's not the first time a public body has turned to ethical hacking to probe its defences. In July, it was revealed that the Met Office had previously asked cloud security firm Cloudreach to <a href="http://www.cloudpro.co.uk/hr/training/6904/met-office-asks-cloudreach-to-purposefully-break-its-systems">purposefully break its systems</a> in an effort to test how well its teams were able to deal with major outages.</p><p>The move is the latest attempt to try and overhaul the NHS' outdated IT systems, which were considered to have been a soft target for the WannaCry malware. A recent report by the National Audit Office found that "basic IT security" could have prevented the spread of the ransomware, and that the NHS had been warned previously about its reliance on the outdated Windows XP operating system.</p><p>"Given the impact of the WannaCry attack, one must ask why it has taken them so long to create an SOC," said Matt Lock, director of sales engineers at Varonis, in a statement to <em>IT Pro</em>.</p><p>"The new centre must be a part of an ongoing effort to keep up with the latest attacks from extremely well-funded and experienced criminals intent on compromising the NHS system.</p><p>"An SOC is an important piece of the overall security posture for large organizations, but continuous improvement and advancements are critical parts of the equation."</p><p><strong>31/10/2017: North Korea denies it created the WannaCry ransomware</strong></p><p>North Korea yesterday denied being behind the devastating WannaCry attack, after the UK government identified the nation as the creator of the ransomware.</p><p>Home Office Minister Ben Wallace told the <em><a href="http://www.bbc.co.uk/news/technology-41753022%5D">BBC</a> </em>last week that the government was "as sure as possible" that North Korea was behind the cyber attack in May, which caused chaos among NHS hospitals, dozens of which had to suspend and postpone appointments and operations.</p><p>But a spokesperson for the North's Korea-Europe Association denounced this as a "wicked attempt" to toughen sanctions against the country, which is currently embroiled in a war of words with the US over its nuclear tests.</p><p>In the statement, published on the <em>Korean Central News Agency</em>, the spokesperson <a href="http://www.kcna.kp/kcna.user.article.retrieveNewsViewInfoList.kcmsf#this">said</a>: "It does not make any sense that the DPRK, which gives the highest priority to the life and health of its people, would carry out a cyber attack on the UK health service.</p><p>"The moves of the UK government to doggedly associate the DPRK with the cyber attack cannot be interpreted in any other way than a wicked attempt to lure the international community into harbouring greater mistrust of the DPRK and further tighten sanctions and pressure against the latter."</p><p>The spokesperson added: "This is an act beyond the limit of our tolerance and it makes us question the real purpose behind the UK's move."</p><p>Along with the UK government, Microsoft also said it believed North Korea was behind the WannaCry attack. Brad Smith, Microsoft's president and chief legal officer, said that the attack was carried out by the country using cyber tools stolen from the NSA in the US.</p><p>An investigation into the ransomware attack found that the NHS failed to follow basic IT security principles that could have prevented the malware from taking effect, such as upgrading from the unsupported Windows XP operating system.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="/security/28084/what-is-ransomware">What is ransomware?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/28070/best-ransomware-removal-tools" data-original-url="/security/ransomware/28070/best-ransomware-removal-tools">Best ransomware removal tools</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/malware/28153/whats-the-difference-between-antimalware-and-antivirus" data-original-url="/malware/28153/whats-the-difference-between-antimalware-and-antivirus">What's the difference between antimalware and antivirus?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack" data-original-url="/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack">No-one is blameless when it comes to the NHS WannaCry hack</a></p></div></div><p><strong>27/10/2017: NHS ransomware: "Basic IT security" could've prevented WannaCry</strong></p><p>A report conducted by the National Audit Office found that the NHS was informed by the Department of Health and the Cabinet as early as 2014 about the dangers of cyber attacks and were encouraged to make plans to move away from old software like Windows XP by April 2015.</p><p>Despite the NHS's critical alerts telling organisations to patch their system to prevent the spread of WannaCry ransomware, the department had "no formal mechanism for assessing whether local NHS organisations had complied with their advice and guidance and whether they were prepared for a cyber attack".</p><p>"The WannaCry cyber attack had potentially serious implications for the NHS and its ability to provide care to patients. It was a relatively unsophisticated attack and could have been prevented by the NHS following basic IT security best practice. There are more sophisticated cyber threats out there than WannaCry so the department and the NHS need to get their act together to ensure the NHS is better protected against future attacks," said Amyas Morse, head of the National Audit Office.</p><p>The attack, which occurred on 12 May 2017, affected 81 out of 236 NHS organisations in England. It also lead to the cancellation of 19,500 medical appointments, the locking of 600 GP surgeries, and the diversion of ambulances from five hospitals, according to <a href="https://www.nao.org.uk/report/investigation-wannacry-cyber-attack-and-the-nhs">the report</a>.</p><p>Although the department, NHS England, and the National Crime Agency said that no NHS organisation paid the ransom, the report found that the department does not know how much the attacks cost the NHS when considering costs such as the cancelled appointments, IT support and consultants, along with the restoration of data.</p><p>"What the NHS needed was the ability to detect and put a stop to malicious behaviour as early as possible in the kill chain," Nick Pollard, security intelligence and analytics director at Nuix said.</p><p>He suggested the use of next-generation endpoint security, which "can analyse unknown processes and terminates those that exhibit bad behaviours, keeping end users from clicking on unusual and potentially harmful attachments and applications even before they knew you were in danger".</p><p>The report said that the NHS has learned from WannaCry and is taking action to secure local firewalls by asking hospital trust boards to make sure they have implemented measures outlined in all alerts issued between March and May 2017.</p><p><strong>16/10/17: Microsoft says North Korea was behind WannaCry attack</strong></p><p>Microsoft's president and chief legal officer has said that North Korea was behind the WannaCry attack that affected companies worldwide.</p><p>Brad Smith told <a href="http://www.itv.com/news/2017-10-13/hacking-threat-is-as-serious-as-terrorism-says-microsoft-boss"><em>ITV News</em></a>: "I think at this point that all observers in the know have concluded that WannaCry was caused by North Korea using cyber tools or weapons that were stolen from the National Security Agency in the United States."</p><p>Smith also said cyber-attacks conducted by nation-states have become more frequent and more severe. He added that governments around the world should do more to protect people from harm.</p><p>"We need governments to come together as they did in Geneva in 1949 and adopt a new digital Geneva Convention that makes clear that these cyber-attacks against civilians, especially in times of peace, are off-limits and a violation of international law," said Smith.</p><p>He addressed criticism over the fact that Microsoft left Windows XP vulnerable to attackers since it had withdrawn support for the operating system. "When there's a broad attack, we provide patches for [all versions of Windows]," he said. "We did so with WannaCry, we did it again in June when Ukraine was attacked."</p><p>He added: "At the same time we repeatedly asked people, we explained to people, we virtually pleaded with people 'please don't rely on software that now belongs in a museum'."</p><p>Smith underlined that hospitals need to give more priority to upgrading their IT systems. "When hospitals think about the equipment that is critical to protecting their patients they've got to think not only about the beds...Computers play a fundamental role in the delivery of healthcare and patients shouldn't have to rely on healthcare based on an old computer."</p><p>WannaCry affected over 200,000 computers in 150 countries and demanded money for users to access their files.</p><p>Marcus Hutchins, the British security researcher who stopped the attack, <a href="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges" data-original-url="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges">was charged by US authorities with creating and distributing the Kronos banking Trojan in August.</a></p><p>At IP Expo 2017, Microsoft's Brad Anderson told <em>IT Pro</em> that <a href="https://www.itpro.com/security/29632/microsoft-sees-300-increase-in-cyber-attacks-in-the-last-year" data-original-url="https://www.itpro.com/security/29632/microsoft-sees-300-increase-in-cyber-attacks-in-the-last-year">the company had seen a 300% increase in cyber attacks in the last year</a>. The sophistication of the attacks have increased and the most sophisticated ones he has seen are from nation-states.</p><p><strong>18/08/2017: 'WannaCry' ransomware hits LG self-service kiosks</strong></p><p>Electronics giant LG has likely become the latest victim of the WannaCry ransomware, which infected self-service kiosks found at its service centres.</p><p>LG has yet to confirm the infection was definitely the WannaCry ransomware, but a spokesperson told <a href="http://www.koreaherald.com/view.php?ud=20170816000700"><em>The Korea Herald</em></a> that the malware bears a strong resemblance to WannaCry, which caused widespread chaos when it targeted NHS hospitals and businesses in May.</p><p>"The problem was found to be caused by ransomware. There was no damage such as data encryption or asking for money, as we immediately shut down the service centre network," the spokesperson said.</p><p>The infection was reported to the state-run Korean Internet & Security Agency, which noted that it had found samples of code in the LG kiosks that were identical to code used in the original WannaCry ransomware campaign.</p><p>LG moved to quickly shut down the kiosks and pushed out a security update for them, and said that all the of the kiosks are now back up and running.</p><p>Dean Ferrando, EMEA manager at cyber security firm Tripwire, suggested that the infection of LG's kiosks is down to the company failing to apply a security update to the vulnerable machines.</p><p>"Reports suggest that the company had not applied all the security updates available from Microsoft. This highlights something that we already knew - many organisations are not good at applying software security updates," he said.</p><p>"Applying available patches is one of the easiest ways to keep an organisation safe from new attacks however, the unfortunate truth is that, despite the warnings and advisories to patch and secure the systems, there will always be a system that is missed."</p><p><strong>17/08/2017: WannaCry paralyses 200 computers in Delhi</strong></p><p>WannaCry has infected over 200 computers belonging to book publishing company Rachna Sagar in the Indian capital New Delhi.</p><p>The attack was reported on 9 August as staff found they could no longer access their user accounts, according to <em><a href="http://indianexpress.com/article/cities/delhi/200-accounts-locked-in-delhis-first-wannacry-attack-publishing-firm-hit-4800160">The</a> </em><em><a href="http://indianexpress.com/article/cities/delhi/200-accounts-locked-in-delhis-first-wannacry-attack-publishing-firm-hit-4800160">Indian Express</a></em>.</p><p>Users were faced with a message demanding $800-$1000 US dollars in <a href="https://www.itpro.com/strategy/28261/bitcoin-news" data-original-url="https://www.itpro.com/strategy/28261/bitcoin-news">Bitcoin</a> in order to unlock their computers.</p><p>A complaint filed by the company at the Darya Ganj police station read: "This morning, when we started our work and opened Busy software, we received a text message which said our files are encrypted. The message said we have to pay money to enable decryption of our files."</p><p>The company uses "Busy" accounting software where employees have two accounts: live and busy. In order to conduct business, they need to access their live account which has been blocked by hackers.</p><p>A source told <em>The Indian Express</em>: "The hackers have locked out their data since April. Employees have not been able to conduct any business since the day of the cyber attack. Their billing process has been delayed and they are even scared to use net banking as they fear online payment systems may be compromised."</p><p><em>IT Pro</em> has contacted Rachna Sagar for comment.</p><p>This isn't the first WannaCry attack to hit India. There were isolated incidents reported in Andhra Pradesh, Gujarat, Kerala and West Bengal, but it is the capital's first attack.</p><p>Marcus Hutchins, the British national who stopped the initial spread of WannaCry, was arrested in Las Vegas charged on six counts relating to the <a href="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges" data-original-url="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges">creation and distribution of a banking Trojan known as Kronos</a>. The judge has set a trial date for October and released Hutchins on bail. He's not allowed to access the server he used to prevent WannaCry from spreading and must remain under house arrest.</p><p><strong>04/08/2017: WannaCry hackers 'blocked' from cashing ransomware bitcoins</strong></p><p>WannaCry hackers who tried to launder their ransom money have been blacklisted by the exchange they used, digital asset exchange ShapeShift, according to <a href="https://www.forbes.com/sites/thomasbrewster/2017/08/03/wannacry-hackers-use-shapeshift-to-launder-bitcoin/#2e33961b3d0d"><em>Forbes</em></a>.</p><p>ShapeShift allows customers to change Bitcoin into an alternative cryptocurrency without creating an account, but said the attackers' attempt to use the service to convert their bitcoins into Monero, an allegedly <a href="https://getmonero.org">secure, private, and untraceable currency</a>, broke its terms of service.</p><p>A spokesperson for ShapeShift told<em>Forbes</em>: "As of today, we have taken measures to blacklist all addresses associated with the WannaCry attackers that are known to the ShapeShift team, as is our policy for any transactions we deem breach our terms of service. We are closely watching the situation as it continues to unfold as to block any further addresses associated."</p><p>The hackers, who leveraged WannaCry against NHS hospitals and other business targets, attempted to move $36,922 of the $140,000, according to Chainalysis co-founder Jonathan Levin, speaking to <em>Forbes</em>.</p><p>The Shapeshift spokesperson added: "Any transactions made through ShapeShift can not be hidden or obscured and are thus 100% transparent, making laundering of any digital tokens impossible.</p><p>"Additionally, we are engaging directly with law enforcement involved with the WannaCry case and will assist them with any needs they may request to apprehend the perpetrators."</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/893443412137062401"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/893443412137062401"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>The WannaCry attack affected over 200,000 computers in 150 countries and demanded money for users to access their files.</p><p>Marcus Hutchins, the British security researcher who stopped the WannaCry attack, <a href="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges" data-original-url="https://www.itpro.com/security/29172/marcus-hutchins-wannacry-kronos-charges">was charged by US authorities with creating and distributing the Kronos banking Trojan</a>this week. Hutchins, 23, tried to leave the US after attending the Black Hat and Defcon security conferences in Las Vegas, but was arrested at the airport.</p><p><strong>03/08/2017: WannaCry's $140,000 Bitcoin wallets are emptied</strong></p><p>More than $140,000 in bitcoins paid by victims of the WannaCry attack have been moved from their online wallets.</p><p>Keith Collins, a technology reporter at Quartz, set up an online Twitter bot called "actual ransom" to monitor three Bitcoin wallets tied to the WannaCry attack which would post whenever money was moved from the wallets.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/892946969152434176"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/892946969152434176"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>At 3 am today, it reported the wallets held $142,361.51 which they had collected through 338 payments.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/892945778041380864"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/892945778041380864"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Starting at 4:10 am, there were a series of seven tweets saying that different amounts of money had been taken out, ranging from $19,318.06 to $27,514.04. The balance of the wallets are now zero.</p><p>Now, the money may be sent through a Bitcoin mixer which will help to obscure its trail. This mixer sends the money to a high volume address, such as an exchange, where legitimate money frequently passes. This is carried out in order to hide where the ransomware money eventually goes, as reported <a href="https://qz.com/1028936/watch-these-bitcoin-ransom-payments-get-lost-in-the-expanse-of-the-blockchain">by Collins</a>. The purpose of this is to confuse and obscure anyone who is following the money trail and can be thought of as "online laundering".</p><p>WannaCry affected more than 200,000 computers in 150 countries and blocked users from accessing their files. The files were only recoverable through a $300 to $600 Bitcoin payment. This ransomware exploited vulnerabilities in the Microsoft Cryptographic API built into Windows to create and hide a decryption key.</p><p><strong>29/06/2017: WannaCry was "inevitable" due to NHS underfunding, says BCS</strong></p><p>The NHS has been criticised for a lack of investment and accountability in IT security measures that allegedly led to the widespread Wannacry outbreak last month.</p><p>The Chartered Institute for IT (BCS) said that despite efforts with limited resources available, some hospital IT teams lacked access to trained, registered and accountable cyber security professionals with the power to assure hospital boards that computer systems were fit for purpose.</p><p>David Evans, director of community and policy at The Chartered Institute for IT, said that the healthcare sector has struggled to keep pace with cyber security best practice, and with a systemic lack of investment, ultimately, the Wannacry attack was an "inevitability".</p><p>"Patients should be able to trust that hospital computer systems are as solid as the first-class doctors and nurses that make our NHS the envy of the world," he said.</p><p>"Unfortunately, without the necessary IT professionals, proper investment and training the damage caused by the Wannacry ransomware virus was an inevitability, but with the roadmap we are releasing today, [that] will make it less likely that such an attack will have the same impact in the future."</p><p>BCS has joined forces with the Patient's Association, the Royal College of Nursing, BT and Microsoft to produce a blueprint that outlines steps NHS trusts should take to avoid another crippling cyber attack.</p><p>Most important was ensuring there are clearly laid out standards for accrediting relevant IT professionals. NHS boards are being urged to ensure they understand their responsibilities, and how to make use of registered cyber security experts. The blueprint also states that the number of properly qualified and registered IT professionals needs to be increased.</p><p>Almost 50 NHS Trusts were hit last month by Wannacry, with the ransomware encrypting computers and leaving them unusable in many areas of the health service, with hackers threatening that valuable files would be lost forever unless a ransom was paid.</p><p><strong>23/06/2017: </strong>WannaCry isn't over. Honda was forced to shut a car manufacturing plant in Japan after being struck by the ransomware, while reports suggest Australian traffic cameras were knocked offline by the attack.</p><p>Honda shut its Sayama plant on Monday after being hit by the ransomware over the weekend, which then spread across the car maker's networks. The factory was back online the next day. It produces about 1,000 cars a day.</p><p>The car maker didn't say how it was infected, or why its systems were still at risk several weeks after the initial attack, which was halted when a security engineer triggered a kill switch. Microsoft has since released patches to prevent infection.</p><p>Honda isn't the only organisation to still be reeling from WannaCry. An Australian traffic control system was infected by the ransomware, though the 55 cameras continued working throughout the attack.</p><p>In this case, the spread of WannaCry was human error, after a contractor working for the government connected an infected device to the camera network. A patch is being rolled out to stop the infection, and any fines that are mistakenly doled out as a result of the incident will be refunded, the department of justice in Victoria said.</p><p><strong>30/05/2017: Why WannaCry's creator could be Chinese</strong></p><p>The creator of WannaCry may be Chinese, according to a fresh analysis of the notices sent to victims of the ransomware, including NHS trusts, earlier this month.</p><p>Flashpoint's research concludes that the native language of the author, or authors, may have been Chinese, and that while they were familiar with the English language, were not native speakers.</p><p>The security firm's analysis found that nearly all of the ransom notes for WannaCry were translated using Google Translate and that only three languages; English and the two Chinese versions (simplified and traditional) were likely to have been written by a human, instead of translated by a machine.</p><p>The researchers deduced that the English note appeared to be written by someone with a strong command of English, although it apparently contained a glaring grammatical error (which Flashpoint did not detail) suggesting the speaker is non-native or poorly educated.</p><p>They also found that while the English note was the source text for machine translation into the other languages, the Chinese ransom note served as the original source for the English version, because it "contains content not in any of the others, though no other notes contain content not in the Chinese".</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/867788636409823234"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/867788636409823234"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>This means it's possible that Chinese is the writer or writers' native tongue, but other languages cannot be ruled out. Flashpoint added: "It is also possible that the malware author(s)' intentionally used a machine translation of their native tongue to mask their identity. It is worth noting that characteristics marking the Chinese note as authentic are subtle. It is thus possible, though unlikely, that they were intentionally included to mislead.</p><p>Experts had previously pointed to North Korea as the creator of the ransomware that shut down NHS hospitals earlier this month, though a think tank last week aired its doubts over this attribution, questioning suspect the Lazarus Group's alleged links to the country.</p><p>The cyber attack infected more than 200,000 computers in 150 countries. The FBI, Europol and the UK's National Crime Agency are investigating who was responsible for the attack.</p><p>Multiple security experts have said that the majority of computers infected by WannaCry were running Windows 7, in contrast to previous assumptions that it was unpatched XP machines responsible for the quick spread of the ransomware.</p><p>WannaCry blocked users from accessing files which were only recoverable through a $300 to $600 Bitcoin payment. The ransomware exploited vulnerabilities in the Microsoft Cryptographic API built into Windows to create and hide a decryption key.</p><p><strong>24/05/2017: North Korea may not be behind WannaCry</strong></p><p>As experts point to North Korea as the creator of WannaCry ransomware that shut down NHS hospitals earlier this month, one sceptical note still sounds.</p><p>Cyber security vendors including Symantec have linked WannaCry to the Lazarus Group, allegedly a group of North Korean hackers, but a think tank has called for caution amid the finger-pointing.</p><p>"To be abundantly clear, the recent speculation concerning WannaCry attributes the malware to the Lazarus Group, not to North Korea, and even those connections are premature and not wholly convincing," wrote James Scott, a senior fellow at the Instiutute for Critical Infrastructure Technology (ICIT).</p><p>He added: "Lazarus itself has never been definitively proven to be a North Korean state-sponsored advanced persistent threat."</p><p>The comments follow multiple vendors blaming North Korea for initiating the ransomware, which locked files and demanding Bitcoin payments to release them at 16 NHS organisations, among other targets, though the NHS initially found no evidence of personal data being compromised.</p><p>"From all that we see, the technical evidence points to the fact that this is Lazarus," Symantec investigator Eric Chien told the <a href="https://www.nytimes.com/2017/05/22/technology/north-korea-ransomware-attack.html"><em>New York Times</em></a> on Monday.</p><p>The publication referred to "digital crumbs" that the cyber security firm had traced to previous attacks widely attributed to North Korea, like <a href="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack" data-original-url="https://www.itpro.com/malware/26110/security-experts-uncover-masterminds-behind-sony-pictures-hack">the Sony Pictures hack in late 2014</a>.</p><p>Symantec also found similar tools and computer code in the WannaCry attack to previous hacks on South Korean targets.</p><p>But ICIT claimed the Lazarus Group was a "cyber-mercenary" outfit, and Scott said of the similarity between the malware tools used in WannaCry and previous attacks: "These claims should not be seen as overly definitive despite their presentation because Lazarus was known for borrowing code from other malware and because it remains possible that outdated Lazarus malware was captured by the WannaCry threat actors and occasionally used as a template for their less sophisticated malware development."</p><p>He added: "At best, WannaCry either borrowed heavily from outdated Lazarus code and failed to change elements, such as calls to C2 servers, or WannaCry was a side campaign of a minuscule subcontractor or group within the massive cybercriminal Lazarus APT."</p><p><strong>22/05/2017: NHS ransomware: Wannacry spread via Windows 7, not XP</strong></p><p>The majority of computers infected by WannaCry were running Windows 7, according to multiple security experts - and contrary to assumptions that unpatched XP machines were to blame for the ransomware's quick spread.</p><p>When the ransomware shut down NHS hospital systems on 12 May, Microsoft had already issued a patch for the vulnerability being abused to spread the infection, but Windows XP users only got that patch if they were paying for custom support, as the two-decade-old OS is out of standard support.That left many assuming XP was the main attack vector, with 90% of NHS trusts <a href="https://www.itpro.com/public-sector/27740/nine-in-10-nhs-trusts-still-use-windows-xp" data-original-url="https://www.itpro.com/public-sector/27740/nine-in-10-nhs-trusts-still-use-windows-xp">still using the OS at the end of last year</a>.</p><p>However, it instead appears to be down to organisations and individuals failing to run keep Windows up to date.</p><p>Kaspersky Labs <a href="https://twitter.com/craiu/status/865562842149392384">released data</a> showing Windows 7 dominated infections at 97%, with negligible numbers of Windows XP infections. Windows 10 was unaffected, as the vulnerability didn't infect the latest OS. Those figures are for PCs running Kaspersky software.</p><p>That data was backed up by a <em><a href="http://www.reuters.com/article/us-cyber-attack-failures-idUSKCN18E2SG">Reuters</a></em>-commissioned report by BitSight, which suggested two-thirds of PCs infected by WannaCry were running Windows 7 without the latest security patches. The report suggested XP could be infected, but didn't help spread the ransomware, with the OS handily crashing before WannaCry can spread.</p><p>Hackers have been trying to restart the WannaCry attack by targeting the domain that acted as a kill-switch and was set up by a 22-year-old British security researcher, who goes by MalwareTech online. They've been using <a href="https://twitter.com/MalwareTechBlog/status/866313617658060801">Mirai botnets to run a DDoS attack</a> to target the servers, he noted.</p><p><strong>19/05/2017: Researcher claims to have bypassed WannaCry encryption</strong></p><p>Victims hit by the recent WannaCry attack may be able to avoid paying the $300 to $600 ransom demand, as a researcher says he has found a way to access the secret decryption key.</p><p>Adrien Guinet of France-based research firm Quarkslab has made software available that he says granted him access to the decryption key on a system running Windows XP, allowing him to bypass the payment demand and recover his files.</p><p>"This software has only been tested and known to work under Windows XP," wrote Guinet, <a href="https://github.com/aguinet/wannakey">in a message alongside his GitHub post</a>. "In order to work, your computer must not have been rebooted after being infected. Please also note that you need some luck for this to work and so it might not work in every case!"</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/865168794586632192"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/865168794586632192"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>So far it appears the software, known as WannaKey, hasn't been tested fully in the wild so it's difficult to say whether it's a reliable work around.</p><p>WannaCry is the most recent widespread ransomware campaign, which infected and encrypted data on networks across the world last week, most notably the NHS. The infection is able to block users from accessing files that are normally only recoverable through a $300 to $600 payment. WannaCry exploited vulnerabilities in the Microsoft Cryptographic API built into Windows to create and hide a decryption key.</p><p>More modern versions of Windows erase this key through memory cleanups, however, a flaw in Windows XP allows for some instances where WannaKey is able to scour the system memory for traces of the variables used to generate the key. Importantly, this only works if the computer has not been powered down, so it is advised that affected machines are left running.</p><p>If a match is found during the scan, a key will be generated which can then be used to decrypt affected files."If you are lucky (that is the associated memory hasn't been reallocated and erased), these prime numbers might still be in memory," added Guinet.</p><p>As the software makes use of an oversight on Windows XP, those affected users running later operating systems will need to look elsewhere for a solution. The advice is to leave affected machines powered on and wait to see if a work around becomes available.</p><p><strong>Update:</strong> A second WannaCry software workaround appears to have been successful at sourcing the decryption key on a Windows 7 machine. Matt Suiche, researcher and founder of Comae Technologies, reports that a tool known as <a href="https://blog.comae.io/wannacry-decrypting-files-with-wanakiwi-demo-86bafb81112d">WannaKiwi</a>, which works in a similar way to Wannakey, has been able to decrypt data on a machine running Windows 7.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/865443334550036481"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/865443334550036481"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p><strong>16/05/2017: WannaCry attackers may be North Korean</strong></p><p>Similarities between the WannaCry ransomware attack that knocked NHS hospitals offline and previous cyber incidents suggest the culprits are based in North Korea, security experts have said.</p><p>The evidence is not conclusive, but multiple security researchers have discovered similarities between the code used in early versions of the WannaCry ransomware and attacks on targets including Bangladeshi and Polish banks and Sony Pictures - attacks that were later attributed to North Korea. "The scale of the Lazarus operations is shocking," Kaspersky Lab researchers <a href="https://securelist.com/blog/research/78431/wannacry-and-lazarus-group-the-missing-link">said in a blog post</a>.</p><p>These links were pointed out by a <a href="https://twitter.com/neelmehta/status/864164081116225536">Google</a> researcher on Twitter, and the <em><a href="https://www.nytimes.com/2017/05/15/us/nsa-hacking-shadow-brokers.html?smid=tw-nytimesworld&smtyp=cur">New York Times</a> </em>reports that they were corroborated by Symantec. However, Kaspersky researchers noted that this could be a 'false flag operation', designed to trick experts into thinking the attacks were carried out by someone else.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/864164081116225536"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/864164081116225536"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>It was also spotted that the code linking WannaCry to the Lazarus attacks was not present in the latest sample of the malware, meaning that the perpetrators could be trying to cover their tracks. Kaspersky Labs called for further scrutiny. "For now, more research is required into older versions of Wannacry," the post said. "We believe this might hold the key to solve some of the mysteries around this attack."</p><p>Indeed, others noted that such code overlap doesn't prove anything other than the fact hackers borrow and steal from each other."The similarities we see between malware linked to that group and WannaCry are not unique enough to be strongly suggestive of a common operator," FireEye researcher John Miller told <a href="http://www.newsweek.com/north-korea-behind-cyber-attack-reseear-609692"><em>Newsweek</em></a>.</p><p>Whoever the culprits are, they haven't made much cash from the disruption their hack has caused. A White House spokesperson said yesterday that while 300,000 computers in 150 countries were infected, only about $70,000 in ransom had been paid, according to a <a href="http://www.reuters.com/article/us-cyber-attack-ransom-idUSKCN18B2DG">Reuters</a> report.</p><p><strong>15/05/2017: Labour says NHS is 'wide open' to cyber attacks</strong></p><p>The government's response to the recent NHS cyber attack has been described as 'chaotic' by Labour, arguing that recent cuts have left hospitals 'wide open' to hacks.</p><p>Shadow health secretary Jon Ashworth has said Labour would invest an extra 5 billion into new IT infrastructure for the NHS, after hospitals and services were affected by the widespread ransomware attack on Friday.</p><p>Speaking to <em>Sky News</em>, Ashworth said: "The truth is, if you're going to cut infrastructure budgets and if you're not going to allow the NHS to invest in upgrading its IT, then you are going to leave hospitals wide open to this sort of attack."</p><p>The comments coincide with allegations that health secretary Jeremy Hunt was previously warned that the NHS was susceptible to cyber attacks of this kind, following an assessment he commissioned last year, according to the <em>BBC</em>.Diane Fiona Caldicott and the Care Quality Commission assessed the cybersecurity capabilities of 60 hospitals throughout the UK, which found that not only were many sites still using outdated IT systems, but the report identified an increasing number cases where malware was being sent by email.</p><p>However, security minister Ben Wallace claimed the NHS were following "pretty good procedures" for dealing with the cyber attack, and insisted that affected trusts had enough resources to deal with attacks of this kind.</p><p>"We make sure the trusts are aware of their vulnerabilities and ask them to make sure they keep themselves up to date. What we don't do in our NHS is micromanage it from the desk," said Wallace, speaking to BBC Breakfast.</p><p>It is thought 47 NHS trusts were affected by the ransomware attack, which will continue to cause disruption through the coming week.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/864046955344875520"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/864046955344875520"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>United Lincolnshire Trust said it has been forced to cancel all routine appointments in its hospitals on Monday, while Northumbria Healthcare has postponed all CT and MRI scans until further notice. Southport and Ormskirk Hospital Trust will run GP appointments as normal on Monday throughout West Lancashire, however it is advising patients to expect severe delays.</p><p><strong>15/05/2017: Microsoft points to NSA leaks for NHS ransomware</strong></p><p>Microsoft has confirmed the exploits that took out NHS networks and others around the world last week were stolen from the US National Security Agency, as security experts warned the ransomware could start spreading again today as workers startup their computers.</p><p>On Friday, the WannaCrypt or WannaDecryptor malware exploded across networks, including 16 NHS systems, leading to ambulances being diverted and some appointments being cancelled. The ransomware wasn't specifically targeted at the NHS, but part of a wider attack that took in organisations around the world.</p><p>The spread of the ransomware was partially halted by one British security researcher, who bought a domain listed in software and was rewarded for their efforts by having their identity revealed by British tabloids.</p><p>Microsoft also released a patch for XP, which is no longer being supported except by special arrangement and extra fees, which the British government decided against paying. NHS Direct said fewer than 4.7% of its devices use XP, and that includes "expensive hardware" such as MRI scanners that aren't easily updated.</p><p>In a <a href="https://blogs.microsoft.com/on-the-issues/2017/05/14/need-urgent-collective-action-keep-people-safe-online-lessons-last-weeks-cyberattack/#sm.0000549eh513wf1lqak1dyomgv7vv">blog post</a>, Microsoft's legal counsel Brad Smith said companies like his own were "increasingly among the first responders" in such attacks, and that online security is a "shared responsibility between tech companies and customers".</p><p>Customers, be they individuals or corporations, need to keep their machines updated, but Smith admitted that's not always easy, adding "we are dedicated to developing further steps to help ensure security updates are applied immediately to all IT environments".</p><p>Such work is made harder when governments are stockpiling and then losing vulnerabilities, he added, confirming that the exploits abused to infect the NHS and the other organisations on Friday were indeed those stolen by the NSA earlier this year.</p><p>"We have seen vulnerabilities stored by the CIA show up on WikiLeaks, and now this vulnerability stolen from the NSA has affected customers around the world," he said. "Repeatedly, exploits in the hands of governments have leaked into the public domain and caused widespread damage. An equivalent scenario with conventional weapons would be the US military having some of its Tomahawk missiles stolen."</p><p>Smith said the attack should be a "wake-up call" to governments on cybersecurity. "They need to take a different approach and adhere in cyberspace to the same rules applied to weapons in the physical world," he said. "We need governments to consider the damage to civilians that comes from hoarding these vulnerabilities and the use of these exploits."</p><p><strong>12/05/2017: NHS hospitals targeted by ransomware attack</strong></p><p>The NHS has been hit by a major ransomware attack, shutting down multiple hospital IT systems - as well as companies and universities elsewhere.</p><p>NHS Digital said the NHS itself was not specifically the target of the attack but part of a wider "Wanna Decryptor" ransomware campaign. <a href="https://www.bleepingcomputer.com/news/security/telefonica-tells-employees-to-shut-down-computers-amid-massive-ransomware-outbreak">Telefonica was also hit by a similar attack</a> as well as a <a href="http://uk.reuters.com/article/uk-spain-cyber-idUKKBN1881TI">range of other Spanish organisations</a>, and reports on Twitter suggest <a href="https://twitter.com/laurabailey/status/863047235084455938">universities are facing similar malware</a>.</p><p>Hospital trusts across England and Scotland have admitted they've been caught up in the attack, with appointments cancelled, phone lines down and ambulances diverted. Doctors and other staff have also been sharing further details on Twitter, with one screenshot suggesting the ransomware is demanding $300 in bitcoin to decrypt files, with the price doubling after three days.</p><p>NHS Digital confirmed the attacks, with a spokesperson saying 16 NHS organisations had reported they've been impacted by ransomware. "The investigation is at an early stage but we believe the malware variant is Wanna Decryptor," the spokesperson said. "At this stage we do not have any evidence that patient data has been accessed. We will continue to work with affected organisations to confirm this."</p><p>The statement added: "This attack was not specifically targeted at the NHS and is affecting organisations from across a range of sectors. Our focus is on supporting organisations to manage the incident swiftly and decisively, but we will continue to communicate with NHS colleagues and will share more information as it becomes available."</p><p>The East and North Hertfordshire NHS trust confirmed it was hit by the attack.</p><p>"Immediately on discovery of the problem, the trust acted to protect its IT systems by shutting them down; it also meant that the trust's telephone system is not able to accept incoming calls," a spokesperson said in a statement. "The trust is postponing all non-urgent activity for today and is asking people not to come to A&E - please ring NHS 111 for urgent medical advice or 999 if it is a life-threatening emergency."</p><p>"To ensure that all back-up processes and procedures were put in place quickly, the trust declared a major internal incident to make sure that patients already in the trust's hospitals continued to receive the care they need," it added.</p><p>Blackpool Teaching Hospitals tweeted that it was having "issues with our computer system", asking people not to come to A&E unless it's an emergency, while North Staffordshire and Barts Health Trust in London have also said they've been hit by the ransomware.</p><p>"We are experiencing a major IT disruption and there are delays at all of our hospitals. We have activated our major incident plan to make sure we can maintain the safety and welfare of patients," a <a href="http://bartshealth.nhs.uk/media/latest-news/2017/may/it-disruption">statement from Barts said</a>. "We are very sorry that we have to cancel routine appointments, and would ask members of the public to use other NHS services wherever possible. Ambulances are being diverted to neighbouring hospitals. The problem is also affecting the switchboard at Newham hospital but direct line phones are working. All our staff are working hard to minimise the impact and we will post regular updates on the website."</p><p>Others have shared images of the screenshot that shows the ransom demand.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/863032679595421696"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/863032679595421696"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>In a security alert, the Spanish National Centre for Cryptology stated: "The ransomware, a version of WannaCry, infects a computer, encrypting all its files and, using a remote code execution vulnerability through the SMB (server message block), distributes itself to the rest of the Windows machines connected to the same network."</p><p>The organisation stated that Windows Vista SP2 through to Windows 10, including RT 8.1, are all affected by the vulnerability that allows computers to be infected by the malware. Windows Server 2008 SP2 and SP1 through to Server 2016 are also affected.</p><p>Microsoft <a href="https://technet.microsoft.com/en-us/library/security/ms17-010">issued a patch for the vulnerability in March</a>, but it would appear it hasn't been rolled out across all organisations. Windows XP isn't listed as one of the operating systems affected, however as support for the aged operating system ended in 2014, it's possible the vulnerability also affects that OS and will never be patched.</p><p>The researchers at MalwareHunterTeam <a href="https://twitter.com/malwrhunterteam/status/862994000420188160">reported earlier today</a> that the particular strain of ransomware was quickly spreading, spotted in 11 countries within a few hours - and that's before the NHS attacks.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/862988042231054338"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/862988042231054338"></a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Research last year revealed that 90% of <a href="https://www.itpro.com/public-sector/27740/nine-in-10-nhs-trusts-still-use-windows-xp" data-original-url="https://www.itpro.com/public-sector/27740/nine-in-10-nhs-trusts-still-use-windows-xp">NHS trusts still used no-longer-supported Windows XP in some way</a>, but it remains unclear how this ransomware infected the hospital trusts. Wanna Decryptor is also known as WannaCry or WCry. These attacks appear to be using the second version of the ransomware, based on the screenshots, which spreads via dodgy attachments in email.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 2017's biggest security horror stories ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Cybersecurity is always top of mind for businesses, but that's especially been the case in 2017.</p><p>From ransomware to botnets, this year's tech news has been dominated by a regular flow of security crises.</p><p>Here are some of the top cybersecurity incidents of 2017 that we don't want to see repeated in 2018.</p><h3 class="article-body__section" id="section-unsecured-clouds-and-databases"><span>Unsecured clouds and databases</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="SqKEWgGvLCoVy67jqodyEM" name="" alt="Bucket leaking water" src="https://cdn.mos.cms.futurecdn.net/SqKEWgGvLCoVy67jqodyEM-1920-80.jpg" mos="https://cdn.mos.cms.futurecdn.net/SqKEWgGvLCoVy67jqodyEM.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Big Stock)</span></figcaption></figure><p>Probably the trend that can most easily be prevented by users is databases facing the public internet that should have been secured, but weren't.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="/security/28133/what-is-cyber-security">What is cyber security?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/innovation-at-work/29580/the-truth-about-encryption" data-original-url="/security/innovation-at-work/29580/the-truth-about-encryption">The truth about encryption</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="/security/28084/what-is-ransomware">What is ransomware?</a></p></div></div><p>Two of the biggest bungles in this area relate to Amazon Web Services' (AWS) S3 cloud storage service and MongoDB's NoSQL database.</p><p>A spate of data leaks across 2017 came about because of unencrypted S3 buckets, affecting organisations including <a href="https://www.itpro.com/security/29694/accenture-exposes-137gb-of-client-data-on-unsecured-aws-buckets" data-original-url="https://www.itpro.com/security/29694/accenture-exposes-137gb-of-client-data-on-unsecured-aws-buckets">Accenture</a>, <a href="https://www.itpro.com/security/29019/three-million-wwe-fan-accounts-exposed-online" data-original-url="https://www.itpro.com/security/29019/three-million-wwe-fan-accounts-exposed-online">WWE</a>, the <a href="https://www.itpro.com/security/28996/aa-our-handling-of-security-breach-fell-short" data-original-url="https://www.itpro.com/security/28996/aa-our-handling-of-security-breach-fell-short">AA</a> and <a href="https://www.itpro.com/security/29071/two-million-dow-jones-customer-details-exposed-via-cloud" data-original-url="https://www.itpro.com/security/29071/two-million-dow-jones-customer-details-exposed-via-cloud">Dow Jones</a>.</p><p>These companies had apparently failed to read the small print of their contracts with AWS and hadn't realised this particular storage service wasn't encrypted by default.Thus, customer data was left exposed on the open web for anyone to see, leading to major security crises.</p><p>The issue was finally resolved in November <a href="https://www.itpro.com/security/29907/aws-adds-default-encryption-to-leaky-s3-buckets" data-original-url="https://www.itpro.com/security/29907/aws-adds-default-encryption-to-leaky-s3-buckets">when AWS decided it would add default encryption to S3 buckets</a>, taking the onus off customers.</p><p>In the case of MongoDB, the situation was much the same. Users failed to encrypt their databases, which led to <a href="https://www.itpro.com/security/27885/26000-unsecured-mongodb-servers-hit-by-ransomware" data-original-url="https://www.itpro.com/security/27885/26000-unsecured-mongodb-servers-hit-by-ransomware">several waves of ransomware attacks</a> rather than data leaks, with the cybercriminals encrypting the exposed servers and demanding Bitcoin for their release.</p><p>Unfortunately for the victims, there is no central resolution as with AWS S3, as MongoDB offers database software, rather than a cloud storage service, that can be installed on pretty much any server. The general advice, from both the company and the security community, is to turn on encryption, or at the very least password protection, at the point of installation sage advice for any IT administrator, irrespective of the service or software they are using.</p><h3 class="article-body__section" id="section-ransomware-attacks"><span>Ransomware attacks</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KtKFCSr53Qf22hEveofYDb" name="" alt="Graphic of a user engaging in a ransomware exchange" src="https://cdn.mos.cms.futurecdn.net/KtKFCSr53Qf22hEveofYDb-1920-80.jpg" mos="https://cdn.mos.cms.futurecdn.net/KtKFCSr53Qf22hEveofYDb.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Bigstock)</span></figcaption></figure><p>While ransomware has been a popular tool for cybercriminals for many years, 2017 saw an uptick in large-scale attacks.</p><p>Two of the most notable global ransomware attacks were WannaCry, which hit in May, and NotPetya, which landed in June.</p><p>WannaCry made global news after it spread rapidly around the world, with the<a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">NHS in England and Wales being particularly badly hit</a>. The attack was notable for several reasons. First, the speed of the spread; within hours of the first incidents being reported in Asia on 12 May, it had started to spread internationally. By the end of the day, over 230,000 computers in 150 countries were infected.</p><p>Second is the systems affected. WannaCry exclusively infected Windows operating systems, both server and desktop. Although Microsoft had issued a patch for the vulnerability in March 2017, many large organisations' systems <a href="https://www.itpro.com/security/innovation-at-work/29794/what-have-we-learnt-from-the-nhs-ransomware-attack" data-original-url="https://www.itpro.com/security/innovation-at-work/29794/what-have-we-learnt-from-the-nhs-ransomware-attack">hadn't been updated for one reason or another</a> (sometimes due to staffing, sometimes due to dependent software or other technical reasons).</p><p>Many were quick to point to the continued use of Windows XP despite it no longer being supported by Microsoft for several years. However, research from Kaspersky Lab demonstrated that, in fact, most of the infected computers were running Windows 7, which was still covered by Microsoft support at the time.</p><p>The third interesting thing about WannaCry is its alleged provenance. While there's no indication the US National Security Agency (NSA) created the ransomware itself, it has been suggested that EternalBlue, the Windows vulnerability that allowed the malware to spread and infect numerous systems at such high speed, was discovered by the agency some years ago but not reported to Microsoft. Instead, the organisation allegedly used it as an offensive tool in cyber warfare and defence. The existence of EternalBlue and other similar tools <a href="https://www.itpro.com/hacking/27125/was-an-insider-behind-the-nsa-hack" data-original-url="https://www.itpro.com/hacking/27125/was-an-insider-behind-the-nsa-hack">were revealed by Shadow Brokers in 2016</a>.</p><p>While WannaCry was fast and effective, it was short-lived British independent security researcher Marcus Hutchins discovered a so-called "kill switch" embedded in the ransomware's code and was able to disable the initial attack in one fell swoop.</p><p>The same can't be said for NotPetya. According to WebRoot, this malware strain <a href="https://www.itpro.com/security/29863/notpetya-was-nastier-than-wannacry-ransomware-say-experts" data-original-url="https://www.itpro.com/security/29863/notpetya-was-nastier-than-wannacry-ransomware-say-experts">was the most damaging and dangerous to emerge in 2017</a>. Despite using the same EternalBlue exploit as WannaCry, NotPetya was less widespread, but it was more persistent: first emerging in June 2017, it continued to infect systems all the way through to the autumn.</p><p>The creator's MO was also different: although it looked like a traditional ransomware attack, including displaying a ransom message, it didn't simply encrypt the system it created utter havoc. Once affected, the files were irrevocably scrambled, meaning that even if victims did pay the ransom they still wouldn't get their files back. Indeed, it has been speculated by various researchers that havoc and infamy were the main objectives of these criminals, rather than generating money.</p><h3 class="article-body__section" id="section-botnets"><span>Botnets</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="K4eR6BTeCSEvtjHyKQrma3" name="" alt="DDoS Attack on screen" src="https://cdn.mos.cms.futurecdn.net/K4eR6BTeCSEvtjHyKQrma3-1920-80.jpg" mos="https://cdn.mos.cms.futurecdn.net/K4eR6BTeCSEvtjHyKQrma3.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Like the other tactics on this list, botnets aren't new. What is new, however, is how they're powered.</p><p>Continuing a trend started by the <a href="https://www.itpro.com/security/27292/new-scanner-allows-users-to-check-iot-devices-for-mirai-malware-infection" data-original-url="https://www.itpro.com/security/27292/new-scanner-allows-users-to-check-iot-devices-for-mirai-malware-infection">Mirai botnet in 2016</a>, 2017 saw outbreaks of DDoS and other attacks from botnets powered by Internet of Things (IoT) devices.</p><p>As such devices aren't typically thought of as computers, consumers in particular have failed to change default passwords before connecting them to the internet. To make the situation worse, some of these so-called "headless" devices don't give users any control over security settings anyway, meaning there's no way to protect them once they're exposed online.</p><p>While Mirai continued to cause disruption through 2017, with <a href="https://www.itpro.com/security/28407/us-college-hit-by-54-hour-mirai-ddos-attack" data-original-url="https://www.itpro.com/security/28407/us-college-hit-by-54-hour-mirai-ddos-attack">a 54-hour DDoS attack on an American university in March</a> being the most notable of these.</p><p>Later in the year, <a href="https://www.itpro.com/malware/29783/iot-reaper-will-be-worse-than-mirai" data-original-url="https://www.itpro.com/malware/29783/iot-reaper-will-be-worse-than-mirai">a new IoT botnet dubbed Reaper emerged, which security researchers claimed will be worse than Mirai</a>. This is because rather than cracking default or weak passwords, as Mirai did, Reaper infiltrates IoT devices via unpatched vulnerabilities. Once again, this is something that is largely in the hands of vendors, rather than consumers, to secure.</p><p><a href="https://www.itpro.com/malware/29783/iot-reaper-will-be-worse-than-mirai" data-original-url="https://www.itpro.com/malware/29783/iot-reaper-will-be-worse-than-mirai"></a><a href="https://www.itpro.com/security/29837/reaper-iot-botnet-only-partially-mobilised" data-original-url="https://www.itpro.com/security/29837/reaper-iot-botnet-only-partially-mobilised">Reaper is only partially mobilise</a><a href="https://www.itpro.com/malware/29783/iot-reaper-will-be-worse-than-mirai" target="_blank" data-original-url="https://www.itpro.com/malware/29783/iot-reaper-will-be-worse-than-mirai">d, a</a><a href="https://www.itpro.com/malware/29783/iot-reaper-will-be-worse-than-mirai" data-original-url="https://www.itpro.com/malware/29783/iot-reaper-will-be-worse-than-mirai">ccording to a report released in late 2017 by Arbor Networks</a>,with several thousand infected devices lying dormant. This raises concerns of a potential wide-scale DDoS attack in 2018.</p><p>Cybersecurity is a constant game of cat and mouse and true total security is unattainable but that doesn't mean businesses, consumers and vendors can't do their best to mitigate vulnerabilities and build up protection. Let's hope that in 2018 we see greater use of basic security precautions to defend against these potential monster attacks.</p><p><em>Pictures: Bigstock</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/30140/2017s-biggest-security-horror-stories</link>
                                                                            <description>
                            <![CDATA[ The year's worst security incidents we'd hate to see again in 2018 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sxuetR8FUa1zLDyQTCMPWS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/G3hDdZ7EVEA5669KdffBPQ-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 15 Dec 2017 17:02:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/G3hDdZ7EVEA5669KdffBPQ-1920-80.jpg">
                                                            <media:credit><![CDATA[Bigstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Open padlock on circuit board]]></media:description>                                                            <media:text><![CDATA[Open padlock on circuit board]]></media:text>
                                <media:title type="plain"><![CDATA[Open padlock on circuit board]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/G3hDdZ7EVEA5669KdffBPQ-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cybersecurity is always top of mind for businesses, but that's especially been the case in 2017.</p><p>From ransomware to botnets, this year's tech news has been dominated by a regular flow of security crises.</p><p>Here are some of the top cybersecurity incidents of 2017 that we don't want to see repeated in 2018.</p><h3 class="article-body__section" id="section-unsecured-clouds-and-databases"><span>Unsecured clouds and databases</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="SqKEWgGvLCoVy67jqodyEM" name="" alt="Bucket leaking water" src="https://cdn.mos.cms.futurecdn.net/SqKEWgGvLCoVy67jqodyEM-1920-80.jpg" mos="https://cdn.mos.cms.futurecdn.net/SqKEWgGvLCoVy67jqodyEM.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Big Stock)</span></figcaption></figure><p>Probably the trend that can most easily be prevented by users is databases facing the public internet that should have been secured, but weren't.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="/security/28133/what-is-cyber-security">What is cyber security?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/innovation-at-work/29580/the-truth-about-encryption" data-original-url="/security/innovation-at-work/29580/the-truth-about-encryption">The truth about encryption</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="/security/28084/what-is-ransomware">What is ransomware?</a></p></div></div><p>Two of the biggest bungles in this area relate to Amazon Web Services' (AWS) S3 cloud storage service and MongoDB's NoSQL database.</p><p>A spate of data leaks across 2017 came about because of unencrypted S3 buckets, affecting organisations including <a href="https://www.itpro.com/security/29694/accenture-exposes-137gb-of-client-data-on-unsecured-aws-buckets" data-original-url="https://www.itpro.com/security/29694/accenture-exposes-137gb-of-client-data-on-unsecured-aws-buckets">Accenture</a>, <a href="https://www.itpro.com/security/29019/three-million-wwe-fan-accounts-exposed-online" data-original-url="https://www.itpro.com/security/29019/three-million-wwe-fan-accounts-exposed-online">WWE</a>, the <a href="https://www.itpro.com/security/28996/aa-our-handling-of-security-breach-fell-short" data-original-url="https://www.itpro.com/security/28996/aa-our-handling-of-security-breach-fell-short">AA</a> and <a href="https://www.itpro.com/security/29071/two-million-dow-jones-customer-details-exposed-via-cloud" data-original-url="https://www.itpro.com/security/29071/two-million-dow-jones-customer-details-exposed-via-cloud">Dow Jones</a>.</p><p>These companies had apparently failed to read the small print of their contracts with AWS and hadn't realised this particular storage service wasn't encrypted by default.Thus, customer data was left exposed on the open web for anyone to see, leading to major security crises.</p><p>The issue was finally resolved in November <a href="https://www.itpro.com/security/29907/aws-adds-default-encryption-to-leaky-s3-buckets" data-original-url="https://www.itpro.com/security/29907/aws-adds-default-encryption-to-leaky-s3-buckets">when AWS decided it would add default encryption to S3 buckets</a>, taking the onus off customers.</p><p>In the case of MongoDB, the situation was much the same. Users failed to encrypt their databases, which led to <a href="https://www.itpro.com/security/27885/26000-unsecured-mongodb-servers-hit-by-ransomware" data-original-url="https://www.itpro.com/security/27885/26000-unsecured-mongodb-servers-hit-by-ransomware">several waves of ransomware attacks</a> rather than data leaks, with the cybercriminals encrypting the exposed servers and demanding Bitcoin for their release.</p><p>Unfortunately for the victims, there is no central resolution as with AWS S3, as MongoDB offers database software, rather than a cloud storage service, that can be installed on pretty much any server. The general advice, from both the company and the security community, is to turn on encryption, or at the very least password protection, at the point of installation sage advice for any IT administrator, irrespective of the service or software they are using.</p><h3 class="article-body__section" id="section-ransomware-attacks"><span>Ransomware attacks</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KtKFCSr53Qf22hEveofYDb" name="" alt="Graphic of a user engaging in a ransomware exchange" src="https://cdn.mos.cms.futurecdn.net/KtKFCSr53Qf22hEveofYDb-1920-80.jpg" mos="https://cdn.mos.cms.futurecdn.net/KtKFCSr53Qf22hEveofYDb.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Bigstock)</span></figcaption></figure><p>While ransomware has been a popular tool for cybercriminals for many years, 2017 saw an uptick in large-scale attacks.</p><p>Two of the most notable global ransomware attacks were WannaCry, which hit in May, and NotPetya, which landed in June.</p><p>WannaCry made global news after it spread rapidly around the world, with the<a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">NHS in England and Wales being particularly badly hit</a>. The attack was notable for several reasons. First, the speed of the spread; within hours of the first incidents being reported in Asia on 12 May, it had started to spread internationally. By the end of the day, over 230,000 computers in 150 countries were infected.</p><p>Second is the systems affected. WannaCry exclusively infected Windows operating systems, both server and desktop. Although Microsoft had issued a patch for the vulnerability in March 2017, many large organisations' systems <a href="https://www.itpro.com/security/innovation-at-work/29794/what-have-we-learnt-from-the-nhs-ransomware-attack" data-original-url="https://www.itpro.com/security/innovation-at-work/29794/what-have-we-learnt-from-the-nhs-ransomware-attack">hadn't been updated for one reason or another</a> (sometimes due to staffing, sometimes due to dependent software or other technical reasons).</p><p>Many were quick to point to the continued use of Windows XP despite it no longer being supported by Microsoft for several years. However, research from Kaspersky Lab demonstrated that, in fact, most of the infected computers were running Windows 7, which was still covered by Microsoft support at the time.</p><p>The third interesting thing about WannaCry is its alleged provenance. While there's no indication the US National Security Agency (NSA) created the ransomware itself, it has been suggested that EternalBlue, the Windows vulnerability that allowed the malware to spread and infect numerous systems at such high speed, was discovered by the agency some years ago but not reported to Microsoft. Instead, the organisation allegedly used it as an offensive tool in cyber warfare and defence. The existence of EternalBlue and other similar tools <a href="https://www.itpro.com/hacking/27125/was-an-insider-behind-the-nsa-hack" data-original-url="https://www.itpro.com/hacking/27125/was-an-insider-behind-the-nsa-hack">were revealed by Shadow Brokers in 2016</a>.</p><p>While WannaCry was fast and effective, it was short-lived British independent security researcher Marcus Hutchins discovered a so-called "kill switch" embedded in the ransomware's code and was able to disable the initial attack in one fell swoop.</p><p>The same can't be said for NotPetya. According to WebRoot, this malware strain <a href="https://www.itpro.com/security/29863/notpetya-was-nastier-than-wannacry-ransomware-say-experts" data-original-url="https://www.itpro.com/security/29863/notpetya-was-nastier-than-wannacry-ransomware-say-experts">was the most damaging and dangerous to emerge in 2017</a>. Despite using the same EternalBlue exploit as WannaCry, NotPetya was less widespread, but it was more persistent: first emerging in June 2017, it continued to infect systems all the way through to the autumn.</p><p>The creator's MO was also different: although it looked like a traditional ransomware attack, including displaying a ransom message, it didn't simply encrypt the system it created utter havoc. Once affected, the files were irrevocably scrambled, meaning that even if victims did pay the ransom they still wouldn't get their files back. Indeed, it has been speculated by various researchers that havoc and infamy were the main objectives of these criminals, rather than generating money.</p><h3 class="article-body__section" id="section-botnets"><span>Botnets</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="K4eR6BTeCSEvtjHyKQrma3" name="" alt="DDoS Attack on screen" src="https://cdn.mos.cms.futurecdn.net/K4eR6BTeCSEvtjHyKQrma3-1920-80.jpg" mos="https://cdn.mos.cms.futurecdn.net/K4eR6BTeCSEvtjHyKQrma3.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Like the other tactics on this list, botnets aren't new. What is new, however, is how they're powered.</p><p>Continuing a trend started by the <a href="https://www.itpro.com/security/27292/new-scanner-allows-users-to-check-iot-devices-for-mirai-malware-infection" data-original-url="https://www.itpro.com/security/27292/new-scanner-allows-users-to-check-iot-devices-for-mirai-malware-infection">Mirai botnet in 2016</a>, 2017 saw outbreaks of DDoS and other attacks from botnets powered by Internet of Things (IoT) devices.</p><p>As such devices aren't typically thought of as computers, consumers in particular have failed to change default passwords before connecting them to the internet. To make the situation worse, some of these so-called "headless" devices don't give users any control over security settings anyway, meaning there's no way to protect them once they're exposed online.</p><p>While Mirai continued to cause disruption through 2017, with <a href="https://www.itpro.com/security/28407/us-college-hit-by-54-hour-mirai-ddos-attack" data-original-url="https://www.itpro.com/security/28407/us-college-hit-by-54-hour-mirai-ddos-attack">a 54-hour DDoS attack on an American university in March</a> being the most notable of these.</p><p>Later in the year, <a href="https://www.itpro.com/malware/29783/iot-reaper-will-be-worse-than-mirai" data-original-url="https://www.itpro.com/malware/29783/iot-reaper-will-be-worse-than-mirai">a new IoT botnet dubbed Reaper emerged, which security researchers claimed will be worse than Mirai</a>. This is because rather than cracking default or weak passwords, as Mirai did, Reaper infiltrates IoT devices via unpatched vulnerabilities. Once again, this is something that is largely in the hands of vendors, rather than consumers, to secure.</p><p><a href="https://www.itpro.com/malware/29783/iot-reaper-will-be-worse-than-mirai" data-original-url="https://www.itpro.com/malware/29783/iot-reaper-will-be-worse-than-mirai"></a><a href="https://www.itpro.com/security/29837/reaper-iot-botnet-only-partially-mobilised" data-original-url="https://www.itpro.com/security/29837/reaper-iot-botnet-only-partially-mobilised">Reaper is only partially mobilise</a><a href="https://www.itpro.com/malware/29783/iot-reaper-will-be-worse-than-mirai" target="_blank" data-original-url="https://www.itpro.com/malware/29783/iot-reaper-will-be-worse-than-mirai">d, a</a><a href="https://www.itpro.com/malware/29783/iot-reaper-will-be-worse-than-mirai" data-original-url="https://www.itpro.com/malware/29783/iot-reaper-will-be-worse-than-mirai">ccording to a report released in late 2017 by Arbor Networks</a>,with several thousand infected devices lying dormant. This raises concerns of a potential wide-scale DDoS attack in 2018.</p><p>Cybersecurity is a constant game of cat and mouse and true total security is unattainable but that doesn't mean businesses, consumers and vendors can't do their best to mitigate vulnerabilities and build up protection. Let's hope that in 2018 we see greater use of basic security precautions to defend against these potential monster attacks.</p><p><em>Pictures: Bigstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ICO: Only 20% of UK citizens trust companies with their data  ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Only one-fifth of UK citizens trust companies to securely store their personal information, according to a survey published yesterday by the Information Commissioner's Office (ICO).</p><p>The <a href="https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2017/11/ico-survey-shows-most-uk-citizens-don-t-trust-organisations-with-their-data" target="_blank">report</a>, which was conducted by ComRes on behalf of the ICO, also found that only 10% of UK adults have a good understanding of how their personal data is used once it has been collected.</p><p>"As personal information becomes the currency by which society does business, organisations need to start making people's data protection rights a priority," said Steve Wood, deputy commissioner of the ICO. "Putting data protection at the centre of digital businesses strategies is the key to improving trust and digital growth."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-breaches/29418/equifax-data-breach-cost-14-billion-so-far" data-original-url="/data-breaches/29418/equifax-data-breach-cost-14-billion-so-far">Equifax data breach: Ex-CIO to serve four months in prison for insider trading</a> General Data Protection Regulation (GDPR)</p></div></div><p>The results come after a year of high profile data breaches. The breach on <a href="https://www.itpro.com/security/27288/canadian-pleads-guilty-to-yahoo-hack" target="_blank" data-original-url="https://www.itpro.com/security/27288/canadian-pleads-guilty-to-yahoo-hack">Yahoo's</a> systems, initially reported in September 2016, is now thought to have affected all three billion of its accounts, considered to be the largest breach in industry history.</p><p>The year since has been filled with a spate of hacks on corporate systems, including electronics company <a href="https://www.itpro.com/security/29345/two-million-customers-hit-by-cex-hack" target="_blank" data-original-url="https://www.itpro.com/security/29345/two-million-customers-hit-by-cex-hack">CEX</a>, <a href="https://www.itpro.com/security/28996/aa-our-handling-of-security-breach-fell-short" target="_blank" data-original-url="https://www.itpro.com/security/28996/aa-our-handling-of-security-breach-fell-short">AA</a>, <a href="https://www.itpro.com/security/29205/ico-fines-talktalk-100k-for-data-breach" target="_blank" data-original-url="https://www.itpro.com/security/29205/ico-fines-talktalk-100k-for-data-breach">TalkTalk</a>, <a href="https://www.itpro.com/security/28608/26000-customers-affected-by-debenhams-flowers-cyber-attack" target="_blank" data-original-url="https://www.itpro.com/security/28608/26000-customers-affected-by-debenhams-flowers-cyber-attack">Debenhams Flowers</a>, and most recently, <a href="https://www.itpro.com/data-breaches/29418/equifax-data-breach-cost-14-billion-so-far" target="_blank" data-original-url="https://www.itpro.com/data-breaches/29418/equifax-data-breach-cost-14-billion-so-far">Equifax</a>, which is thought to have affected at least 700,000 UK customers, alongside millions of US citizens.</p><p>The ICO pointed out that under <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know/page/0/1">the EU's forthcoming General Data Protection Regulation (GDPR)</a>, businesses will have an obligation to ensure the data they hold is not only secure, but is made more transparent to give customers a clear understanding about how it's used.</p><p>"By now organisations should be aware of the changes to data protection law next May," said Wood. "It's no longer acceptable to see the law as a box-ticking exercise. Organisations will need to be accountable, to their customers and to the regulator.</p><p>Of the 2,153 British citizens interviewed by the ICO, the majority were found to have more trust in public bodies to hold their personal data than private organisations. Just over 60% said they had confidence in the NHS or their local GP when it came to handling their data, while 53% said the same of the police. However, only 49% said they trusted the government and its various departments or organisations.</p><p>This is despite the increasing number of cyber attacks targeting the UK's public bodies over the past year, largely facilitated by outdated IT systems. A report by the <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">National Audit Office</a> last month said that the WannaCry attack on the NHS could have been prevented if it had deployed "basic IT security", such as upgrading machines running the outdated Windows XP operating system.</p><p>The UK also suffered a <a href="https://www.itpro.com/security/28920/was-iran-behind-parliaments-email-hack" target="_blank" data-original-url="https://www.itpro.com/security/28920/was-iran-behind-parliaments-email-hack">hack in June</a> which led to the breach of 90 email accounts belonging to MPs, while in August the <a href="https://www.itpro.com/security-breaches/29231/scottish-parliament-hit-with-brute-force-cyber-attack" target="_blank" data-original-url="https://www.itpro.com/security-breaches/29231/scottish-parliament-hit-with-brute-force-cyber-attack">Scottish parliament</a> described being hit by an almost identical "brute force" cyber attack that attempted to breach its systems.</p><p>"These are sobering facts that should act as a wake-up call to businesses," said Fraiser Kyne, CTO of Bromium. "The fact is our online economy relies on trust, which is a fragile thing. This lack of trust could result in people turning away from online services in the future, which could have a serious business impact.</p><p>"The only way we can start to rebuild trust is to stop these attacks from happening, and that is never going to happen if we just carry on doing the same thing we always have."</p><p>The ICO's Wood hopes to see improvements in these figures, saying: "It's time for organisations to start building the UK public's trust and confidence in how data is used and made available".</p><p><em>Picture: Bigstock</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/29897/ico-only-20-of-uk-citizens-trust-companies-with-their-data</link>
                                                                            <description>
                            <![CDATA[ British public still trusts most public bodies despite year of data breaches ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xuxC7ZGkZpbb983ZK9LCSD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UwLUtEKJ7Vowt3hjDreAsR-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Nov 2017 10:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UwLUtEKJ7Vowt3hjDreAsR-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Graphic showing a digital padlock overlaid above information that has been encrypted ]]></media:description>                                                            <media:text><![CDATA[Graphic showing a digital padlock overlaid above information that has been encrypted ]]></media:text>
                                <media:title type="plain"><![CDATA[Graphic showing a digital padlock overlaid above information that has been encrypted ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UwLUtEKJ7Vowt3hjDreAsR-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Only one-fifth of UK citizens trust companies to securely store their personal information, according to a survey published yesterday by the Information Commissioner's Office (ICO).</p><p>The <a href="https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2017/11/ico-survey-shows-most-uk-citizens-don-t-trust-organisations-with-their-data" target="_blank">report</a>, which was conducted by ComRes on behalf of the ICO, also found that only 10% of UK adults have a good understanding of how their personal data is used once it has been collected.</p><p>"As personal information becomes the currency by which society does business, organisations need to start making people's data protection rights a priority," said Steve Wood, deputy commissioner of the ICO. "Putting data protection at the centre of digital businesses strategies is the key to improving trust and digital growth."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-breaches/29418/equifax-data-breach-cost-14-billion-so-far" data-original-url="/data-breaches/29418/equifax-data-breach-cost-14-billion-so-far">Equifax data breach: Ex-CIO to serve four months in prison for insider trading</a> General Data Protection Regulation (GDPR)</p></div></div><p>The results come after a year of high profile data breaches. The breach on <a href="https://www.itpro.com/security/27288/canadian-pleads-guilty-to-yahoo-hack" target="_blank" data-original-url="https://www.itpro.com/security/27288/canadian-pleads-guilty-to-yahoo-hack">Yahoo's</a> systems, initially reported in September 2016, is now thought to have affected all three billion of its accounts, considered to be the largest breach in industry history.</p><p>The year since has been filled with a spate of hacks on corporate systems, including electronics company <a href="https://www.itpro.com/security/29345/two-million-customers-hit-by-cex-hack" target="_blank" data-original-url="https://www.itpro.com/security/29345/two-million-customers-hit-by-cex-hack">CEX</a>, <a href="https://www.itpro.com/security/28996/aa-our-handling-of-security-breach-fell-short" target="_blank" data-original-url="https://www.itpro.com/security/28996/aa-our-handling-of-security-breach-fell-short">AA</a>, <a href="https://www.itpro.com/security/29205/ico-fines-talktalk-100k-for-data-breach" target="_blank" data-original-url="https://www.itpro.com/security/29205/ico-fines-talktalk-100k-for-data-breach">TalkTalk</a>, <a href="https://www.itpro.com/security/28608/26000-customers-affected-by-debenhams-flowers-cyber-attack" target="_blank" data-original-url="https://www.itpro.com/security/28608/26000-customers-affected-by-debenhams-flowers-cyber-attack">Debenhams Flowers</a>, and most recently, <a href="https://www.itpro.com/data-breaches/29418/equifax-data-breach-cost-14-billion-so-far" target="_blank" data-original-url="https://www.itpro.com/data-breaches/29418/equifax-data-breach-cost-14-billion-so-far">Equifax</a>, which is thought to have affected at least 700,000 UK customers, alongside millions of US citizens.</p><p>The ICO pointed out that under <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know/page/0/1">the EU's forthcoming General Data Protection Regulation (GDPR)</a>, businesses will have an obligation to ensure the data they hold is not only secure, but is made more transparent to give customers a clear understanding about how it's used.</p><p>"By now organisations should be aware of the changes to data protection law next May," said Wood. "It's no longer acceptable to see the law as a box-ticking exercise. Organisations will need to be accountable, to their customers and to the regulator.</p><p>Of the 2,153 British citizens interviewed by the ICO, the majority were found to have more trust in public bodies to hold their personal data than private organisations. Just over 60% said they had confidence in the NHS or their local GP when it came to handling their data, while 53% said the same of the police. However, only 49% said they trusted the government and its various departments or organisations.</p><p>This is despite the increasing number of cyber attacks targeting the UK's public bodies over the past year, largely facilitated by outdated IT systems. A report by the <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">National Audit Office</a> last month said that the WannaCry attack on the NHS could have been prevented if it had deployed "basic IT security", such as upgrading machines running the outdated Windows XP operating system.</p><p>The UK also suffered a <a href="https://www.itpro.com/security/28920/was-iran-behind-parliaments-email-hack" target="_blank" data-original-url="https://www.itpro.com/security/28920/was-iran-behind-parliaments-email-hack">hack in June</a> which led to the breach of 90 email accounts belonging to MPs, while in August the <a href="https://www.itpro.com/security-breaches/29231/scottish-parliament-hit-with-brute-force-cyber-attack" target="_blank" data-original-url="https://www.itpro.com/security-breaches/29231/scottish-parliament-hit-with-brute-force-cyber-attack">Scottish parliament</a> described being hit by an almost identical "brute force" cyber attack that attempted to breach its systems.</p><p>"These are sobering facts that should act as a wake-up call to businesses," said Fraiser Kyne, CTO of Bromium. "The fact is our online economy relies on trust, which is a fragile thing. This lack of trust could result in people turning away from online services in the future, which could have a serious business impact.</p><p>"The only way we can start to rebuild trust is to stop these attacks from happening, and that is never going to happen if we just carry on doing the same thing we always have."</p><p>The ICO's Wood hopes to see improvements in these figures, saying: "It's time for organisations to start building the UK public's trust and confidence in how data is used and made available".</p><p><em>Picture: Bigstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NotPetya was nastier than WannaCry ransomware, say experts ]]></title>
                                                                                                <dc:content><![CDATA[ <p><a href="https://www.itpro.com/security/28940/notpetya-ransomware" target="_blank" data-original-url="https://www.itpro.com/security/28940/notpetya-ransomware">NotPetya</a> was 2017's most damaging ransomware attack, according to analysis from malware experts, beating notable campaigns such as Locky and WannaCry.</p><p>While <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">WannaCry</a> gained notoriety through sky-high infection rates and its impact on the NHS, which saw 81 of its bodies affected, researchers from security company Webroot said that the less widespread NotPetya outbreak was actually more dangerous, due to the fact that it was specifically engineered to disrupt and damage important systems.</p><p>The two malware strains are heavily based on the same exploit, a flaw in Windows Server Message Block system codenamed EternalBlue, which was part of a series of alleged NSA hacking tools dumped by the Shadow Brokers.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28940/notpetya-ransomware" data-original-url="/security/28940/notpetya-ransomware">NotPetya ransomware: White House joins UK in blaming Russia for NotPetya cyberattack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29808/bad-rabbit-ransomware-found-to-be-similar-to-notpetya" data-original-url="/security/29808/bad-rabbit-ransomware-found-to-be-similar-to-notpetya">'Bad Rabbit' ransomware found to be similar to NotPetya</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a></p></div></div><p>"This past year was unlike anything we've ever seen," said Webroot's vice president of engineering and cyber security, David Dufour. "Attacks such as NotPetya and WannaCry were hijacking computers worldwide and spreading new infections through tried-and-true methods.</p><p>"Although headlines have helped educate users on the devastating effects of ransomware, businesses and consumers need to follow basic cyber security standards to protect themselves."</p><p>A variant of the Petya ransomware from last year, NotPetya was first discovered in June 2017. Unlike most ransomware, NotPetya wasn't designed to encrypt files in order to extort money from victims. Instead, its goal was to wreak as much havoc on systems as possible, spreading within networks and permanently scrambling filesystems.</p><p>In fact, the researchers discovered that its resemblance to ransomware was nothing more than a cover to disguise its true purpose - even if victims paid, there was no way for NotPetya's creators to decrypt their files.</p><p>NotPetya, WannaCry and Locky were dubbed the nastiest malware campaigns of 2017 by Webroot, with other strains such as Cerber, CrySis and Nemucod also making the list.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/29863/notpetya-was-nastier-than-wannacry-ransomware-say-experts</link>
                                                                            <description>
                            <![CDATA[ The malware tops the list of 2017's worst ransomware outbreaks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8ZmZ9Yet9VJU9i3vDM4iwh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jpMiuQLHHoxgan6q6eJeDg-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Nov 2017 11:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jpMiuQLHHoxgan6q6eJeDg-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A padlock on a motherboard surrounded by keys]]></media:description>                                                            <media:text><![CDATA[A padlock on a motherboard surrounded by keys]]></media:text>
                                <media:title type="plain"><![CDATA[A padlock on a motherboard surrounded by keys]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jpMiuQLHHoxgan6q6eJeDg-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28940/notpetya-ransomware" target="_blank" data-original-url="https://www.itpro.com/security/28940/notpetya-ransomware">NotPetya</a> was 2017's most damaging ransomware attack, according to analysis from malware experts, beating notable campaigns such as Locky and WannaCry.</p><p>While <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">WannaCry</a> gained notoriety through sky-high infection rates and its impact on the NHS, which saw 81 of its bodies affected, researchers from security company Webroot said that the less widespread NotPetya outbreak was actually more dangerous, due to the fact that it was specifically engineered to disrupt and damage important systems.</p><p>The two malware strains are heavily based on the same exploit, a flaw in Windows Server Message Block system codenamed EternalBlue, which was part of a series of alleged NSA hacking tools dumped by the Shadow Brokers.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28940/notpetya-ransomware" data-original-url="/security/28940/notpetya-ransomware">NotPetya ransomware: White House joins UK in blaming Russia for NotPetya cyberattack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29808/bad-rabbit-ransomware-found-to-be-similar-to-notpetya" data-original-url="/security/29808/bad-rabbit-ransomware-found-to-be-similar-to-notpetya">'Bad Rabbit' ransomware found to be similar to NotPetya</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a></p></div></div><p>"This past year was unlike anything we've ever seen," said Webroot's vice president of engineering and cyber security, David Dufour. "Attacks such as NotPetya and WannaCry were hijacking computers worldwide and spreading new infections through tried-and-true methods.</p><p>"Although headlines have helped educate users on the devastating effects of ransomware, businesses and consumers need to follow basic cyber security standards to protect themselves."</p><p>A variant of the Petya ransomware from last year, NotPetya was first discovered in June 2017. Unlike most ransomware, NotPetya wasn't designed to encrypt files in order to extort money from victims. Instead, its goal was to wreak as much havoc on systems as possible, spreading within networks and permanently scrambling filesystems.</p><p>In fact, the researchers discovered that its resemblance to ransomware was nothing more than a cover to disguise its true purpose - even if victims paid, there was no way for NotPetya's creators to decrypt their files.</p><p>NotPetya, WannaCry and Locky were dubbed the nastiest malware campaigns of 2017 by Webroot, with other strains such as Cerber, CrySis and Nemucod also making the list.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What have we learnt from the NHS ransomware attack? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>In May 2017, a ransomware attack of unprecedented scale was unleashed on the world, with the NHS in England and, to a lesser extent, Scotland being hit the hardest of any organisation in the UK. Around 70,000 devices were infected, leading the attack to be known colloquially as the NHS hack.</p><p>How such an attack happened and how it was shut down offers valuable information to IT professionals on how to avoid falling victim to such an incident themselves in the future.</p><p><em><strong>Day Zero: 12 May 2017</strong></em></p><p>In the early morning of 12 May, reports started to emerge of the first computers infected by WannaCry. While some researchers, including those at <a href="https://nakedsecurity.sophos.com/2017/05/17/wannacry-the-ransomware-worm-that-didnt-arrive-on-a-phishing-hook">Sophos</a> concluded the first infections cropped up in Asia, it wasn't until Spanish telecoms giant Telfonica reported its systems had been compromised that it started to come to the attention of those with an interest in technology and security.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/innovation-at-work/29792/the-truth-about-hacking" data-original-url="/security/innovation-at-work/29792/the-truth-about-hacking">The truth about hacking</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/innovation-at-work/29793/the-white-hat-brigade" data-original-url="/security/innovation-at-work/29793/the-white-hat-brigade">The white hat brigade</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/innovation-at-work/29578/hope-for-the-best-plan-for-the-worst" data-original-url="/security/innovation-at-work/29578/hope-for-the-best-plan-for-the-worst">Hope for the best, plan for the worst</a></p></div></div><p>Within just a few hours the attack had snowballed, swallowing up an estimated 47 NHS Trusts in England and Scotland. Other high-profile victims included Deutsche Bahn, Renault, FedEx and the Russian Ministry of the interior.</p><p>The impact on the NHS was particularly potent, with approximately 70,000 devices including MRI scanners, blood storage refrigerators and operating theatre equipment, as well as computer terminals, being infected.</p><p>Some hospitals, including Barts in London, had to cancel routine planned operations, while others told patients only to come to A&E if it was a "life-threatening emergency".</p><p>In the end, it's thought that around 200,000 devices running Microsoft Windows were infected across 150 countries. </p><p><em><strong>Aftermath and investigation</strong></em></p><p>Somewhat miraculously, WannCry was stopped in its tracks the same day it started by a 22-year-old British cyber security researcher, Marcus Hutchins, who discovered a kill-switch' embedded in the ransomware's code. </p><p>This was a considerable stroke of luck for the world's IT systems, but for those that had already been affected, there was a lot of cleanup to be done, including disinfecting and restoring systems, patching (more on that in a minute) and so on.</p><p>For the NHS, this also included rescheduling all the routine appointments that had to be cancelled, leading to disruption that continued over the following few weeks.</p><p>It was also in the wake of the attack's subsidence that questions began to be raised about how such an infection was able to run rampant in the first place, given Microsoft had already issued a patch for the vulnerability exploited by WannaCry.</p><p>While the ransomware wasn't targeted, as the wide range of organisations affected demonstrates, it unwittingly took advantage of a critical weakness in many business systems "just patch" isn't always an option.</p><p>In large organisations in particular, there are often valid reasons systems can't be patched or updated. The most common among those is dependance on critical applications or hardware that aren't compatible with newer operating systems or some patches.</p><p>In this scenario, IT administrators face a choice: update the system, but potentially risk rendering inoperable a very expensive piece of hardware or the patient database software, or don't update it in order to keep the organisation running, but risk a crippling attack, as happened in May. Most take the potential risk of being hit by ransomware or another infection in the future over the certainty of breaking existing infrastructure.</p><p><em><strong>Mitigation is better than a cure</strong></em></p><p>Here's the obvious advice: patch your systems.</p><p>"WannaCry only hit organisation running older versions of Windows, so the obvious advice is to update those, which of course has a cost," says Bob Tarzey, analyst and director at Quocirca.</p><p>But, as stated above, that's not always possible.</p><p>"Another option is to better isolate older systems," Tarzey continues. </p><p>Jeff Pollard, principal analyst at Forrester, agrees: "We recommend a zero trust' approach to security strategy. Zero trust means trusting nothing people or systems until they prove they are trustworthy. Make sure environments are segmented so an automated worm [like WannaCry] can't infect every system."</p><p>This has the primary benefit of isolating the infection, which means not needing to throw the switches on all systems in order to stop it from spreading an approach that had to be taken by some NHS trusts, despite being disruptive in itself. </p><p>Pollard further advises organisations "understand the identity of users, systems, and workloads, and make sure that least privilege is in place". </p><p>There's also the question of having an educated and aware workforce. Although WannaCry wasn't spread via phishing emails, many ransomware infections and other malware attacks are, so drilling into users that they mustn't open links and attachments, particularly if they're unexpected, is vital. Other basic steps include having an enterprise-grade firewall in place, as well as business-focused anti-malware software running wherever it can (although, once again, in some embedded systems this might not be possible).</p><p>WannaCry was unusual in the way it attacked systems and the speed with which the infection spread, with the high-profile nature of the victims also being notable. What was surprising in May, however, may become par for the course in the future and this is an eventuality organisations must prepare for.</p><p>"Breaches and malware infections are inevitable. What matters is the ability to continue to operate, contain the issue, and bounce back from the problem and get back to business as usual," Pollard concludes.</p><p><a href="http://pubads.g.doubleclick.net/gampad/clk?id=4467444939&iu=/359/itpro.co.uk" target="_blank"><em>Make sure your organisation is resiliant enough to bounce back from an attack like this...</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/innovation-at-work/29794/what-have-we-learnt-from-the-nhs-ransomware-attack</link>
                                                                            <description>
                            <![CDATA[ The malware that made businesses everywhere WannaCry is an important case study for everyone. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dpTKJVnSbwaQmnQso7jA56</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KTN9NnWGeSEGPdLVXQXMV8-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Oct 2017 16:33:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                <cf:isSponsored>true</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KTN9NnWGeSEGPdLVXQXMV8-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KTN9NnWGeSEGPdLVXQXMV8-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In May 2017, a ransomware attack of unprecedented scale was unleashed on the world, with the NHS in England and, to a lesser extent, Scotland being hit the hardest of any organisation in the UK. Around 70,000 devices were infected, leading the attack to be known colloquially as the NHS hack.</p><p>How such an attack happened and how it was shut down offers valuable information to IT professionals on how to avoid falling victim to such an incident themselves in the future.</p><p><em><strong>Day Zero: 12 May 2017</strong></em></p><p>In the early morning of 12 May, reports started to emerge of the first computers infected by WannaCry. While some researchers, including those at <a href="https://nakedsecurity.sophos.com/2017/05/17/wannacry-the-ransomware-worm-that-didnt-arrive-on-a-phishing-hook">Sophos</a> concluded the first infections cropped up in Asia, it wasn't until Spanish telecoms giant Telfonica reported its systems had been compromised that it started to come to the attention of those with an interest in technology and security.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/innovation-at-work/29792/the-truth-about-hacking" data-original-url="/security/innovation-at-work/29792/the-truth-about-hacking">The truth about hacking</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/innovation-at-work/29793/the-white-hat-brigade" data-original-url="/security/innovation-at-work/29793/the-white-hat-brigade">The white hat brigade</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/innovation-at-work/29578/hope-for-the-best-plan-for-the-worst" data-original-url="/security/innovation-at-work/29578/hope-for-the-best-plan-for-the-worst">Hope for the best, plan for the worst</a></p></div></div><p>Within just a few hours the attack had snowballed, swallowing up an estimated 47 NHS Trusts in England and Scotland. Other high-profile victims included Deutsche Bahn, Renault, FedEx and the Russian Ministry of the interior.</p><p>The impact on the NHS was particularly potent, with approximately 70,000 devices including MRI scanners, blood storage refrigerators and operating theatre equipment, as well as computer terminals, being infected.</p><p>Some hospitals, including Barts in London, had to cancel routine planned operations, while others told patients only to come to A&E if it was a "life-threatening emergency".</p><p>In the end, it's thought that around 200,000 devices running Microsoft Windows were infected across 150 countries. </p><p><em><strong>Aftermath and investigation</strong></em></p><p>Somewhat miraculously, WannCry was stopped in its tracks the same day it started by a 22-year-old British cyber security researcher, Marcus Hutchins, who discovered a kill-switch' embedded in the ransomware's code. </p><p>This was a considerable stroke of luck for the world's IT systems, but for those that had already been affected, there was a lot of cleanup to be done, including disinfecting and restoring systems, patching (more on that in a minute) and so on.</p><p>For the NHS, this also included rescheduling all the routine appointments that had to be cancelled, leading to disruption that continued over the following few weeks.</p><p>It was also in the wake of the attack's subsidence that questions began to be raised about how such an infection was able to run rampant in the first place, given Microsoft had already issued a patch for the vulnerability exploited by WannaCry.</p><p>While the ransomware wasn't targeted, as the wide range of organisations affected demonstrates, it unwittingly took advantage of a critical weakness in many business systems "just patch" isn't always an option.</p><p>In large organisations in particular, there are often valid reasons systems can't be patched or updated. The most common among those is dependance on critical applications or hardware that aren't compatible with newer operating systems or some patches.</p><p>In this scenario, IT administrators face a choice: update the system, but potentially risk rendering inoperable a very expensive piece of hardware or the patient database software, or don't update it in order to keep the organisation running, but risk a crippling attack, as happened in May. Most take the potential risk of being hit by ransomware or another infection in the future over the certainty of breaking existing infrastructure.</p><p><em><strong>Mitigation is better than a cure</strong></em></p><p>Here's the obvious advice: patch your systems.</p><p>"WannaCry only hit organisation running older versions of Windows, so the obvious advice is to update those, which of course has a cost," says Bob Tarzey, analyst and director at Quocirca.</p><p>But, as stated above, that's not always possible.</p><p>"Another option is to better isolate older systems," Tarzey continues. </p><p>Jeff Pollard, principal analyst at Forrester, agrees: "We recommend a zero trust' approach to security strategy. Zero trust means trusting nothing people or systems until they prove they are trustworthy. Make sure environments are segmented so an automated worm [like WannaCry] can't infect every system."</p><p>This has the primary benefit of isolating the infection, which means not needing to throw the switches on all systems in order to stop it from spreading an approach that had to be taken by some NHS trusts, despite being disruptive in itself. </p><p>Pollard further advises organisations "understand the identity of users, systems, and workloads, and make sure that least privilege is in place". </p><p>There's also the question of having an educated and aware workforce. Although WannaCry wasn't spread via phishing emails, many ransomware infections and other malware attacks are, so drilling into users that they mustn't open links and attachments, particularly if they're unexpected, is vital. Other basic steps include having an enterprise-grade firewall in place, as well as business-focused anti-malware software running wherever it can (although, once again, in some embedded systems this might not be possible).</p><p>WannaCry was unusual in the way it attacked systems and the speed with which the infection spread, with the high-profile nature of the victims also being notable. What was surprising in May, however, may become par for the course in the future and this is an eventuality organisations must prepare for.</p><p>"Breaches and malware infections are inevitable. What matters is the ability to continue to operate, contain the issue, and bounce back from the problem and get back to business as usual," Pollard concludes.</p><p><a href="http://pubads.g.doubleclick.net/gampad/clk?id=4467444939&iu=/359/itpro.co.uk" target="_blank"><em>Make sure your organisation is resiliant enough to bounce back from an attack like this...</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Politicians’ ignorant reactions to the latest ransomware attacks make Jon wanna cry ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Dear Prime Minister,</p><p>A few weeks ago, many organisations, including the NHS, were hit with a nasty virus outbreak, which took advantage of a hole in the security of Windows. Microsoft had issued a patch for it, but the nature of these things is that many hadn't gotten around to applying the patch. Vast swathes of that huge organisation called the NHS were compromised, from local GPs to hospital departments. Some weren't patched due to sheer incompetence. Some due to scheduled time pressures. Some because you can't just slap a patch onto a MRI machine or piece of expensive technical test equipment that happens to run Windows as its control surface, and presume that it will continue to work just fine afterwards.</p><p>I understand why it happened. It doesn't stop me being hugely angry, and if I were in charge, I would be demanding a 12-week period in which every machine had its sysinfo file dumped into a secure cloud storage facility so it could be ascertained exactly what machines are in use, running which OS, with some or no patches.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/malware/29055/nhs-gets-21m-to-boost-cyber-defences-after-wannacry-ransomware" data-original-url="/malware/29055/nhs-gets-21m-to-boost-cyber-defences-after-wannacry-ransomware">NHS gets £21m to boost cyber defences after WannaCry ransomware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack" data-original-url="/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack">No-one is blameless when it comes to the NHS WannaCry hack</a></p></div></div><p>But what makes me angrier still is this. The NSA, or GCHQ, or some other trusted spook central, built these tools. It appears that they worked very well, and doubtless lots of useful information was gleaned from those machines that were targeted. It only went bad when it leaked to the great unwashed, and a person or persons decided to unleash it on the world.</p><p>Now, let's take that scenario and turn it on its head. Companies such as Apple, Google and Microsoft deliver, and want to continue to deliver, heavily encrypted software to the public. The government wants them to build a special private backdoor in there so that they can go snooping around. All of that is just fine, and I am convinced that some companies have been working hand in hand with said government departments in the past.</p><p>But what happens when that backdoor becomes public knowledge? Someone, somewhere will exploit it and we will have WannaCry all over again. It doesn't matter if the NSA finds a hole in Windows, or whether Google does a deal with the NSA. When there is a hole, there will be a period when it could be exploited for the benefit of the security services, and then it will leak and all hell breaks loose. Why this is so difficult to understand is frankly beyond me.</p><p>Dear Prime Minister, if you think that you can force backdoors into encrypted software, and that will not herald another WannaCry in the future, then I have no words for your gullibility. If you're being briefed and advised that an encryption backdoor would somehow be different, you're being briefed and advised by people who simply do not have a clue.</p><p>Without a doubt, the person inside GCHQ who wrote the first briefing paper knows what they're saying. But this will have gone through enough layers and transfers within the process of moving from them to you that, just like Chinese Whispers, the people who are briefing you have no clue.</p><p>WannaCry should be making you sit up and think "hold on, how could it be different in the future with some encryption backdoor?" The answer is simple it won't. No ifs, no buts.</p><p>We have to confront the reality that encryption is a necessary thing that will not go away. Geeks won't put up with a government-firewalled UK. We will drop down to transmitting email and "fancy a beer?" messages as a wave function in the noise floor of video images, and hand those around, just for the giggles of being able to do it. We will use YouTube as the vehicle of choice, because why not? If you don't know the wave function, you won't find the data. Why not put it out there in public space? It would be invisible.</p><p>Today, everyone has access to unlimited storage, unlimited CPU power and effectively unlimited bandwidth. The geeks already have a dozen methods of staying secure without resorting to anything so low-rent and obvious as a VPN tunnel. We can do it for fun because it would be an interesting geeky thing. If we can, the bad guys can, too.</p><p>Prime Minister, get yourself better briefed. Be part of the solution, not part of the problem. Give me 30 minutes of your time, and a decent cup of coffee. I dare you.</p><p><em>Main image credit: Reproduced with the permission of parliament</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/public-sector/29435/politicians-ignorant-reactions-to-the-latest-ransomware-attacks-make-jon-wanna</link>
                                                                            <description>
                            <![CDATA[ The government bungles its responses, while spy agencies let slip their tools ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">up5Lt2iUHYL689kT2tSf8U</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/k2y74cjz4idRT58QfnuVwd-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 30 Sep 2017 04:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jon Honeyball ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/k2y74cjz4idRT58QfnuVwd-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/k2y74cjz4idRT58QfnuVwd-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Dear Prime Minister,</p><p>A few weeks ago, many organisations, including the NHS, were hit with a nasty virus outbreak, which took advantage of a hole in the security of Windows. Microsoft had issued a patch for it, but the nature of these things is that many hadn't gotten around to applying the patch. Vast swathes of that huge organisation called the NHS were compromised, from local GPs to hospital departments. Some weren't patched due to sheer incompetence. Some due to scheduled time pressures. Some because you can't just slap a patch onto a MRI machine or piece of expensive technical test equipment that happens to run Windows as its control surface, and presume that it will continue to work just fine afterwards.</p><p>I understand why it happened. It doesn't stop me being hugely angry, and if I were in charge, I would be demanding a 12-week period in which every machine had its sysinfo file dumped into a secure cloud storage facility so it could be ascertained exactly what machines are in use, running which OS, with some or no patches.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/malware/29055/nhs-gets-21m-to-boost-cyber-defences-after-wannacry-ransomware" data-original-url="/malware/29055/nhs-gets-21m-to-boost-cyber-defences-after-wannacry-ransomware">NHS gets £21m to boost cyber defences after WannaCry ransomware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack" data-original-url="/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack">No-one is blameless when it comes to the NHS WannaCry hack</a></p></div></div><p>But what makes me angrier still is this. The NSA, or GCHQ, or some other trusted spook central, built these tools. It appears that they worked very well, and doubtless lots of useful information was gleaned from those machines that were targeted. It only went bad when it leaked to the great unwashed, and a person or persons decided to unleash it on the world.</p><p>Now, let's take that scenario and turn it on its head. Companies such as Apple, Google and Microsoft deliver, and want to continue to deliver, heavily encrypted software to the public. The government wants them to build a special private backdoor in there so that they can go snooping around. All of that is just fine, and I am convinced that some companies have been working hand in hand with said government departments in the past.</p><p>But what happens when that backdoor becomes public knowledge? Someone, somewhere will exploit it and we will have WannaCry all over again. It doesn't matter if the NSA finds a hole in Windows, or whether Google does a deal with the NSA. When there is a hole, there will be a period when it could be exploited for the benefit of the security services, and then it will leak and all hell breaks loose. Why this is so difficult to understand is frankly beyond me.</p><p>Dear Prime Minister, if you think that you can force backdoors into encrypted software, and that will not herald another WannaCry in the future, then I have no words for your gullibility. If you're being briefed and advised that an encryption backdoor would somehow be different, you're being briefed and advised by people who simply do not have a clue.</p><p>Without a doubt, the person inside GCHQ who wrote the first briefing paper knows what they're saying. But this will have gone through enough layers and transfers within the process of moving from them to you that, just like Chinese Whispers, the people who are briefing you have no clue.</p><p>WannaCry should be making you sit up and think "hold on, how could it be different in the future with some encryption backdoor?" The answer is simple it won't. No ifs, no buts.</p><p>We have to confront the reality that encryption is a necessary thing that will not go away. Geeks won't put up with a government-firewalled UK. We will drop down to transmitting email and "fancy a beer?" messages as a wave function in the noise floor of video images, and hand those around, just for the giggles of being able to do it. We will use YouTube as the vehicle of choice, because why not? If you don't know the wave function, you won't find the data. Why not put it out there in public space? It would be invisible.</p><p>Today, everyone has access to unlimited storage, unlimited CPU power and effectively unlimited bandwidth. The geeks already have a dozen methods of staying secure without resorting to anything so low-rent and obvious as a VPN tunnel. We can do it for fun because it would be an interesting geeky thing. If we can, the bad guys can, too.</p><p>Prime Minister, get yourself better briefed. Be part of the solution, not part of the problem. Give me 30 minutes of your time, and a decent cup of coffee. I dare you.</p><p><em>Main image credit: Reproduced with the permission of parliament</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NHS gets £21m to boost cyber defences after WannaCry ransomware ]]></title>
                                                                                                <dc:content><![CDATA[ <p>NHS hospitals will receive 21 million to upgrade their cyber security measures following <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">the WannaCry attacks</a> that wreaked havoc on NHS IT systems earlier this summer.</p><p>The Department for Health (DfH) announced the funding yesterday as the government accepted all the recommendations set out by the National Data Guardian review and the Care Quality Commission review into data security standards, carried out before the ransomware debacle.</p><p>Health minister Lord O'Shaughnessy said in a statement: "The NHS has a long history of safeguarding confidential data, but with the growing threat of cyber attacks including the WannaCry ransomware attack in May, this government has acted to protect information across the NHS.</p><p>"Only by leading cultural change and backing organisations to drive up security standards across the health and social care system can we build the resilience the NHS needs in the face of a global threat."</p><p>The 21 million will be spent on increasing cyber security measures of major trauma hospitals, with the government calling this "an immediate priority", as well as boosting NHS Digital's national monitoring and response capabilities.</p><p>It also prioritised finding a way <a href="https://www.itpro.com/public-sector/27740/nine-in-10-nhs-trusts-still-use-windows-xp" target="_blank" data-original-url="https://www.itpro.com/public-sector/27740/nine-in-10-nhs-trusts-still-use-windows-xp">to finally migrate NHS systems from Windows XP</a>, the Microsoft operating system that expired three years ago.</p><p>XP was at first identified as a prime attack vector for the WannaCry ransomware attacks in May due its lack of security updates, until Kaspersky Lab discovered that the in-support Windows 7 accounted for 97% of operating system among affected machines.</p><p>WannaCry locked NHS files, demanding a ransom be paid to unlock them again, causing chaos for 48 hospitals relying on this data for upcoming operations and appointments, many of which had to be cancelled.</p><p>The DfH also said NHS trusts will have to bring their policies in line with the National Data Guardian's recommendations - outlined in a report last year - that are designed to bolster healthcare data protection standards.</p><p>These include carrying out security training for staff, reviewing processes annually, and drawing up contingency plans for data security threats.</p><p>NHS Digital will support hospitals by carrying out on-site assessments and sharing best practice among UK trusts, as well as raising general awareness through broadcast ads and providing a hotline for dealing with cyber incidents.</p><p>The funding and stricter cyber security measures were part of a response to the CQC and National Data Guardian's reviews, which had warned of the likelihood of an impending cyber threat.</p><p>In the fallout after the WannaCry attacks, the Chartered Institute of IT <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">blamed the security breaches on a lack of investment and accountability for IT security measures within the NHS</a>.</p><p><em>Picture: Bigstock</em></p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28992/only-50-of-cios-improve-cyber-security-after-wannacry" data-original-url="/security/28992/only-50-of-cios-improve-cyber-security-after-wannacry">Only 50% of CIOs improve cyber security after WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="/security/28084/what-is-ransomware">What is ransomware?</a></p></div></div> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/malware/29055/nhs-gets-21m-to-boost-cyber-defences-after-wannacry-ransomware</link>
                                                                            <description>
                            <![CDATA[ Government funding comes hand-in-hand with stricter data security measures ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vt3F1ffBBZow4bxgyEJPth</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iZTvxTK6bAx3Z4BHJQpFge-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Jul 2017 11:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iZTvxTK6bAx3Z4BHJQpFge-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iZTvxTK6bAx3Z4BHJQpFge-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>NHS hospitals will receive 21 million to upgrade their cyber security measures following <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">the WannaCry attacks</a> that wreaked havoc on NHS IT systems earlier this summer.</p><p>The Department for Health (DfH) announced the funding yesterday as the government accepted all the recommendations set out by the National Data Guardian review and the Care Quality Commission review into data security standards, carried out before the ransomware debacle.</p><p>Health minister Lord O'Shaughnessy said in a statement: "The NHS has a long history of safeguarding confidential data, but with the growing threat of cyber attacks including the WannaCry ransomware attack in May, this government has acted to protect information across the NHS.</p><p>"Only by leading cultural change and backing organisations to drive up security standards across the health and social care system can we build the resilience the NHS needs in the face of a global threat."</p><p>The 21 million will be spent on increasing cyber security measures of major trauma hospitals, with the government calling this "an immediate priority", as well as boosting NHS Digital's national monitoring and response capabilities.</p><p>It also prioritised finding a way <a href="https://www.itpro.com/public-sector/27740/nine-in-10-nhs-trusts-still-use-windows-xp" target="_blank" data-original-url="https://www.itpro.com/public-sector/27740/nine-in-10-nhs-trusts-still-use-windows-xp">to finally migrate NHS systems from Windows XP</a>, the Microsoft operating system that expired three years ago.</p><p>XP was at first identified as a prime attack vector for the WannaCry ransomware attacks in May due its lack of security updates, until Kaspersky Lab discovered that the in-support Windows 7 accounted for 97% of operating system among affected machines.</p><p>WannaCry locked NHS files, demanding a ransom be paid to unlock them again, causing chaos for 48 hospitals relying on this data for upcoming operations and appointments, many of which had to be cancelled.</p><p>The DfH also said NHS trusts will have to bring their policies in line with the National Data Guardian's recommendations - outlined in a report last year - that are designed to bolster healthcare data protection standards.</p><p>These include carrying out security training for staff, reviewing processes annually, and drawing up contingency plans for data security threats.</p><p>NHS Digital will support hospitals by carrying out on-site assessments and sharing best practice among UK trusts, as well as raising general awareness through broadcast ads and providing a hotline for dealing with cyber incidents.</p><p>The funding and stricter cyber security measures were part of a response to the CQC and National Data Guardian's reviews, which had warned of the likelihood of an impending cyber threat.</p><p>In the fallout after the WannaCry attacks, the Chartered Institute of IT <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">blamed the security breaches on a lack of investment and accountability for IT security measures within the NHS</a>.</p><p><em>Picture: Bigstock</em></p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28992/only-50-of-cios-improve-cyber-security-after-wannacry" data-original-url="/security/28992/only-50-of-cios-improve-cyber-security-after-wannacry">Only 50% of CIOs improve cyber security after WannaCry</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="/security/28084/what-is-ransomware">What is ransomware?</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Only 50% of CIOs improve cyber security after WannaCry ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Research among CIOs and IT leaders has found that only half have implemented new security safeguards following the <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">WannaCry ransomware attack</a>, and only 15% plan changes in response to Petya.</p><p>This is despite 27% admitting their organisations have suffered ransomware attacks, according to IT governance non-profit ISACA's survey of 450 CIOs.</p><p>The vast majority (76%) said that their organisations were either highly or somewhat prepared to deal with the increased frequency on ransomware style attacks against their networks. However, only 50% of organisations have carried out staff training programmes to help them deal with the threat.</p><p>The research also found that less than a quarter of organisations are applying the latest security software patches within the first 24 hours of release. In some cases it can take over a month before the software is updated.</p><p>What is particularly concerning is that almost 15% of respondents said that their organisations won't take any further precautions following the <a href="https://www.itpro.com/security/28940/notpetya-ransomware" target="_blank" data-original-url="https://www.itpro.com/security/28940/notpetya-ransomware">Petya attack earlier this month</a>, despite the fact that the vast majority (83%) expect further ransomware attacks in the future. Only 6% said they would pay the ransom.</p><p>"Our poll shows that more than one in four organisations typically wait longer than a month to apply the latest software patches," said ISACA CEO Matt Loeb.</p><p>"Given the escalating volume and complexity of threats enterprises are facing, placing greater urgency on rapid, comprehensive patching is a critical component of protecting an organization from the business- and infrastructure-crippling consequences of an attack."</p><p>The WannaCry attack in May affected over 300,000 computer systems globally, and while the ransom was fairly modest at $300, it highlighted a widespread vulnerability to this style of attack that would be exploited again by Petya the following month.</p><p>However, following analysis of the Petya malware, experts now believe that its main purpose was to destroy data, rather than generate cash.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28940/notpetya-ransomware" data-original-url="/security/28940/notpetya-ransomware">NotPetya ransomware: White House joins UK in blaming Russia for NotPetya cyberattack</a></p></div></div><p>Ahead of the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">upcoming GDPR regulations</a>, companies will need to demonstrate they are doing all they can to protect the data they hold, including shoring up their security against malware.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/28992/only-50-of-cios-improve-cyber-security-after-wannacry</link>
                                                                            <description>
                            <![CDATA[ A quarter of CIOs have experienced ransomware attacks, survey finds ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3ZDpPQBdt55beDT4X7hU3W</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3D8Pua5HPRiNsqgkPu3EHT-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Jul 2017 10:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3D8Pua5HPRiNsqgkPu3EHT-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3D8Pua5HPRiNsqgkPu3EHT-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Research among CIOs and IT leaders has found that only half have implemented new security safeguards following the <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">WannaCry ransomware attack</a>, and only 15% plan changes in response to Petya.</p><p>This is despite 27% admitting their organisations have suffered ransomware attacks, according to IT governance non-profit ISACA's survey of 450 CIOs.</p><p>The vast majority (76%) said that their organisations were either highly or somewhat prepared to deal with the increased frequency on ransomware style attacks against their networks. However, only 50% of organisations have carried out staff training programmes to help them deal with the threat.</p><p>The research also found that less than a quarter of organisations are applying the latest security software patches within the first 24 hours of release. In some cases it can take over a month before the software is updated.</p><p>What is particularly concerning is that almost 15% of respondents said that their organisations won't take any further precautions following the <a href="https://www.itpro.com/security/28940/notpetya-ransomware" target="_blank" data-original-url="https://www.itpro.com/security/28940/notpetya-ransomware">Petya attack earlier this month</a>, despite the fact that the vast majority (83%) expect further ransomware attacks in the future. Only 6% said they would pay the ransom.</p><p>"Our poll shows that more than one in four organisations typically wait longer than a month to apply the latest software patches," said ISACA CEO Matt Loeb.</p><p>"Given the escalating volume and complexity of threats enterprises are facing, placing greater urgency on rapid, comprehensive patching is a critical component of protecting an organization from the business- and infrastructure-crippling consequences of an attack."</p><p>The WannaCry attack in May affected over 300,000 computer systems globally, and while the ransom was fairly modest at $300, it highlighted a widespread vulnerability to this style of attack that would be exploited again by Petya the following month.</p><p>However, following analysis of the Petya malware, experts now believe that its main purpose was to destroy data, rather than generate cash.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28940/notpetya-ransomware" data-original-url="/security/28940/notpetya-ransomware">NotPetya ransomware: White House joins UK in blaming Russia for NotPetya cyberattack</a></p></div></div><p>Ahead of the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">upcoming GDPR regulations</a>, companies will need to demonstrate they are doing all they can to protect the data they hold, including shoring up their security against malware.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware gangs shift focus to big businesses ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Ransomware gangs are starting to shift their focus from wide-ranging campaigns to targeted attacks on large companies and banks, according to new research.</p><p>Rather than simply attempting to spread their ransomware to as many users as possible, Kaspersky Lab's annual ransomware report has revealed that cyber criminals are making a concerted effort to target big businesses.</p><p>The security firm has identified eight separate criminal groups that are targeting financial institutions and major corporations, including the Mamba group. These gangs pick their targets carefully, identify business-critical resources and wait patiently while the malware spreads, with some samples proliferating through an organisation for up to six months.</p><p>"The reason for the trend is clear," the report said; "criminals consider targeted ransomware attacks against businesses potentially more profitable than mass attacks against private users."</p><p>This tactic evidently had some merit - Kaspersky observed cases where criminals were asking for $1,000 in Bitcoin to decrypt each individual endpoint, as well as cases where the total ransomware demands for a company's infection came to over half a million dollars.</p><p>Another emerging trend the report highlighted was cyber criminals stealing each others' work. Despite the creators of the Petya ransomware building in anti-theft measures designed to prevent other hackers using it for their own ends without permission, a new strain was discovered to be doing just that.</p><p>The PetrWrap ransomware, which was discovered in March of this year, uses the Petya encryption algorithm to lock its victims files - but uses its own decryption keys, meaning that the gang behind it don't need the original authors to decrypt the files after the ransom is paid. Researchers are taking this as evidence that increased competition in the ransomware space is causing some criminals to start fighting amongst themselves for market share.</p><p>"Theoretically, this is good, because the more time criminal actors spend on fighting and fooling each other, the less organised and effective their malicious campaigns will be," the report said.</p><p>"The worrying thing here is the fact that PetrWrap is used in targeted attacks. This is not the first case of targeted ransomware attacks and unfortunately is unlikely to be the last."</p><p>Ilia Kolochenko, CEO of web security firm High-Tech Bridge, agreed that cyber crime gangs are starting to wise up and pursue more profitable targets. "The report is a clear indicator that the ransomware market is becoming more professional and mature," he said. "Actors are working on various niche specialisations to avoid direct competition and maximise their profit."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="/security/28084/what-is-ransomware">What is ransomware?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28117/how-to-protect-against-cyber-threats-2" data-original-url="/security/28117/how-to-protect-against-cyber-threats-2">How to protect against cyber threats</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/27568/how-to-beat-ransomware-1" data-original-url="/security/27568/how-to-beat-ransomware-1">How to beat ransomware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a></p></div></div> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/28930/ransomware-gangs-shift-focus-to-big-businesses</link>
                                                                            <description>
                            <![CDATA[ Research shows that criminals are going after more banks and corporations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uUY3e6LKV4vHA4wqnMvxvC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KtKFCSr53Qf22hEveofYDb-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 27 Jun 2017 10:34:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KtKFCSr53Qf22hEveofYDb-1920-80.jpg">
                                                            <media:credit><![CDATA[Bigstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Graphic of a user engaging in a ransomware exchange]]></media:description>                                                            <media:text><![CDATA[Graphic of a user engaging in a ransomware exchange]]></media:text>
                                <media:title type="plain"><![CDATA[Graphic of a user engaging in a ransomware exchange]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KtKFCSr53Qf22hEveofYDb-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Ransomware gangs are starting to shift their focus from wide-ranging campaigns to targeted attacks on large companies and banks, according to new research.</p><p>Rather than simply attempting to spread their ransomware to as many users as possible, Kaspersky Lab's annual ransomware report has revealed that cyber criminals are making a concerted effort to target big businesses.</p><p>The security firm has identified eight separate criminal groups that are targeting financial institutions and major corporations, including the Mamba group. These gangs pick their targets carefully, identify business-critical resources and wait patiently while the malware spreads, with some samples proliferating through an organisation for up to six months.</p><p>"The reason for the trend is clear," the report said; "criminals consider targeted ransomware attacks against businesses potentially more profitable than mass attacks against private users."</p><p>This tactic evidently had some merit - Kaspersky observed cases where criminals were asking for $1,000 in Bitcoin to decrypt each individual endpoint, as well as cases where the total ransomware demands for a company's infection came to over half a million dollars.</p><p>Another emerging trend the report highlighted was cyber criminals stealing each others' work. Despite the creators of the Petya ransomware building in anti-theft measures designed to prevent other hackers using it for their own ends without permission, a new strain was discovered to be doing just that.</p><p>The PetrWrap ransomware, which was discovered in March of this year, uses the Petya encryption algorithm to lock its victims files - but uses its own decryption keys, meaning that the gang behind it don't need the original authors to decrypt the files after the ransom is paid. Researchers are taking this as evidence that increased competition in the ransomware space is causing some criminals to start fighting amongst themselves for market share.</p><p>"Theoretically, this is good, because the more time criminal actors spend on fighting and fooling each other, the less organised and effective their malicious campaigns will be," the report said.</p><p>"The worrying thing here is the fact that PetrWrap is used in targeted attacks. This is not the first case of targeted ransomware attacks and unfortunately is unlikely to be the last."</p><p>Ilia Kolochenko, CEO of web security firm High-Tech Bridge, agreed that cyber crime gangs are starting to wise up and pursue more profitable targets. "The report is a clear indicator that the ransomware market is becoming more professional and mature," he said. "Actors are working on various niche specialisations to avoid direct competition and maximise their profit."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="/security/28084/what-is-ransomware">What is ransomware?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28117/how-to-protect-against-cyber-threats-2" data-original-url="/security/28117/how-to-protect-against-cyber-threats-2">How to protect against cyber threats</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/27568/how-to-beat-ransomware-1" data-original-url="/security/27568/how-to-beat-ransomware-1">How to beat ransomware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Over a million corporate file-shares are exposed to attacks ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Vast amounts of companies are leaving their corporate networks exposed, experts have revealed, risking the possibility of a second <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">WannaCry</a>-style malware outbreak.</p><p>The <a href="https://www.rapid7.com/info/national-exposure-index" target="_blank"><em>National Exposure Index</em></a> report, compiled by security firm Rapid7, revealed that internal file-sharing systems were being exposed by over one million unsecured endpoints, potentially exposing business-critical systems and data to malicious external hackers.</p><p>The vast majority of the vulnerable endpoints observed by Rapid7 - more than 800,000, in fact - were Windows systems that used the server message block (SMB) protocol. A vulnerability in this protocol is one of the main reasons behind the swift and prolific spread of the WannaCry ransomware earlier this year, which used the flaw to propagate across the internet.</p><p>Running a scan for SMB port 455 revealed over 5.5 million responsive nodes, and Rapid7 warned that blocking these ports from being publicly-addressable could go a long way towards stopping the spread of similar attacks to WannaCry in the future.</p><p>However, the report did note some areas of improvement. Belgium, last year's most exposed country, did not even make the top 50 in 2017's report after 250,000 publicly-exposed servers had their access culled.</p><p>Similarly, there has been a 33% drop in the amount of telnet exposure. This was partly judged to be a result of ISPs blocking access to port 23 in response to the <a href="https://www.itpro.com/hacking/27449/was-mirai-malware-behind-dyn-ddos-attack" target="_blank" data-original-url="https://www.itpro.com/hacking/27449/was-mirai-malware-behind-dyn-ddos-attack">Mirai botnet</a> - although Rapid7 also noted that it was likely due in part to nodes being knocked offline by Mirai itself.</p><p>Zimbabwe, Hong Kong and Samoa topped this year's list of the most exposed countries. The UK came in at number 37, despite having the world's fourth-largest allocation of IPv4 addresses.</p><p>"The UK's position at #37 on the National Exposure Index is reflective of the fact that while it is generally in line with similar nations' exposure, the UK has an uncomfortably high exposure rate of qualified SMB," Rapid7 said as part of the report. "IT administrators and internet service providers in the UK would do well to review what is both allowed and expected to be available on the internet."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/27449/was-mirai-malware-behind-dyn-ddos-attack" data-original-url="/hacking/27449/was-mirai-malware-behind-dyn-ddos-attack">Was Mirai malware behind Dyn DDoS attack?</a></p></div></div> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/28853/over-a-million-corporate-file-shares-are-exposed-to-attacks</link>
                                                                            <description>
                            <![CDATA[ Vulnerable SMB ports could lead to a second WannaCry outbreak, say experts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aGQ73aYxgDxFEptyU5DcLn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SRcyAeMpkrrL5kawjGXtuX-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 15 Jun 2017 10:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SRcyAeMpkrrL5kawjGXtuX-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Click here for malware]]></media:description>                                                            <media:text><![CDATA[Click here for malware]]></media:text>
                                <media:title type="plain"><![CDATA[Click here for malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SRcyAeMpkrrL5kawjGXtuX-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Vast amounts of companies are leaving their corporate networks exposed, experts have revealed, risking the possibility of a second <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">WannaCry</a>-style malware outbreak.</p><p>The <a href="https://www.rapid7.com/info/national-exposure-index" target="_blank"><em>National Exposure Index</em></a> report, compiled by security firm Rapid7, revealed that internal file-sharing systems were being exposed by over one million unsecured endpoints, potentially exposing business-critical systems and data to malicious external hackers.</p><p>The vast majority of the vulnerable endpoints observed by Rapid7 - more than 800,000, in fact - were Windows systems that used the server message block (SMB) protocol. A vulnerability in this protocol is one of the main reasons behind the swift and prolific spread of the WannaCry ransomware earlier this year, which used the flaw to propagate across the internet.</p><p>Running a scan for SMB port 455 revealed over 5.5 million responsive nodes, and Rapid7 warned that blocking these ports from being publicly-addressable could go a long way towards stopping the spread of similar attacks to WannaCry in the future.</p><p>However, the report did note some areas of improvement. Belgium, last year's most exposed country, did not even make the top 50 in 2017's report after 250,000 publicly-exposed servers had their access culled.</p><p>Similarly, there has been a 33% drop in the amount of telnet exposure. This was partly judged to be a result of ISPs blocking access to port 23 in response to the <a href="https://www.itpro.com/hacking/27449/was-mirai-malware-behind-dyn-ddos-attack" target="_blank" data-original-url="https://www.itpro.com/hacking/27449/was-mirai-malware-behind-dyn-ddos-attack">Mirai botnet</a> - although Rapid7 also noted that it was likely due in part to nodes being knocked offline by Mirai itself.</p><p>Zimbabwe, Hong Kong and Samoa topped this year's list of the most exposed countries. The UK came in at number 37, despite having the world's fourth-largest allocation of IPv4 addresses.</p><p>"The UK's position at #37 on the National Exposure Index is reflective of the fact that while it is generally in line with similar nations' exposure, the UK has an uncomfortably high exposure rate of qualified SMB," Rapid7 said as part of the report. "IT administrators and internet service providers in the UK would do well to review what is both allowed and expected to be available on the internet."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/27449/was-mirai-malware-behind-dyn-ddos-attack" data-original-url="/hacking/27449/was-mirai-malware-behind-dyn-ddos-attack">Was Mirai malware behind Dyn DDoS attack?</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft patches expired Windows XP again as fresh exploits emerge ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Microsoft has taken the extraordinary step of pushing out an emergency patch for its outdated Windows XP operating system for the second time in a matter of weeks, this time following the release of a host of NSA exploits.</p><p>As part of June's Patch Tuesday, the company took the unusual step of issuing more fixes for XP, which went out of support in 2014, in anticipation of more WannaCry-style attacks against the platform - it patched XP's<a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">WannaCry</a>vulnerability some weeks ago.</p><p>The<a href="https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched" target="_blank" data-original-url="https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched">Shadow Brokers group</a>released the three exploits that prompted Microsoft to patch its ancient OS. The flaws areconsidered to pose an "elevated risk of cyber attacks by government organisations", Microsoft warned in a<a href="https://blogs.windows.com/windowsexperience/2017/06/13/microsoft-releases-additional-updates-protect-potential-nation-state-activity/#KZDK4VL1cef4ty2Q.97" target="_blank">blog post</a>.</p><p>"Due to the elevated risk for destructive cyber attacks at this time, we made the decision to take this action because applying these updates provides further protection against potential attacks with characteristics similar to WannaCrypt," said Adrienne Hall, general manager for Microsoft's cyber defence operations centre.</p><p>Microsoft received criticism for its response to the WannaCry ransomware attack, as Windows XP, which still retains almost 6% of the<a href="https://www.netmarketshare.com/operating-system-market-share.aspx?qprid=10&qpcustomd=0" target="_blank">operating system market share</a>, was patched much later than Windows 7, 8.1 and 10. Microsoft has said that the latest security patch will be available to all users, including those running outdated operating systems.</p><p>The<a href="https://blogs.technet.microsoft.com/msrc/2017/04/14/protecting-customers-and-evaluating-risk" target="_blank">three exploits</a>, known as "EnglishmanDentist", "EsteemAudit" and "ExplodingCan" are all classed as remote execution vulnerabilities, allowing hackers to gain access with full user rights. EsteemAudit (CVE-2017-0176) exploits a flaw in the Windows remote code execution protocol, while EnglishmanDentist allows the execution of malware through Windows OLE.</p><p>This update is in addition to the regular Patch Tuesday, and while those with automatic updates enabled on Windows 7 or later will receive the patches immediately, those on older systems such as Windows Vista and XP will need to manually update their systems through the Microsoft Download Centre.</p><p>"Our decision today to release these security updates for platforms not in extended support should not be viewed as a departure from our standard servicing policies," said Eric Doerr, general manager at Microsoft's security response centre. "Based on an assessment of the current threat landscape by our security engineers, we made the decision to make updates available more broadly."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/public-sector/27740/nine-in-10-nhs-trusts-still-use-windows-xp" data-original-url="/public-sector/27740/nine-in-10-nhs-trusts-still-use-windows-xp">Nine in 10 NHS trusts still use Windows XP</a></p></div></div> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/28846/microsoft-patches-expired-windows-xp-again-as-fresh-exploits-emerge</link>
                                                                            <description>
                            <![CDATA[ Redmond updates old OS to respond to Shadow Brokers' latest leak ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oXAr24WVAKmoX3JdPCYqF9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3YoMwxhP43RzimoKKfgtjM-1920-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 14 Jun 2017 11:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Microsoft]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/3YoMwxhP43RzimoKKfgtjM-1920-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3YoMwxhP43RzimoKKfgtjM-1920-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has taken the extraordinary step of pushing out an emergency patch for its outdated Windows XP operating system for the second time in a matter of weeks, this time following the release of a host of NSA exploits.</p><p>As part of June's Patch Tuesday, the company took the unusual step of issuing more fixes for XP, which went out of support in 2014, in anticipation of more WannaCry-style attacks against the platform - it patched XP's<a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">WannaCry</a>vulnerability some weeks ago.</p><p>The<a href="https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched" target="_blank" data-original-url="https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched">Shadow Brokers group</a>released the three exploits that prompted Microsoft to patch its ancient OS. The flaws areconsidered to pose an "elevated risk of cyber attacks by government organisations", Microsoft warned in a<a href="https://blogs.windows.com/windowsexperience/2017/06/13/microsoft-releases-additional-updates-protect-potential-nation-state-activity/#KZDK4VL1cef4ty2Q.97" target="_blank">blog post</a>.</p><p>"Due to the elevated risk for destructive cyber attacks at this time, we made the decision to take this action because applying these updates provides further protection against potential attacks with characteristics similar to WannaCrypt," said Adrienne Hall, general manager for Microsoft's cyber defence operations centre.</p><p>Microsoft received criticism for its response to the WannaCry ransomware attack, as Windows XP, which still retains almost 6% of the<a href="https://www.netmarketshare.com/operating-system-market-share.aspx?qprid=10&qpcustomd=0" target="_blank">operating system market share</a>, was patched much later than Windows 7, 8.1 and 10. Microsoft has said that the latest security patch will be available to all users, including those running outdated operating systems.</p><p>The<a href="https://blogs.technet.microsoft.com/msrc/2017/04/14/protecting-customers-and-evaluating-risk" target="_blank">three exploits</a>, known as "EnglishmanDentist", "EsteemAudit" and "ExplodingCan" are all classed as remote execution vulnerabilities, allowing hackers to gain access with full user rights. EsteemAudit (CVE-2017-0176) exploits a flaw in the Windows remote code execution protocol, while EnglishmanDentist allows the execution of malware through Windows OLE.</p><p>This update is in addition to the regular Patch Tuesday, and while those with automatic updates enabled on Windows 7 or later will receive the patches immediately, those on older systems such as Windows Vista and XP will need to manually update their systems through the Microsoft Download Centre.</p><p>"Our decision today to release these security updates for platforms not in extended support should not be viewed as a departure from our standard servicing policies," said Eric Doerr, general manager at Microsoft's security response centre. "Based on an assessment of the current threat landscape by our security engineers, we made the decision to make updates available more broadly."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/public-sector/27740/nine-in-10-nhs-trusts-still-use-windows-xp" data-original-url="/public-sector/27740/nine-in-10-nhs-trusts-still-use-windows-xp">Nine in 10 NHS trusts still use Windows XP</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Emergency patches cost companies almost $100,000 every month ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Issuing emergency patches for newly-discovered security threats is costing businesses almost $100,000 per month and taking up more than 60 man-hours, new research has revealed.</p><p>According to an independent survey of 500 CISOs from companies in the UK, US and Germany with more than 1,000 employees, crisis patch management the practise of scrambling to apply fixes for vulnerabilities such as the SMB flaw behind <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">last month's WannaCry ransomware attack</a> is causing businesses a major headache.</p><p>The survey, which was commissioned by security firm Bromium, found that on average, businesses were having to issue a whopping five emergency patches every month. That equates to more than one a week and with each patch taking an average of more than 12 man-hours to apply, it's easy to see why more than half of CISOs say that issuing them is a 'major disruption' for their teams.</p><p>More importantly, these last-minute patch jobs are putting a huge hole in companies' bottom line. Over 50% of businesses have had to either pay overtime to IT staff or bring a third-party response unit to deal with emergency patches and security issues. According to the study, this costs companies almost $20,000 per patch.</p><p>"We can see with the recent WannaCry outbreak where an emergency patch was issued to stop the spread of the worm that enterprises are still having to paper over the cracks in order to secure their systems," said Simon Crosby, Bromium's co-founder and CTO.</p><p>"The fact that these patches have to be issued right away can be hugely disruptive to security teams, and often very costly to businesses, but not doing so can have dire consequences. WannaCry certainly isn't an isolated case and as ransomware and polymorphic malware become increasingly sophisticated and difficult to defend against, we are going to see many more emergency patches become a crisis although, sadly, they will often be too late."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack" data-original-url="/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack">No-one is blameless when it comes to the NHS WannaCry hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="/security/28084/what-is-ransomware">What is ransomware?</a></p></div></div> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/28756/emergency-patches-cost-companies-almost-100000-every-month</link>
                                                                            <description>
                            <![CDATA[ Applying last-minute security fixes is hitting companies hard, says report ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qauykbRYS3YZKXfmaJTuF3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dvzx3wHZq4QnNT7Lr7cNvH-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 01 Jun 2017 09:03:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dvzx3wHZq4QnNT7Lr7cNvH-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dvzx3wHZq4QnNT7Lr7cNvH-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Issuing emergency patches for newly-discovered security threats is costing businesses almost $100,000 per month and taking up more than 60 man-hours, new research has revealed.</p><p>According to an independent survey of 500 CISOs from companies in the UK, US and Germany with more than 1,000 employees, crisis patch management the practise of scrambling to apply fixes for vulnerabilities such as the SMB flaw behind <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">last month's WannaCry ransomware attack</a> is causing businesses a major headache.</p><p>The survey, which was commissioned by security firm Bromium, found that on average, businesses were having to issue a whopping five emergency patches every month. That equates to more than one a week and with each patch taking an average of more than 12 man-hours to apply, it's easy to see why more than half of CISOs say that issuing them is a 'major disruption' for their teams.</p><p>More importantly, these last-minute patch jobs are putting a huge hole in companies' bottom line. Over 50% of businesses have had to either pay overtime to IT staff or bring a third-party response unit to deal with emergency patches and security issues. According to the study, this costs companies almost $20,000 per patch.</p><p>"We can see with the recent WannaCry outbreak where an emergency patch was issued to stop the spread of the worm that enterprises are still having to paper over the cracks in order to secure their systems," said Simon Crosby, Bromium's co-founder and CTO.</p><p>"The fact that these patches have to be issued right away can be hugely disruptive to security teams, and often very costly to businesses, but not doing so can have dire consequences. WannaCry certainly isn't an isolated case and as ransomware and polymorphic malware become increasingly sophisticated and difficult to defend against, we are going to see many more emergency patches become a crisis although, sadly, they will often be too late."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack" data-original-url="/security/28658/no-one-is-blameless-when-it-comes-to-the-nhs-wannacry-hack">No-one is blameless when it comes to the NHS WannaCry hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="/security/28084/what-is-ransomware">What is ransomware?</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ShadowBrokers offers CISOs zero-day details for $21,000 ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The criminal group responsible <a href="https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched" target="_blank" data-original-url="https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched">for leaking NSA hacking tools over the past nine months</a> is marketing regular exploit kit notices at CISOs.</p><p>Shadow Brokers plans to charge security professionals and white hat hackers a $21,000 subscription fee for access to dumps of new zero-day exploits, giving them the opportunity to develop countermeasures to hacking tools that could otherwise prove catastrophic if released into the wild.</p><p>The person or group responsible for originally stealing and leaking NSA hacking tools has previously released data dumps that included two tools <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">that were eventually used in the WannaCry ransomware attack</a>, which affected over 200,000 computer systems in 150 countries.</p><p>While Shadow Brokers said it will make new hacking arsenals available for those that pay its fee, so anyone - including hackers - can sign up, its messaging appeared to target organisations trying to prepare themselves against the potential damage of a WannaCry 2.0.</p><p>"Question to be asking. 'Can my organisation afford not to be first to get access to the Shadow Brokers dumps'", Shadow Brokers' post reads.</p><p>The post makes it clear that this is a "high-roller risk", and gives little indication of what will be included in the data dump, although previous posts boast that it has 75% of the NSA toolkits, covering everything from browser exploits to compromised network data from Russian and Chinese nuclear missile programs.</p><p>Yet whether security professionals should pay to access the tools raises a moral question, as they are in effect directly funding Shadow Brokers' activities. What's more, this dump could be completely worthless.</p><p>Graham Cluley, security analyst and blogger, told<em>IT Pro</em>that he believes there are too many unknowns around the data dump: "It's something I would feel uncomfortable with. If you pay malicious hackers for exploits you are creating a demand, and - in effect - encouraging them to continue to supply by doing more illegal hacking."</p><p>"Without knowing details of the exploits its hard to say how quickly they could be patched," added Cluley. "Certainly big technology companies have moved quickly in the past to resolve zero-day threats."</p><p>"But the proof of the pudding is in the eating. And this is a pudding that costs $21,000."</p><p>Pieter Antz, malware intelligence analyst at Malwarebytes, argues that simply knowing what the exploits are is not always enough to understand the damage they could cause.</p><p>"The problem is that knowing the exploits does not help white-hats, unless it is very obvious how they can be used in malware," said Antz, in an email to <em>IT Pro</em>. "It could help the firms that created the exploitable software however, and enable them to close the gaps and issue patches for them."</p><p>However, Antz warns that companies still run the risk of being stung by false promises: "It's the same as paying to have your files unlocked from ransomware - there's no guarantee the files will be released and you're helping to perpetuate the behaviour."</p><p>There isn't long to decide. In a<a href="https://steemit.com/shadowbrokers/@theshadowbrokers/theshadowbrokers-monthly-dump-service-june-2017" target="_blank">cryptographically signed message</a>, published on Tuesday, the group said that if a user sends 100 ZEC (one ZEC is currently worth $237), a virtually untraceable cryptocurrency known as Zcash, to a specified z_address, they would receive an email with a link and a password when the dump is made available in June.</p><p>In broken English, the post added: "Act quickly is good chance Zcash price increasing over time."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched" data-original-url="/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched">Shadow Brokers: Microsoft Windows flaws were already patched</a></p></div></div> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/28751/shadowbrokers-offers-cisos-zero-day-details-for-21000</link>
                                                                            <description>
                            <![CDATA[ The NSA-leaking group goads companies into forking out for early access to exploits ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wr2zp257oYjeWA44dHX88X</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KAE3tGXMEcRfgDxLP9qFH4-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 31 May 2017 11:19:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KAE3tGXMEcRfgDxLP9qFH4-1920-80.jpg">
                                                            <media:credit><![CDATA[Bigstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Bright blue code appearing on screen to denote hacking]]></media:description>                                                            <media:text><![CDATA[Bright blue code appearing on screen to denote hacking]]></media:text>
                                <media:title type="plain"><![CDATA[Bright blue code appearing on screen to denote hacking]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KAE3tGXMEcRfgDxLP9qFH4-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The criminal group responsible <a href="https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched" target="_blank" data-original-url="https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched">for leaking NSA hacking tools over the past nine months</a> is marketing regular exploit kit notices at CISOs.</p><p>Shadow Brokers plans to charge security professionals and white hat hackers a $21,000 subscription fee for access to dumps of new zero-day exploits, giving them the opportunity to develop countermeasures to hacking tools that could otherwise prove catastrophic if released into the wild.</p><p>The person or group responsible for originally stealing and leaking NSA hacking tools has previously released data dumps that included two tools <a href="https://www.itpro.com/security/28648/nhs-ransomware-attack" target="_blank" data-original-url="https://www.itpro.com/security/28648/nhs-ransomware-attack">that were eventually used in the WannaCry ransomware attack</a>, which affected over 200,000 computer systems in 150 countries.</p><p>While Shadow Brokers said it will make new hacking arsenals available for those that pay its fee, so anyone - including hackers - can sign up, its messaging appeared to target organisations trying to prepare themselves against the potential damage of a WannaCry 2.0.</p><p>"Question to be asking. 'Can my organisation afford not to be first to get access to the Shadow Brokers dumps'", Shadow Brokers' post reads.</p><p>The post makes it clear that this is a "high-roller risk", and gives little indication of what will be included in the data dump, although previous posts boast that it has 75% of the NSA toolkits, covering everything from browser exploits to compromised network data from Russian and Chinese nuclear missile programs.</p><p>Yet whether security professionals should pay to access the tools raises a moral question, as they are in effect directly funding Shadow Brokers' activities. What's more, this dump could be completely worthless.</p><p>Graham Cluley, security analyst and blogger, told<em>IT Pro</em>that he believes there are too many unknowns around the data dump: "It's something I would feel uncomfortable with. If you pay malicious hackers for exploits you are creating a demand, and - in effect - encouraging them to continue to supply by doing more illegal hacking."</p><p>"Without knowing details of the exploits its hard to say how quickly they could be patched," added Cluley. "Certainly big technology companies have moved quickly in the past to resolve zero-day threats."</p><p>"But the proof of the pudding is in the eating. And this is a pudding that costs $21,000."</p><p>Pieter Antz, malware intelligence analyst at Malwarebytes, argues that simply knowing what the exploits are is not always enough to understand the damage they could cause.</p><p>"The problem is that knowing the exploits does not help white-hats, unless it is very obvious how they can be used in malware," said Antz, in an email to <em>IT Pro</em>. "It could help the firms that created the exploitable software however, and enable them to close the gaps and issue patches for them."</p><p>However, Antz warns that companies still run the risk of being stung by false promises: "It's the same as paying to have your files unlocked from ransomware - there's no guarantee the files will be released and you're helping to perpetuate the behaviour."</p><p>There isn't long to decide. In a<a href="https://steemit.com/shadowbrokers/@theshadowbrokers/theshadowbrokers-monthly-dump-service-june-2017" target="_blank">cryptographically signed message</a>, published on Tuesday, the group said that if a user sends 100 ZEC (one ZEC is currently worth $237), a virtually untraceable cryptocurrency known as Zcash, to a specified z_address, they would receive an email with a link and a password when the dump is made available in June.</p><p>In broken English, the post added: "Act quickly is good chance Zcash price increasing over time."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28648/nhs-ransomware-attack" data-original-url="/security/28648/nhs-ransomware-attack">NHS ransomware: UK government says it's North Korea's fault WannaCry happened</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched" data-original-url="/security/28498/shadow-brokers-microsoft-windows-flaws-were-already-patched">Shadow Brokers: Microsoft Windows flaws were already patched</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>